0%
1 min left of 1 min read Microsoft 365 help →
01622 721000 info@kesuk.net
  • Facebook
  • X
  • Instagram
  • Facebook
  • X
  • Instagram
KES
  • Home
  • Managed IT
    • Managed Services
    • Free Technology MOT
    • Essential IT Support Pack
    • Business User Pack
    • Remote Managed IT Support
    • accountants-it
    • IT Support for Professional Services
    • Private Data Rooms
  • Services
    • Microsoft 365
    • Cyber Security
    • Connectivity
    • Hosted Voice
    • IT Support Maidstone
    • Leased Lines
    • Computer Repair
    • Computer Sales
    • Renewed Computers
    • Green Recycling
  • Pricing
    • IT Support Pricing Calculator
    • Leased Line Pricing Calculator
    • Fibre Broadband
    • Managed Services Pricing FAQ
  • Learning Centre
    • IT Support
    • Microsoft 365
      • Microsoft 365 News
      • Microsoft 365 Licensing
      • Microsoft 365 Security
      • Microsoft 365 Guides
    • Cyber Security
    • Backup & Recovery
    • Connectivity
    • View All Articles
  • Contact Us
  • Support
Select Page

How to Check Who Has Access to Your Microsoft 365 Files

by Mark Roach | Jul 10, 2026 | Guides

Microsoft 365 file access review showing SharePoint, OneDrive and Teams permissions on a laptop

Microsoft 365 file access can become difficult to manage as a business grows. Files may be stored in OneDrive, SharePoint, Teams, email attachments and shared folders, with different permissions depending on how they were created or shared.

Over time, this can lead to a common problem: business owners and managers are not always sure who can access important company files.

That does not mean Microsoft 365 is insecure. In fact, Microsoft 365 includes strong access controls. The issue is usually that sharing permissions build up gradually. A document is shared for a project, an external user is invited into a Teams channel, a folder is shared with a supplier, or an employee leaves and nobody reviews what they previously had access to.

This guide explains why Microsoft 365 file access reviews matter, where permissions are usually managed, and what businesses should check regularly.

Why Microsoft 365 file access reviews matter

Most businesses use Microsoft 365 every day for email, documents, spreadsheets, Teams chats and shared files. That makes it one of the most important places to keep under control.

If file permissions are not reviewed, businesses can end up with:

  • former employees still having access through old accounts or shared links
  • external guests with access to folders they no longer need
  • staff able to see sensitive HR, payroll or finance documents
  • public or organisation-wide sharing links being used where they are not appropriate
  • Teams and SharePoint sites with unclear ownership
  • files being shared directly from personal OneDrive areas instead of controlled SharePoint locations

These issues are common in small and medium-sized businesses because Microsoft 365 tends to grow organically. People create Teams, share folders, invite guests and collaborate quickly. That flexibility is useful, but it also means access can drift over time.

Where Microsoft 365 files are usually stored

Before checking permissions, it helps to understand where Microsoft 365 files are normally held.

OneDrive

OneDrive is usually linked to an individual user. It is often used for personal work files, drafts and documents that a user has chosen to share with someone else.

OneDrive is convenient, but businesses should be careful when important company files live only in a user’s OneDrive. If that person leaves, changes role or deletes files, it can create access and recovery problems.

SharePoint

SharePoint is normally the better place for department, team or company files. It allows files to be stored in shared document libraries with permissions controlled at site, library, folder or file level.

Many businesses are using SharePoint without realising it because Teams uses SharePoint in the background for file storage.

Microsoft Teams

When users share files inside a Team or Channel, those files are usually stored in the connected SharePoint site. Permissions are often linked to the Team membership.

This means a Teams membership review is also a file access review. If someone is a member of a Team, they may have access to the documents stored behind it.

Sharing links

Microsoft 365 allows users to share files through links. Depending on your settings, these links may be limited to specific people, available to anyone in the organisation, or available to external users.

Sharing links are useful, but they are one of the most common ways file access becomes unclear.

What should you check?

A practical Microsoft 365 file access review should cover the main places where access can build up.

1. Review Teams membership

Start with Microsoft Teams. Check each Team and confirm whether the members still need access.

Pay particular attention to Teams used for:

  • management
  • finance
  • HR
  • client work
  • supplier discussions
  • projects involving confidential documents

If a user no longer needs access to a Team, remove them. This may also remove their access to the associated SharePoint files.

2. Check SharePoint site permissions

SharePoint permissions can be simple or complicated depending on how the site has been managed.

Review who has access to each important SharePoint site and whether they are owners, members or visitors.

Site owners usually have broad control, so this list should be kept small. If too many people are site owners, permissions become harder to manage and mistakes become more likely.

3. Check document libraries and folders

In many businesses, permissions are not only set at site level. They may also be changed on individual document libraries, folders or files.

This is where access can become messy. A folder may have unique permissions that do not match the rest of the site. A sensitive file may have been shared directly with users outside the normal group structure.

Look for folders or files with unique permissions and check whether those exceptions are still needed.

4. Review external users and guests

External sharing is useful for working with clients, suppliers, accountants, solicitors and contractors. However, external access should not be left unmanaged.

Check which guest users exist in Microsoft 365 and whether they still need access. If a supplier project has finished, or a client folder is no longer active, remove access.

This is especially important where external users were invited into Teams or SharePoint sites rather than being given access to one specific file.

5. Check sharing links

Sharing links are easy to create and easy to forget.

Look for links that allow broad access, such as links available to anyone in the organisation or external users. These may be appropriate in some cases, but they should be intentional.

For sensitive documents, it is usually better to use links that only work for named people.

6. Check leavers and old accounts

When an employee leaves, their Microsoft 365 access should be reviewed properly. It is not enough to only change a password or remove the licence.

A proper leaver process should check:

  • whether the account is blocked from signing in
  • whether email access has been delegated or converted to a shared mailbox
  • whether OneDrive files need to be transferred
  • whether the user was a Teams or SharePoint owner
  • whether they created important sharing links
  • whether their device access has been removed

This is where many businesses find hidden risk. A former employee may no longer have an active licence, but their files, permissions, ownerships and shared links may still need attention.

Common warning signs

There are some clear signs that a Microsoft 365 file access review is overdue.

  • You do not know who owns your main SharePoint sites.
  • Staff regularly use personal OneDrive folders for company files.
  • External guests have not been reviewed for months.
  • There are Teams that nobody actively manages.
  • Users share files using broad links because it is quicker.
  • Leavers are removed from email, but their OneDrive and Teams access is not reviewed.
  • Managers are unsure where important company documents are stored.

If any of these apply, it is worth reviewing your Microsoft 365 setup before it becomes a bigger problem.

How often should businesses review Microsoft 365 file access?

For most small and medium-sized businesses, a basic access review every few months is sensible.

Higher-risk areas should be checked more often. This includes HR, finance, management, client files, legal documents and any data that would cause a problem if shared with the wrong person.

A practical schedule could be:

  • Monthly: review leavers, guest users and high-risk Teams.
  • Quarterly: review SharePoint site owners and key document libraries.
  • Annually: review the wider Microsoft 365 structure, sharing policies and security settings.

The important thing is to make file access review part of normal business administration rather than only checking it after something has gone wrong.

Microsoft 365 settings also matter

Access reviews are not only about looking at individual users and folders. Your Microsoft 365 settings decide what users are allowed to do in the first place.

Businesses should review settings for:

  • external sharing
  • guest access
  • anonymous links
  • default sharing permissions
  • Teams creation
  • SharePoint site ownership
  • multi-factor authentication
  • Conditional Access, where available
  • audit and alerting

If these settings are too open, users may be able to share data more widely than the business expects. If they are too restrictive, staff may find workarounds. The right setup should balance security with usability.

KES view

Microsoft 365 gives businesses excellent tools for collaboration, but it needs to be managed properly. File sharing should not be left to chance.

The biggest risks usually come from everyday activity: quick sharing links, old Teams, external guests, leavers and unclear ownership. None of these are unusual, but they can create real security and data protection issues if they are not reviewed.

For most businesses, the aim should not be to block sharing altogether. Staff need to collaborate. The aim is to make sure sharing is controlled, visible and appropriate.

KES can help review your Microsoft 365 setup, including Teams, SharePoint, OneDrive, external sharing, user access, account security and backup. If you are not sure who can access your Microsoft 365 files, it is better to check now than wait for a problem.

You may also find these related pages useful:

  • Microsoft 365 Business Premium
  • Cyber Security
  • Security Review
  • Business User Pack
  • Business Email Exposure Check
author avatar
Mark Roach
See Full Bio

Recent Posts

  • SharePoint Can Now Split and Merge PDFs with Copilot
  • Windows 11 Automatic Settings Backup: Are Files Protected?
  • Windows 11 26H2 Is Available: Should Your Business Upgrade Now?
  • The 30-Minute IT Check Every Small Business Should Do Once a Month
  • Windows 11 Black Screen After Sign-In: Microsoft Confirms Virtual Desktop Issue

Recent Comments

No comments to show.
KES logo: circular blue gradient with the letters KES in lighter blue

Kent Electronic Services (KES) Limited, provide IT managed services & support. Your trusted outsourced IT department provider.

Managed Services

  • Managed Services
  • Remote Monitoring & Management
  • Microsoft 365
  • M365 Cloud Backup
  • Referral Program
  • Contact Us
  • Terms & Conditions
  • Privacy
  • Sitemap

Our Address

Map showing Kent Electronic Services at The Friars in Aylesford Open in Google Maps

Copyright © 2026 - Kent Electronic Services (KES) Limited

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}