External Sharing in SharePoint and OneDrive: Auditing What’s Already Public
External sharing is one of SharePoint and OneDrive’s most useful features. It lets employees collaborate with customers, suppliers, contractors and professional advisers without sending uncontrolled email attachments.
It can also leave sensitive documents accessible long after the original project, contract or conversation has ended.
A file may still be available through an old anonymous link. A former supplier may remain listed as a guest. A folder shared from an employee’s OneDrive may contain documents added months after the original invitation. A site owner may have approved access for an entire external domain when only one person required it.
The biggest challenge is visibility.
Many organisations review their current sharing settings but never investigate what employees have already shared. Tightening the tenant configuration today does not, by itself, provide a complete inventory of historical links, direct permissions and guest access.
This guide explains how to audit external sharing across SharePoint and OneDrive, identify content that is effectively public, remove unnecessary access and establish a safer long-term sharing process.
What Does “Public” Mean in SharePoint and OneDrive?
Not every externally shared file is public in the same way.
Microsoft 365 provides several sharing methods, each with a different risk level.
Anyone Links
An Anyone link can be used by any person who receives it. The recipient generally does not need to sign in or prove their identity.
The link can also be:
- Forwarded to another person
- Copied into a personal message
- Stored in a document
- Posted in a chat
- Accidentally published online
Microsoft allows administrators to control whether Anyone links are permitted, how long they can remain valid and whether they can allow editing or only viewing.
An Anyone link is the closest SharePoint and OneDrive come to making a document publicly accessible. It does not necessarily mean the file is indexed by a search engine, but anyone possessing the link may be able to open it.
Specific People Links
A Specific people link is intended for named recipients.
Recipients may need to sign in or verify their identity using a one-time passcode. This provides more accountability than an anonymous link because access is connected to the intended person. Microsoft supports one-time-passcode verification when a recipient is not already present in the organisation’s directory.
Existing Guest Access
A person may already exist in Microsoft Entra ID as a guest and have access through:
- Direct file or folder permissions
- SharePoint site membership
- Microsoft 365 group membership
- Teams membership
- A previous sharing invitation
Removing one sharing link does not necessarily remove every other permission held by that guest.
Organisation Links
A People in your organisation link is not external. It can normally be used by authenticated members of your Microsoft 365 organisation.
However, it can still expose information more broadly internally than the document owner intended.
External Sharing vs. Guest Access
External sharing is the wider process that allows content to be shared outside the organisation.
Guest access is one method through which an external person can receive access.
A guest may be added to:
- A SharePoint site
- A Microsoft Team
- A Microsoft 365 group
- A particular file or folder
An Anyone link, by contrast, may provide access without creating a guest identity.
This distinction matters during an audit because reviewing the Microsoft Entra guest list will not reveal every anonymous sharing link.
Likewise, reviewing link activity alone will not identify every guest who has direct site membership.
Why Old Sharing Links Become a Security Risk
A sharing request may have been legitimate when it was created.
The risk grows when:
- The project ends.
- The supplier relationship changes.
- The recipient leaves their organisation.
- The document gains additional content.
- The link is forwarded.
- The original owner changes role.
- Nobody remembers why access exists.
- The link has no expiration date.
A folder link can be particularly risky because new files placed in that folder may inherit or remain subject to the existing sharing access.
The person who created the link may no longer understand the full contents now available through it.
Changing the Tenant Setting Is Not a Complete Audit
The SharePoint admin centre lets administrators choose the maximum external-sharing level permitted for SharePoint and OneDrive.
Typical levels include:
- Anyone
- New and existing guests
- Existing guests only
- Only people in the organisation
Individual sites can be configured more restrictively than the organisation-wide setting, but not more permissively. Site settings can be reviewed and changed from Active sites in the SharePoint admin centre.
However, an organisation-wide configuration review answers only:
What sharing can users create now?
It does not fully answer:
What files, folders and sites have already been shared, with whom, and through which type of access?
That requires reporting, audit searches and site-owner review.
Step 1: Review the Organisation-Wide Sharing Configuration
In the SharePoint admin centre:
- Open Policies.
- Select Sharing.
- Review the SharePoint sharing level.
- Review the OneDrive sharing level.
- Confirm whether Anyone links are enabled.
- Check link expiration requirements.
- Check default link type and permission.
- Review domain restrictions.
- Review guest expiration settings.
- Record the current configuration.
Microsoft allows separate external-sharing controls for SharePoint and OneDrive, although OneDrive cannot be configured more permissively than SharePoint.
Questions to Ask
- Does the business genuinely require anonymous links?
- Should anonymous links allow editing?
- How long should Anyone links remain valid?
- Should the default link be “Specific people”?
- Are users allowed to invite new external guests?
- Are external domains restricted?
- Are OneDrive settings too permissive for personal working areas?
- Are sensitive sites configured more restrictively?
The default link type matters because most employees use whichever option appears first.
Step 2: Review Every SharePoint Site’s Sharing Level
The tenant setting defines the maximum allowed sharing level, but individual sites may be more restrictive.
In SharePoint admin centre → Active sites, review:
- External-sharing level
- Site owner
- Site sensitivity label
- Last activity
- Storage usage
- Team or group connection
- Business purpose
Microsoft allows administrators to select a site and open More sharing settings to change its external-sharing configuration.
Prioritise sites containing:
- Finance documents
- HR records
- Customer information
- Legal material
- Intellectual property
- Board information
- Security documentation
- Personal data
A public marketing-resource site may need different sharing controls from a payroll or legal site.
Step 3: Run Site-Level Sharing Reports
SharePoint and OneDrive provide sharing reports that can show how content has been shared.
For a SharePoint site, a site owner or administrator can generate a report containing information about files, folders and access. OneDrive users can also run a sharing report from their OneDrive settings. Microsoft documents the OneDrive process under OneDrive settings → More settings → Run sharing report.
A sharing report can help identify:
- Externally shared files
- Externally shared folders
- Sharing link types
- Named recipients
- Guest access
- Direct permissions
The report should be treated as a working inventory, not simply exported and archived.
For each entry, determine:
- Is the content still required?
- Is the external recipient still involved?
- Is the sharing method appropriate?
- Could access be narrower?
- Should the file be moved to a controlled site?
- Does the link require an expiration date?
- Is anonymous access really necessary?
Step 4: Use Microsoft Purview Audit
Microsoft Purview Audit records many sharing-related events for SharePoint and OneDrive.
Microsoft’s sharing-audit guidance explains how administrators can search and export audit records to identify resources shared with external users. The exported data can be filtered using fields such as the target user type, including guest recipients.
Useful sharing events can include actions involving:
- Anonymous links
- Secure links
- Sharing invitations
- External-user invitations
- Access requests
- Sharing changes
- Link creation
- Link removal
- Permission changes
The exact event names and availability can change, so use Microsoft’s current audit-activity reference when building searches.
A Practical Audit Search
In Microsoft Purview:
- Open Audit.
- Create a new search.
- Select a suitable date range.
- Select SharePoint and OneDrive sharing activities.
- Add users or sites when narrowing the investigation.
- Run the search.
- Export the results.
- Filter for external, guest or anonymous activity.
- Investigate the underlying content.
Useful questions include:
- Who created the link?
- When was it created?
- Which file or folder was shared?
- Was the recipient a guest?
- Was an anonymous link created?
- Was the permission later changed?
- Was the link subsequently removed?
- Did the guest access the file?
Audit Logs Show Activity, Not Always the Complete Current State
Audit logs are historical event records.
They are useful for showing that a sharing action happened, but they may not be the easiest way to determine the exact permissions that exist today.
For example:
- A link may have been created and later removed.
- A guest may have received access through a group.
- The event may fall outside the retained audit period.
- The file may have moved.
- The current site permissions may differ from the original event.
Use audit data alongside:
- Current site permissions
- Sharing reports
- Microsoft Entra guest records
- Group membership
- Link reports
- Site-owner confirmation
No single report necessarily provides the entire picture.
Step 5: Use Data Access Governance Reports
SharePoint Data Access Governance reports can help identify oversharing patterns across sites.
Microsoft’s sharing-links activity report identifies sites where users created the most new sharing links during the previous 28 days. Microsoft recommends first running a site-permissions report to understand the existing sharing baseline, then using link-activity reporting to monitor continuing behaviour.
These reports can help prioritise:
- Sites generating many Anyone links
- Sites with large numbers of external users
- Sites with broad permissions
- Sites showing rapid increases in sharing
- Sites containing sensitive information
Some Data Access Governance capabilities require SharePoint Advanced Management or qualifying Microsoft 365 licensing. Confirm current licensing before designing an audit process around them.
Activity Reports Are Not a Permanent Historical Inventory
The sharing-links activity report focuses on recent activity, currently using a 28-day window.
That makes it useful for monitoring new behaviour, but it does not replace a complete review of links created months or years earlier.
Use it to answer:
Where is new sharing happening most frequently?
Use site reports and current-permission reviews to answer:
What access exists now?
Use Purview Audit to answer:
Who performed the sharing action and when?
Step 6: Review Anonymous “Anyone” Links First
Anonymous links should receive the highest priority because the user opening the link may not be required to authenticate.
For each Anyone link, determine:
- Who created it?
- Why was anonymous access required?
- Does it allow view or edit?
- Does it have an expiration date?
- Is the file still relevant?
- Could the link have been forwarded?
- Does the content contain sensitive data?
- Can it be replaced with a Specific people link?
Remove anonymous links where the business case no longer exists.
Where anonymous sharing is still necessary:
- Allow view only where possible.
- Set a short expiration.
- Avoid sharing folders containing changing content.
- Keep sensitive information out of the shared location.
- Record a business owner.
- Review the link before renewing it.
Configure Anyone-Link Expiration
Microsoft lets administrators require Anyone links to expire after a maximum number of days. Administrators can also restrict anonymous links to view-only access.
A suitable period depends on the use case.
Examples might include:
- Temporary file collection: 7 days
- Tender documents: 14 days
- Customer download: 30 days
- Public marketing asset: reviewed separately
Expiration reduces long-term exposure but does not undo data already downloaded by a recipient.
Step 7: Review External Guests
In Microsoft Entra ID, review external identities for:
- Last sign-in
- Created date
- Sponsoring employee
- Group membership
- Application assignments
- Administrative roles
- Current employer
- Business purpose
Look for guests associated with:
- Completed projects
- Former suppliers
- Previous professional advisers
- Departed partner employees
- Old customer engagements
- Temporary contractors
Removing an Entra guest may affect access across Teams, SharePoint and other applications, so confirm ownership before deletion.
However, leaving inactive guests indefinitely increases the chance that access persists unnoticed.
Guest Expiration Is Helpful but Not Sufficient
SharePoint supports expiration of external-user access.
This can require site owners to review or extend access after a configured period. It is a useful control, but it should not replace regular access reviews.
A guest may still have access through:
- Several sites
- A Microsoft 365 group
- Teams
- Direct permissions
- Another application
The review should confirm the person’s continuing need, not simply renew everyone automatically.
Step 8: Review Site and Group Membership
External access may be inherited through:
- SharePoint Members
- SharePoint Visitors
- Microsoft 365 groups
- Teams membership
- Security groups
- Nested permissions
- Private channels
- Shared channels
A file’s sharing dialog may not immediately explain every route through which the person can access the content.
Review:
- Site owners
- Site members
- Site visitors
- Connected group membership
- Teams guests
- Private and shared-channel membership
- Direct item permissions
Pay special attention to external users who are site owners or have edit rights.
Step 9: Audit OneDrive Separately
OneDrive is designed primarily as an individual user’s working area.
That makes external sharing harder to govern because access is distributed across many personal storage locations.
Common risks include:
- Customer documents stored permanently in one employee’s OneDrive
- Folders shared externally without expiration
- Business records owned by an employee who later leaves
- Anonymous links created for convenience
- Personal project folders becoming unofficial collaboration sites
For each high-risk user or department:
- Run the OneDrive sharing report.
- Review anonymous and external access.
- Transfer long-term shared content to SharePoint.
- Remove obsolete links.
- Confirm the business owner.
- Review the user’s departure or role-change risk.
Long-running external collaboration should normally take place in a managed SharePoint site rather than an individual employee’s OneDrive.
Step 10: Review Sensitive Content That Is Externally Shared
Not every shared file carries the same risk.
Prioritise content containing:
- Customer records
- Employee information
- Payment details
- Identification documents
- Contracts
- Confidential pricing
- Intellectual property
- Security information
- Legal advice
- Credentials or recovery information
Microsoft Purview sensitivity labels and Data Loss Prevention policies can help identify and protect sensitive content, but these controls need to be configured deliberately.
A useful policy may:
- Warn users before external sharing.
- Block anonymous sharing of labelled documents.
- Require encryption.
- Restrict access to named recipients.
- Generate an alert for high-risk sharing.
- Prevent sharing from unmanaged devices.
Do Not Assume a Sensitivity Label Automatically Removes Existing Links
Applying a label or changing a site policy does not necessarily perform every historical cleanup action you need.
After strengthening a label or DLP policy:
- Test existing links.
- Review prior permissions.
- Remove inappropriate anonymous links.
- Confirm whether external users retain access.
- Re-run relevant reports.
Policy improvement and historical remediation are separate workstreams.
Step 11: Delegate Reviews to Site Owners
Central IT may know that a site has 45 external users, but it may not know which of them are still required.
Site owners are generally better positioned to identify:
- Active customers
- Current suppliers
- Completed projects
- Obsolete documents
- Legitimate anonymous links
- Users who should be removed
Microsoft supports site-access reviews that let administrators delegate review of overshared SharePoint sites to their owners. Microsoft notes that these reviews are available for SharePoint sites but not currently for OneDrive accounts.
Provide site owners with a simple decision framework:
- Keep
- Restrict
- Replace with named access
- Expire
- Remove
- Escalate for investigation
Do not simply ask owners to “review sharing” without explaining what a good decision looks like.
Step 12: Remove Access Safely
Before deleting access, confirm whether it supports an active business process.
Then remediate using the narrowest appropriate action:
- Delete the Anyone link.
- Replace it with a Specific people link.
- Remove an external user’s direct permission.
- Remove the guest from the site.
- Remove the guest from the Microsoft 365 group.
- Remove them from Teams.
- Reduce edit access to view.
- Add an expiration date.
- Move the file into a controlled collaboration site.
- Remove the obsolete content entirely.
Record important changes so the organisation can explain:
- What access was removed
- Who approved the change
- Why it was removed
- Whether the recipient was notified
- Whether a replacement sharing method was provided
Be Careful With Business-Critical Integrations
Some external access supports:
- Customer portals
- Automated document exchange
- Supplier submissions
- Legal case collaboration
- Board portals
- External workflows
Do not remove access based only on the age of the link.
Confirm:
- Current owner
- Business process
- Service dependency
- Recipient organisation
- Alternative access method
- Data-retention requirement
When the access cannot be justified or no owner can be found, it should be treated as a risk requiring escalation.
Recommended Sharing Configuration
A sensible small or medium-sized business baseline may include:
- Specific people as the default link type
- View as the default permission
- Anyone links disabled unless genuinely required
- Short expiration for permitted Anyone links
- Guest expiration enabled
- Sensitive sites restricted to existing guests or internal users
- Domain restrictions for controlled partner scenarios
- DLP or sensitivity-label controls for confidential content
- Regular audit and site-owner review
The exact configuration should reflect how the business collaborates.
A design agency distributing public campaign assets may legitimately require anonymous links. A law firm or payroll provider may have very little reason to permit them.
Restrict Sharing by Domain Where Appropriate
SharePoint and OneDrive can restrict external sharing to approved or blocked domains.
An allow list can be useful where collaboration occurs with a small, stable group of partner organisations.
For example:
approved-customer.com
legal-partner.co.uk
primary-supplier.net
However, domain restrictions are not a complete identity check.
They do not protect against:
- A compromised partner account
- Incorrectly approved domains
- Personal accounts
- Anonymous links
- A legitimate external user sharing data onward
Use them as one layer within a broader access process.
Create an External-Sharing Request Process
For sensitive or long-running collaboration, collect:
- Business sponsor
- External organisation
- Named recipients
- Data being shared
- Site or folder
- Required permission level
- Start date
- Expiration date
- Sensitivity classification
- Reason anonymous access is needed, if applicable
- Review date
This makes external sharing deliberate rather than accidental.
Routine low-risk sharing can remain user-driven, while higher-risk scenarios receive additional approval.
Monitor New Sharing Continuously
A one-time audit will slowly become outdated.
A practical monitoring cycle could include:
Weekly
- High-risk DLP alerts
- New anonymous links on sensitive sites
- Unusual volumes of sharing
- External sharing by privileged users
Monthly
- Audit-log sharing activity
- Recently created guests
- Top sites creating external links
- Anonymous-link creation
- External-sharing incidents
Quarterly
- Site-owner access reviews
- Approved external domains
- Guest accounts
- OneDrive sharing for high-risk departments
- Exceptions and allow lists
- Sensitive-site configuration
Annually
- Full external-sharing policy review
- SharePoint and OneDrive configuration
- Licensing and reporting capability
- Staff guidance
- Incident-response testing
What to Do When Sensitive Data Was Publicly Shared
Treat the situation as a potential data-security incident.
1. Remove or Disable the Link
Stop continuing access as quickly as practical.
2. Preserve Evidence
Record:
- URL
- File or folder
- Owner
- Link type
- Creation date
- Permissions
- Known recipients
- Audit events
- Access activity
3. Determine the Exposure
Investigate:
- Whether the link was used
- Who accessed it
- Whether the content was downloaded
- Whether the link was forwarded
- How long it was active
- What information the content contained
4. Notify Security, Privacy or Legal Teams
Sensitive personal, financial or regulated information may require formal assessment and notification.
5. Review the Account
Check whether the sharing resulted from:
- User error
- Account compromise
- Malicious insider activity
- An unsafe business process
- Misconfigured default settings
6. Search for Similar Exposure
The same person or site may have created additional links using the same unsafe process.
Common External-Sharing Mistakes
Reviewing Guests but Ignoring Anonymous Links
Anyone links may not create guest identities.
Tightening Settings Without Auditing Existing Access
The organisation feels safer while historical exposure remains.
Allowing Anonymous Edit Links
Anyone possessing the link may be able to alter or delete content.
Using OneDrive as a Permanent External Portal
Ownership and continuity depend too heavily on one employee.
Never Expiring Access
Temporary collaboration becomes permanent.
Assuming the Link Was Sent to Only One Person
The original recipient may forward an anonymous link.
Removing the Link but Leaving Direct Permissions
The external user may still have another access route.
Asking IT to Judge Every Business Relationship
Site and data owners should participate in access decisions.
Exporting Reports Without Acting on Them
An audit provides value only when findings are remediated.
External-Sharing Audit Checklist
Tenant Settings
- Review SharePoint sharing level.
- Review OneDrive sharing level.
- Set the default link type.
- Set the default permission.
- Configure Anyone-link expiration.
- Review guest expiration.
- Review domain restrictions.
SharePoint Sites
- Inventory active sites.
- Identify externally enabled sites.
- Review sensitive and high-activity sites first.
- Confirm site owners.
- Run sharing reports.
- Review site and group membership.
- Remove obsolete external access.
OneDrive
- Review high-risk departments.
- Run user sharing reports.
- Identify anonymous links.
- Move long-term collaboration to SharePoint.
- Review OneDrive data during employee offboarding.
Audit and Monitoring
- Search Purview sharing events.
- Export and filter audit data.
- Review recent link activity.
- Use Data Access Governance reports where licensed.
- Alert on sensitive external sharing.
- Repeat reviews regularly.
Remediation
- Remove unnecessary Anyone links.
- Replace anonymous links with named access.
- Reduce edit access to view.
- Expire temporary access.
- Remove inactive guests.
- Transfer ownership.
- Document significant changes.
Final Thoughts
External sharing is not inherently unsafe. Unreviewed external sharing is.
SharePoint and OneDrive can support secure collaboration when organisations understand:
- Which sites allow external access
- Which files and folders have been shared
- Which links are anonymous
- Which guests still have permissions
- Who owns each external relationship
- When access should expire
Begin with the organisation-wide sharing configuration, but do not stop there.
Run site and OneDrive sharing reports. Search the Microsoft Purview audit log. Review Data Access Governance information where available. Inspect guests, groups and direct permissions. Ask site owners to confirm the business need.
Most importantly, remove access that no longer has a clear owner, purpose or expiry.
A link created for a two-week project should not remain active two years later simply because nobody remembered it existed.
Unsure What Your Business Has Already Shared Externally?
Hamilton Group can help you audit and secure SharePoint and OneDrive external sharing.
Our experts can help you:
- Review tenant and site-level sharing settings
- Identify anonymous Anyone links
- Audit external guests and permissions
- Run SharePoint and OneDrive sharing reports
- Search Microsoft Purview audit activity
- Review high-risk and overshared sites
- Configure link and guest expiration
- Implement sensitivity labels and DLP controls
- Build site-owner access reviews
- Remove obsolete sharing safely
- Create a practical external-collaboration process
Visit hgmssp.com, call Hamilton Group on 0330 043 0069, or book a meeting with one of our experts to find out what information is already accessible outside your organisation.