By default, SharePoint Online and OneDrive in Microsoft 365 allow users to share files with people outside your organisation — including anyone with a link, without requiring a sign-in. For most businesses, this is far too permissive.
Microsoft 365 has four levels of external sharing, from most to least permissive:
The risk with "Anyone" links: A user shares a link to a sensitive document, sends it to a client, and the client forwards it to someone else. That third person now has access — with no audit trail and no way to revoke access for just them.
For most businesses: New and existing guests is the right balance. It allows legitimate external collaboration while requiring recipients to verify their identity. Sensitive industries (legal, financial, healthcare) should consider Existing guests only or Only people in your organisation for most sites.
You can also set different policies at the site collection level — useful if most of your SharePoint is internal but you have a specific collaboration site for external partners.
M365Clarity scans your SharePoint sharing policy as part of every scan and flags it red if it's set to "Anyone" (unauthenticated access permitted), amber if it's "New and existing guests", and green if it's restricted to existing guests or internal only.
Connect your tenant, run a scan, and see exactly what needs attention — in plain English. Free plan available.
Scan your tenant free →Related articles