SharePoint External Sharing Best Practices for Microsoft 365

Most file-sharing risk in Microsoft 365 comes down to two decisions. The first is where shared content lives: OneDrive or SharePoint. The second is how external parties get access: anonymous links or authenticated guest accounts.

Our recommendation on both is direct. Keep shared business content in SharePoint, and require guest accounts for all external access. This guide covers the SharePoint external sharing best practices behind that recommendation, and what adopting them means for your team.

Two Recommendations for Microsoft 365 Sharing

  • Store shared content in SharePoint. Business-critical or team-owned files belong in SharePoint sites, not in personal OneDrive accounts.
  • Require guest accounts for external access. External collaborators should authenticate through a guest account, never through an anonymous "Anyone" link.

Both recommendations use controls that Microsoft 365 already provides. What they need from you is a decision, applied consistently. The rest of this guide explains the reasoning behind each one.

SharePoint vs. OneDrive: Where Shared Content Should Live

OneDrive is personal storage. It is the right place for drafts and individual work. It was never built to be a durable, governed home for content your business depends on.

When shared content lives in OneDrive instead of SharePoint, risk shows up in five specific ways.

  • Continuity risk when people leave. OneDrive content is tied to one person's identity. When that person leaves, their OneDrive is generally deleted within 30 days unless someone moves the content first. Files your team still relies on can simply disappear.
  • Inconsistent access control. SharePoint permissions are managed through groups at the site level, so access can be reviewed centrally. OneDrive sharing happens one file at a time, at each person's discretion. The result is access that is inconsistent and hard to audit.
  • Weaker data protection. SharePoint libraries can automatically apply sensitivity labels and data-loss-prevention rules to everything stored in them. In OneDrive, those same protections depend on each person applying them correctly, every time.
  • Lost visibility. There is no single view of everything shared across OneDrive, SharePoint, and Teams. The more content sits in personal OneDrive accounts, the harder it becomes to answer a basic question: who has access to this, and why?
  • Fragmentation through Teams. Files shared in Teams chats are stored in the sender's personal OneDrive by default. If the sender deletes a file, everyone in the conversation loses access. Centralizing shared content in SharePoint avoids this kind of accidental loss.

SharePoint gives your organization a single, governed home for shared content. It survives personnel changes and can be protected consistently. OneDrive was never designed to carry that responsibility.

The Link Types Behind Microsoft 365 Sharing

When you share a file from SharePoint or OneDrive, Microsoft 365 offers several link types. Three of them matter for this discussion.

  • "Anyone with the link." This link requires no sign-in. Whoever holds it can open the file, no matter how they got it.
  • "People in your organization." This link works for your own staff only. External recipients cannot use it.
  • "Specific people." This link works only for the named recipients. Each one must verify their identity before the file opens.

External sharing risk concentrates in the first type, the anonymous "Anyone" link. The sections below explain why, and what to use instead.

Guest Accounts vs. Anyone Links for External Access

The second decision is how partners, vendors, and clients open what you share with them. Microsoft 365 offers two very different models.

An "Anyone with the link" link requires no sign-in at all. A guest account requires the recipient to prove who they are before opening anything.

We recommend guest accounts for any external access to business content, for five reasons.

  • Anonymous links cannot verify identity. Anyone who obtains an "Anyone" link can open it, whether they received it directly or through repeated forwarding. A guest account requires the person to authenticate first.
  • Guest access can be audited. Guest activity is logged against a real identity in your directory. Anonymous link activity is far less traceable. Standard logs often cannot show who actually opened a file.
  • Guest access can be revoked. A guest account can be shut off centrally and immediately. Disabling an anonymous link stops new access, but you cannot know who already opened, downloaded, or forwarded the file.
  • Guest accounts support ongoing security controls. A guest account is a real identity. You can require multi-factor authentication (MFA) and apply conditional access rules, such as blocking sign-ins from unexpected locations. An anonymous link has no identity to attach those protections to.
  • Compliance requires named access. For regulated or sensitive data, naming exactly who has access is typically a baseline requirement. Guest accounts make that possible. Anonymous links make it structurally impossible.

A guest is a real entry in your directory, with a name attached. You can add it to groups, cover it with sign-in policies, and see it by name in audit logs. None of that exists for an anonymous recipient.

The compliance point carries extra weight for defense contractors. If your files include controlled unclassified information, review what counts as CUI before sharing anything externally.

Microsoft Is Moving External Sharing in the Same Direction

Microsoft's own roadmap points to authenticated guest identities. The company is retiring SharePoint's legacy one-time passcode sign-in for external recipients. Authentication for SharePoint external sharing is moving to Microsoft Entra B2B instead. Under that model, every external collaborator gets a guest account in your directory.

The rollout applies to all Microsoft 365 tenants, and there is no opt-out. Microsoft has designed the transition to be low-friction. Links you have already shared keep working once the recipient has a guest account, and duplicate accounts are not created for existing collaborators.

Note what the change does not cover: Anyone links are not affected. Turning them off remains your policy decision, not Microsoft's. Standardizing on guest accounts now aligns your tenant with where the platform is already going.

What This Changes for Your Team

Guest accounts add a small amount of friction compared to an anonymous link. External users must accept a guest invitation and sign in before they can open content. Each collaborator goes through that acceptance step once, not once per file.

Your team also needs a light recurring process for reviewing active guest accounts. When a project wraps up, someone removes the access that is no longer needed. A short quarterly review is usually enough to keep the directory clean.

In our experience, this overhead is minor compared to the risk it closes off. Guest reviews also pair naturally with your broader vendor oversight. Our post on third-party risk management covers that discipline in a CMMC context.

How to Put This in Place

Three steps cover the bulk of SharePoint external sharing governance. Each one is a configuration choice plus a habit, not a new tool purchase.

  1. Establish SharePoint sites as the default home for any content shared with a team or an external party.
  2. Require authenticated guest accounts for external access to business content.
  3. Set a recurring review of active guest accounts, and remove access that is no longer needed. Quarterly is a common cadence.

Essendis can set up and run this process for you as part of managed cloud services. That way, governance does not become a burden on your team.

Our advisors define the sharing policy, and our engineers configure and run it. The same accountable team carries the work from plan to build. To talk through your tenant's configuration, contact Essendis.

Frequently Asked Questions

What happens to files a departing employee shared from OneDrive?

Their OneDrive, including everything shared from it, is generally deleted within 30 days of their departure. Content survives only if someone moves it to a shared location first. Storing team files in SharePoint removes that dependency.

Can guest accounts be required to use MFA?

Yes. A guest account is an identity in your directory. You can require MFA for it and apply conditional access rules. An anonymous link supports neither.

Do guest accounts slow down collaboration?

Slightly, and only at first. A new guest must accept an invitation and sign in once before opening content. After that, permissions work much as they do for internal users, and access stays auditable and revocable.

We already shared files with Anyone links. What should we do?

Move the content itself into SharePoint, then reshare it with authenticated guests. Disabling an old anonymous link stops new access, but it cannot tell you who already opened the file. Treat widely forwarded links as potentially exposed, and reshare deliberately.

Does this guidance apply to Teams files too?

Yes. Files shared in a Teams channel live in that team's SharePoint site, so they already follow SharePoint's rules. Files shared in private chats live in the sender's personal OneDrive. That is exactly the fragmentation problem described above, and one more reason to move working files into SharePoint.

Should we turn off Anyone links entirely?

For business content, yes: that is our recommendation. Microsoft still supports Anyone links, so leaving them on is a choice your organization has to own. If a file matters to your business or your clients, it deserves an authenticated recipient.

Talk to a Cloud Cybersecurity Expert

Thank you for contacting Essendis. Our team is reviewing your submission and will be in touch shortly. 
We look forward to assisting with your cybersecurity and cloud computing needs. 

Continue Exploring Essendis’ Offerings

Return to Essendis
Oops! Something went wrong while submitting the form.