Here’s the short version: SharePoint external sharing is a ceiling you set on purpose, not a convenience toggle. Anyone-links and immortal guests are how client files leave the firm. Disable Anyone, expire guests, and make finance sites stricter than the marketing library.
Microsoft documents external sharing and how to turn it on or off. The product is flexible. Your insurer is not. “We needed to send a file” is not a control.
This is the explainer next to our SharePoint oversharing cleanup case study. If Copilot is on your roadmap, read Microsoft 365 Copilot security after this. Copilot will summarize whatever these settings allow.
The four SharePoint external sharing levels
Microsoft’s collaboration options page is the planning version of this list. From most open to most closed:
- Anyone (anonymous links). No sign-in. Forwardable. The default disaster.
- New and existing guests. People can be invited. They get a guest account.
- Existing guests. Only people already in your directory as guests.
- Only people in your organization. No external sharing on that site.
The org-wide setting is the maximum. A site can be tighter. A site cannot be looser than the org. That is the fact people miss when they “lock one library” and leave the tenant on Anyone. Microsoft says the same in site-level sharing: site settings cannot be more permissive than the organization.
OneDrive cannot be more open than SharePoint org defaults. Teams channel files follow the site. Private chat files follow OneDrive. Treat them as one problem. If you only flip SharePoint admin and leave OneDrive on Anyone, you did not finish.
Anyone-links are not a workflow
Microsoft’s shareable links article is blunt: people using an Anyone link do not authenticate, and their access cannot be audited the way a guest can. The link is a transferable, revocable secret. Forwarding is the feature.
They feel fast. They do not expire unless you force expiration. They get forwarded to a personal Gmail, then to a contractor, then to whoever bought that inbox. You will not see a guest object to disable when the person leaves, because there is no person in your directory.
If you must keep Anyone for one public brochure library, isolate that site, do not use it for client work, and set link expiration in hours or days, not “never.” View-only if you even allow edit.
For client files, specific people or existing guests. Always.
People will say they cannot work. What they mean is they cannot paste an Anyone-link into a text. The new path is: invite this person, or share with this email, or ask help desk. That is slower by thirty seconds and faster than a breach notification.
When a client refuses to create a Microsoft account, you have options: a guest they accept, a portal you already use, or a short-lived link on a library built for that. You do not have “turn Anyone back on for the whole tenant.”

Guests need owners and end dates
A guest without an owner is a vendor you forgot. Offboarding has to include guests. Vendor risk has to include SharePoint, not only VPN.
SharePoint and Entra B2B integration is why a SharePoint invite often creates a real guest in Entra. B2B collaboration is the directory side of that guest. That is good: you can disable the person. It is also why a guest on a Teams site may still have a directory object after you delete one sharing link. Removing a link is not the same as removing the guest.
Policy that works in a 20-person firm:
- Every guest has an internal owner.
- 90-day access reviews or auto-expire. Microsoft’s org sharing page includes guest access to a site or OneDrive will expire automatically after this many days. Turn it on.
- Finance, HR, legal, clinical sites: no guests unless a named exception.
- No guests on the whole-company hub site.
Microsoft Entra access reviews exist if you have the license. If you do not, a quarterly export and a spreadsheet still beats never.
Train the people who actually share: office manager, paralegals, producers. A 40-person all-hands is theater. Two 15-minute sessions with the people who click Share is the project.
Site-by-site beats one tenant slider
Set the org to “new and existing guests” or “existing only” with Anyone off. Then walk the sites that hold real work. Site settings are in SharePoint admin, per site. The default the Share dialog offers is a separate control: change the default sharing link for the organization, then override it on the sites that should be stricter.
| Site type | Suggested sharing |
|---|---|
| Intranet / all-staff | Internal only |
| Finance / HR | Internal only |
| Client project | Existing guests or specific people |
| Marketing assets meant to be public | Isolated site, tight expiration if Anyone at all |
Broken inheritance is how one “temp” folder stays open for years. Note it. Fix it or accept it in writing.
Default link type should be specific people, not “people in your organization” and not Anyone. Default permission view, not edit, unless the site is a working library where edit is the point.
OneDrive must match. Confirm it. Then open a Teams channel, click Share on a file, and see what the dialog offers. The dialog is the user experience. The admin slider is not.
How to test SharePoint external sharing
- Create a dummy file in a client library. Not a real matter.
- Try an Anyone-link. It should fail if you did the job.
- Invite a test guest to a project site. Confirm they cannot see finance.
- As a normal user, confirm they cannot raise sharing above the site default.
- Check OneDrive defaults match.
- Open sharing reports. Sort by Anyone and by oldest.
If step 2 succeeds on a matter file, you are not done. The org slider can look locked while a library with broken inheritance still mints anonymous URLs.
Reports you should actually open
Sharing reports in SharePoint admin. Guest list in Entra. Data loss prevention if you have it, for the “went to a personal Gmail” class. None of these are exciting. All of them beat a feeling.
If Copilot is coming, these reports are the readiness test. If a typical user can already open the file, Copilot can talk about it. Sharing is the control. The chat box is the loudspeaker.

A two-week cleanup
Week 1: stop the bleeding
Screenshot org sharing and OneDrive sharing first. Then org Anyone off. Default link type to specific people. Expiration on. OneDrive matched.
Week 2: reports and guests
Sharing reports. Kill old Anyone-links on finance and legal first. Disable orphan guests. Tell the office why “just send the link” changed.
Help desk will hear “I cannot share.” Give them the new path: specific people, named guest, or a ticket.
A 30-person firm we cleaned had org sharing on Anyone, “because clients.” Sharing reports showed 200 live anonymous links, including a compensation worksheet and a folder named Final-Final that was a matter file. We set org to existing guests, Anyone off, 14-day link expiration, OneDrive matched. Then we killed Anyone-links on finance and HR the same afternoon. Project sites kept named guests. Two clients complained for a day. Help desk sent a three-line how-to. The compensation file stopped being a URL.
That is the whole job: ceiling, then the sites that would embarrass you on a portal.
Do not wait for Copilot or a breach to do this. Cybersecurity without a sharing default is a program that still emails the file room to the world.
Law firms, clinics, and client files
Privilege and ePHI do not care that the link was convenient. A matter folder on Anyone is a disclosure waiting for a forward. A clinic library shared to the whole company is a Copilot answer later. Set those sites to internal only, then share a specific file with a named person when you must.
If a client portal already exists (Clio, a PACS, a billing site), use it. SharePoint is not always the right truck.
Expiration is not rude. It is how you stop last year’s deal from staying world-readable. 7 or 14 days for Anyone if you even allow it. 90 days for guests. Owners get a mail before expiry. That mail is the reminder to renew on purpose.
People will store the same file in email anyway. That is a different control (M365 backup, DLP, MFA). Sharing defaults are still worth doing.
Printable sharing checklist
- Screenshot org sharing and OneDrive sharing.
- Set Anyone off. Default to specific people. Turn on expiration.
- Match OneDrive to SharePoint. Confirm Teams files follow.
- Set finance, HR, legal, clinical sites to internal only.
- Run sharing reports. Sort by Anyone and by oldest.
- Delete or expire Anyone-links on those sites first.
- Export guests. Owner or disable.
- Test with a dummy file: Anyone should fail on a matter library.
- Tell the people who actually click Share.
- Re-check reports in 30 days. New Anyone-links are the drift.
If step 8 fails, stop and fix the site. Do not declare victory from the org slider alone. A library with broken inheritance will ignore your speech.
If you want Anyone-links killed and guests dated as a project, contact Secure Techies. We work from Canoga Park. We will set the ceiling, then walk the sites that actually hold client files. Bring a list of sites you think are confidential. We will check whether the tenant agrees.
