Module 5 of StartCloud's Microsoft 365 Security Essentials learning pathway, in six short units with a knowledge check: how SharePoint and OneDrive sharing links work, why Anyone links are the risky default, the four organisation-level external sharing settings, and a sensible small-business baseline with step-by-step setup.
Keeping Data Where It Belongs: SharePoint and OneDrive Sharing
How company files actually leak
When people picture a data leak they picture a hacker in a hoodie. The reality in most small businesses is far less cinematic. It is a quote spreadsheet shared with a supplier two years ago, forwarded on to someone you have never met, still opening perfectly today. Nobody broke in. Someone was let in, and the door never shut.
SharePoint and OneDrive make sharing wonderfully easy, and that is mostly a good thing. Microsoft actually recommends leaving external sharing on, because the alternative is worse: staff emailing attachments around or stashing files in personal Dropbox accounts where you have no visibility at all. The goal of this module is not to bolt everything shut. It is to set sensible defaults so the easy path is also the safe path.
The main culprit has a name: the Anyone link. It works for anyone who has it, no sign-in required, and because nobody signs in, you cannot see who has been reading your files. It can be forwarded endlessly, and unless you say otherwise, it never expires.
An Anyone link is the office key under the front mat. Handy when the plumber needs to get in, but once one person knows where it is, you have no idea who else does. The rest of this module is about deciding when the key comes out, and making sure it does not live under the mat forever.