SharePoint and OneDrive make it easy to collaborate with clients, vendors, consultants, and project partners. That convenience becomes a problem when the business can no longer answer three basic questions: who has access, what can they reach, and who still owns the decision?

An external-sharing audit is not a blanket order to remove every guest. It is a structured review that preserves useful collaboration while closing access that no longer has a business reason.

01

Start with the business relationship

Do not begin by clicking through individual files. Begin with the outside relationships the company expects to maintain.

List active clients, vendors, contractors, advisors, board members, and partner organizations that should still collaborate in Microsoft 365. Assign an internal owner to each relationship. That owner should be able to explain why access exists, what information is appropriate to share, and when the relationship should be reviewed again.

If nobody inside the company will own an external relationship, its access deserves immediate attention.

02

Review the tenant-level boundary

Microsoft 365 sharing behavior is shaped by more than the permission shown beside one document. Tenant-wide SharePoint and OneDrive settings establish the broad boundary. Individual sites, Microsoft 365 groups, Teams, folders, files, and sharing links can then narrow or extend practical access within that boundary.

The review should establish:

  • Whether new and existing guests can be invited
  • Whether anyone with an edit role may reshare content
  • Whether anonymous “Anyone” links are permitted
  • How long sharing links remain valid
  • Whether guest access is restricted by domain
  • Who receives and approves access requests
  • Whether OneDrive sharing follows the intended business policy

The correct answer is not always the strictest setting. It is the setting that matches the company’s real collaboration model and can be administered consistently.

04

Look for the patterns that create hidden exposure

Certain patterns deserve priority because they are easy to forget and difficult for ordinary staff to see.

  • Former vendors or contractors remain members of active Teams
  • A project site has no current internal owner
  • Sensitive folders use one-off permissions that no longer inherit from the parent
  • Anonymous links were created for a deadline and never expired
  • A departed employee’s OneDrive still contains business material shared externally
  • A renamed or reorganized client folder retains the old sharing structure
  • Staff can invite new guests without a consistent approval or review process

The objective is not to produce a frightening spreadsheet. It is to turn these exceptions into decisions: keep, narrow, transfer, expire, or remove.

05

Change access in controlled passes

Do not perform a large permission cleanup immediately before a deadline, transaction, exhibition opening, or client delivery. Start with a report, confirm ownership, and test changes with a limited group.

A sensible sequence is:

  1. Preserve the original findings and date of review.
  2. Remove clearly obsolete anonymous links and dormant guests with owner approval.
  3. Replace one-off access with understandable groups where appropriate.
  4. Restore permission inheritance where exceptions are no longer required.
  5. Confirm that active collaborators can still complete real tasks.
  6. Record who approved the result and when it should be reviewed again.

If the environment is also preparing for a Microsoft 365 tenant-to-tenant migration, complete this work early. Moving unexplained permissions into a new tenant preserves the confusion and makes migration acceptance harder.

06

Make the next audit smaller

The best result is not a perfectly clean report on one afternoon. It is an environment that stays understandable.

Give every shared site an internal owner. Use groups that correspond to real roles. Set reasonable link expiration. Include guest access in offboarding and vendor-closeout checklists. Schedule recurring reviews based on risk rather than waiting for a scare.

For a Greater Boston small office that needs help tracing SharePoint guests, OneDrive sharing, and inherited permissions, Microsoft 365 management can begin with a documented, scoped review.

07

Official sources