SharePoint and OneDrive make it easy to collaborate with clients, vendors, consultants, and project partners. That convenience becomes a problem when the business can no longer answer three basic questions: who has access, what can they reach, and who still owns the decision?
An external-sharing audit is not a blanket order to remove every guest. It is a structured review that preserves useful collaboration while closing access that no longer has a business reason.
Start with the business relationship
Do not begin by clicking through individual files. Begin with the outside relationships the company expects to maintain.
List active clients, vendors, contractors, advisors, board members, and partner organizations that should still collaborate in Microsoft 365. Assign an internal owner to each relationship. That owner should be able to explain why access exists, what information is appropriate to share, and when the relationship should be reviewed again.
If nobody inside the company will own an external relationship, its access deserves immediate attention.
Review the tenant-level boundary
Microsoft 365 sharing behavior is shaped by more than the permission shown beside one document. Tenant-wide SharePoint and OneDrive settings establish the broad boundary. Individual sites, Microsoft 365 groups, Teams, folders, files, and sharing links can then narrow or extend practical access within that boundary.
The review should establish:
- Whether new and existing guests can be invited
- Whether anyone with an edit role may reshare content
- Whether anonymous “Anyone” links are permitted
- How long sharing links remain valid
- Whether guest access is restricted by domain
- Who receives and approves access requests
- Whether OneDrive sharing follows the intended business policy
The correct answer is not always the strictest setting. It is the setting that matches the company’s real collaboration model and can be administered consistently.
Inventory guests, links, and owners
A useful audit separates three kinds of access that are often discussed as though they were the same.
Guest identities
Guest accounts represent people invited into the organization’s directory. Review whether the person is recognizable, whether the sponsoring relationship remains active, and whether the guest still belongs to groups, Teams, or sites.
Sharing links
A file or folder may be reachable through a named-person link, an organization-wide link, or an anonymous link depending on policy. Review the link type, creation date, intended audience, expiration, and whether the content still needs to be shared.
Direct and inherited permissions
Access may come directly from a file, from a folder, through a SharePoint group, through a Microsoft 365 group, or by inheritance from a parent location. Removing one visible permission does not necessarily remove every path.
That is why a reliable cleanup documents the access path before changing it.
Change access in controlled passes
Do not perform a large permission cleanup immediately before a deadline, transaction, exhibition opening, or client delivery. Start with a report, confirm ownership, and test changes with a limited group.
A sensible sequence is:
- Preserve the original findings and date of review.
- Remove clearly obsolete anonymous links and dormant guests with owner approval.
- Replace one-off access with understandable groups where appropriate.
- Restore permission inheritance where exceptions are no longer required.
- Confirm that active collaborators can still complete real tasks.
- Record who approved the result and when it should be reviewed again.
If the environment is also preparing for a Microsoft 365 tenant-to-tenant migration, complete this work early. Moving unexplained permissions into a new tenant preserves the confusion and makes migration acceptance harder.
Make the next audit smaller
The best result is not a perfectly clean report on one afternoon. It is an environment that stays understandable.
Give every shared site an internal owner. Use groups that correspond to real roles. Set reasonable link expiration. Include guest access in offboarding and vendor-closeout checklists. Schedule recurring reviews based on risk rather than waiting for a scare.
For a Greater Boston small office that needs help tracing SharePoint guests, OneDrive sharing, and inherited permissions, Microsoft 365 management can begin with a documented, scoped review.

