Module 5 of StartCloud's Microsoft 365 Security Essentials learning pathway, in six short units with a knowledge check: how SharePoint and OneDrive sharing links work, why Anyone links are the risky default, the four organisation-level external sharing settings, and a sensible small-business baseline with step-by-step setup.
Keeping Data Where It Belongs: SharePoint and OneDrive Sharing
How company files actually leak
When people picture a data leak they picture a hacker in a hoodie. The reality in most small businesses is far less cinematic. It is a quote spreadsheet shared with a supplier two years ago, forwarded on to someone you have never met, still opening perfectly today. Nobody broke in. Someone was let in, and the door never shut.
SharePoint and OneDrive make sharing wonderfully easy, and that is mostly a good thing. Microsoft actually recommends leaving external sharing on, because the alternative is worse: staff emailing attachments around or stashing files in personal Dropbox accounts where you have no visibility at all. The goal of this module is not to bolt everything shut. It is to set sensible defaults so the easy path is also the safe path.
The main culprit has a name: the Anyone link. It works for anyone who has it, no sign-in required, and because nobody signs in, you cannot see who has been reading your files. It can be forwarded endlessly, and unless you say otherwise, it never expires.
An Anyone link is the office key under the front mat. Handy when the plumber needs to get in, but once one person knows where it is, you have no idea who else does. The rest of this module is about deciding when the key comes out, and making sure it does not live under the mat forever.
Every time someone hits Share in SharePoint or OneDrive, they are creating a link, and the type of link decides who can open it. Microsoft gives you three main types, and the whole game of sharing security is knowing which one is in play.
(There is a fourth option in the share dialog, People with existing access, which grants nothing new. It just hands out the address to people who could already get in.)
The open link
Works for anyone who has it, inside or outside your business, with no sign-in at all. Microsoft describes it as a transferable, revocable secret key: it can be forwarded to anybody, you can kill it by deleting it, but you cannot see who has used it because nobody authenticates.
- No sign-in, so access cannot be audited
- Forwards freely to people you never chose
- Can be revoked by deleting the link
- The one to keep on a short leash
The internal link
Works only for members of your Microsoft 365 tenant, and everyone has to sign in. It still forwards freely, but only inside the walls: send it to someone outside the business (or even a guest in your directory) and it simply does not work.
- Recipients must sign in as a member
- Useless outside your tenant, guests included
- Forwards safely within the business
- Great default for everyday internal sharing
The named-invitation link
Works only for the exact people named when the link is created, inside or outside the business, and each of them has to prove who they are. Microsoft calls it a nontransferable, revocable secret key: forward it to anyone else and it is a dud.
- Only works for the people you name
- Recipients authenticate, so access is auditable
- Safest way to share outside the business
- The best habit to teach your team
Worth knowing: creating a link does not broadcast the file to everyone it could reach. A People in your organisation link, for example, does not make the file visible to the whole company. Someone still has to be given the link and click it before they get access.
Link types are what your staff choose day to day. Sitting above them is a control only admins see: the organisation-level external sharing setting on the Sharing page of the SharePoint admin center. Think of it as a dial with four positions, from wide open to fully shut.
Whatever you pick, the more restrictive options underneath remain available to users. Setting the dial to Anyone does not force anyone to use Anyone links, it just permits them.
Staff can create Anyone links that work with no sign-in, plus everything the levels below allow. This is the out-of-the-box setting, which is exactly why so many tenants are oversharing without knowing it.
Sharing outside the business still works, but every outsider must sign in or verify a code, and they are added to your directory as a guest. You can see who they are and cut them off later. Anyone links stop being possible.
Staff can only share with guests who are already in your directory. Nobody new gets in via a sharing invite. Sounds tidy, but Microsoft does not recommend it because guests arrive in the directory through plenty of other routes anyway.
External sharing is off entirely. Right for genuinely sensitive sites, but as a whole-of-business setting it usually just pushes people back to email attachments.
Two dials, one rule. SharePoint and OneDrive each get their own dial, but the OneDrive setting can never be more permissive than the SharePoint one. Tighten SharePoint and OneDrive follows.
Sites can only tighten, never loosen. The organisation setting is the ceiling. Individual sites can be locked down further (your finance site can be internal-only while the rest of the business shares with guests), but no site can ever be more open than the organisation allows.
There is no single right answer for every business, but after setting this up for a lot of Perth SMBs, the combination below is where we usually land. It keeps collaboration easy while quietly closing the doors that cause the horror stories.
Sharing with clients and suppliers keeps working, but everyone outside the business has to prove who they are, and you keep an auditable guest list. Set SharePoint and OneDrive both to this level.
The share dialog pre-selects the safest link, so the lazy click is also the safe click. Staff can still deliberately pick a broader link when they genuinely need one.
Guest access to a site or OneDrive lapses automatically after the period you set, so a contractor from two financial years ago is not still wandering the halls.
Per-site overrides let you lock down finance, HR, and anything with payroll in it, while everyday project sites stay collaborative.
What if you genuinely need Anyone links?
Some businesses have a real case for them, like collecting files from the public with OneDrive file requests, which only work when Anyone links are on. If that is you, keep the dial at Anyone but use the two guard rails Microsoft provides: force every Anyone link to expire within a set number of days (30 is a good start), and restrict Anyone links on files to view-only. A link that dies in a month and cannot be edited is a much smaller key under the mat.
If you move the dial from a guest-friendly setting to Only people in your organisation, existing links shared with guests stop working, and guests typically lose access within about an hour. That is usually the point of the exercise, but do it unannounced and your phone will tell you exactly who was relying on those links. A short heads-up email saves the drama.
Everything below happens in the SharePoint admin center. Get there from the Microsoft 365 admin center at admin.microsoft.com (under Admin centers, choose SharePoint), signed in as a SharePoint Administrator or Global Administrator.
- 1In the SharePoint admin center, go to Policies, then Sharing.
- 2Under External sharing, drag the SharePoint slider to New and existing guests, and set OneDrive to the same level (it can match SharePoint or be stricter, never looser).
- 3Under File and folder links, set the default link type to Specific people, and pick the default permission your business prefers (View is the cautious choice).
- 4Expand More external sharing settings and set guest access to expire automatically, for example after 90 days.
- 5If you kept the dial at Anyone, also set the advanced Anyone-link options: links must expire within your chosen number of days, and file permissions are View only.
- 6Select Save.
- 1In the SharePoint admin center, go to Sites, then Active sites.
- 2Select the site you want to tighten (finance, HR, board papers, anywhere payroll lives).
- 3On the Settings tab, select More sharing settings.
- 4Choose Only people in your organisation, and select Save.
- 5Repeat for each sensitive site. Everyday project sites can stay on the organisation default.
The same screen lets you override the default link type and guest expiry for that one site, by clearing the Same as organisation-level setting boxes. Handy when one site needs different rules to the rest.
If you ever switch external sharing off for the whole organisation and later switch it back on, guests get their old access back. If you tightened things because of a specific site, turn off sharing on that site as well, not just at the organisation level.
- Microsoft Learn: How shareable links work in OneDrive and SharePoint in Microsoft 365
- Microsoft Learn: Manage sharing settings for SharePoint and OneDrive in Microsoft 365
- Microsoft Learn: Plan sharing and collaboration options in SharePoint and OneDrive
- Microsoft Learn: Change the sharing settings for a site
- Microsoft Learn: Change the default sharing link type for a site
Steps were current at the time of writing (July 2026). Microsoft occasionally moves things around the admin centre, so screens may vary slightly.
Knowledge check
5 quick questions. Get 4 right and the module is yours.
1. Which sharing link works without any sign-in at all?
2. Why are Anyone links the risky default to tame?
3. Which organisation-level setting switches external sharing off entirely?
4. What does a sensible baseline look like for most small businesses?
5. You tighten the dial from New and existing guests to Only people in your organisation. What happens to files already shared with guests?