SecureMyEmail logoSecureMyEmail

Google Workspace security guide

Tighten sharing links in Google Workspace

A practical, step-by-step guide for Australian businesses. Restrict external sharing, disable anonymous links, and keep Google Drive collaboration under control.

Google Workspace Drive sharing links secured with green shield and padlock icons

Recommended method: restrict external sharing, disable anonymous links, and review regularly

Prevent anonymous access to business files and regularly review files shared with people outside the organisation. These controls apply to Google Drive content, including Google Docs, Sheets and Slides, files and folders in My Drive, shared drives, Google Sites, My Maps, and certain Gemini files and Gems stored in Drive.

Recommended configuration

SettingRecommended value
External sharingAllowed only where required
Anonymous link sharingDisabled
Default accessRestricted
External recipientsNamed and authenticated users
Visitor sharingDisabled unless required
Trusted-domain sharingUse where practical
External warning indicatorEnabled
External-access reviewMonthly, with a formal quarterly review

“Restricted” access means only people specifically added to the file can open it, and external recipients must be named and authenticated.

Before you begin

  • Sign in using a dedicated Google Workspace administrator account.
  • Confirm the account has Super Admin or Drive and Docs administrator privileges.
  • Document the existing Drive sharing settings.
  • Identify departments and users that legitimately share files with clients, suppliers or contractors.
  • Check for public website downloads, client upload folders, public forms, embedded documents, shared reports or dashboards, automated applications using shared Drive links, and files supplied to clients using “Anyone with the link”.
  • Notify staff before making the change.
  • Where possible, test the settings against a small organisational unit or configuration group first.
1

Restrict external sharing

  • Open the Google Admin console.
  • Go to Menu → Apps → Google Workspace → Drive and Docs.
  • Select Sharing settings.
  • Open Sharing options.
  • Select the top-level organisational unit unless you intend to test the change on a smaller organisational unit or configuration group.
  • Choose the appropriate external-sharing setting.
  • For departments that do not need external collaboration, set external sharing to Off.
  • For staff who legitimately need to share with clients or suppliers, leave external sharing On, disable the option that allows users to make files or published web content visible to anyone with the link, and require users to share directly with named recipients.
  • If your interface provides an option to warn users before sharing externally, enable it.
  • Select Save.
  • If configuring a child organisational unit, select Override when prompted.

Google states that these changes can take up to 24 hours to apply and that old and new settings may be intermittently enforced during that period.

2

Avoid anonymous links

Google Drive files normally have a General access setting. The safest setting is Restricted.

  • In Apps → Google Workspace → Drive and Docs → Sharing settings, open Sharing options.
  • Locate the setting concerning link sharing or allowing content to be visible to anyone with the link.
  • Turn off the option allowing users to create “Anyone with the link” access, publicly accessible Drive files, and publicly published web content where this is controlled by the same setting.
  • Confirm external sharing, where allowed, requires users to enter the recipient’s email address.
  • Select Save.

Disabling anonymous links provides better accountability because external access is associated with an identified recipient rather than an unverified link.

3

Consider restricting sharing to trusted domains

If users normally collaborate with a known group of organisations, restrict external sharing to approved domains.

  • In the Admin console, go to Account → Domains → Allowlisted domains.
  • Add each approved partner domain.
  • Confirm that the domain is correct before saving.
  • Avoid approving broad consumer domains such as gmail.com or outlook.com, as this would allow sharing with a very large number of unrelated accounts.
  • Return to Apps → Google Workspace → Drive and Docs → Sharing settings → Sharing options.
  • Select the relevant organisational unit or configuration group.
  • Choose Allowlisted Domains and configure the available sharing options.
  • Select Save or Override.

Allowlisted-domain sharing can block users from sharing with personal accounts. Test it carefully if clients commonly use personal Gmail addresses.

4

Control visitor sharing

Visitor sharing lets a recipient without a Google Account access content after verifying their email address with a PIN.

  • Go to Apps → Google Workspace → Drive and Docs → Sharing settings.
  • Locate Visitor sharing.
  • Select the relevant organisational unit or group.
  • Choose one of the following: turn visitor sharing Off if all external recipients can use Google Accounts; permit visitor sharing only when there is a documented business need; or restrict visitor sharing to trusted domains if your Workspace edition and configuration permit it.
  • Select Save.

Visitor sharing should not be confused with anonymous access. Visitors verify control of their email address, but they may not be managed by the external organisation.

5

Display warnings on external files

Enable visible warnings to help employees recognise externally accessible content.

  • Go to Apps → Google Workspace → Drive and Docs → Sharing settings → Sharing options.
  • Select the appropriate organisational unit or group.
  • Open Highlight external files.
  • Select Highlight external files.
  • Select Save.

This causes Google to display an external indicator when a Drive file or shared drive is owned by, or shared with, someone outside the organisation. It does not remove external access; it only makes the exposure more visible.

6

Limit external sharing to authorised users

A practical approach is to block external sharing for most employees and permit it only for approved departments.

  • Create an organisational unit or configuration group for staff authorised to share externally.
  • In the Admin console, go to Apps → Google Workspace → Drive and Docs → Sharing settings → Sharing options.
  • Select the top-level organisational unit and turn external sharing Off.
  • Select the approved organisational unit or configuration group, override the inherited setting, and turn authenticated external sharing On.
  • Keep anonymous “Anyone with the link” sharing disabled.
  • Select Save.

Be aware that configuration-group settings override organisational-unit settings. If a user belongs to several configuration groups, Google applies the setting from the highest-priority applicable group.

7

Use shared drives for external collaboration

Instead of allowing external sharing throughout users’ My Drives, create controlled shared drives for client collaboration.

  • Open the Admin console.
  • Go to Apps → Google Workspace → Drive and Docs → Manage shared drives.
  • Create or identify a shared drive intended for external collaboration.
  • Assign responsible internal managers.
  • Add only approved external members.
  • Grant the lowest suitable permission: Viewer for read-only access, Commenter where feedback is required, or Contributor where uploading or editing is required. Avoid Content manager or Manager for external users unless essential.
  • Review the shared drive’s members and sharing restrictions.
  • Store sensitive internal files in a different shared drive where external access is disabled.
8

Review externally shared files

Review Drive log events

  • Open the Google Admin console.
  • Go to Reporting → Audit and investigation → Drive log events.
  • Set an appropriate date range, such as the previous 30 or 90 days.
  • Add filters relevant to sharing, including where available: Visibility changed, Sharing permissions changed, User or group added, External user, Link sharing enabled, Published, and Downloaded by an external user.
  • Run the search.
  • Review files changed to public or link-accessible, files shared with personal email accounts, sensitive files shared externally, large numbers of sharing events by one user, access given to former clients, suppliers or contractors, and unexpected external domains.
  • Export the results if you need a record of the review.
  • Contact the file owner to confirm whether each unusual sharing event is legitimate.

Organisations with a supported Google Workspace edition can use the Security Investigation Tool for deeper analysis and, where permitted, remediation. Go to Security → Security centre → Investigation tool, select Drive log events as the data source, search for external sharing or visibility changes, and take remediation action only after confirming the access is unauthorised.

9

Remove unnecessary external access

For an individual file or folder

  • Open Google Drive.
  • Locate the file or folder.
  • Select Share.
  • Under People with access, review every external user and group.
  • Remove recipients who no longer need access.
  • Change excessive permissions from Editor to Viewer where appropriate.
  • Under General access, select Restricted.
  • Select Done.

For a shared drive

  • Open the shared drive.
  • Select Manage members.
  • Review all external members.
  • Remove obsolete users.
  • Reduce permission levels where full editing or management rights are unnecessary.
  • Check important folders and files for separately assigned access.

Removing a person from a shared drive does not necessarily remove access to content independently shared with that person from another location.

10

Establish an ongoing review process

  • Review Drive sharing events every month.
  • Review shared-drive memberships every quarter.
  • Review trusted domains every quarter.
  • Remove external access when a project or contract ends.
  • Review access immediately when an employee, supplier or contractor leaves.
  • Assign an internal owner to every externally accessible shared drive.
  • Record the business reason for sensitive external sharing.
  • Use reporting rules or alerts for high-risk sharing events if supported by your edition.

Warnings

  • Turning external sharing off immediately removes external users’ access to previously shared items.
  • Public website documents, embedded files and downloads may stop working.
  • Client collaboration folders may become inaccessible.
  • Forms, reports, dashboards and automated processes may depend on existing sharing permissions.
  • Allowlisting domains may prevent sharing with clients who use personal Gmail or other consumer accounts.
  • Disabling visitor sharing may prevent recipients without Google Accounts from opening files.
  • Sharing restrictions apply according to the file owner’s organisational unit or configuration group, which can produce unexpected results.
  • Group-based configuration can override organisational-unit settings.
  • A user might share a file with a Google Group containing external members, so group membership must also be reviewed.
  • Settings can take up to 24 hours to apply.
  • Changing the policy does not replace the need to review and remove existing file permissions individually.
  • Some reporting, investigation, trust-rule and remediation capabilities require higher Google Workspace editions.

Google Workspace disclaimer

These instructions provide general Google Workspace security guidance. They may not account for your organisation’s Workspace edition, file ownership, shared-drive structure, client workflows, regulatory obligations or third-party integrations.

Incorrect sharing changes can interrupt access to critical documents, customer portals, website resources, forms and automated systems. Document the existing configuration, test changes with a small organisational unit and maintain a rollback plan before deploying them broadly.

Where Google Workspace contains business-critical, confidential, health, legal or financial information, Netlogyx/Securemyemail recommends having the settings reviewed and implemented by a qualified Google Workspace engineer.