SecureMyEmail logoSecureMyEmail

Microsoft 365 security guide

Tighten sharing links in Microsoft 365

A practical, step-by-step guide for Australian businesses. Stop anonymous file access, default sharing links to Specific people, and keep external collaboration under control across SharePoint, OneDrive and Teams.

Microsoft 365 sharing links secured with green shield and padlock icons

Recommended method: disable anonymous links, default to Specific people, and review site-by-site

Prevent anonymous access to company files and ensure external users only retain access when there is a legitimate business requirement. These settings affect files stored in SharePoint Online, OneDrive for Business and Microsoft Teams, because Teams files are stored in SharePoint or OneDrive.

Recommended configuration

SettingRecommended value
SharePoint external sharingNew and existing guests
OneDrive external sharingNew and existing guests or Existing guests
Default sharing linkSpecific people
Default permissionView
Anonymous "Anyone" linksDisabled
Guest access expiration60–90 days
External sharing permissionsRestrict to authorised staff where practical

“Specific people” links require the recipient to verify their identity and generally will not work if forwarded to someone else.

Before you begin

  • Sign in using a dedicated Microsoft 365 administrator account.
  • Confirm that you have the SharePoint Administrator or Global Administrator role.
  • Notify staff that external sharing behaviour may change.
  • Identify any client portals, contractors, automated workflows or file-request processes that depend on public links.
  • Consider testing the changes on a small number of SharePoint sites before applying them broadly.

Important

Microsoft’s OneDrive Request Files feature requires the OneDrive sharing level to permit "Anyone" links. Disabling anonymous sharing can stop existing file-request links from working.

1

Disable anonymous “Anyone” links

  • Open the SharePoint admin centre.
  • Select Policies from the left menu.
  • Select Sharing.
  • Under External sharing, locate the sliders for SharePoint and OneDrive.
  • Move the SharePoint setting to New and existing guests. This permits legitimate external collaboration, but recipients must sign in or verify their identity.
  • Set OneDrive to either New and existing guests for normal external collaboration, or Existing guests if users should only share with guests already approved in your directory.
  • Do not select Anyone. This option creates anonymous links that can be forwarded and used without authentication.
  • Select Save.

The OneDrive setting can be equally restrictive or more restrictive than SharePoint, but it cannot be less restrictive. Microsoft advises that changes may take approximately one hour to fully apply.

2

Change the default link to “Specific people”

This reduces accidental oversharing when a user selects Share.

  • Remain in SharePoint admin centre → Policies → Sharing.
  • Scroll to File and folder links.
  • Under Choose the type of link that’s selected by default when users share files and folders, select Specific people.
  • Under default link permissions, select View.
  • Users can still deliberately grant editing access when it is required and permitted.
  • Select Save.

Avoid using People in your organisation as the default for sensitive information because a forwarded link may work for any authenticated user within the organisation.

3

Configure guest access expiration

  • In Policies → Sharing, expand More external sharing settings.
  • Find Guest access to a site or OneDrive will expire automatically after this many days.
  • Enable the setting.
  • Enter an appropriate period: 60 days for higher-security environments, or 90 days for ordinary business collaboration.
  • If displayed, configure people using verification codes to reauthenticate periodically. A period of approximately 30 days is a reasonable starting point for reauthentication.
  • Select Save.

Site owners may be prompted to extend legitimate guest access before it expires.

4

Restrict who can share externally

For stronger control, allow only approved staff to initiate external sharing.

  • Go to SharePoint admin centre → Policies → Sharing.
  • Expand More external sharing settings.
  • Select Allow only users in specific security groups to share externally.
  • Select Manage security groups.
  • Add the security group containing authorised users, such as External Sharing Approved Users.
  • For each group, select Authenticated guests only.
  • Select Save.

Do not select Anyone for these groups unless there is a documented and approved requirement for anonymous sharing. Microsoft currently permits up to 12 security groups in this setting.

5

Review each SharePoint site

Organisation-wide settings establish the maximum sharing level. Individual sites can be configured more restrictively.

  • Open SharePoint admin centre.
  • Select Sites → Active sites.
  • Review the External sharing column.
  • Pay particular attention to sites containing financial information, payroll or employee records, client information, legal documents, medical or health information, passwords or technical documentation.
  • Select a site.
  • Open Settings.
  • Select More sharing settings.
  • Choose the appropriate level: Only people in your organisation for confidential internal sites, Existing guests for tightly controlled collaboration, or New and existing guests where external collaboration is genuinely required.
  • If external access is limited to trusted partners, expand Advanced settings for external sharing and configure allowed or blocked domains.
  • Confirm the default sharing link is Specific people and the default permission is View.
  • Select Save.

A site cannot be configured more permissively than the organisation-wide setting.

6

Review existing external users and access

Changing the default link type does not automatically prove that all existing permissions are appropriate.

Review site access

  • For each important SharePoint site, open the site.
  • Select Settings → Site permissions.
  • Select Advanced permissions settings or review the displayed owners, members and visitors.
  • Look for external email addresses, guest accounts, unexpected groups, former suppliers or contractors, and users who no longer need access.
  • Remove unnecessary access.
  • For individual files or folders, select the item and then Details → Manage access.
  • Remove obsolete users and delete unnecessary sharing links.

Review guest accounts

  • Open the Microsoft 365 admin centre.
  • Go to Users → Guest users.
  • Review each guest account.
  • Confirm who invited the guest, which organisation they represent, whether access is still required, and whether their access is appropriately limited.
  • Remove guest accounts that no longer have a legitimate business requirement.

Do not remove a Microsoft 365 group from a Teams-connected SharePoint site without understanding the effect. Doing so can disrupt Teams file access and other collaboration functions.

Removing a guest account can affect every Microsoft 365 resource assigned to that guest, not just one document.

7

Audit sharing activity

  • Open the Microsoft Purview portal.
  • Select Solutions → Audit.
  • Create a new search.
  • Under activities, select Sharing and access request activities.
  • Select an appropriate date range.
  • Run the search.
  • Review or export the results.
  • Pay particular attention to AnonymousLinkCreated, AnonymousLinkUsed, SharingInvitationCreated, SharingInvitationAccepted, SecureLinkCreated and AddedToSecureLink.
  • Look for unusual volumes of external sharing and sensitive files shared outside the organisation.

Organisations with suitable SharePoint Advanced Management or Microsoft 365 E5 licensing may also use SharePoint admin centre → Reports → Data access governance. The sharing-links and site-permissions reports can help identify overshared sites. Microsoft recommends baseline permission reviews quarterly and recent sharing-activity reviews monthly.

Warnings

  • Existing anonymous links may stop working after "Anyone" sharing is disabled.
  • Client upload links and OneDrive Request Files links may fail.
  • External clients, suppliers and contractors may temporarily lose access.
  • Users may need to reshare files using Specific people links.
  • Automated systems that use anonymous SharePoint or OneDrive URLs may stop functioning.
  • Removing a guest from Microsoft Entra ID may revoke access across SharePoint, Teams and other Microsoft 365 services.
  • Turning external sharing off and later turning it back on can restore some previously configured access. Remove unwanted permissions and links rather than relying only on the organisation-wide switch.
  • Restricting sharing does not replace sensitivity labels, data-loss prevention, access reviews, MFA or ongoing auditing.
  • Microsoft changes its admin portals regularly, so some menu names may vary slightly.

Recommended ongoing procedure

  • Review external sharing activity monthly.
  • Review high-risk SharePoint sites quarterly.
  • Review guest accounts at least quarterly.
  • Require site owners to justify continuing external access.
  • Remove access immediately when a supplier, contractor or staff member leaves.
  • Maintain a business owner for every externally shared site.

Microsoft 365 disclaimer

These instructions are general security guidance and may not account for your Microsoft 365 licensing, business workflows, regulatory obligations or existing integrations. Incorrectly changing sharing permissions can interrupt client access, Teams collaboration, automated processes and external file collection.

Create a rollback plan, document the original settings and test changes before applying them across the organisation. Where Microsoft 365 contains business-critical or sensitive information, Netlogyx/Securemyemail recommends having the configuration reviewed and implemented by a qualified Microsoft 365 engineer.