← Microsoft 365 audit scope

SharePoint & OneDrive

10 checks · 2 sub-categories

Oversharing is quieter than a breach and just as damaging. Default Microsoft 365 sharing settings allow 'Anyone with the link' access that outlives the person who created it, and a departing staff member's OneDrive can vanish 30 days after their account is deleted — taking evidence and records with it.

External sharing posture

  • Default external sharing level

    Reports whether your tenant allows anonymous 'Anyone' links, and how many are currently live.

    • Privacy Act — unauthorised disclosure
    • CIS 3.6
  • Guests must sign in with the invited account

    Stops a shared invitation being forwarded and redeemed by somebody else entirely.

  • Guests blocked from resharing

    Prevents an external party passing your documents on to their own contacts without your knowledge.

  • Link expiry and default permission settings

    Checks whether sharing links expire and whether they default to view-only rather than edit.

  • Site-level overrides on sensitive sites

    Tenant-level settings can be loosened per site. We report any site sharing more widely than the tenant baseline.

Governance and retention

  • Site creation restricted to administrators

    Uncontrolled site sprawl produces data stores nobody owns, secures or backs up.

  • Deleted user OneDrive retention

    Confirms a departing staff member's OneDrive is retained (Microsoft's recommendation is one year) rather than the 30-day default.

    • Privacy Act — record retention
  • Data Loss Prevention policies in place

    Checks for DLP rules detecting TFNs, Medicare numbers, credit cards and other sensitive data leaving via sharing or email.

    • Privacy Act / NDB
    • CIS 3.4
  • Sensitivity labels and retention policies

    Whether Purview labelling exists and is actually applied, versus configured and unused.

  • Version history and recycle bin settings

    Adequate versioning is a meaningful part of ransomware recovery for cloud-stored documents.

    • Essential Eight — Regular backups

Want to know where you actually stand?

Every one of these checks is run as part of a single point-in-time audit, delivered as a plain-English, risk-prioritised report.