Skip to main content

External Sharing in SharePoint and OneDrive: Auditing What’s Already Public

Media External Sharing in SharePoint and OneDrive Auditing What’s Already Public

 

External sharing is one of SharePoint and OneDrive’s most useful features. It lets employees collaborate with customers, suppliers, contractors and professional advisers without sending uncontrolled email attachments.

It can also leave sensitive documents accessible long after the original project, contract or conversation has ended.

A file may still be available through an old anonymous link. A former supplier may remain listed as a guest. A folder shared from an employee’s OneDrive may contain documents added months after the original invitation. A site owner may have approved access for an entire external domain when only one person required it.

The biggest challenge is visibility.

Many organisations review their current sharing settings but never investigate what employees have already shared. Tightening the tenant configuration today does not, by itself, provide a complete inventory of historical links, direct permissions and guest access.

This guide explains how to audit external sharing across SharePoint and OneDrive, identify content that is effectively public, remove unnecessary access and establish a safer long-term sharing process.

What Does “Public” Mean in SharePoint and OneDrive?

Not every externally shared file is public in the same way.

Microsoft 365 provides several sharing methods, each with a different risk level.

Anyone Links

An Anyone link can be used by any person who receives it. The recipient generally does not need to sign in or prove their identity.

The link can also be:

  • Forwarded to another person
  • Copied into a personal message
  • Stored in a document
  • Posted in a chat
  • Accidentally published online

Microsoft allows administrators to control whether Anyone links are permitted, how long they can remain valid and whether they can allow editing or only viewing. 

An Anyone link is the closest SharePoint and OneDrive come to making a document publicly accessible. It does not necessarily mean the file is indexed by a search engine, but anyone possessing the link may be able to open it.

Specific People Links

A Specific people link is intended for named recipients.

Recipients may need to sign in or verify their identity using a one-time passcode. This provides more accountability than an anonymous link because access is connected to the intended person. Microsoft supports one-time-passcode verification when a recipient is not already present in the organisation’s directory. 

Existing Guest Access

A person may already exist in Microsoft Entra ID as a guest and have access through:

  • Direct file or folder permissions
  • SharePoint site membership
  • Microsoft 365 group membership
  • Teams membership
  • A previous sharing invitation

Removing one sharing link does not necessarily remove every other permission held by that guest.

Organisation Links

A People in your organisation link is not external. It can normally be used by authenticated members of your Microsoft 365 organisation.

However, it can still expose information more broadly internally than the document owner intended.

External Sharing vs. Guest Access

External sharing is the wider process that allows content to be shared outside the organisation.

Guest access is one method through which an external person can receive access.

A guest may be added to:

  • A SharePoint site
  • A Microsoft Team
  • A Microsoft 365 group
  • A particular file or folder

An Anyone link, by contrast, may provide access without creating a guest identity.

This distinction matters during an audit because reviewing the Microsoft Entra guest list will not reveal every anonymous sharing link.

Likewise, reviewing link activity alone will not identify every guest who has direct site membership.

Why Old Sharing Links Become a Security Risk

A sharing request may have been legitimate when it was created.

The risk grows when:

  • The project ends.
  • The supplier relationship changes.
  • The recipient leaves their organisation.
  • The document gains additional content.
  • The link is forwarded.
  • The original owner changes role.
  • Nobody remembers why access exists.
  • The link has no expiration date.

A folder link can be particularly risky because new files placed in that folder may inherit or remain subject to the existing sharing access.

The person who created the link may no longer understand the full contents now available through it.

Changing the Tenant Setting Is Not a Complete Audit

The SharePoint admin centre lets administrators choose the maximum external-sharing level permitted for SharePoint and OneDrive.

Typical levels include:

  • Anyone
  • New and existing guests
  • Existing guests only
  • Only people in the organisation

Individual sites can be configured more restrictively than the organisation-wide setting, but not more permissively. Site settings can be reviewed and changed from Active sites in the SharePoint admin centre. 

However, an organisation-wide configuration review answers only:

What sharing can users create now?

It does not fully answer:

What files, folders and sites have already been shared, with whom, and through which type of access?

That requires reporting, audit searches and site-owner review.

Step 1: Review the Organisation-Wide Sharing Configuration

In the SharePoint admin centre:

  1. Open Policies.
  2. Select Sharing.
  3. Review the SharePoint sharing level.
  4. Review the OneDrive sharing level.
  5. Confirm whether Anyone links are enabled.
  6. Check link expiration requirements.
  7. Check default link type and permission.
  8. Review domain restrictions.
  9. Review guest expiration settings.
  10. Record the current configuration.

Microsoft allows separate external-sharing controls for SharePoint and OneDrive, although OneDrive cannot be configured more permissively than SharePoint. 

Questions to Ask

  • Does the business genuinely require anonymous links?
  • Should anonymous links allow editing?
  • How long should Anyone links remain valid?
  • Should the default link be “Specific people”?
  • Are users allowed to invite new external guests?
  • Are external domains restricted?
  • Are OneDrive settings too permissive for personal working areas?
  • Are sensitive sites configured more restrictively?

The default link type matters because most employees use whichever option appears first.

Step 2: Review Every SharePoint Site’s Sharing Level

The tenant setting defines the maximum allowed sharing level, but individual sites may be more restrictive.

In SharePoint admin centre → Active sites, review:

  • External-sharing level
  • Site owner
  • Site sensitivity label
  • Last activity
  • Storage usage
  • Team or group connection
  • Business purpose

Microsoft allows administrators to select a site and open More sharing settings to change its external-sharing configuration. 

Prioritise sites containing:

  • Finance documents
  • HR records
  • Customer information
  • Legal material
  • Intellectual property
  • Board information
  • Security documentation
  • Personal data

A public marketing-resource site may need different sharing controls from a payroll or legal site.

Step 3: Run Site-Level Sharing Reports

SharePoint and OneDrive provide sharing reports that can show how content has been shared.

For a SharePoint site, a site owner or administrator can generate a report containing information about files, folders and access. OneDrive users can also run a sharing report from their OneDrive settings. Microsoft documents the OneDrive process under OneDrive settings → More settings → Run sharing report. 

A sharing report can help identify:

  • Externally shared files
  • Externally shared folders
  • Sharing link types
  • Named recipients
  • Guest access
  • Direct permissions

The report should be treated as a working inventory, not simply exported and archived.

For each entry, determine:

  • Is the content still required?
  • Is the external recipient still involved?
  • Is the sharing method appropriate?
  • Could access be narrower?
  • Should the file be moved to a controlled site?
  • Does the link require an expiration date?
  • Is anonymous access really necessary?

Step 4: Use Microsoft Purview Audit

Microsoft Purview Audit records many sharing-related events for SharePoint and OneDrive.

Microsoft’s sharing-audit guidance explains how administrators can search and export audit records to identify resources shared with external users. The exported data can be filtered using fields such as the target user type, including guest recipients. 

Useful sharing events can include actions involving:

  • Anonymous links
  • Secure links
  • Sharing invitations
  • External-user invitations
  • Access requests
  • Sharing changes
  • Link creation
  • Link removal
  • Permission changes

The exact event names and availability can change, so use Microsoft’s current audit-activity reference when building searches. 

A Practical Audit Search

In Microsoft Purview:

  1. Open Audit.
  2. Create a new search.
  3. Select a suitable date range.
  4. Select SharePoint and OneDrive sharing activities.
  5. Add users or sites when narrowing the investigation.
  6. Run the search.
  7. Export the results.
  8. Filter for external, guest or anonymous activity.
  9. Investigate the underlying content.

Useful questions include:

  • Who created the link?
  • When was it created?
  • Which file or folder was shared?
  • Was the recipient a guest?
  • Was an anonymous link created?
  • Was the permission later changed?
  • Was the link subsequently removed?
  • Did the guest access the file?

Audit Logs Show Activity, Not Always the Complete Current State

Audit logs are historical event records.

They are useful for showing that a sharing action happened, but they may not be the easiest way to determine the exact permissions that exist today.

For example:

  • A link may have been created and later removed.
  • A guest may have received access through a group.
  • The event may fall outside the retained audit period.
  • The file may have moved.
  • The current site permissions may differ from the original event.

Use audit data alongside:

  • Current site permissions
  • Sharing reports
  • Microsoft Entra guest records
  • Group membership
  • Link reports
  • Site-owner confirmation

No single report necessarily provides the entire picture.

Step 5: Use Data Access Governance Reports

SharePoint Data Access Governance reports can help identify oversharing patterns across sites.

Microsoft’s sharing-links activity report identifies sites where users created the most new sharing links during the previous 28 days. Microsoft recommends first running a site-permissions report to understand the existing sharing baseline, then using link-activity reporting to monitor continuing behaviour. 

These reports can help prioritise:

  • Sites generating many Anyone links
  • Sites with large numbers of external users
  • Sites with broad permissions
  • Sites showing rapid increases in sharing
  • Sites containing sensitive information

Some Data Access Governance capabilities require SharePoint Advanced Management or qualifying Microsoft 365 licensing. Confirm current licensing before designing an audit process around them. 

Activity Reports Are Not a Permanent Historical Inventory

The sharing-links activity report focuses on recent activity, currently using a 28-day window.

That makes it useful for monitoring new behaviour, but it does not replace a complete review of links created months or years earlier. 

Use it to answer:

Where is new sharing happening most frequently?

Use site reports and current-permission reviews to answer:

What access exists now?

Use Purview Audit to answer:

Who performed the sharing action and when?

Step 6: Review Anonymous “Anyone” Links First

Anonymous links should receive the highest priority because the user opening the link may not be required to authenticate.

For each Anyone link, determine:

  • Who created it?
  • Why was anonymous access required?
  • Does it allow view or edit?
  • Does it have an expiration date?
  • Is the file still relevant?
  • Could the link have been forwarded?
  • Does the content contain sensitive data?
  • Can it be replaced with a Specific people link?

Remove anonymous links where the business case no longer exists.

Where anonymous sharing is still necessary:

  • Allow view only where possible.
  • Set a short expiration.
  • Avoid sharing folders containing changing content.
  • Keep sensitive information out of the shared location.
  • Record a business owner.
  • Review the link before renewing it.

Configure Anyone-Link Expiration

Microsoft lets administrators require Anyone links to expire after a maximum number of days. Administrators can also restrict anonymous links to view-only access. 

A suitable period depends on the use case.

Examples might include:

  • Temporary file collection: 7 days
  • Tender documents: 14 days
  • Customer download: 30 days
  • Public marketing asset: reviewed separately

Expiration reduces long-term exposure but does not undo data already downloaded by a recipient.

Step 7: Review External Guests

In Microsoft Entra ID, review external identities for:

  • Last sign-in
  • Created date
  • Sponsoring employee
  • Group membership
  • Application assignments
  • Administrative roles
  • Current employer
  • Business purpose

Look for guests associated with:

  • Completed projects
  • Former suppliers
  • Previous professional advisers
  • Departed partner employees
  • Old customer engagements
  • Temporary contractors

Removing an Entra guest may affect access across Teams, SharePoint and other applications, so confirm ownership before deletion.

However, leaving inactive guests indefinitely increases the chance that access persists unnoticed.

Guest Expiration Is Helpful but Not Sufficient

SharePoint supports expiration of external-user access.

This can require site owners to review or extend access after a configured period. It is a useful control, but it should not replace regular access reviews.

A guest may still have access through:

  • Several sites
  • A Microsoft 365 group
  • Teams
  • Direct permissions
  • Another application

The review should confirm the person’s continuing need, not simply renew everyone automatically.

Step 8: Review Site and Group Membership

External access may be inherited through:

  • SharePoint Members
  • SharePoint Visitors
  • Microsoft 365 groups
  • Teams membership
  • Security groups
  • Nested permissions
  • Private channels
  • Shared channels

A file’s sharing dialog may not immediately explain every route through which the person can access the content.

Review:

  • Site owners
  • Site members
  • Site visitors
  • Connected group membership
  • Teams guests
  • Private and shared-channel membership
  • Direct item permissions

Pay special attention to external users who are site owners or have edit rights.

Step 9: Audit OneDrive Separately

OneDrive is designed primarily as an individual user’s working area.

That makes external sharing harder to govern because access is distributed across many personal storage locations.

Common risks include:

  • Customer documents stored permanently in one employee’s OneDrive
  • Folders shared externally without expiration
  • Business records owned by an employee who later leaves
  • Anonymous links created for convenience
  • Personal project folders becoming unofficial collaboration sites

For each high-risk user or department:

  1. Run the OneDrive sharing report.
  2. Review anonymous and external access.
  3. Transfer long-term shared content to SharePoint.
  4. Remove obsolete links.
  5. Confirm the business owner.
  6. Review the user’s departure or role-change risk.

Long-running external collaboration should normally take place in a managed SharePoint site rather than an individual employee’s OneDrive.

Step 10: Review Sensitive Content That Is Externally Shared

Not every shared file carries the same risk.

Prioritise content containing:

  • Customer records
  • Employee information
  • Payment details
  • Identification documents
  • Contracts
  • Confidential pricing
  • Intellectual property
  • Security information
  • Legal advice
  • Credentials or recovery information

Microsoft Purview sensitivity labels and Data Loss Prevention policies can help identify and protect sensitive content, but these controls need to be configured deliberately.

A useful policy may:

  • Warn users before external sharing.
  • Block anonymous sharing of labelled documents.
  • Require encryption.
  • Restrict access to named recipients.
  • Generate an alert for high-risk sharing.
  • Prevent sharing from unmanaged devices.

Do Not Assume a Sensitivity Label Automatically Removes Existing Links

Applying a label or changing a site policy does not necessarily perform every historical cleanup action you need.

After strengthening a label or DLP policy:

  • Test existing links.
  • Review prior permissions.
  • Remove inappropriate anonymous links.
  • Confirm whether external users retain access.
  • Re-run relevant reports.

Policy improvement and historical remediation are separate workstreams.

Step 11: Delegate Reviews to Site Owners

Central IT may know that a site has 45 external users, but it may not know which of them are still required.

Site owners are generally better positioned to identify:

  • Active customers
  • Current suppliers
  • Completed projects
  • Obsolete documents
  • Legitimate anonymous links
  • Users who should be removed

Microsoft supports site-access reviews that let administrators delegate review of overshared SharePoint sites to their owners. Microsoft notes that these reviews are available for SharePoint sites but not currently for OneDrive accounts. 

Provide site owners with a simple decision framework:

  • Keep
  • Restrict
  • Replace with named access
  • Expire
  • Remove
  • Escalate for investigation

Do not simply ask owners to “review sharing” without explaining what a good decision looks like.

Step 12: Remove Access Safely

Before deleting access, confirm whether it supports an active business process.

Then remediate using the narrowest appropriate action:

  • Delete the Anyone link.
  • Replace it with a Specific people link.
  • Remove an external user’s direct permission.
  • Remove the guest from the site.
  • Remove the guest from the Microsoft 365 group.
  • Remove them from Teams.
  • Reduce edit access to view.
  • Add an expiration date.
  • Move the file into a controlled collaboration site.
  • Remove the obsolete content entirely.

Record important changes so the organisation can explain:

  • What access was removed
  • Who approved the change
  • Why it was removed
  • Whether the recipient was notified
  • Whether a replacement sharing method was provided

Be Careful With Business-Critical Integrations

Some external access supports:

  • Customer portals
  • Automated document exchange
  • Supplier submissions
  • Legal case collaboration
  • Board portals
  • External workflows

Do not remove access based only on the age of the link.

Confirm:

  • Current owner
  • Business process
  • Service dependency
  • Recipient organisation
  • Alternative access method
  • Data-retention requirement

When the access cannot be justified or no owner can be found, it should be treated as a risk requiring escalation.

Recommended Sharing Configuration

A sensible small or medium-sized business baseline may include:

  • Specific people as the default link type
  • View as the default permission
  • Anyone links disabled unless genuinely required
  • Short expiration for permitted Anyone links
  • Guest expiration enabled
  • Sensitive sites restricted to existing guests or internal users
  • Domain restrictions for controlled partner scenarios
  • DLP or sensitivity-label controls for confidential content
  • Regular audit and site-owner review

The exact configuration should reflect how the business collaborates.

A design agency distributing public campaign assets may legitimately require anonymous links. A law firm or payroll provider may have very little reason to permit them.

Restrict Sharing by Domain Where Appropriate

SharePoint and OneDrive can restrict external sharing to approved or blocked domains.

An allow list can be useful where collaboration occurs with a small, stable group of partner organisations.

For example:

approved-customer.com

legal-partner.co.uk

primary-supplier.net

However, domain restrictions are not a complete identity check.

They do not protect against:

  • A compromised partner account
  • Incorrectly approved domains
  • Personal accounts
  • Anonymous links
  • A legitimate external user sharing data onward

Use them as one layer within a broader access process.

Create an External-Sharing Request Process

For sensitive or long-running collaboration, collect:

  • Business sponsor
  • External organisation
  • Named recipients
  • Data being shared
  • Site or folder
  • Required permission level
  • Start date
  • Expiration date
  • Sensitivity classification
  • Reason anonymous access is needed, if applicable
  • Review date

This makes external sharing deliberate rather than accidental.

Routine low-risk sharing can remain user-driven, while higher-risk scenarios receive additional approval.

Monitor New Sharing Continuously

A one-time audit will slowly become outdated.

A practical monitoring cycle could include:

Weekly

  • High-risk DLP alerts
  • New anonymous links on sensitive sites
  • Unusual volumes of sharing
  • External sharing by privileged users

Monthly

  • Audit-log sharing activity
  • Recently created guests
  • Top sites creating external links
  • Anonymous-link creation
  • External-sharing incidents

Quarterly

  • Site-owner access reviews
  • Approved external domains
  • Guest accounts
  • OneDrive sharing for high-risk departments
  • Exceptions and allow lists
  • Sensitive-site configuration

Annually

  • Full external-sharing policy review
  • SharePoint and OneDrive configuration
  • Licensing and reporting capability
  • Staff guidance
  • Incident-response testing

What to Do When Sensitive Data Was Publicly Shared

Treat the situation as a potential data-security incident.

1. Remove or Disable the Link

Stop continuing access as quickly as practical.

2. Preserve Evidence

Record:

  • URL
  • File or folder
  • Owner
  • Link type
  • Creation date
  • Permissions
  • Known recipients
  • Audit events
  • Access activity

3. Determine the Exposure

Investigate:

  • Whether the link was used
  • Who accessed it
  • Whether the content was downloaded
  • Whether the link was forwarded
  • How long it was active
  • What information the content contained

4. Notify Security, Privacy or Legal Teams

Sensitive personal, financial or regulated information may require formal assessment and notification.

5. Review the Account

Check whether the sharing resulted from:

  • User error
  • Account compromise
  • Malicious insider activity
  • An unsafe business process
  • Misconfigured default settings

6. Search for Similar Exposure

The same person or site may have created additional links using the same unsafe process.

Common External-Sharing Mistakes

Reviewing Guests but Ignoring Anonymous Links

Anyone links may not create guest identities.

Tightening Settings Without Auditing Existing Access

The organisation feels safer while historical exposure remains.

Allowing Anonymous Edit Links

Anyone possessing the link may be able to alter or delete content.

Using OneDrive as a Permanent External Portal

Ownership and continuity depend too heavily on one employee.

Never Expiring Access

Temporary collaboration becomes permanent.

Assuming the Link Was Sent to Only One Person

The original recipient may forward an anonymous link.

Removing the Link but Leaving Direct Permissions

The external user may still have another access route.

Asking IT to Judge Every Business Relationship

Site and data owners should participate in access decisions.

Exporting Reports Without Acting on Them

An audit provides value only when findings are remediated.

External-Sharing Audit Checklist

Tenant Settings

  • Review SharePoint sharing level.
  • Review OneDrive sharing level.
  • Set the default link type.
  • Set the default permission.
  • Configure Anyone-link expiration.
  • Review guest expiration.
  • Review domain restrictions.

SharePoint Sites

  • Inventory active sites.
  • Identify externally enabled sites.
  • Review sensitive and high-activity sites first.
  • Confirm site owners.
  • Run sharing reports.
  • Review site and group membership.
  • Remove obsolete external access.

OneDrive

  • Review high-risk departments.
  • Run user sharing reports.
  • Identify anonymous links.
  • Move long-term collaboration to SharePoint.
  • Review OneDrive data during employee offboarding.

Audit and Monitoring

  • Search Purview sharing events.
  • Export and filter audit data.
  • Review recent link activity.
  • Use Data Access Governance reports where licensed.
  • Alert on sensitive external sharing.
  • Repeat reviews regularly.

Remediation

  • Remove unnecessary Anyone links.
  • Replace anonymous links with named access.
  • Reduce edit access to view.
  • Expire temporary access.
  • Remove inactive guests.
  • Transfer ownership.
  • Document significant changes.

Final Thoughts

External sharing is not inherently unsafe. Unreviewed external sharing is.

SharePoint and OneDrive can support secure collaboration when organisations understand:

  • Which sites allow external access
  • Which files and folders have been shared
  • Which links are anonymous
  • Which guests still have permissions
  • Who owns each external relationship
  • When access should expire

Begin with the organisation-wide sharing configuration, but do not stop there.

Run site and OneDrive sharing reports. Search the Microsoft Purview audit log. Review Data Access Governance information where available. Inspect guests, groups and direct permissions. Ask site owners to confirm the business need.

Most importantly, remove access that no longer has a clear owner, purpose or expiry.

A link created for a two-week project should not remain active two years later simply because nobody remembered it existed.

Unsure What Your Business Has Already Shared Externally?

Hamilton Group can help you audit and secure SharePoint and OneDrive external sharing.

Our experts can help you:

  • Review tenant and site-level sharing settings
  • Identify anonymous Anyone links
  • Audit external guests and permissions
  • Run SharePoint and OneDrive sharing reports
  • Search Microsoft Purview audit activity
  • Review high-risk and overshared sites
  • Configure link and guest expiration
  • Implement sensitivity labels and DLP controls
  • Build site-owner access reviews
  • Remove obsolete sharing safely
  • Create a practical external-collaboration process

Visit hgmssp.com, call Hamilton Group on 0330 043 0069, or book a meeting with one of our experts to find out what information is already accessible outside your organisation.