Security assessment
Safe external sharing and guest access in SharePoint, OneDrive and Teams
Collaboration with outside people is the point of Microsoft 365. Here's how to keep it deliberate: the settings that matter, sensible defaults, and how to clean up years of old links and guests.
Part of our guide: Microsoft 365 security assessment checklist (2026)
On this page
- SharePoint and OneDrive: the four sharing levels
- Default links and "Anyone" links
- Guests in Microsoft Entra ID
- Teams: guest access vs external access
- Ownership: the control people forget
- Review guests on a schedule
- Cleaning up years of sharing
- Sensitivity labels for sites and teams
- Why this matters more with Copilot
- Recommended starting settings
- How M365Assessments helps
External sharing in Microsoft 365 happens in three layers that are easy to confuse: Microsoft Entra ID decides who can be invited as a guest, SharePoint and OneDrive decide what kind of links and sharing are allowed (Teams files live in SharePoint), and Teams has its own settings for guest access and for chatting with people in other organizations. An assessment has to look at all three.
SharePoint and OneDrive: the four sharing levels
In the SharePoint admin center (Policies › Sharing), the organization-level setting is one of:
| Level | What it allows | Typical use |
|---|---|---|
| Anyone | Links that work without signing in, plus everything below | Organizations that genuinely share files publicly |
| New and existing guests | Sharing with people outside who sign in or verify with a code | Most organizations that collaborate externally |
| Existing guests | Sharing only with guests already in the directory | Organizations that onboard guests centrally |
| Only people in your organization | No external sharing | Highly restricted environments, or specific sites |
OneDrive's level can match SharePoint's or be more restrictive. Each site can then be set to the same level or stricter. Microsoft documents this in manage sharing settings for SharePoint and OneDrive.
A common, balanced setup is New and existing guests at the organization level, with sites holding sensitive content (HR, finance, board) set to Only people in your organization or Existing guests.
Default links and "Anyone" links
- Default link type: set to Specific people, so a quick share doesn't create a broader link than intended. See change the default sharing link.
- Default permission: View, rather than Edit, for new links.
- "Anyone" link expiry: if you allow Anyone links, set them to expire (for example 30 days), and consider View-only for files and folders.
- Limit by domain: if you only work with known partners, allow sharing only with their domains, or block specific domains. See restrict sharing by domain.
- Guest access expiration: SharePoint can remove a guest's access to a site after a set number of days, so old access doesn't linger.
Guests in Microsoft Entra ID
Every guest is a Microsoft Entra B2B account in your directory. The key settings are under External Identities › External collaboration settings; see configure external collaboration settings:
- Guest user access: the most restrictive option limits guests to their own directory objects, so they can't browse your users and groups.
- Guest invite settings: decide who can invite. Many SMBs allow members to invite; stricter organizations limit it to admins and the Guest Inviter role.
- Collaboration restrictions: allow invitations only to specific domains, or deny specific domains.
- Conditional Access for guests: require MFA for guest users. Our Conditional Access baseline includes this policy.
SharePoint and OneDrive use Entra B2B for guests by default in current tenants; if yours is older, check SharePoint and OneDrive integration with Microsoft Entra B2B, which makes guests manageable in one place.
Teams: guest access vs external access
Teams has two different external features, and people often mean one when they say the other:
- Guest access adds an outside person to a team, with access to its channels and files. It's governed by Entra B2B, SharePoint sharing and the Teams guest settings. See guest access in Microsoft Teams.
- External access (federation) lets your users chat and call with people in other Microsoft 365 organizations without adding them to anything. You can allow all external domains, only specific ones, or none, and separately decide whether to allow unmanaged Teams accounts. See manage external meetings and chat.
For meetings, review who can bypass the lobby. Having anonymous and external participants wait in the lobby until admitted is a sensible default for most organizations.
Ownership: the control people forget
Every Microsoft 365 group and team should have at least two owners who are current staff. Owners decide who's in the team, including guests. Ownerless groups are where guest access goes unreviewed for years. Microsoft 365 group expiration and ownership policies can help keep this tidy.
Review guests on a schedule
With Microsoft Entra ID P2 or Microsoft Entra ID Governance, access reviews can ask team owners (or the guests themselves) every quarter whether access is still needed, and remove guests who aren't confirmed. Without those licenses, run a manual review: export guests with their last sign-in date, and remove those who haven't signed in for a set period, after checking with the sponsoring team.
Cleaning up years of sharing
Changing defaults only affects new links. Existing links and guests need a plan:
Report first. Use the SharePoint admin center's sharing reports (and, with SharePoint Advanced Management, data access governance reports) to find sites with the most external sharing and Anyone links.
Tell site owners what will change, when, and how to re-share properly if they need to.
Tighten high-risk sites first: HR, finance, legal and executive sites.
Expire or remove Anyone links on sensitive content, and remove stale guests.
Re-assess after a month to confirm the numbers moved.
Sensitivity labels for sites and teams
If you use Microsoft Purview sensitivity labels, labels for Teams, groups and sites can enforce the sharing level, guest access and privacy of a site based on its classification. It's a scalable way to keep confidential sites internal without checking each one by hand.
Why this matters more with Copilot
Microsoft 365 Copilot can only surface content a user already has permission to see, but it makes that content much easier to find. Broad internal sharing ("Everyone except external users", organization-wide links) is therefore just as important to review as external sharing. See getting a tenant ready for Copilot.
Recommended starting settings
| Setting | Starting point for most SMBs |
|---|---|
| SharePoint organization-level sharing | New and existing guests |
| OneDrive sharing | Same as SharePoint, or Existing guests |
| Sensitive sites | Only people in your organization, or Existing guests |
| Default link type and permission | Specific people, View |
| "Anyone" links | Off, or on with expiry and View-only |
| Guest access expiration | On, with a period that matches your projects |
| Guest user access in Entra ID | Restricted to their own directory objects |
| Guest MFA | Required by Conditional Access |
| Teams external access | Allowed for partner domains you work with, or all with unmanaged accounts off |
| Meeting lobby | Anonymous and external participants wait in the lobby |
Adjust to the business: an organization that publishes files to customers daily will reasonably allow more than a law firm.
How M365Assessments helps
The early-access SharePoint & OneDrive and Teams modules read tenant sharing settings, site inventory, anonymous links in sampled sites and Teams guest and external access settings with read-only permissions. Core adds guest and external-access settings from Entra ID. Findings come with a recommended fix, and run history shows whether the clean-up is working. See modules explained and the permissions each module uses.