Most file-sharing risk in Microsoft 365 comes down to two decisions. The first is where shared content lives: OneDrive or SharePoint. The second is how external parties get access: anonymous links or authenticated guest accounts.
Our recommendation on both is direct. Keep shared business content in SharePoint, and require guest accounts for all external access. This guide covers the SharePoint external sharing best practices behind that recommendation, and what adopting them means for your team.
Both recommendations use controls that Microsoft 365 already provides. What they need from you is a decision, applied consistently. The rest of this guide explains the reasoning behind each one.
OneDrive is personal storage. It is the right place for drafts and individual work. It was never built to be a durable, governed home for content your business depends on.
When shared content lives in OneDrive instead of SharePoint, risk shows up in five specific ways.
SharePoint gives your organization a single, governed home for shared content. It survives personnel changes and can be protected consistently. OneDrive was never designed to carry that responsibility.
When you share a file from SharePoint or OneDrive, Microsoft 365 offers several link types. Three of them matter for this discussion.
External sharing risk concentrates in the first type, the anonymous "Anyone" link. The sections below explain why, and what to use instead.
The second decision is how partners, vendors, and clients open what you share with them. Microsoft 365 offers two very different models.
An "Anyone with the link" link requires no sign-in at all. A guest account requires the recipient to prove who they are before opening anything.
We recommend guest accounts for any external access to business content, for five reasons.
A guest is a real entry in your directory, with a name attached. You can add it to groups, cover it with sign-in policies, and see it by name in audit logs. None of that exists for an anonymous recipient.
The compliance point carries extra weight for defense contractors. If your files include controlled unclassified information, review what counts as CUI before sharing anything externally.
Microsoft's own roadmap points to authenticated guest identities. The company is retiring SharePoint's legacy one-time passcode sign-in for external recipients. Authentication for SharePoint external sharing is moving to Microsoft Entra B2B instead. Under that model, every external collaborator gets a guest account in your directory.
The rollout applies to all Microsoft 365 tenants, and there is no opt-out. Microsoft has designed the transition to be low-friction. Links you have already shared keep working once the recipient has a guest account, and duplicate accounts are not created for existing collaborators.
Note what the change does not cover: Anyone links are not affected. Turning them off remains your policy decision, not Microsoft's. Standardizing on guest accounts now aligns your tenant with where the platform is already going.
Guest accounts add a small amount of friction compared to an anonymous link. External users must accept a guest invitation and sign in before they can open content. Each collaborator goes through that acceptance step once, not once per file.
Your team also needs a light recurring process for reviewing active guest accounts. When a project wraps up, someone removes the access that is no longer needed. A short quarterly review is usually enough to keep the directory clean.
In our experience, this overhead is minor compared to the risk it closes off. Guest reviews also pair naturally with your broader vendor oversight. Our post on third-party risk management covers that discipline in a CMMC context.
Three steps cover the bulk of SharePoint external sharing governance. Each one is a configuration choice plus a habit, not a new tool purchase.
Essendis can set up and run this process for you as part of managed cloud services. That way, governance does not become a burden on your team.
Our advisors define the sharing policy, and our engineers configure and run it. The same accountable team carries the work from plan to build. To talk through your tenant's configuration, contact Essendis.
Their OneDrive, including everything shared from it, is generally deleted within 30 days of their departure. Content survives only if someone moves it to a shared location first. Storing team files in SharePoint removes that dependency.
Yes. A guest account is an identity in your directory. You can require MFA for it and apply conditional access rules. An anonymous link supports neither.
Slightly, and only at first. A new guest must accept an invitation and sign in once before opening content. After that, permissions work much as they do for internal users, and access stays auditable and revocable.
Move the content itself into SharePoint, then reshare it with authenticated guests. Disabling an old anonymous link stops new access, but it cannot tell you who already opened the file. Treat widely forwarded links as potentially exposed, and reshare deliberately.
Yes. Files shared in a Teams channel live in that team's SharePoint site, so they already follow SharePoint's rules. Files shared in private chats live in the sender's personal OneDrive. That is exactly the fragmentation problem described above, and one more reason to move working files into SharePoint.
For business content, yes: that is our recommendation. Microsoft still supports Anyone links, so leaving them on is a choice your organization has to own. If a file matters to your business or your clients, it deserves an authenticated recipient.

