Call NowFree Quote
Microsoft 365

How to Audit External Sharing in SharePoint and OneDrive

Every "just share it with them quickly" link is reasonable in the moment. The problem is nobody circles back to remove access once the reason for sharing has passed, and years of this leaves most businesses with far more externally accessible data than anyone realises.

Why This Matters More Than It Used To

Broad or forgotten external sharing was always a risk, but it's become more visible with tools like Copilot actively searching across everything a user can access - a file shared too broadly years ago can suddenly become far easier to surface. See our guide on the Microsoft 365 Copilot readiness checklist for that specific angle.

Understanding the Sharing Link Types

  • Anyone links: work for whoever has the URL, no sign-in required - the broadest, riskiest option
  • Specific people links: require the recipient to verify their identity, far more controllable
  • Organisation-wide links: accessible to anyone signed into your tenant, useful internally but shouldn't be confused with genuinely external sharing

How to Run the Audit

Step 1: Pull a Sharing Report

The SharePoint admin centre includes reporting on externally shared content across sites and OneDrive. This is the starting inventory - export it rather than trying to check site by site manually.

Step 2: Prioritise "Anyone" Links First

These carry the most risk since anyone with the link can access the file indefinitely, regardless of whether they were the intended recipient. Review and convert these to specific-people links, or remove them, as the first priority.

Step 3: Check for Stale External Access

Cross-reference external sharing against active projects, clients, and partners - access still active for a project that finished a year ago is exactly the kind of forgotten permission this audit exists to catch.

Step 4: Review Guest User Accounts

External sharing often creates guest user accounts in your tenant. Review these alongside the sharing audit - a guest account from a long-closed engagement is both a sharing risk and an unnecessary account sitting in your directory.

Reducing the Risk Going Forward

  • Set a default expiration date on external sharing links at the tenant level, so forgotten links naturally lapse
  • Default to "specific people" links rather than "anyone" links where practical
  • Apply sensitivity labels to genuinely sensitive content so it can't be shared externally at all, regardless of user intent
  • Build a periodic sharing review into your regular Microsoft 365 maintenance, not just a one-off cleanup

Where This Fits Into Broader Governance

This audit pairs naturally with a general permissions review - see our guide on auditing Microsoft 365 user permissions for the wider process, and our guide on Microsoft Purview DLP for how to prevent risky sharing before it happens, not just find it after the fact.

Frequently Asked Questions

What's the difference between 'Anyone' links and 'Specific people' links?

An 'Anyone' link works for whoever has the URL, with no sign-in required - the broadest and riskiest sharing option, since the link can be forwarded indefinitely. 'Specific people' links restrict access to named individuals who must verify their identity, which is far more controllable and the safer default for anything sensitive.

Can I stop external sharing organisation-wide instead of auditing individual files?

You can restrict external sharing at the tenant or site level through SharePoint admin settings, which is a reasonable option for businesses that don't have a genuine ongoing need for it. Most businesses do need some external sharing capability, though, which is why an audit-and-clean-up approach is usually more practical than an outright ban.

Do expiring links solve this problem automatically?

Setting a default expiration on external sharing links (available as a tenant setting) significantly reduces the risk of forgotten access lingering indefinitely, and is worth enabling as a baseline control, but it doesn't retroactively fix links already shared without an expiry, which is what an audit specifically catches.

How often should this audit be repeated?

At least twice a year for most small businesses, and it pairs naturally with a broader Microsoft 365 permissions review - see our guide on auditing Microsoft 365 user permissions for how these two reviews fit together.

We run external sharing and permissions audits for Perth businesses as part of ongoing Microsoft 365 management, so old sharing links don't quietly turn into a real risk.

Microsoft 365 Services →

Not sure how much of your data is currently shared externally?

Call 0433 087 091 - we'll run a sharing audit across your tenant, no obligation.

Get a Free Sharing Audit

For related reading, see our guides to auditing Microsoft 365 user permissions and secure file sharing for Perth businesses.

Share this article