SharePoint Governance: How to Control External Sharing Without Killing Productivity
External sharing in SharePoint is necessary but dangerous. Learn to configure policies that protect your data without blocking your team.
The SharePoint dilemma: sharing vs. protecting
SharePoint Online is the document backbone of Microsoft 365. Every file you upload to Teams, every document you share in OneDrive, and every library in your intranet lives in SharePoint. It's your organization's document nervous system.
The problem: SharePoint's default configuration allows any user to share files with anyone outside your organization — no approval, no audit trail, and sometimes without the user even realizing the implications.
How data leaks through SharePoint
The common scenario
An employee needs to send a file to a vendor. Instead of attaching it to email, they copy the SharePoint link and send it via WhatsApp. The link has "anyone with the link" permissions — no authentication required. The vendor forwards it to a colleague. That colleague saves it to their personal Google Drive. Your confidential file now lives in a Gmail account you don't control.
The dangerous scenario
A former employee has saved links to documents that were shared while they worked with you. If "anyone" links weren't revoked at offboarding, those documents remain accessible months later.
The invisible scenario
SharePoint indexes public sites by default. If a team site has open sharing, search engines can index documents you assumed were internal.
The 5 sharing levels in SharePoint
Microsoft offers 5 sharing levels, from most open to most restrictive:
1. Anyone: No authentication. Anyone with the link can access. The most dangerous level.
2. New and existing guests: Requires the external person to create or have a Microsoft account. Creates an audit trail.
3. Existing guests: Only people who already exist in your directory as guests.
4. Only people in your organization: No external sharing possible.
5. Specific people: The user chooses exactly who can access.
The recommendation for SMBs: set the tenant default to "Existing guests" (level 3), and enable more open levels only on specific sites with documented justification.
How to configure SharePoint correctly
Step 1: Tenant-level policy
In the SharePoint Admin Center, set organization-level sharing to "Existing guests." This means that to share with someone external, that person must first be invited as a guest in Azure AD — which creates an audit record and allows revocation.
Step 2: Site-level policies
Not all sites need the same level. "Marketing" may need to share with external agencies, while "Finance" shouldn't share anything externally. Configure exceptions per site, not the other way around.
Step 3: Link expiration
Set automatic expiration on shared links: 30 days for "anyone" links, 90 days for guest links. This prevents persistent access after the business need ends.
Step 4: Sensitivity labels
Apply sensitivity labels (Confidential, Internal, Public) that automatically restrict sharing based on document classification. A document labeled "Confidential" blocks external sharing, period.
Step 5: Audit and alerts
Enable DLP alerts for when an unusual volume of files is shared externally, or when sensitive file types (financial statements, contracts, personal data) are shared outside the organization.
The most common insecure configurations the 201 rules detect:
- Tenant-level sharing set to "Anyone" (the most insecure level)
- Zero expiration on shared links
- No sensitivity labels configured
- Sharing audit disabled
- Team sites with hundreds of active external links that nobody reviews
First step
Our free scan evaluates the 155 Microsoft Graph rules of the 201-rule library, including SharePoint sharing configuration, link policies, and external permissions. In 90 seconds you know exactly where your gaps are. The 46 Azure Resource Manager controls add on with admin consent.
Is your business protected?
A free Microsoft 365 audit—the automated scan delivers a preview in 90 seconds. Find risks before they become incidents.