What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Neither SharePoint Online nor SharePoint Server is inherently safer in every organization. The key difference is who operates the infrastructure and which security controls your team must configure and maintain. Microsoft operates the SharePoint Online service, but customers remain responsible for identities, permissions, sharing, and data governance. With SharePoint Server, the organization must also secure and operate the farm, servers, databases, and network connections.
How security responsibilities differ
| Area | SharePoint Online | SharePoint Server on-premises |
|---|---|---|
| Infrastructure | Microsoft describes service-side datacenter, network, application, monitoring, and patching safeguards. The organization configures its tenant and manages access to its content. | The organization operates and hardens the farm, hosts, databases, and network boundaries, in addition to managing access to content. |
| Identity and access | The organization configures Microsoft 365 identity protections, permissions, and sharing settings. | The organization configures identity integration and authentication for its deployment, then manages SharePoint permissions and any app or server-to-server trust. |
| Network and host exposure | Microsoft operates the service infrastructure; the customer still manages tenant configuration and connected identities, devices, and apps. | Farm topology determines which servers, services, ports, and connections must be protected. The organization is responsible for the resulting configuration. |
| Monitoring and recovery | Microsoft describes service monitoring, audit resources, and recovery features. The organization must decide how to monitor its tenant and validate recovery against its own needs. | The organization operates farm monitoring and recovery processes and must test them against its business requirements. |
Microsoft’s cloud safeguards documentation describes service controls; it is not, by itself, an independent comparative security assessment. The cited Microsoft documentation does not establish that either deployment has a lower breach or incident rate.
Secure SharePoint Online with tenant-side controls
Microsoft’s “How SharePoint and OneDrive safeguard your data in the cloud” guidance (last updated January 13, 2025) describes protections including encryption in transit and at rest, restricted and time-limited engineer access subject to approval and audit events, antimalware scanning of uploads, and service monitoring and patching. These are Microsoft’s descriptions of its service design, not a guarantee that a tenant is configured safely. Microsoft states, “You control your data.”
Protect administrator and user identities
- Enable two-factor authentication for Microsoft 365 identities. Microsoft recommends starting with Global Administrators, then covering other administrators and site collection administrators.
- Use device-based Conditional Access, where available in your configuration and licensing, to limit access from unmanaged devices. Review session sign-out controls as part of the same access policy.
- Review app permissions and connected access paths as well as interactive user sign-ins; a strong sign-in policy does not by itself constrain what an authorized app can access.
Control sharing and data exposure
- Set external-sharing options to match business need, and review who can invite external users and which sites allow sharing.
- Use data loss prevention policies where applicable to help prevent accidental exposure of sensitive information. Validate policy scope and behavior against your tenant’s licensing and configuration.
- Review site, library, folder, and item access rather than treating one tenant-level sharing setting as proof that every document is appropriately restricted.
Secure the SharePoint Server farm and its connections
For on-premises SharePoint, Microsoft’s “Plan security hardening for SharePoint Server” guidance (last updated January 19, 2023) makes hardening dependent on server role and farm design. Treat the farm as an operational security boundary: a safe setting for one topology may be inappropriate for another.
#1 Best Overall
Review the actual farm topology
- Place firewalls between farm servers and outside requests, and limit access to Central Administration to the administrators and systems that need it.
- Harden Web.config and retain only required services. Review application-specific ports and SQL Server communication for the enabled roles and service applications.
- Do not apply a generic port list as a universal firewall recipe. Confirm external connections, enabled components, and supported settings for the deployed SharePoint and Windows Server versions.
- Include the surrounding environment in the threat review: Microsoft’s hardening page says it does not cover hardening other software in the environment.
Review authentication and trust separately
SharePoint Server authentication options vary by version and configuration. Microsoft’s authentication overview documents Windows, forms-based, SAML, and OpenID Connect (OIDC)-based claims authentication; it specifically notes OIDC 1.0 support for Subscription Edition. Confirm the supported method for the exact SharePoint Server version and deployment.
Server-to-server OAuth trust is not the same as a user signing in. Microsoft’s server-to-server guidance calls for a configured trust and appropriate permissions, and requires SSL on web applications with incoming or outgoing server-to-server endpoints. Review app and server-to-server authorization independently of user authentication.
Rank #2
Manage permissions and sharing in either deployment
Authentication validates who is making a request; authorization determines what that identity can do. SharePoint permissions can apply at the site, list or library, folder, and document or item level. Access commonly inherits from a parent scope until inheritance is broken and unique assignments are created.
- Grant the least privilege needed for the work, and use groups to manage access for roles or teams instead of assigning permissions person by person wherever practical.
- Preserve inheritance when it fits the access model. Unique permissions can be appropriate for a real exception, but extensive fine-grained access makes reviews harder and can slow access.
- Include permission reviews in the business process: identify content owners, check group membership and exceptions, and remove access when it is no longer needed.
- For SharePoint Online, include external sharing in those reviews. For SharePoint Server, include unique permissions across sites, libraries, folders, and items.
Microsoft’s “Overview of site permissions in SharePoint Server” and “Plan site permissions in SharePoint Server” guidance (both last updated January 19, 2023) describe these permission scopes, inheritance, least privilege, and the administrative trade-offs of extensive unique permissions. The same access-design principle is useful when reviewing SharePoint Online content.
Plan monitoring and recovery around your requirements
For SharePoint Online, determine which tenant activity your organization needs to audit and monitor, who investigates alerts, and how the response process handles suspected account compromise or unintended sharing. Microsoft describes service monitoring and audit resources, but the organization still needs to monitor its own tenant activity and act on findings.
Microsoft’s cloud safeguards page, last updated January 13, 2025, states that metadata backups are retained for 14 days and metadata can be restored to a point in time within a five-minute window. The page also describes version history and recycle-bin options. These are dated Microsoft statements, not a blanket guarantee that every item, tenant, or recovery scenario has identical retention or restoration behavior. Check current service documentation and terms, then validate that available recovery options meet your organization’s recovery requirements.
Rank #4
For SharePoint Server, define and test recovery for the farm components and content your business needs, and assign responsibility for monitoring and incident response. Recovery plans should reflect the deployed topology and the organization’s required recovery outcomes.
Quick Recap
A practical control review
- Document the deployment. Record whether the environment is SharePoint Online or SharePoint Server, the applicable version or edition, tenant configuration, farm topology, and relevant licensing.
- Map access. Identify administrators, users, groups, apps, external users, and server-to-server trusts that can reach SharePoint content.
- Check authorization. Review least privilege, group membership, inherited access, unique permission exceptions, and external sharing against business need.
- Check the deployment-specific boundary. For Online, review identity, Conditional Access, session, sharing, and DLP configuration. For Server, review role-specific hosts, firewalls, Central Administration, services, Web.config, SQL communication, and farm connections.
- Exercise operations. Confirm who monitors activity, responds to an incident, and tests recovery; verify these procedures against current product guidance and business requirements.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →

