External sharing in SharePoint and OneDrive allows people inside your business to share files, folders and sites with people outside your organisation. That could include clients, suppliers, contractors, accountants, solicitors, consultants or other trusted partners.
Used properly, external sharing is useful. It helps businesses collaborate without emailing documents back and forth or relying on personal file-sharing services. But if it is not reviewed, external sharing can become a security risk. Old links may still work, files may be shared with people who no longer need access, and sensitive data may be available outside the business for longer than intended.
This guide explains what external sharing means, where to check it, what mistakes to look for, and how to keep SharePoint and OneDrive sharing under better control.
What is external sharing in Microsoft 365?
External sharing is the ability to share Microsoft 365 content with people outside your organisation. In SharePoint and OneDrive, this usually means sharing files, folders, document libraries or sites with external users.
Microsoft describes external sharing as a way to collaborate with people outside the organisation, such as partners, suppliers, clients and customers. It should be considered as part of your wider permissions planning, not treated as a simple on/off setting.
In practical terms, external sharing can include:
- sharing a OneDrive file with a client;
- giving a supplier access to a SharePoint folder;
- allowing a contractor to access a project site;
- sending a sharing link to someone outside the business;
- adding a guest user to a Microsoft Teams-connected SharePoint site.
Why external sharing matters
Most businesses need to share documents externally at some point. The issue is not whether external sharing should exist. The issue is whether it is controlled properly.
External sharing matters because it affects:
- data security: who can access business files;
- confidentiality: whether sensitive information is shared too widely;
- compliance: whether access is appropriate for the type of data held;
- business continuity: whether access remains manageable when staff leave;
- Copilot readiness: whether Microsoft 365 data is structured and permissioned sensibly before AI tools are used more widely.
If external sharing is left unmanaged, a business may not know which files are available to people outside the organisation. That becomes more serious when documents include financial information, customer records, HR files, contracts or internal planning documents.
SharePoint external sharing vs OneDrive external sharing
SharePoint and OneDrive both support external sharing, but they are usually used for different purposes.
OneDrive is personal work storage. It is commonly used for files that belong mainly to one user, such as drafts, working notes and documents that are being prepared before they are moved into a shared team location.
SharePoint is team, department or company storage. It is better suited to shared business files, document libraries, policies, project folders and information that needs to remain available to the organisation.
That distinction matters because a file shared from OneDrive is usually linked to one user’s storage. A file shared from SharePoint is usually part of a wider team or company structure.
For more background, see our guide on SharePoint vs OneDrive and which your business should use.
What should businesses check?
When reviewing external sharing in SharePoint and OneDrive, businesses should check both the high-level settings and the individual files, folders and sites that may already have been shared.
A good review should include:
- organisation-wide sharing settings;
- SharePoint site sharing settings;
- individual OneDrive sharing settings;
- external guest users;
- anonymous or “anyone with the link” sharing links;
- files shared with specific external people;
- old project folders and historic sharing links;
- sensitive areas such as finance, HR, management and customer data.
Check the organisation-wide sharing settings
The first place to review is the organisation-level sharing configuration. This controls the broadest level of external sharing available across SharePoint and OneDrive.
For example, a business may allow:
- no external sharing;
- sharing only with existing guests;
- sharing with new and existing guests;
- anonymous links, often described as “anyone with the link”.
The more open the setting, the more carefully it needs to be managed. “Anyone with the link” sharing can be convenient, but it is often unsuitable for sensitive business information because access may be harder to trace and control.
Microsoft’s guidance also explains that external sharing can be restricted further for specific users’ OneDrive accounts after the organisation-wide SharePoint and OneDrive settings are configured. :contentReference[oaicite:1]{index=1}
Check external sharing on SharePoint sites
Next, check the sharing settings for individual SharePoint sites. This is important because different sites may hold very different types of data.
For example, a general marketing site may have different sharing requirements from a finance, HR or management site. A project site used with a trusted external contractor may also need different controls from an internal-only company policy site.
Microsoft notes that SharePoint site sharing settings require SharePoint Administrator permissions to change, and that Microsoft Entra guest access settings should also be reviewed as part of SharePoint and OneDrive sharing setup. :contentReference[oaicite:2]{index=2}
When checking SharePoint sites, review:
- which sites allow external sharing;
- whether external users have access to whole sites or only specific folders/files;
- whether external access is still needed;
- whether sensitive sites are more restricted;
- whether Microsoft Teams-connected sites have inherited guest access that is no longer needed.
Check external sharing in OneDrive
OneDrive sharing needs particular attention because users may share files directly from their own storage. That can be useful for quick collaboration, but it can also create unmanaged sharing links over time.
When reviewing OneDrive, check:
- which users are allowed to share externally;
- whether senior staff or sensitive departments need tighter controls;
- whether old files are still shared externally;
- whether leavers had shared important business files from their OneDrive;
- whether staff understand when to use OneDrive and when to use SharePoint instead.
Microsoft’s OneDrive guidance confirms that individual OneDrive external sharing can be further restricted after the organisation-wide settings are set. :contentReference[oaicite:3]{index=3}
Review “anyone with the link” sharing
One of the most important checks is whether the business allows links that work for anyone who has the link.
These links can be convenient, especially when sending information to a client who does not have a Microsoft account. But they also carry more risk because access is not tied as strongly to a named person.
Where possible, businesses should favour more controlled sharing, such as sharing with specific people who need to verify their identity.
Microsoft’s guidance on restricting external sharing to security groups distinguishes between authenticated guest sharing and “Anyone” links, noting that with Anyone links you cannot track who has access to shared items or who has accessed them. :contentReference[oaicite:4]{index=4}
Consider who is allowed to share externally
Not every user needs the same sharing rights. In many businesses, it may be sensible to allow external sharing only for certain roles or groups.
For example:
- project managers may need to share with contractors;
- finance staff may need to share with accountants;
- sales staff may need to share proposals with prospects;
- most general users may not need open external sharing at all.
Microsoft allows administrators to restrict external sharing so that only users in specific security groups can share SharePoint and OneDrive files and folders externally. :contentReference[oaicite:5]{index=5}
Common mistakes businesses make
Leaving external sharing too open
The most obvious mistake is allowing external sharing too broadly across the whole organisation. This can make collaboration easier, but it also increases the chance of accidental oversharing.
Using OneDrive for long-term shared business files
OneDrive is useful for personal work files and drafts, but it should not become the long-term home for shared company documents. Important business files should usually be moved into a suitable SharePoint location.
Not reviewing old links
External sharing often starts with a genuine business need. The problem is that access may remain in place long after the project, contract or client work has finished.
Giving external users too much access
Sometimes external users are given access to a whole site or folder when they only need one file. This increases risk and makes permissions harder to manage.
Ignoring Teams-connected SharePoint sites
Microsoft Teams and SharePoint are closely connected. Files shared in Teams channels are usually stored in SharePoint, so guest access and team membership can affect document access too.
Assuming Microsoft 365 backup is automatic
External sharing and backup are separate issues, but they are connected in practice. If files are accidentally deleted, overwritten or affected by compromised accounts, businesses need to understand what can be recovered and how quickly.
For more detail, see our guide on Microsoft 365 backup and why recovery matters.
Best practice for external sharing
External sharing does not need to be switched off completely, but it should be deliberate and reviewed regularly.
Good practice includes:
- using SharePoint for shared business files;
- using OneDrive mainly for personal work files and drafts;
- limiting “anyone with the link” sharing;
- sharing with specific people where possible;
- reviewing external users and guest access regularly;
- using security groups to control who can share externally;
- applying stricter controls to sensitive sites;
- training staff on when and how to share files;
- checking external sharing before rolling out Copilot more widely.
External sharing and Copilot readiness
Microsoft 365 Copilot makes it easier for users to find, summarise and work with business content they already have permission to access. That means permissions and sharing settings become more important, not less.
If documents are shared too widely, Copilot may make those documents easier to discover by users who already have access. This is why file permissions, external sharing and SharePoint structure should be reviewed before wider Copilot adoption.
For related guidance, read our articles on how to check who has access to Microsoft 365 files and Copilot in SharePoint and why file permissions matter.
Where KES can help
KES helps businesses review Microsoft 365 security, file sharing, OneDrive, SharePoint, permissions, backup and wider IT resilience.
If your business has used Microsoft 365 for several years, there may be old sharing links, guest users, Teams sites and OneDrive files that have never been properly reviewed.
A KES Technology MOT can help identify where files are being shared, whether external access is still appropriate, and whether your Microsoft 365 setup is ready for wider use of tools such as Copilot.
Conclusion
External sharing in SharePoint and OneDrive is useful, but it needs to be managed carefully. Businesses should know who can share files externally, which files and sites are already shared, and whether old access still needs to exist.
For most organisations, the best approach is not to block all external sharing. It is to make external sharing deliberate, controlled and regularly reviewed.
If you are unsure how exposed your Microsoft 365 files are, contact KES to arrange a Microsoft 365 review.
External Sharing in SharePoint and OneDrive FAQs
What is external sharing in SharePoint and OneDrive?
External sharing allows users to share SharePoint and OneDrive files, folders or sites with people outside the organisation, such as clients, suppliers, contractors or partners.
Is external sharing safe?
External sharing can be safe when it is properly controlled. The risk comes from sharing too broadly, using anonymous links, giving external users more access than they need, or failing to review old sharing links.
Should businesses allow “anyone with the link” sharing?
For sensitive business data, “anyone with the link” sharing should usually be avoided or tightly restricted. Sharing with specific authenticated people is normally safer and easier to control.
Can external sharing be restricted for specific users?
Yes. Microsoft 365 allows external sharing settings to be managed at organisation, site and user level. Administrators can also restrict external sharing to specific security groups.
Why does external sharing matter for Microsoft 365 Copilot?
Copilot can help users find and work with information they already have permission to access. If files are shared too widely, Copilot may make that information easier to discover. That is why permissions and external sharing should be reviewed before wider Copilot adoption.