Frontrow Technology
← All insights & guides
Guide

Microsoft 365

External sharing in Microsoft 365: a sensible default for a small business

Anonymous, org-only and specific-people links all say share but behave very differently. A sensible default that will not push people back to email attachments.

Simon Aspinall · 19 August 2026 · 10 min read

Someone needs to send a file to a client, an accountant, or a contractor who doesn't have an account in the business's Microsoft 365 tenant. They click Share, Microsoft 365 offers a handful of options that all say roughly the same thing, and most people pick whichever one is fastest without knowing that the choice materially changes who can see the file and for how long. That's not a criticism of the person clicking Share, the options genuinely aren't self-explanatory, and getting this wrong in either direction causes real problems: too loose, and a sensitive document ends up reachable by anyone who gets forwarded a link; too locked down, and people quietly go back to emailing attachments instead, which is worse in almost every way that matters.

Every sharing link in SharePoint and OneDrive falls into one of three categories, and the wording in the share dialog is the only clue to which one is selected:

  • Anyone with the link: no sign-in required at all. Whoever has the URL can open the file, and because there's no identity check, the link can be forwarded on by the original recipient with no way to know it's happened. This is the fastest option and the one that needs the most care.
  • People in your organisation: only accounts signed in to the business's own Microsoft 365 tenant can open it. Useful for sharing between internal staff without emailing a copy around, but it does nothing for someone genuinely external, they'll be blocked at sign-in.
  • Specific people: the sharer names exact individuals, by email address, and Microsoft 365 verifies the identity of whoever opens the link, either through a one-time passcode or an existing account. This is the most restrictive option, the most auditable, and the only one of the three that guarantees the person who opens the file is actually who it was sent to.

The default a tenant starts with matters more than any individual choice, because most people take whatever option the share dialog opens on rather than deliberately changing it.

Adding someone external as a guest in a Teams team is a deeper, more persistent kind of access than a sharing link, and worth understanding as genuinely different rather than a variation on the same idea. A sharing link grants access to one file or folder, on whatever terms were set when it was created. Guest access adds a person to a specific team, giving them ongoing access to that team's channels, files and chat for as long as the membership lasts, not just a single document. A guest doesn't get access to the wider organisation, only the teams they've actually been added to, and they show up in the tenant's people list with a visible Guest label, which makes it straightforward to see at a glance who's external.

Guest access is the right tool for someone in an ongoing working relationship, a retained contractor, an accountant who needs recurring access to a specific team's files, not for a one-off document handover, which a sharing link handles more simply and with less lingering access to clean up later.

Two settings do most of the work of keeping external sharing under control without banning it outright, and both are worth deliberately configuring rather than leaving on whatever a fresh tenant ships with.

  1. 1In the SharePoint admin centre's sharing settings, a tenant-wide default link type can be set, so the share dialog opens on 'specific people' rather than 'anyone with the link' unless someone deliberately changes it for that share.
  2. 2The same sharing settings area allows an expiration period to be enforced on anonymous links, so any 'anyone with the link' share automatically stops working after a set number of days rather than staying live indefinitely.
  3. 3Individual users can also set an expiry date, and in some configurations a password, on a specific link at the point of creating it, which is worth using for a one-off external share even if the tenant-wide default doesn't force it.

The real tension: lock it down too hard and people email attachments instead

This is the trade-off that gets missed in most sharing guidance, which tends to treat 'external sharing' as something to minimise as an end in itself. It isn't. An email attachment leaves the controlled environment entirely: it can't be revoked once sent, it isn't logged anywhere the business can see, it duplicates the document into someone else's inbox forever, and it has no expiry. A sharing link, even a reasonably permissive one, stays inside Microsoft 365's ecosystem the whole time, it's revocable with a click, it's logged, and it can be given an expiry date. The goal of a sensible sharing policy isn't zero external sharing, it's making sure external sharing happens through a mechanism that can be reviewed and switched off, rather than through an inbox nobody controls.

A sensible default for a small business

None of this needs to be complicated to be effective. A workable default posture for most small and medium businesses looks like this:

  • Set the tenant default link type to 'specific people' for anything that isn't deliberately public, so the safest option is also the easiest one to leave unchanged.
  • Reserve 'anyone with the link' for genuinely low-sensitivity material, a public event flyer, a published document, and set an expiry on it regardless.
  • Use Teams guest access for real, ongoing external collaborators, not for a single document handover that a link would handle more simply.
  • Set an expiry date on external links as a habit, even when the tenant doesn't force one, particularly for anything time-bound like a project, a quote, or a contract review.
  • Review the list of active guests and live external links on a regular cadence, not just when something goes wrong, since this is the step almost every business skips.

Common questions

Frequently asked

Is 'anyone with the link' sharing always a bad idea?
No, it's a reasonable choice for genuinely low-sensitivity material where verifying identity doesn't matter, a public flyer or a published brochure, for example. The problem isn't the option existing, it's it being used by default for sensitive documents simply because it's the fastest click in the dialog.
What can a Teams guest actually see once they're added?
A guest can see the specific team, or teams, they've been added to, including that team's channels, files and chat history, but nothing outside those teams. They don't get general access to the organisation's directory or to teams they haven't been invited into, and they appear with a visible Guest label wherever they show up.
If we lock sharing down, won't people just email documents instead?
This is the real risk with an overly strict policy, and it's worth taking seriously rather than dismissing. An email attachment is harder to control than almost any link setting, since it can't be revoked, isn't logged, and has no expiry. A sensible policy makes the safe, logged option, a link with an expiry, also the fast option, so there's no reason to reach for email instead.
How do we find out which external links and guests are still active?
SharePoint and OneDrive both offer sharing reports at the site and tenant level, and Microsoft Entra maintains a list of external guest accounts across the tenant. Reviewing both periodically, rather than assuming they'll surface a problem automatically, is the step that actually keeps sharing under control over time.
Does setting a link expiry inconvenience the person we're sharing with?
Only mildly, and usually for the better. A link that's expired can be recreated in seconds if access is still genuinely needed, and in the meantime it closes the far more common problem of a share nobody remembers is still live, reachable by anyone who still has the URL.

Want Frontrow to run this with your team?

A 30-minute call with a senior consultant. No deck. Frontrow walks through your tenant, your priorities and the next sensible move.