Someone needs to send a file to a client, an accountant, or a contractor who doesn't have an account in the business's Microsoft 365 tenant. They click Share, Microsoft 365 offers a handful of options that all say roughly the same thing, and most people pick whichever one is fastest without knowing that the choice materially changes who can see the file and for how long. That's not a criticism of the person clicking Share, the options genuinely aren't self-explanatory, and getting this wrong in either direction causes real problems: too loose, and a sensitive document ends up reachable by anyone who gets forwarded a link; too locked down, and people quietly go back to emailing attachments instead, which is worse in almost every way that matters.
Three kinds of link, and what each one actually does
Every sharing link in SharePoint and OneDrive falls into one of three categories, and the wording in the share dialog is the only clue to which one is selected:
- Anyone with the link: no sign-in required at all. Whoever has the URL can open the file, and because there's no identity check, the link can be forwarded on by the original recipient with no way to know it's happened. This is the fastest option and the one that needs the most care.
- People in your organisation: only accounts signed in to the business's own Microsoft 365 tenant can open it. Useful for sharing between internal staff without emailing a copy around, but it does nothing for someone genuinely external, they'll be blocked at sign-in.
- Specific people: the sharer names exact individuals, by email address, and Microsoft 365 verifies the identity of whoever opens the link, either through a one-time passcode or an existing account. This is the most restrictive option, the most auditable, and the only one of the three that guarantees the person who opens the file is actually who it was sent to.
The default a tenant starts with matters more than any individual choice, because most people take whatever option the share dialog opens on rather than deliberately changing it.
Guest access in Teams: a different thing to a sharing link
Adding someone external as a guest in a Teams team is a deeper, more persistent kind of access than a sharing link, and worth understanding as genuinely different rather than a variation on the same idea. A sharing link grants access to one file or folder, on whatever terms were set when it was created. Guest access adds a person to a specific team, giving them ongoing access to that team's channels, files and chat for as long as the membership lasts, not just a single document. A guest doesn't get access to the wider organisation, only the teams they've actually been added to, and they show up in the tenant's people list with a visible Guest label, which makes it straightforward to see at a glance who's external.
Guest access is the right tool for someone in an ongoing working relationship, a retained contractor, an accountant who needs recurring access to a specific team's files, not for a one-off document handover, which a sharing link handles more simply and with less lingering access to clean up later.
Setting link expiry and a sensible default link type
Two settings do most of the work of keeping external sharing under control without banning it outright, and both are worth deliberately configuring rather than leaving on whatever a fresh tenant ships with.
- 1In the SharePoint admin centre's sharing settings, a tenant-wide default link type can be set, so the share dialog opens on 'specific people' rather than 'anyone with the link' unless someone deliberately changes it for that share.
- 2The same sharing settings area allows an expiration period to be enforced on anonymous links, so any 'anyone with the link' share automatically stops working after a set number of days rather than staying live indefinitely.
- 3Individual users can also set an expiry date, and in some configurations a password, on a specific link at the point of creating it, which is worth using for a one-off external share even if the tenant-wide default doesn't force it.
The real tension: lock it down too hard and people email attachments instead
This is the trade-off that gets missed in most sharing guidance, which tends to treat 'external sharing' as something to minimise as an end in itself. It isn't. An email attachment leaves the controlled environment entirely: it can't be revoked once sent, it isn't logged anywhere the business can see, it duplicates the document into someone else's inbox forever, and it has no expiry. A sharing link, even a reasonably permissive one, stays inside Microsoft 365's ecosystem the whole time, it's revocable with a click, it's logged, and it can be given an expiry date. The goal of a sensible sharing policy isn't zero external sharing, it's making sure external sharing happens through a mechanism that can be reviewed and switched off, rather than through an inbox nobody controls.
A sensible default for a small business
None of this needs to be complicated to be effective. A workable default posture for most small and medium businesses looks like this:
- Set the tenant default link type to 'specific people' for anything that isn't deliberately public, so the safest option is also the easiest one to leave unchanged.
- Reserve 'anyone with the link' for genuinely low-sensitivity material, a public event flyer, a published document, and set an expiry on it regardless.
- Use Teams guest access for real, ongoing external collaborators, not for a single document handover that a link would handle more simply.
- Set an expiry date on external links as a habit, even when the tenant doesn't force one, particularly for anything time-bound like a project, a quote, or a contract review.
- Review the list of active guests and live external links on a regular cadence, not just when something goes wrong, since this is the step almost every business skips.