Security assessment

Safe external sharing and guest access in SharePoint, OneDrive and Teams

Collaboration with outside people is the point of Microsoft 365. Here's how to keep it deliberate: the settings that matter, sensible defaults, and how to clean up years of old links and guests.

Part of our guide: Microsoft 365 security assessment checklist (2026)

On this page

External sharing in Microsoft 365 happens in three layers that are easy to confuse: Microsoft Entra ID decides who can be invited as a guest, SharePoint and OneDrive decide what kind of links and sharing are allowed (Teams files live in SharePoint), and Teams has its own settings for guest access and for chatting with people in other organizations. An assessment has to look at all three.

SharePoint and OneDrive: the four sharing levels

In the SharePoint admin center (Policies › Sharing), the organization-level setting is one of:

SharePoint external sharing levels
LevelWhat it allowsTypical use
AnyoneLinks that work without signing in, plus everything belowOrganizations that genuinely share files publicly
New and existing guestsSharing with people outside who sign in or verify with a codeMost organizations that collaborate externally
Existing guestsSharing only with guests already in the directoryOrganizations that onboard guests centrally
Only people in your organizationNo external sharingHighly restricted environments, or specific sites

OneDrive's level can match SharePoint's or be more restrictive. Each site can then be set to the same level or stricter. Microsoft documents this in manage sharing settings for SharePoint and OneDrive.

A common, balanced setup is New and existing guests at the organization level, with sites holding sensitive content (HR, finance, board) set to Only people in your organization or Existing guests.

  • Default link type: set to Specific people, so a quick share doesn't create a broader link than intended. See change the default sharing link.
  • Default permission: View, rather than Edit, for new links.
  • "Anyone" link expiry: if you allow Anyone links, set them to expire (for example 30 days), and consider View-only for files and folders.
  • Limit by domain: if you only work with known partners, allow sharing only with their domains, or block specific domains. See restrict sharing by domain.
  • Guest access expiration: SharePoint can remove a guest's access to a site after a set number of days, so old access doesn't linger.

Guests in Microsoft Entra ID

Every guest is a Microsoft Entra B2B account in your directory. The key settings are under External Identities › External collaboration settings; see configure external collaboration settings:

  • Guest user access: the most restrictive option limits guests to their own directory objects, so they can't browse your users and groups.
  • Guest invite settings: decide who can invite. Many SMBs allow members to invite; stricter organizations limit it to admins and the Guest Inviter role.
  • Collaboration restrictions: allow invitations only to specific domains, or deny specific domains.
  • Conditional Access for guests: require MFA for guest users. Our Conditional Access baseline includes this policy.

SharePoint and OneDrive use Entra B2B for guests by default in current tenants; if yours is older, check SharePoint and OneDrive integration with Microsoft Entra B2B, which makes guests manageable in one place.

Teams: guest access vs external access

Teams has two different external features, and people often mean one when they say the other:

  • Guest access adds an outside person to a team, with access to its channels and files. It's governed by Entra B2B, SharePoint sharing and the Teams guest settings. See guest access in Microsoft Teams.
  • External access (federation) lets your users chat and call with people in other Microsoft 365 organizations without adding them to anything. You can allow all external domains, only specific ones, or none, and separately decide whether to allow unmanaged Teams accounts. See manage external meetings and chat.

For meetings, review who can bypass the lobby. Having anonymous and external participants wait in the lobby until admitted is a sensible default for most organizations.

Ownership: the control people forget

Every Microsoft 365 group and team should have at least two owners who are current staff. Owners decide who's in the team, including guests. Ownerless groups are where guest access goes unreviewed for years. Microsoft 365 group expiration and ownership policies can help keep this tidy.

Review guests on a schedule

With Microsoft Entra ID P2 or Microsoft Entra ID Governance, access reviews can ask team owners (or the guests themselves) every quarter whether access is still needed, and remove guests who aren't confirmed. Without those licenses, run a manual review: export guests with their last sign-in date, and remove those who haven't signed in for a set period, after checking with the sponsoring team.

Cleaning up years of sharing

Changing defaults only affects new links. Existing links and guests need a plan:

  1. Report first. Use the SharePoint admin center's sharing reports (and, with SharePoint Advanced Management, data access governance reports) to find sites with the most external sharing and Anyone links.

  2. Tell site owners what will change, when, and how to re-share properly if they need to.

  3. Tighten high-risk sites first: HR, finance, legal and executive sites.

  4. Expire or remove Anyone links on sensitive content, and remove stale guests.

  5. Re-assess after a month to confirm the numbers moved.

Sensitivity labels for sites and teams

If you use Microsoft Purview sensitivity labels, labels for Teams, groups and sites can enforce the sharing level, guest access and privacy of a site based on its classification. It's a scalable way to keep confidential sites internal without checking each one by hand.

Why this matters more with Copilot

Microsoft 365 Copilot can only surface content a user already has permission to see, but it makes that content much easier to find. Broad internal sharing ("Everyone except external users", organization-wide links) is therefore just as important to review as external sharing. See getting a tenant ready for Copilot.

Recommended starting settings

Recommended starting sharing settings
SettingStarting point for most SMBs
SharePoint organization-level sharingNew and existing guests
OneDrive sharingSame as SharePoint, or Existing guests
Sensitive sitesOnly people in your organization, or Existing guests
Default link type and permissionSpecific people, View
"Anyone" linksOff, or on with expiry and View-only
Guest access expirationOn, with a period that matches your projects
Guest user access in Entra IDRestricted to their own directory objects
Guest MFARequired by Conditional Access
Teams external accessAllowed for partner domains you work with, or all with unmanaged accounts off
Meeting lobbyAnonymous and external participants wait in the lobby

Adjust to the business: an organization that publishes files to customers daily will reasonably allow more than a law firm.

How M365Assessments helps

The early-access SharePoint & OneDrive and Teams modules read tenant sharing settings, site inventory, anonymous links in sampled sites and Teams guest and external access settings with read-only permissions. Core adds guest and external-access settings from Entra ID. Findings come with a recommended fix, and run history shows whether the clean-up is working. See modules explained and the permissions each module uses.

See where a tenant stands in minutes

M365Assessments runs these checks for you with read-only modules and turns them into a prioritized, plain-English report.

Requires a Microsoft Entra ID (work or school) account.