Microsoft 365 file access can become difficult to manage as a business grows. Files may be stored in OneDrive, SharePoint, Teams, email attachments and shared folders, with different permissions depending on how they were created or shared.
Over time, this can lead to a common problem: business owners and managers are not always sure who can access important company files.
That does not mean Microsoft 365 is insecure. In fact, Microsoft 365 includes strong access controls. The issue is usually that sharing permissions build up gradually. A document is shared for a project, an external user is invited into a Teams channel, a folder is shared with a supplier, or an employee leaves and nobody reviews what they previously had access to.
This guide explains why Microsoft 365 file access reviews matter, where permissions are usually managed, and what businesses should check regularly.
Why Microsoft 365 file access reviews matter
Most businesses use Microsoft 365 every day for email, documents, spreadsheets, Teams chats and shared files. That makes it one of the most important places to keep under control.
If file permissions are not reviewed, businesses can end up with:
- former employees still having access through old accounts or shared links
- external guests with access to folders they no longer need
- staff able to see sensitive HR, payroll or finance documents
- public or organisation-wide sharing links being used where they are not appropriate
- Teams and SharePoint sites with unclear ownership
- files being shared directly from personal OneDrive areas instead of controlled SharePoint locations
These issues are common in small and medium-sized businesses because Microsoft 365 tends to grow organically. People create Teams, share folders, invite guests and collaborate quickly. That flexibility is useful, but it also means access can drift over time.
Where Microsoft 365 files are usually stored
Before checking permissions, it helps to understand where Microsoft 365 files are normally held.
OneDrive
OneDrive is usually linked to an individual user. It is often used for personal work files, drafts and documents that a user has chosen to share with someone else.
OneDrive is convenient, but businesses should be careful when important company files live only in a user’s OneDrive. If that person leaves, changes role or deletes files, it can create access and recovery problems.
SharePoint
SharePoint is normally the better place for department, team or company files. It allows files to be stored in shared document libraries with permissions controlled at site, library, folder or file level.
Many businesses are using SharePoint without realising it because Teams uses SharePoint in the background for file storage.
Microsoft Teams
When users share files inside a Team or Channel, those files are usually stored in the connected SharePoint site. Permissions are often linked to the Team membership.
This means a Teams membership review is also a file access review. If someone is a member of a Team, they may have access to the documents stored behind it.
Sharing links
Microsoft 365 allows users to share files through links. Depending on your settings, these links may be limited to specific people, available to anyone in the organisation, or available to external users.
Sharing links are useful, but they are one of the most common ways file access becomes unclear.
What should you check?
A practical Microsoft 365 file access review should cover the main places where access can build up.
1. Review Teams membership
Start with Microsoft Teams. Check each Team and confirm whether the members still need access.
Pay particular attention to Teams used for:
- management
- finance
- HR
- client work
- supplier discussions
- projects involving confidential documents
If a user no longer needs access to a Team, remove them. This may also remove their access to the associated SharePoint files.
2. Check SharePoint site permissions
SharePoint permissions can be simple or complicated depending on how the site has been managed.
Review who has access to each important SharePoint site and whether they are owners, members or visitors.
Site owners usually have broad control, so this list should be kept small. If too many people are site owners, permissions become harder to manage and mistakes become more likely.
3. Check document libraries and folders
In many businesses, permissions are not only set at site level. They may also be changed on individual document libraries, folders or files.
This is where access can become messy. A folder may have unique permissions that do not match the rest of the site. A sensitive file may have been shared directly with users outside the normal group structure.
Look for folders or files with unique permissions and check whether those exceptions are still needed.
4. Review external users and guests
External sharing is useful for working with clients, suppliers, accountants, solicitors and contractors. However, external access should not be left unmanaged.
Check which guest users exist in Microsoft 365 and whether they still need access. If a supplier project has finished, or a client folder is no longer active, remove access.
This is especially important where external users were invited into Teams or SharePoint sites rather than being given access to one specific file.
5. Check sharing links
Sharing links are easy to create and easy to forget.
Look for links that allow broad access, such as links available to anyone in the organisation or external users. These may be appropriate in some cases, but they should be intentional.
For sensitive documents, it is usually better to use links that only work for named people.
6. Check leavers and old accounts
When an employee leaves, their Microsoft 365 access should be reviewed properly. It is not enough to only change a password or remove the licence.
A proper leaver process should check:
- whether the account is blocked from signing in
- whether email access has been delegated or converted to a shared mailbox
- whether OneDrive files need to be transferred
- whether the user was a Teams or SharePoint owner
- whether they created important sharing links
- whether their device access has been removed
This is where many businesses find hidden risk. A former employee may no longer have an active licence, but their files, permissions, ownerships and shared links may still need attention.
Common warning signs
There are some clear signs that a Microsoft 365 file access review is overdue.
- You do not know who owns your main SharePoint sites.
- Staff regularly use personal OneDrive folders for company files.
- External guests have not been reviewed for months.
- There are Teams that nobody actively manages.
- Users share files using broad links because it is quicker.
- Leavers are removed from email, but their OneDrive and Teams access is not reviewed.
- Managers are unsure where important company documents are stored.
If any of these apply, it is worth reviewing your Microsoft 365 setup before it becomes a bigger problem.
How often should businesses review Microsoft 365 file access?
For most small and medium-sized businesses, a basic access review every few months is sensible.
Higher-risk areas should be checked more often. This includes HR, finance, management, client files, legal documents and any data that would cause a problem if shared with the wrong person.
A practical schedule could be:
- Monthly: review leavers, guest users and high-risk Teams.
- Quarterly: review SharePoint site owners and key document libraries.
- Annually: review the wider Microsoft 365 structure, sharing policies and security settings.
The important thing is to make file access review part of normal business administration rather than only checking it after something has gone wrong.
Microsoft 365 settings also matter
Access reviews are not only about looking at individual users and folders. Your Microsoft 365 settings decide what users are allowed to do in the first place.
Businesses should review settings for:
- external sharing
- guest access
- anonymous links
- default sharing permissions
- Teams creation
- SharePoint site ownership
- multi-factor authentication
- Conditional Access, where available
- audit and alerting
If these settings are too open, users may be able to share data more widely than the business expects. If they are too restrictive, staff may find workarounds. The right setup should balance security with usability.
KES view
Microsoft 365 gives businesses excellent tools for collaboration, but it needs to be managed properly. File sharing should not be left to chance.
The biggest risks usually come from everyday activity: quick sharing links, old Teams, external guests, leavers and unclear ownership. None of these are unusual, but they can create real security and data protection issues if they are not reviewed.
For most businesses, the aim should not be to block sharing altogether. Staff need to collaborate. The aim is to make sure sharing is controlled, visible and appropriate.
KES can help review your Microsoft 365 setup, including Teams, SharePoint, OneDrive, external sharing, user access, account security and backup. If you are not sure who can access your Microsoft 365 files, it is better to check now than wait for a problem.
You may also find these related pages useful: