By default, Microsoft 365 allows users to create 'Anyone' links in SharePoint Online. While this simplifies collaboration, it also increases the risk of oversharing, unauthorized access, and data leaks.
Open access can further lead to cyber threats and compliance concerns. As an admin, you can control default sharing link type and limit broad access. Here's how to manage file and folder sharing links in SharePoint Online to keep your data secure.
- Log in to the SharePoint Online admin center and navigate to Sharing under Policies.
- Locate the "File and folder links" section to configure sharing links and control external sharing in SharePoint Online.
1. Link type for file and folder sharing in SharePoint and OneDrive
This setting defines the type of sharing link that will be created by default when a user shares a file or folder in SharePoint or OneDrive. You can choose from the following link types:
- Specific people(Most secure) – Allows access only to explicitly named users.
- People in your organization – Restricts access to signed-in users within your Microsoft 365 tenant.
- Anyone with the link(Least Secure) – Allows access to anyone who receives the link.
Recommendation: Set the default link type to "Only people in your organization" to prevent accidental external sharing and ensure files remain accessible only to internal users.
2. Default link permissions for sharing links
The link permission setting defines the level of access granted when a sharing link is used. This helps to prevent unintended modifications or deletions by recipients.
- View – Allows users to view and download files but prevents changes.
- Edit – Grants full access to view, modify, upload, and delete files or folders.
Recommendation: Set the default link permission to "View" to reduce the risk of data tampering, especially when links are shared unintentionally.
3. Default expiration and permissions for "Anyone" Links
When allowing anonymous sharing (Anyone links), it’s important to apply expiration and permission controls to maintain security.
- You can turn on expiration for anyone links by clicking the "These links must expire within this many days" check box.
- Additionally, you can also configure a default expiration period for sharing links between 1 to 730 days to prevent indefinite access under the setting.
You can manage link permissions of SharePoint files and folders under 'These links can give these permissions’.
Recommendation:- For files, set the default permission to "View" to prevent unauthorized edits, since users accessing the link won’t need to sign in.
- For folders, use "View and Upload" to allow contributors to add files without altering or deleting existing content.