Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

You can keep external collaboration available in SharePoint without making every site or every link equally open. Use narrower site settings, authenticated guest access, approved partner domains, designated sharing groups, and time-limited links; reserve fully disabled sharing for sites that must remain internal. Microsoft’s planning guidance recommends leaving external sharing enabled when it can be governed appropriately.

Choose controls by scope, recipient, and duration

These options apply to SharePoint in Microsoft 365. They can be layered: tenant settings set the outer boundary, while site settings can be more restrictive. The right combination depends on which content is being shared, who may receive access, which employees can share it, and how long access should last. Microsoft’s external sharing overview and sharing settings guidance describe the available controls.

  • Scope: apply a broad rule across the tenant or a narrower rule to selected sites.
  • Recipient: allow anyone with a link, authenticated new guests, existing guests, or internal users only.
  • Sharer: allow all eligible users to share externally or limit that ability to selected security groups.
  • Reach: allow or block invitations based on recipient email domains.
  • Duration and link behavior: set expiration, reauthentication, link audience, and permission defaults.

1. Disable sharing only on sensitive sites

When a particular site contains information that must not leave the organization, disable external sharing for that site rather than shutting it off everywhere. Keep approved collaboration sites available under the tenant’s permitted settings. Tenant-wide and site-level rules work together, and the more restrictive setting governs.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

This approach separates content by risk: a site containing internal-only material can remain closed, while project or partner sites can support controlled guest access. Microsoft explains how to configure the tenant and site scopes in its SharePoint sharing settings documentation.

2. Require guests to authenticate

Choose New and existing guests when external recipients should be able to collaborate but must sign in or verify their identity. Unlike an Anyone link, access is tied to an authenticated guest identity. This makes it easier to control and review who has access.

This is a useful middle ground for partner work: external sharing remains possible, but recipients cannot access content simply by possessing a forwardable, unauthenticated link. Microsoft’s configuration options are listed in its external sharing settings guidance.

3. Allow sharing only with guests already in the directory

Set a site to Existing guests only when employees should collaborate with external people already represented in the organization’s directory, but should not invite new guests from that site. Existing guests might have accepted an earlier invitation or been added by an administrator.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

This can reduce ad hoc invitations while preserving access for an established partner roster. It is narrower than allowing new and existing guests, but it still permits external sharing with the directory’s existing guest identities.

4. Restrict recipients by partner domain

Use a domain allowlist to limit invitations to approved partner domains, or a blocklist to exclude selected domains. An allowlist is generally the more restrictive choice when collaboration should occur only with named organizations. Microsoft documents a maximum of 5,000 domain entries and does not support wildcard entries.

Tenant-level domain rules take precedence when settings conflict, and a site-level allowlist must fit within the tenant allowlist. Review Microsoft Entra external collaboration restrictions as well, because those controls can also affect invitations and sharing. See Microsoft’s domain restriction guidance for configuration details.

5. Limit external sharing to selected employees

Administrators can allow external sharing only for specified security groups. This is useful when most employees do not need to invite guests, but project owners or trained teams do. Microsoft describes this control under restricting external sharing to specific security groups.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For those groups, the permitted recipient setting can be limited to authenticated guests or can include Anyone links. Anyone links are forwardable; administrators cannot use them to track who has access or who accessed the item. Choose authenticated guest access when identity and access review matter.

The security-group control does not govern sharing in Microsoft 365 Groups or Teams. Review the related guest-access settings for those services separately rather than assuming a SharePoint setting covers them.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

6. Set expiration, reauthentication, and safer link defaults

Reduce lingering access by setting guest access expiration and verification-code reauthentication intervals. You can also choose defaults for link audience and permissions so users start with a narrower sharing option instead of a broader one. Site-level values can differ from tenant defaults.

Sensitivity labels can also configure site sharing and link behavior when the organization has configured the feature and has applicable licensing. These controls are described in Microsoft’s guest access expiration guidance and sharing settings documentation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What happens if you turn sharing off tenant-wide?

Turning off external sharing for the tenant is not a reliable way to permanently remove guests from every site if sharing may later be restored. Microsoft warns that guests can regain access when tenant-wide sharing is turned back on. If specific sites must remain closed, disable sharing for those sites before restoring the broader tenant setting.

Microsoft says guests typically lose access within one hour when sharing is restricted or disabled. See its external sharing overview for this behavior and related access considerations.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.