SharePoint Online external sharing is controlled at several layers: the organization, the individual site, Microsoft Entra ID, Microsoft 365 Groups or Teams, and the sharing link itself. The most permissive option is not automatically the effective one—the most restrictive applicable setting wins.
This guide explains how to configure external sharing, choose the right link type, restrict domains and users, manage guest access, and diagnose common failures without relying on obsolete SharePoint or Azure AD instructions.
How SharePoint external sharing works
External sharing lets people outside your Microsoft 365 organization access SharePoint sites, files, or folders. Depending on your configuration, an external recipient may authenticate with a work or school account, a Microsoft account, a verification code, or no account at all.
There are two related but different sharing models:
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
#1 Best Overall
- Used Book in Good Condition
- Authenticated guest sharing: the recipient signs in or verifies their email address. With Microsoft Entra B2B integration, SharePoint creates or uses a guest account.
- Anyone-link sharing: anyone who receives the link can open the content without authentication. SharePoint cannot identify who used the link.
Sites always use Microsoft Entra B2B for external sharing. File and folder sharing can also use Microsoft Entra B2B when the integration is enabled.
The four SharePoint sharing levels
| Setting | What it permits | Typical use |
|---|---|---|
| Anyone | Anyone links for files and folders, plus site sharing with new and existing authenticated guests | Public downloads or low-risk collaboration |
| New and existing guests | New or existing guests using a work/school account, Microsoft account, or verification code | Normal supplier, customer, or contractor collaboration |
| Existing guests | Only guests already present in the organization directory | Controlled collaboration with a pre-approved guest list |
| Only people in your organization | No external sharing | Confidential or internal-only content |
These levels are available at both organization and site scope, but a site cannot be more permissive than the organization-level SharePoint setting. If the organization is changed to a stricter level, sites become stricter as well. Restoring the organization setting can restore a site’s previous effective setting. Microsoft currently documents external sharing as turned on by default for the SharePoint and OneDrive environment, though individual site defaults vary.
Organization-level configuration
Use the organization setting as the upper limit for every SharePoint site.
- Open the SharePoint admin center.
- Go to Policies > Sharing.
- Under External sharing, select the organization-level SharePoint sharing level.
- Set the OneDrive level separately if required. OneDrive can be more restrictive than SharePoint, but not more permissive.
- Expand More external sharing settings.
- Configure domain restrictions, guest permissions, link expiration, and other advanced options.
- Select Save.
The organization-level SharePoint setting applies to all SharePoint site types, including Microsoft 365 group-connected sites and Teams sites. However, Microsoft 365 Group and Teams guest settings can impose additional restrictions on their connected sites.
Recommended organization-level baseline
For most business tenants, New and existing guests is a practical starting point. It permits authenticated collaboration while preventing anonymous Anyone links. Choose Anyone only when your organization has a clear use case for unauthenticated links and compensating controls such as expiration and view-only permissions.
Site-level external sharing
A site administrator can make a particular site more restrictive than the organization setting.
- In the SharePoint admin center, select Active sites.
- Select the site.
- Open the Settings tab.
- Select More sharing settings.
- In Site content can be shared with, choose the permitted level.
- Save the change.
For a channel site, locate the site through the Channel sites column. The site-level setting controls both site sharing and file/folder sharing. A sensitivity label applied to a site can also control its external-sharing settings.
The label Anyone at site level is not a recipient type. It enables Anyone links for files and folders and permits site sharing with new and existing authenticated guests.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Fix the driver behind crashes, sound loss and screen glitches3Clear out junk files and repair common Windows errorsDocumented default settings by site type
| Site type | Default external-sharing level |
|---|---|
| Classic site | Only people in your organization |
| OneDrive | Anyone |
| Microsoft 365 group-connected site, including Teams | New and existing guests when group owners may add external members; otherwise Existing guests only |
| Communication site | Only people in your organization |
| Modern non-group site | Only people in your organization |
| Root communication site | Anyone |
These are defaults, not guarantees of effective access. Organization policy, Microsoft Entra restrictions, group settings, and sensitivity labels can make a site more restrictive.
Choose the correct sharing link
In the current SharePoint interface, the link labels are:
Rank #2
- Anyone with the link: no sign-in required. Forwarding is possible, and access cannot be attributed to a specific person.
- People in your organization with the link: requires an account in your tenant.
- People with existing access: creates a link without changing permissions.
- Specific people: grants access to the named recipients, who must authenticate or verify their identity.
Anyone with the link is available only when the applicable sharing level is Anyone. If the organization default link type is Anyone but the site or OneDrive allows only authenticated guests, the effective default shown to users becomes People in your organization with the link; users must choose Specific people to share externally with authenticated recipients. The older terms “anonymous access” and “shareable link” refer to this legacy concept; the current label is “Anyone with the link.”
Set the organization default link type
- Go to SharePoint admin center > Policies > Sharing.
- Set the organization-level default sharing link type.
- Select Save.
Set a site default link type
- Open SharePoint admin center > Active sites.
- Select the site.
- On the command bar, select Sharing.
- Clear Same as organization-level setting.
- Choose the default link type and select Save.
The default-link setting applies to libraries using the new SharePoint experience. It does not change link behavior in Outlook Web App, Outlook 2016, or Office clients earlier than Office 2016.
Recommended Free Tools
For Teams private-channel and shared-channel sites, Microsoft documents changing the default link type with the Set-SPOSite PowerShell cmdlet rather than the regular site UI. Check the current Microsoft procedure for the relevant parameter and site URL.
Control Anyone-link risk
If Anyone links are permitted, configure restrictions under SharePoint admin center > Policies > Sharing.
Expiration
Administrators can require Anyone links to expire and specify a maximum lifetime. If the maximum is shortened, existing links are shortened. If a new limit is longer, existing links retain their current expiration rather than automatically gaining more time.
An expired Anyone link cannot be renewed. The owner must create a new link.
Permissions
Anyone links can be limited to View. Depending on the configuration, folder links may also allow:
- View and edit
- View, edit, and upload
Use view-only links for published material. Avoid edit or upload permissions unless the workflow specifically requires them.
OneDrive’s Request Files feature requires Anyone sharing and a link permission that permits editing or uploading. Other OneDrive sharing configurations disable Request Files.
Restrict sharing by domain
Domain restrictions control invitations and new sharing relationships. They do not remove access from guests who already exist in the organization directory.
Free tools Windows power users keep installed
One-click scans. No signup required.
Rank #3
- Go to SharePoint admin center > Policies > Sharing.
- Expand More external sharing settings.
- Select Limit external sharing by domain.
- Choose whether to allow or block domains.
- Enter each domain in
domain.comformat. - Press Enter after each domain.
- Save the configuration.
You can configure up to 5,000 domains. Microsoft Entra collaboration restrictions also apply, and a site-level domain rule cannot override an organization-level or Microsoft Entra restriction.
Restrict which users can share externally
SharePoint can limit file and folder external sharing to members of selected security groups.
- Open SharePoint admin center > Sharing.
- Under External sharing, expand More external sharing settings.
- Enable Allow only users in specific security groups to share externally.
- Select Manage security groups.
- Choose Add a security group.
- Select the group.
- For Can share with, choose Authenticated guests only or Anyone.
- Select Save.
A maximum of 12 security groups can be configured. The default choice, Authenticated guests only, is safer for most environments.
This control applies to SharePoint and OneDrive file/folder sharing. It does not block sharing performed through Microsoft 365 Groups or Teams. A guest added to a group or team may still receive access to the associated SharePoint site.
Microsoft Entra ID settings that can block sharing
SharePoint settings are not the only gate. In the Microsoft Entra admin center, review:
Identity > External Identities > External collaboration settings
- Guest user access
- Guest invite restrictions
- Enable guest self-service sign-up via user flows
- External user leave settings
- Collaboration restrictions
For cross-tenant controls, go to Identity > External Identities > Cross-tenant access settings. Review both Default settings and the Organizational settings tab.
When Microsoft Entra B2B integration is enabled, file, folder, and site sharing creates or uses a guest account and Entra external-collaboration policies apply. Without B2B integration, some file and folder workflows can authenticate externally without creating a guest account; Entra settings do not apply to that particular workflow.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallGuest access, expiration, and permissions
Guest sharing by guests
The organization setting Allow guests to share items they don’t own controls whether guests may reshare content. By default, guests need Full Control to share items externally. Enabling the setting allows guests to share items they do not own. A guest can always share an item for which they have Full Control.
Guest expiration
Guest access to a site or OneDrive can be configured to expire after a specified number of days. Site-level guest expiration can also be configured. This is useful for contractors, temporary projects, and supplier reviews, but it should be paired with an ownership process so legitimate access is renewed intentionally.
Rank #4
Verification-code reauthentication
Verification-code users can be required to authenticate again after a configured number of days. If Microsoft Entra B2B collaboration is enabled, the Microsoft Entra setting takes precedence over the SharePoint setting.
Microsoft 365 Groups and Teams caveats
Teams sites are connected to Microsoft 365 Groups, so several systems affect access:
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →- The SharePoint organization-level sharing limit applies.
- The individual site setting applies within that limit.
- Microsoft 365 Group or Teams guest settings can add another restriction.
- Group-connected site defaults depend on whether group owners are allowed to add people outside the organization.
A guest added to a group or team can still fail to open the connected SharePoint site if Microsoft 365 Group settings prevent guest members from accessing group resources. Turning on SharePoint external sharing does not override that restriction.
How to share a site or file safely
Share with named external people
- Open the site, library, folder, or file.
- Select Share.
- Choose Specific people.
- Enter the recipient’s email address.
- Choose the minimum permission required, normally Can view.
- Add an expiration or message if available.
- Send the invitation.
Use Specific people rather than Anyone with the link when you need an auditable recipient list.
Share a site through advanced permissions
If permissions are granted through the advanced permissions page instead of the Share site button, the guest does not receive an invitation email. The administrator must provide the site link separately. Microsoft recommends granting permissions at site level rather than directly at library or folder level for this workflow.
Common failures and their causes
| Symptom | Likely cause | Check |
|---|---|---|
| Anyone link option is missing | Organization or site is not set to Anyone | SharePoint admin center sharing level and site More sharing settings |
| Guest invitation is rejected | Microsoft Entra collaboration or cross-tenant restriction | External collaboration and cross-tenant access settings |
| Teams guest cannot open files | Group or Teams guest-resource access is blocked | Microsoft 365 Group and Teams guest settings |
| Guest receives no invitation | Access was granted through advanced permissions | Send the site link separately |
| Former guest still has a local copy | Synchronization downloaded content before access was removed | Remove access, then address the retained local copy through your data and device policies |
| Several guests can see one another’s names | They share a folder and appear in Manage Access | Review folder sharing and use separate folders when confidentiality matters |
| Old invitation no longer works | Legacy Invitation Manager invitations stopped granting access in June 2024 | Reshare the document or folder to generate a valid invitation |
B2B Sync limitations
External users can synchronize SharePoint content only under specific conditions:
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →- The content must be shared at the site or folder level. A file shared individually from an Office application cannot be synchronized.
- The recipient must have a guest account in the organization and a Microsoft Entra work or school account.
- Anyone links, Microsoft accounts, and other personal accounts are unsupported.
- The recipient and content tenant must be in the same Microsoft cloud: Azure Commercial, Azure Government, or Azure China 21Vianet.
- Conditional Access policies requiring interactive prompts, such as MFA, Terms of Use, or device-compliance interaction, can prevent synchronization because the sync client does not support that interactive sign-in interface.
- On macOS, external-site Files On-Demand thumbnails do not display.
- A guest account created with a different email-address format from the address used by the sync app can prevent synchronization.
Removing SharePoint permission or deleting the guest account stops current access, but it does not delete content that was already synchronized to the guest’s computer.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.PowerShell and automation warning
Microsoft’s older bulk-invitation example uses the deprecated AzureADPreview module, including Connect-AzureAD, New-AzureADMSInvitation, and Add-AzureADGroupMember. It is not a current Microsoft Graph implementation.
The Microsoft Entra ID and MSOnline PowerShell modules were deprecated on March 30, 2024. Microsoft documented them as continuing to function through March 30, 2025, with limited support, and recommends Microsoft Graph PowerShell for current automation. Treat scripts using commands such as the following as legacy code that needs migration rather than as a new deployment pattern:
Connect-AzureAD -TenantDomain $domain -AccountId $admin
Best Value
Before automating invitations or group membership, confirm the current Microsoft Graph PowerShell cmdlets, permissions, consent model, and approval process for your tenant.
Practical configuration checklist
- Set the organization-level SharePoint sharing limit.
- Set OneDrive to the same level or a stricter level.
- Review Microsoft Entra external collaboration and cross-tenant settings.
- Set stricter sharing levels on sensitive sites.
- Choose Specific people or authenticated guests for business collaboration.
- Enable Anyone links only where their audit limitations are acceptable.
- Require expiration for Anyone links and use view-only permissions where possible.
- Configure allowed or blocked domains.
- Limit external sharing to approved security groups if the business requires it.
- Review Microsoft 365 Groups and Teams guest settings.
- Set guest expiration and reshare permissions deliberately.
- Document who owns guest reviews and access removal.
FAQ
Is external sharing enabled by default in SharePoint Online?
Microsoft currently documents external sharing as turned on by default for the SharePoint and OneDrive environment, although the default sharing level varies by site type. Organization policy and site configuration can make effective access more restrictive.
Can a SharePoint site be more permissive than the organization setting?
No. A site cannot exceed the organization-level SharePoint sharing limit. The most restrictive applicable setting wins.
Why can’t I select Anyone with the link?
The organization or site is probably set to New and existing guests, Existing guests, or Only people in your organization. Anyone with the link is available only when the applicable setting is Anyone.
Recommended Free Tools
Does SharePoint Anyone sharing require a guest account?
No. Anyone links do not require authentication or a guest account. Authenticated external sharing normally uses guest identity, especially when Microsoft Entra B2B integration is enabled.
Can I restrict external sharing to specific email domains?
Yes. Use SharePoint admin center > Policies > Sharing > More external sharing settings > Limit external sharing by domain. You can configure up to 5,000 domains, but existing directory guests are not affected by invitation-domain restrictions.
Do security groups stop guests being added through Teams?
No. The approved security-group restriction applies to SharePoint and OneDrive file/folder sharing. It does not restrict sharing performed through Microsoft 365 Groups or Teams.
What happens when an Anyone link expires?
It cannot be renewed. The owner must create a new link.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Will deleting a guest remove files already synchronized to their computer?
No. Removing permission or deleting the guest stops current SharePoint access, but content already synchronized remains on the guest’s computer.
The Bottom Line
Use organization-level sharing as the ceiling, make sensitive sites stricter, and prefer Specific people with authenticated guests for normal collaboration. If Anyone links are necessary, require expiration and restrict permissions. When access fails, check Microsoft Entra ID, Microsoft 365 Groups, Teams, and site settings together—the SharePoint sharing switch alone does not control every path to a connected site.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

