SharePoint External Sharing Explained: Links, Guests, Expiry, and Governance
Govern SharePoint external sharing with link types, guest lifecycle, expiry policies, and access reviews that balance collaboration and security.
- Published
- Updated
- Reading time
- 3 min read
What you’ll learn
- The link ladder
- Guest lifecycle
- Common mistakes
- Production checklist
- Policy layers from tenant to file
On this page (8 sections)
Direct answer: SharePoint external sharing runs on a ladder: Anyone links (broadest), organization links, specific-people links, and direct guest invitations (tightest). Set the tenant default one rung tighter than teams think they need, require expiry on broad links, review guests quarterly, and assign an owner to every externally shared library.
Start from the SharePoint tutorials hub and permissions explained. Internal sharing mechanics also apply — see document libraries.
The link ladder
| Link type | Exposure | Use when |
|---|---|---|
| Anyone with the link | Highest — forwardable | Public marketing assets only, with expiry. |
| People in your organization | Internal-wide | Company-wide reads where membership lists would rot. |
| Specific people | Named internal or external users | Default for partner collaboration. |
| Guest invitation | One identity, full lifecycle | Ongoing external members needing repeated access. |
Guest lifecycle
Guests arrive through invitations and stay until someone removes them — that someone must be named in advance. Require business justification at invite time, set expiry where the sensitivity allows, and run quarterly reviews asking owners a single question per guest: still needed? Unreviewed guests are the external-sharing equivalent of broken inheritance sprawl.
Common mistakes
- Anyone links as the path of least resistance for partner work — default them off outside marketing libraries.
- Sharing without expiry on time-bound deals, then rediscovering the links during an audit.
- Treating “shared with” as documentation — export and review sharing reports instead of trusting memory.
- No owner for shared libraries, so nobody can answer who approved external access.
Production checklist
Tenant default, site-level overrides with justification, expiry on broad links, quarterly guest reviews, named owners, and an incident path for leaked Anyone links. Pair with the hub architecture so external collaboration has designed homes instead of ad-hoc sites.
Policy layers from tenant to file
Sharing controls stack: tenant-level defaults set the ceiling, site-level settings tighten or inherit with justification, and library or file links operate within both. Most incidents come from setting only one layer — typically the tenant default — while site owners quietly override it. Document the intended setting at each layer for collaboration sites, then audit actuals against intent twice a year.
Expiry and access reviews in practice
- Require expiry on Anyone links everywhere; 30 days is a sane default with renewal on request.
- Apply guest-access reviews quarterly through Entra ID access reviews, routed to library owners — not IT.
- Auto-expire specific-people links on deal-driven libraries after project close dates.
- Keep an incident path: who revokes links, who notifies partners, and how to verify revocation propagated.
Sensitivity labels meet sharing
Labels can enforce the ladder automatically: confidential labels that block Anyone links and external sharing do more work than any policy document. Map your three to four real sensitivity tiers to sharing behaviors, publish the mapping where sharers decide, and let the label carry the rule into every new site through default label policies.
FAQ
Should Anyone links ever be allowed? Yes, narrowly — public marketing assets and event materials where frictionless access is the point. Everywhere else, specific-people links cost seconds and remove the forwarding risk.
What happens to guest access when someone leaves the partner company? Nothing automatic. That is why expiry plus quarterly reviews exist: without them, departed-partner accounts retain access indefinitely. For sensitive libraries, require periodic re-justification instead of open-ended invitations.
Continue with how permissions work and the architecture library.
Related resources
Topics covered
Permissions · Security · Governance
Frequently asked questions
What external sharing link types exist?
Anyone links, people-in-organization links, specific-people links, and guest invitations — each with different exposure, ordered from broadest to tightest.
How should guest access be governed?
Time-bound invitations, expiry policies, quarterly access reviews, and a named owner for every externally shared library.
Does external sharing change internal permissions?
No. Sharing links grant scoped access without altering site membership — but lingering links accumulate, so review them like permissions.
Sources
- Microsoft Learn: External Sharing Overview, Microsoft
- Microsoft Learn: Site Permissions, Microsoft
Have a Microsoft 365 topic idea?
Share article suggestions, community session ideas, corrections, or real-world scenarios for future nextM365 learning notes.
Keep learning Microsoft 365
Explore more practical tutorials for SharePoint, Power Platform, Copilot Studio, migration, automation, governance, and security.
Continue learning
Related tutorials