Data Protection

Restrict External File Sharing

Share with intended recipients, remove unnecessary public access, and check permissions from both authorized and unauthorized accounts.

Content review: 2026-09-22 · Estimated effort: Medium

Priority and effort are editorial starting points, not calculated risk or mandatory deadlines. Adapt to business impact, vendor instructions, available licenses, and applicable obligations. Test changes before broad rollout.

Before you start

Before starting: name the data owner and service administrator. Identify sensitive folders, current external collaborators, and business deadlines. Record existing permissions securely and agree how approved collaboration will continue. Use a synthetic test file, not customer data, for access tests.

Put it into practice

  1. Review organization defaults and the actual site, drive, folder, and file permissions. Include anonymous links, direct grants, inherited group access, guests, and shared links. In SharePoint/OneDrive, organization and site settings interact; a site cannot be more permissive than the organization. In Google Workspace, review Drive and Docs sharing controls and shared-drive settings.
  2. Prefer named, authenticated recipients and view-only access unless editing is required. Make restricted or specific-person links the default where supported. Separate intentionally public resources from sensitive working areas. Limiting a default does not by itself remove existing links or other access grants.
  3. Pilot restrictions in one low-impact location. Remove obsolete anonymous links and unnecessary direct or group permissions with owner approval. Where supported and licensed, use guest/link expiry or domain restrictions; these supplement individual access review rather than prove that every user at an allowed domain is authorized.
  4. Assign an owner and review date to ongoing external access. Remove access when work ends or a person leaves, and check group membership and alternate links as well. Start with built-in sharing lists and manual reviews before buying governance tooling; automated reviews and advanced restrictions vary by subscription.
  5. Verify: allow for the provider's documented propagation period and retest; Google Drive sharing changes can take up to 24 hours, with inconsistent enforcement during propagation. Open the test file as an intended external recipient, as a different unauthorized account, and signed out. Confirm intended permissions, then revoke access and retest after propagation. Incognito alone tests anonymous access, not another authenticated user's permissions. Record outcomes without publishing sensitive paths or names.
  6. If collaboration breaks: restore only the documented approved access and repeat the tests; do not make the whole folder public. Revoking a link cannot recall copies already downloaded. Investigate possible exposure separately, and repeat reviews after changes to ownership, groups, or sharing policy.

Make a start

Tools and templates

Start with what you already have. “Included” means part of an existing eligible product or subscription, not a free standalone service. Options reviewed 2026-09-22; check current vendor terms before choosing.

Start without another software subscription

Use existing sharing permissions and the Excel review worksheet; test approved, unauthorized and signed-out access.

Where this stops: Advanced governance may cost extra. Basic Office does not guarantee SharePoint access, and a free consumer file-sharing account is not a substitute for approved business storage.

See the official sources and eligibility details below. Free software can still require equipment, storage and staff time.

SharePoint and OneDrive sharing controls

Use the controls in your existing SharePoint/OneDrive subscription

In the SharePoint admin center, review Policies > Sharing and the relevant site settings. Check actual file permissions and links as well as organization defaults.

Limits: Requires an administrator and an eligible service subscription. Advanced governance can require additional licensing; changing defaults does not revoke every existing grant.

Your information: Access lists and files remain within your chosen collaboration service. Store review records privately and test with synthetic files.

Official instructions: SharePoint and OneDrive sharing controls ↗

Download a working template

Free to download and adapt for your team. Open CSV files in Microsoft Excel using your existing Office license; Markdown files open in a text editor such as Notepad. Save an Excel Workbook (.xlsx) copy if you add formatting. These are manual worksheets, with no macros, scoring or automatic verification.

  • External sharing review (CSV) ↓

    Review intended recipients and alternate access paths. Record authorized, unauthorized and signed-out test outcomes after allowing for propagation.

Fictional worked example

Illustration only. This is not a customer story, lab result, or evidence that your environment is protected. Replace the example entries and record your own observations.

A project owner needs one external contractor to access a non-sensitive test document.

Use the External sharing review template.

What to enter before testing

Resource reference
EXAMPLE: restricted test document
Intended recipient scope
One approved contractor test account
Approved recipient test
Not tested
Unauthorized account test
Not tested
Signed-out test
Not tested

How to verify

Record existing links and inherited access before an approved change. Test with the intended recipient, a controlled unauthorized account and a signed-out session. After revoking access, allow documented propagation and retest all paths.

If the result is unexpected

If unintended access remains, inspect other links, direct grants and group membership. If the contractor loses required access, correct only the intended grant. Previously downloaded copies are not recalled by changing permissions.

Save completed worksheets privately. They can describe security gaps, systems and people. Do not include passwords, recovery keys or confidential message content. This site does not receive your edits; a cloud editor or synced folder may send them to its provider.

Sources and review approach

Original small-team guidance with selected NIST CSF 2.0 alignments, not an official crosswalk or a complete framework implementation. These instructions are a starting point, not a claim of testing in your environment.

  • NIST CSF 2.0: PR.AA-05: reviewed access permissions
  • NIST CSF 2.0: PR.DS-01: protecting stored data
How this guidance is prepared