Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

SharePoint Online external sharing is controlled at several layers: the organization, the individual site, Microsoft Entra ID, Microsoft 365 Groups or Teams, and the sharing link itself. The most permissive option is not automatically the effective one—the most restrictive applicable setting wins.

This guide explains how to configure external sharing, choose the right link type, restrict domains and users, manage guest access, and diagnose common failures without relying on obsolete SharePoint or Azure AD instructions.

How SharePoint external sharing works

External sharing lets people outside your Microsoft 365 organization access SharePoint sites, files, or folders. Depending on your configuration, an external recipient may authenticate with a work or school account, a Microsoft account, a verification code, or no account at all.

There are two related but different sharing models:

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Authenticated guest sharing: the recipient signs in or verifies their email address. With Microsoft Entra B2B integration, SharePoint creates or uses a guest account.
  • Anyone-link sharing: anyone who receives the link can open the content without authentication. SharePoint cannot identify who used the link.

Sites always use Microsoft Entra B2B for external sharing. File and folder sharing can also use Microsoft Entra B2B when the integration is enabled.

The four SharePoint sharing levels

Setting What it permits Typical use
Anyone Anyone links for files and folders, plus site sharing with new and existing authenticated guests Public downloads or low-risk collaboration
New and existing guests New or existing guests using a work/school account, Microsoft account, or verification code Normal supplier, customer, or contractor collaboration
Existing guests Only guests already present in the organization directory Controlled collaboration with a pre-approved guest list
Only people in your organization No external sharing Confidential or internal-only content

These levels are available at both organization and site scope, but a site cannot be more permissive than the organization-level SharePoint setting. If the organization is changed to a stricter level, sites become stricter as well. Restoring the organization setting can restore a site’s previous effective setting. Microsoft currently documents external sharing as turned on by default for the SharePoint and OneDrive environment, though individual site defaults vary.

Organization-level configuration

Use the organization setting as the upper limit for every SharePoint site.

  1. Open the SharePoint admin center.
  2. Go to Policies > Sharing.
  3. Under External sharing, select the organization-level SharePoint sharing level.
  4. Set the OneDrive level separately if required. OneDrive can be more restrictive than SharePoint, but not more permissive.
  5. Expand More external sharing settings.
  6. Configure domain restrictions, guest permissions, link expiration, and other advanced options.
  7. Select Save.

The organization-level SharePoint setting applies to all SharePoint site types, including Microsoft 365 group-connected sites and Teams sites. However, Microsoft 365 Group and Teams guest settings can impose additional restrictions on their connected sites.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Recommended organization-level baseline

For most business tenants, New and existing guests is a practical starting point. It permits authenticated collaboration while preventing anonymous Anyone links. Choose Anyone only when your organization has a clear use case for unauthenticated links and compensating controls such as expiration and view-only permissions.

Site-level external sharing

A site administrator can make a particular site more restrictive than the organization setting.

  1. In the SharePoint admin center, select Active sites.
  2. Select the site.
  3. Open the Settings tab.
  4. Select More sharing settings.
  5. In Site content can be shared with, choose the permitted level.
  6. Save the change.

For a channel site, locate the site through the Channel sites column. The site-level setting controls both site sharing and file/folder sharing. A sensitivity label applied to a site can also control its external-sharing settings.

The label Anyone at site level is not a recipient type. It enables Anyone links for files and folders and permits site sharing with new and existing authenticated guests.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Documented default settings by site type

Site type Default external-sharing level
Classic site Only people in your organization
OneDrive Anyone
Microsoft 365 group-connected site, including Teams New and existing guests when group owners may add external members; otherwise Existing guests only
Communication site Only people in your organization
Modern non-group site Only people in your organization
Root communication site Anyone

These are defaults, not guarantees of effective access. Organization policy, Microsoft Entra restrictions, group settings, and sensitivity labels can make a site more restrictive.

Choose the correct sharing link

In the current SharePoint interface, the link labels are:

  • Anyone with the link: no sign-in required. Forwarding is possible, and access cannot be attributed to a specific person.
  • People in your organization with the link: requires an account in your tenant.
  • People with existing access: creates a link without changing permissions.
  • Specific people: grants access to the named recipients, who must authenticate or verify their identity.

Anyone with the link is available only when the applicable sharing level is Anyone. If the organization default link type is Anyone but the site or OneDrive allows only authenticated guests, the effective default shown to users becomes People in your organization with the link; users must choose Specific people to share externally with authenticated recipients. The older terms “anonymous access” and “shareable link” refer to this legacy concept; the current label is “Anyone with the link.”

Set the organization default link type

  1. Go to SharePoint admin center > Policies > Sharing.
  2. Set the organization-level default sharing link type.
  3. Select Save.

Set a site default link type

  1. Open SharePoint admin center > Active sites.
  2. Select the site.
  3. On the command bar, select Sharing.
  4. Clear Same as organization-level setting.
  5. Choose the default link type and select Save.

The default-link setting applies to libraries using the new SharePoint experience. It does not change link behavior in Outlook Web App, Outlook 2016, or Office clients earlier than Office 2016.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For Teams private-channel and shared-channel sites, Microsoft documents changing the default link type with the Set-SPOSite PowerShell cmdlet rather than the regular site UI. Check the current Microsoft procedure for the relevant parameter and site URL.

Control Anyone-link risk

If Anyone links are permitted, configure restrictions under SharePoint admin center > Policies > Sharing.

Expiration

Administrators can require Anyone links to expire and specify a maximum lifetime. If the maximum is shortened, existing links are shortened. If a new limit is longer, existing links retain their current expiration rather than automatically gaining more time.

An expired Anyone link cannot be renewed. The owner must create a new link.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Permissions

Anyone links can be limited to View. Depending on the configuration, folder links may also allow:

  • View and edit
  • View, edit, and upload

Use view-only links for published material. Avoid edit or upload permissions unless the workflow specifically requires them.

OneDrive’s Request Files feature requires Anyone sharing and a link permission that permits editing or uploading. Other OneDrive sharing configurations disable Request Files.

Restrict sharing by domain

Domain restrictions control invitations and new sharing relationships. They do not remove access from guests who already exist in the organization directory.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. Go to SharePoint admin center > Policies > Sharing.
  2. Expand More external sharing settings.
  3. Select Limit external sharing by domain.
  4. Choose whether to allow or block domains.
  5. Enter each domain in domain.com format.
  6. Press Enter after each domain.
  7. Save the configuration.

You can configure up to 5,000 domains. Microsoft Entra collaboration restrictions also apply, and a site-level domain rule cannot override an organization-level or Microsoft Entra restriction.

Restrict which users can share externally

SharePoint can limit file and folder external sharing to members of selected security groups.

  1. Open SharePoint admin center > Sharing.
  2. Under External sharing, expand More external sharing settings.
  3. Enable Allow only users in specific security groups to share externally.
  4. Select Manage security groups.
  5. Choose Add a security group.
  6. Select the group.
  7. For Can share with, choose Authenticated guests only or Anyone.
  8. Select Save.

A maximum of 12 security groups can be configured. The default choice, Authenticated guests only, is safer for most environments.

This control applies to SharePoint and OneDrive file/folder sharing. It does not block sharing performed through Microsoft 365 Groups or Teams. A guest added to a group or team may still receive access to the associated SharePoint site.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Microsoft Entra ID settings that can block sharing

SharePoint settings are not the only gate. In the Microsoft Entra admin center, review:

Identity > External Identities > External collaboration settings

  • Guest user access
  • Guest invite restrictions
  • Enable guest self-service sign-up via user flows
  • External user leave settings
  • Collaboration restrictions

For cross-tenant controls, go to Identity > External Identities > Cross-tenant access settings. Review both Default settings and the Organizational settings tab.

When Microsoft Entra B2B integration is enabled, file, folder, and site sharing creates or uses a guest account and Entra external-collaboration policies apply. Without B2B integration, some file and folder workflows can authenticate externally without creating a guest account; Entra settings do not apply to that particular workflow.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Guest access, expiration, and permissions

Guest sharing by guests

The organization setting Allow guests to share items they don’t own controls whether guests may reshare content. By default, guests need Full Control to share items externally. Enabling the setting allows guests to share items they do not own. A guest can always share an item for which they have Full Control.

Guest expiration

Guest access to a site or OneDrive can be configured to expire after a specified number of days. Site-level guest expiration can also be configured. This is useful for contractors, temporary projects, and supplier reviews, but it should be paired with an ownership process so legitimate access is renewed intentionally.

Verification-code reauthentication

Verification-code users can be required to authenticate again after a configured number of days. If Microsoft Entra B2B collaboration is enabled, the Microsoft Entra setting takes precedence over the SharePoint setting.

Microsoft 365 Groups and Teams caveats

Teams sites are connected to Microsoft 365 Groups, so several systems affect access:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • The SharePoint organization-level sharing limit applies.
  • The individual site setting applies within that limit.
  • Microsoft 365 Group or Teams guest settings can add another restriction.
  • Group-connected site defaults depend on whether group owners are allowed to add people outside the organization.

A guest added to a group or team can still fail to open the connected SharePoint site if Microsoft 365 Group settings prevent guest members from accessing group resources. Turning on SharePoint external sharing does not override that restriction.

How to share a site or file safely

Share with named external people

  1. Open the site, library, folder, or file.
  2. Select Share.
  3. Choose Specific people.
  4. Enter the recipient’s email address.
  5. Choose the minimum permission required, normally Can view.
  6. Add an expiration or message if available.
  7. Send the invitation.

Use Specific people rather than Anyone with the link when you need an auditable recipient list.

Share a site through advanced permissions

If permissions are granted through the advanced permissions page instead of the Share site button, the guest does not receive an invitation email. The administrator must provide the site link separately. Microsoft recommends granting permissions at site level rather than directly at library or folder level for this workflow.

Common failures and their causes

Symptom Likely cause Check
Anyone link option is missing Organization or site is not set to Anyone SharePoint admin center sharing level and site More sharing settings
Guest invitation is rejected Microsoft Entra collaboration or cross-tenant restriction External collaboration and cross-tenant access settings
Teams guest cannot open files Group or Teams guest-resource access is blocked Microsoft 365 Group and Teams guest settings
Guest receives no invitation Access was granted through advanced permissions Send the site link separately
Former guest still has a local copy Synchronization downloaded content before access was removed Remove access, then address the retained local copy through your data and device policies
Several guests can see one another’s names They share a folder and appear in Manage Access Review folder sharing and use separate folders when confidentiality matters
Old invitation no longer works Legacy Invitation Manager invitations stopped granting access in June 2024 Reshare the document or folder to generate a valid invitation

B2B Sync limitations

External users can synchronize SharePoint content only under specific conditions:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • The content must be shared at the site or folder level. A file shared individually from an Office application cannot be synchronized.
  • The recipient must have a guest account in the organization and a Microsoft Entra work or school account.
  • Anyone links, Microsoft accounts, and other personal accounts are unsupported.
  • The recipient and content tenant must be in the same Microsoft cloud: Azure Commercial, Azure Government, or Azure China 21Vianet.
  • Conditional Access policies requiring interactive prompts, such as MFA, Terms of Use, or device-compliance interaction, can prevent synchronization because the sync client does not support that interactive sign-in interface.
  • On macOS, external-site Files On-Demand thumbnails do not display.
  • A guest account created with a different email-address format from the address used by the sync app can prevent synchronization.

Removing SharePoint permission or deleting the guest account stops current access, but it does not delete content that was already synchronized to the guest’s computer.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

PowerShell and automation warning

Microsoft’s older bulk-invitation example uses the deprecated AzureADPreview module, including Connect-AzureAD, New-AzureADMSInvitation, and Add-AzureADGroupMember. It is not a current Microsoft Graph implementation.

The Microsoft Entra ID and MSOnline PowerShell modules were deprecated on March 30, 2024. Microsoft documented them as continuing to function through March 30, 2025, with limited support, and recommends Microsoft Graph PowerShell for current automation. Treat scripts using commands such as the following as legacy code that needs migration rather than as a new deployment pattern:

Connect-AzureAD -TenantDomain $domain -AccountId $admin

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Before automating invitations or group membership, confirm the current Microsoft Graph PowerShell cmdlets, permissions, consent model, and approval process for your tenant.

Practical configuration checklist

  1. Set the organization-level SharePoint sharing limit.
  2. Set OneDrive to the same level or a stricter level.
  3. Review Microsoft Entra external collaboration and cross-tenant settings.
  4. Set stricter sharing levels on sensitive sites.
  5. Choose Specific people or authenticated guests for business collaboration.
  6. Enable Anyone links only where their audit limitations are acceptable.
  7. Require expiration for Anyone links and use view-only permissions where possible.
  8. Configure allowed or blocked domains.
  9. Limit external sharing to approved security groups if the business requires it.
  10. Review Microsoft 365 Groups and Teams guest settings.
  11. Set guest expiration and reshare permissions deliberately.
  12. Document who owns guest reviews and access removal.

FAQ

Is external sharing enabled by default in SharePoint Online?

Microsoft currently documents external sharing as turned on by default for the SharePoint and OneDrive environment, although the default sharing level varies by site type. Organization policy and site configuration can make effective access more restrictive.

Can a SharePoint site be more permissive than the organization setting?

No. A site cannot exceed the organization-level SharePoint sharing limit. The most restrictive applicable setting wins.

Why can’t I select Anyone with the link?

The organization or site is probably set to New and existing guests, Existing guests, or Only people in your organization. Anyone with the link is available only when the applicable setting is Anyone.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Does SharePoint Anyone sharing require a guest account?

No. Anyone links do not require authentication or a guest account. Authenticated external sharing normally uses guest identity, especially when Microsoft Entra B2B integration is enabled.

Can I restrict external sharing to specific email domains?

Yes. Use SharePoint admin center > Policies > Sharing > More external sharing settings > Limit external sharing by domain. You can configure up to 5,000 domains, but existing directory guests are not affected by invitation-domain restrictions.

Do security groups stop guests being added through Teams?

No. The approved security-group restriction applies to SharePoint and OneDrive file/folder sharing. It does not restrict sharing performed through Microsoft 365 Groups or Teams.

What happens when an Anyone link expires?

It cannot be renewed. The owner must create a new link.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Will deleting a guest remove files already synchronized to their computer?

No. Removing permission or deleting the guest stops current SharePoint access, but content already synchronized remains on the guest’s computer.

The Bottom Line

Use organization-level sharing as the ceiling, make sensitive sites stricter, and prefer Specific people with authenticated guests for normal collaboration. If Anyone links are necessary, require expiration and restrict permissions. When access fails, check Microsoft Entra ID, Microsoft 365 Groups, Teams, and site settings together—the SharePoint sharing switch alone does not control every path to a connected site.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.