SharePoint and OneDrive external sharing: reduce exposure without stopping collaboration

SharePoint and OneDrive sharing is governed by tenant, site, link, group, and Microsoft Entra settings. A safer model uses intentional collaboration sites, authenticated guests where practical, restrictive defaults, ownership, and recurring access review.

Executive summary

What you need to know

SharePoint and OneDrive sharing is governed by tenant, site, link, group, and Microsoft Entra settings. A safer model uses intentional collaboration sites, authenticated guests where practical, restrictive defaults, ownership, and recurring access review.

Potentially affected

Microsoft 365 organizations whose users share files, folders, sites, Teams-connected content, or OneDrive data with customers, vendors, partners, or other external people.

DSE recommendation

Inventory existing sharing, confirm tenant and site limits, classify collaboration use cases, tighten default links, assign site owners, and test guest access and revocation before changing broad settings.

External sharing is controlled in layers

SharePoint and OneDrive can support secure collaboration with people outside an organization, but no single switch describes the effective result. Sharing is influenced by the organization-level SharePoint setting, each site’s setting, default link choices, site and group membership, Microsoft Entra external collaboration restrictions, and the permissions on the content itself.

Microsoft applies the most restrictive combination of the organization and site sharing levels. A site cannot be made more permissive than the tenant allows. Teams and Microsoft 365 Groups add another layer because guest membership and connected SharePoint sites must both permit the intended access. Allowed or blocked domain settings in Entra can also affect sharing.

Separate collaboration by purpose

Use dedicated sites for distinct external projects instead of exposing a broad internal site and trying to isolate individual folders. Give every site at least two accountable owners, identify its information sensitivity, and document which partner organizations are expected. For OneDrive, use purpose-specific folders rather than sharing an entire personal work area.

  • Prefer authenticated, named guests for ongoing or sensitive collaboration.
  • Use Anyone links only when the business case accepts that the link can be forwarded and the tenant permits them.
  • Set conservative default link types and permissions; users can make an intentional broader choice only when policy allows it.
  • Consider domain restrictions, expiration, reauthentication, sensitivity labels, and access reviews where the required subscriptions support them.
  • Train owners to distinguish site membership, folder permissions, and sharing links.

Inspect before tightening

Abruptly reducing a tenant or site sharing level can break legitimate customer workflows without removing every copy already synchronized or downloaded. Inventory active sites, owners, guests, Anyone links, externally shared content, Teams-connected sites, and stale collaborations. Identify anonymous links and broad guest groups that need remediation. Communicate the target model and provide a supported replacement path before revoking access.

Test representative scenarios with an external account: invitation, redemption, multifactor requirements, browser access, synchronization, link forwarding, expiration, and removal. Microsoft notes that synchronized content can remain on an external user’s computer after permissions are removed. Access revocation controls future service access; it cannot recall every downloaded copy.

Review the surrounding controls

Entra B2B settings determine who may invite guests and can restrict collaboration domains. Conditional Access can add requirements, but it needs suitable licensing and careful guest testing. Purview sensitivity, data-loss-prevention, retention, and audit capabilities vary by subscription and configuration. Do not claim that a label or sharing setting protects data unless its actual enforcement behavior has been verified.

Establish recurring review for site ownership, guests, links, dormant sites, and high-risk content. Remove access when a project ends, but preserve records according to legal and business retention requirements. The objective is not to eliminate external sharing; it is to make the audience, owner, duration, and information boundary visible and reviewable.

Primary reference

Review the official source

Microsoft Learn: External sharing in SharePoint and OneDrive · Verified July 19, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE