← All articles

SharePoint External Sharing: 4 Link Levels, One Tenant Ceiling

Set SharePoint external sharing limits with four link levels, a tenant wide ceiling, Entra guest controls, and practical audit and access fixes.

Administrator configuring SharePoint external sharing

External sharing lets people outside your organization access SharePoint and OneDrive content through links or guest invitations, and it must be treated as a tenant-wide control decision rather than a per-site convenience. We recommend managing the setting at the organization level, restricting sensitive sites individually, and accounting for Microsoft Entra B2B integration before any reshare request catches your help desk off guard, especially by implementing robust video conferencing security controls as part of your overall collaboration platform security.


TL;DR:

  • The organization setting is the ceiling for every site, and SharePoint domain restrictions must be configured separately from Microsoft Entra allow or deny lists.
  • Tenants provisioned after June 2023 generally have Entra B2B integration by default; legacy migrations may require new invitations, so warn partners and flag shared sites.
  • Disable Anyone links broadly, require guest MFA and Conditional Access, and set expiration dates for links and guest access rather than leaving permissions open indefinitely.
  • Use Purview audit records marked Guest to track invitations, anonymous links, and secure links, and allow 60 to 90 minutes for results to appear.
  • Share at file or folder level when possible; remove guests from permission groups before deleting accounts, since one identity may support other active shares.

247techify
Keep External Sharing Under Control
247Techify provides cybersecurity-first managed IT services to help Canadian businesses maintain secure, efficient technology systems.
Visit 247Techify

Table of Contents

SharePoint external sharing runs on two underlying models: native SharePoint external authentication, which issues one-time passcodes to recipients, and Microsoft Entra B2B integration, which converts those recipients into managed guest accounts governed by Conditional Access and other Entra policies. Which model applies to a given share depends on tenant configuration and when the tenant was provisioned.

Within either model, four sharing levels define who can access a link:

  • Anyone: creates an anonymous link that requires no sign-in, the most permissive and highest-risk option.
  • New and existing guests: allows sharing with any external email, generating a new guest account on first access.
  • Existing guests: restricts sharing to people already present as guests in the directory.
  • Only people in your organization: blocks external access entirely at that scope.

The hierarchy rule governs all of this: the organization-level setting is the ceiling, and site-level settings can only be equal to or more restrictive, never more permissive. OneDrive, group-connected team sites, and communication sites each inherit the tenant default unless an admin tightens them individually.

Microsoft Entra B2B integration and recent changes that affect guest access

SharePoint and OneDrive integration with Microsoft Entra B2B standardizes guest identity management by creating a directory object for every external recipient and applying Entra Conditional Access, lifecycle, and access review policies to that identity instead of relying on SharePoint’s own passcode flow. This shift centralizes guest governance, but it also means some shares created under the older model need to be reissued once integration turns on.

Tenants provisioned after June 2023 generally have B2B integration enabled by default and see fewer disruptions. Tenants migrating from the legacy model may encounter cases where previously shared content requires resharing because the recipient’s identity needs to convert from a SharePoint-only guest to a full Entra guest object.

Before rolling this out, we check:

  • Run Get-SPOTenant and confirm the value of EnableAzureADB2BIntegration.
  • Identify sites with heavy external collaboration that may need proactive resharing.
  • Plan a short communication to external partners warning them a new invitation may arrive.

Configure external sharing safely: org and site steps with admin center and PowerShell options

Start at the tenant level, then tighten specific sites. The sequence matters because a permissive site setting is meaningless if the organization-level control already blocks it, and a restrictive organization setting will silently override anything looser configured at the site.

  1. In the SharePoint admin center, go to Policies > Sharing and set the organization-level external sharing option (Anyone, New and existing guests, Existing guests, or Only people in your organization).
  2. For sites holding sensitive data, open Active sites, select the site, choose Sharing, and pick a level equal to or more restrictive than the tenant default.
  3. Configure domain restrictions under Policies > Sharing > Advanced settings to allow or block specific domains for SharePoint and OneDrive sharing; this list is separate from the Microsoft Entra External ID allow or deny list and must be set independently.
  4. For bulk changes across many sites, use PowerShell: Get-SPOTenant to audit current settings, Set-SPOTenant to adjust organization-wide defaults, and Set-SPOSite -Identity <url> -SharingCapability <value> to enforce a restrictive level on individual sites at scale.

Pro Tip: Script the audit pass first with Get-SPOSite -Limit All | Select Url, SharingCapability before changing anything, so you have a rollback reference if a site breaks for legitimate external collaborators.

Monitoring and auditing external sharing: what to log and how to report

Visibility into who shared what, and with whom, is the difference between catching oversharing early and finding out during an incident review. Microsoft Purview identifies external users in audit records using TargetUserOrGroupType:Guest, which lets you filter sharing activity down to genuinely external events.

Track these operations as your core watchlist:

  • SharingInvitationCreated: a guest invitation was sent for a specific item.
  • AnonymousLinkCreated: an Anyone link was generated.
  • SecureLinkCreated and AddedToSecureLink: a specific-people link was created or a user was added to one.
Report method Best for Output format
Site usage report Quick per-site external user count In-browser dashboard
Purview Audit search Investigating specific sharing events CSV export with JSON AuditData field
PnP PowerShell Scheduled tenant-wide extracts CSV or structured object

Admins can pull a site usage report scoped to external users, run a targeted Purview audit search, or script a recurring PnP PowerShell export for larger estates. Give activity explorer and audit pipelines 60 to 90 minutes before assuming a search returned no results by mistake.

Microsoft’s own guidance favors keeping tenant-level sharing enabled for productivity while locking down sensitive sites individually, rather than disabling external sharing across the board, which tends to push users toward unmanaged workarounds.

Build your configuration around these controls:

  • Disable Anyone links tenant-wide or restrict them to specific, low-sensitivity sites only.
  • Set guest link and invitation expiration so stale access does not linger indefinitely.
  • Require Conditional Access and multi-factor authentication for every guest sign-in, not just employee accounts.
  • Apply Data Loss Prevention policies and sensitivity labels so protected content cannot leave through an external link even if sharing is technically permitted.
  • Limit which security groups can invite external guests, rather than leaving that capability open to every user.

Pro Tip: Pair a quarterly access review with your sharing audit logs, this is one of the few checks that catches guests who still have access long after the project that justified it ended.

Our SharePoint security checklist and Conditional Access policy templates walk through both of these controls in more operational detail.

Most external sharing support tickets fall into a handful of predictable categories.

  1. “This organization updated its guest access settings” error: this typically means B2B integration changed the recipient’s identity path, and the content owner needs to reshare the item to reissue a valid link.
  2. Stale Anyone links: audit for AnonymousLinkCreated events, then revoke the link and replace it with a Specific people link scoped to the actual recipients.
  3. Guests who no longer need access: remove the guest from the site’s permission group first; only delete the underlying guest account once you confirm no other site depends on it.
  4. Settings that appear not to have taken effect: check whether the delay is simply tenant-wide propagation, which can take time, before assuming the configuration itself is wrong.

247Techify perspective: practical controls we deploy for secure external sharing

Our cybersecurity-first approach to managed Microsoft 365 support treats external sharing as a standing control, not a one-time setup task. We deploy Conditional Access policy templates for guest sign-in, automate guest account expiration so access does not quietly persist, and run scheduled access reviews instead of relying on someone to remember.

This operational rhythm matters because sharing settings drift as teams change, projects end, and partners rotate. Our Conditional Access policy guidance and SharePoint security checklist outline the same controls we apply directly for clients on managed Microsoft 365 plans.

User experience and permissions management for external users after sharing

Once a share goes out, the experience on the receiving end depends on which model applied. A recipient added as an Entra B2B guest signs in with a Microsoft account or their own organizational credentials and sees the shared item in their own OneDrive or SharePoint interface going forward. A recipient accessing through the native SharePoint flow instead verifies with an email one-time passcode each time the session expires, since no persistent account exists.

Permission scope matters as much as access itself. A guest added at the item level can open that document but cannot browse the rest of the library, while a guest added to a library or site permission group inherits everything else granted to that group, which is where oversharing often starts without anyone intending it. We recommend sharing at the narrowest scope that satisfies the actual collaboration need: a single file or folder rather than a whole site, whenever possible.

Item-level versus group-level SharePoint access

Guests also do not automatically gain visibility into site navigation, other libraries, or Teams channels beyond what they were explicitly granted. Site owners should periodically check the site’s permissions page to confirm that a guest invited for one project has not been swept into a broader group through a later bulk-sharing action.

Managing external sharing invitations and expiration policies

Every guest invitation and external link should carry a defined lifespan rather than standing open indefinitely. The SharePoint admin center lets you set a tenant-wide expiration period for “Anyone” links, after which the link stops working automatically, and a separate expiration setting for guest access itself, after which the guest account’s permissions lapse unless renewed.

For invitations still pending, administrators can see outstanding guest invitations through the site’s permissions interface and resend or cancel them directly. A pending invitation that is never accepted does not grant access, but it is worth clearing out periodically so the permissions list reflects only active collaborators.

We suggest pairing link expiration with a review cadence: set links tied to active projects to expire at the project’s expected close date, rather than defaulting every link to the tenant maximum. This keeps the audit logs meaningful, since an expired link that nobody renewed is a reasonable signal that the collaboration ended, not a sign something broke.

Steps to revoke or modify external sharing access

Revoking access cleanly takes a few distinct steps depending on what was shared and how.

For a specific link, open the item’s Manage access panel, locate the external link, and select Remove link or adjust it to a narrower audience. For a guest added directly to a permission group, remove them from that group rather than deleting the underlying guest account outright, since the same guest identity may hold legitimate access elsewhere in the tenant.

When a guest account needs to be removed entirely, confirm through the audit log or a site access review that no other active share depends on it first. Deleting a shared guest identity without that check can break access for a different project team that assumed the account would persist.

For modifications rather than full revocation, changing a link from Anyone to Specific people, or shortening its expiration date, is usually faster than deleting and recreating the share from scratch. Document the change in your access review notes so the next audit pass has context for why the permission looks different from the prior baseline.

External sharing decisions carry compliance weight beyond the technical configuration, particularly for organizations in regulated sectors like healthcare, finance, or legal services. Before enabling broad external sharing on a site, confirm what category of data it holds and whether your sector’s compliance framework, such as HIPAA or PCI-DSS requirements for applicable organizations, restricts how that data can leave a controlled environment.

Data residency is a frequent question for Canadian businesses evaluating Microsoft 365: Microsoft allows tenants to select a home geo for data storage at provisioning, and organizations with residency requirements should confirm their tenant’s configured region rather than assuming a default. This is a tenant provisioning decision, not something external sharing settings alone control, so it is worth verifying separately from the sharing policies described above.

Audit trails also serve a compliance function beyond security monitoring. Purview audit logs showing exactly when a guest was added, what they accessed, and when access was revoked give you the documentation a compliance review or breach investigation will ask for. Treat the sharing audit log retention period as a compliance control, not just an operational convenience, and confirm it matches what your industry’s recordkeeping requirements expect.

Legal and compliance considerations when sharing externally on SharePoint — overview diagram

What the conventional advice on external sharing gets wrong

Most external sharing guidance treats the tenant-level toggle as the whole decision, when the real risk sits in the gap between what the setting technically allows and what site owners actually do with it day to day. Locking the tenant to “Only people in your organization” looks secure on paper, but it reliably pushes employees toward sending content through personal email or unmanaged file-sharing tools, which is a worse outcome than a well-audited Anyone link with a short expiration.

The more defensible position, and the one the Microsoft Entra B2B changes reinforce, is that guest identity and access review discipline matter more than the sharing level itself. A tenant with permissive sharing but strict Conditional Access, guest expiration, and a quarterly review catches oversharing fast. A tenant with restrictive sharing but no audit habit will not notice a problem until an external party still has access a year after the project ended.

If you take one thing from this, prioritize the audit log review over the initial sharing lockdown. The configuration is a one-time task. The review is the control that actually holds up over time.

— 247techify Team

How 247Techify can help: managed Microsoft 365 security and SharePoint operations

Our cybersecurity-first approach pairs 24/7 support with Microsoft-certified technicians who configure, monitor, and audit external sharing as part of ongoing Microsoft 365 & Cloud management, not a one-time project.

247techify

If your sharing settings have not been reviewed recently, our Microsoft 365 support plans start with a configuration check and move straight into ongoing monitoring.

FAQ

Can I share a SharePoint document with external users without a Microsoft account?

Yes, recipients without a Microsoft account can access shared content through an email one-time passcode sent to verify their identity. This works when the tenant’s sharing level permits external access and does not require the recipient to create an account.

Is SharePoint going away in 2026?

No, SharePoint remains an actively developed and supported part of Microsoft 365, with ongoing updates to external sharing, Entra B2B integration, and auditing capabilities. Current Microsoft Learn documentation continues to cover configuration and governance for SharePoint and OneDrive sharing.

How do I give someone access to a document library in SharePoint?

Open the library’s Manage access or sharing option, enter the person’s email or select from existing guests, and choose a permission level before sending the invitation. The sharing level available depends on both the organization-level and site-level settings, since the organization setting acts as the ceiling for what any individual library can allow.

How do you share a PowerPoint file with someone outside your organization?

Sharing a PowerPoint file stored in SharePoint or OneDrive works the same way as any other document: open the file’s sharing menu, choose Specific people or another available sharing level, and send the link or invitation. The recipient experience then follows the tenant’s configured model, either an Entra B2B guest sign-in or a one-time passcode verification.

What is the difference between SharePoint domain restrictions and Entra allow or block lists?

SharePoint and OneDrive domain allow and block lists are configured separately in the SharePoint admin center and control sharing at that layer specifically. The Microsoft Entra External ID allow or deny list is a distinct control that applies under B2B integration scenarios, so admins need to configure both if they want consistent domain restrictions across the tenant.

Sources