Back to main siteBack Contact us
Solution Brief

Microsoft SharePoint and OneDrive

Document Management

SharePoint and OneDrive: where the sharing links accumulate

Most organizations moved their files to SharePoint and OneDrive and considered the project finished. What follows is slower and less visible: sharing links created for one purpose and never revoked, permissions inherited in ways nobody intended, and no retention policy on content that is now the organization's primary record. This brief covers what needs deciding and in what order.

PlatformMicrosoft SharePoint and OneDrive
CategoryDocument management
Reading timeAbout four minutes
I

Executive summary

The migration is the easy part and it is the part everybody plans for. Files move, staff adjust, and the file server is decommissioned. The governance that the old file server provided by accident, chiefly that sharing outside the organization was difficult, does not move with it.

In its place is a system designed to make sharing simple. That is a genuine improvement in how people work and a genuine change in exposure, and the second half is rarely addressed with the same energy as the first.

Takeaway: the risk appears after the migration succeeds, not during it.

II

Why permissions become unreadable

Permission inheritance is the usual culprit. A folder inherits from its site, somebody breaks that inheritance to give one person access to one document, and from that point the two diverge. Repeat across several years and the effective permissions on a given file bear little relation to what anybody intended.

Sharing links compound it. A link created to send a document to a client may be set to work for anybody who has it, with no expiry. That link continues working after the project, after the client relationship ends, and after the employee who created it has left.

Neither of these is visible in normal use. A file looks the same whether four people or four hundred can open it, which is precisely why the problem grows unobserved.

SITE POLICY INHERITS INHERITANCE BROKEN DIVERGES FROM HERE ON site policy changes no longer apply
Exhibit A. One reasonable exception, and everything below it stops following the policy.

Takeaway: exceptions are permanent unless something reviews them.

III

The approach, in order of value

Start with external sharing settings at tenant level: whether links may be created for anybody who has them, whether they expire, and whether staff may share with external addresses at all. This single set of choices removes most of the ongoing exposure.

Next, report on what already exists. Existing anonymous links are the accumulated risk, and most organizations have never listed them. The list is usually longer than expected and frequently includes material nobody would knowingly publish.

Then set retention. Content in SharePoint is now the organization's record, and how long it is kept should be a decision rather than an accident. Sensitivity labels follow, so that protection travels with a document rather than depending on where it happens to sit.

Finally, backup. The recycle bin and version history cover accidental deletion for a limited period. They are not a backup, and a retention policy that removed something is not recoverable from them.

Takeaway: tenant settings first, because they stop the problem growing while you address the rest.

IV

What each control answers

ConcernControlTypical state
Links working for anybodyExternal sharing policyPermitted
Links with no end dateLink expiryNot set
Who can open this filePermission reportingUnknown
How long content is keptRetention policyIndefinite
Recovering deleted contentThird party backupAssumed, absent

Key findings

  • The file server's accidental governance did not migrate with the files.
  • Anonymous links are the largest single exposure and the least frequently reviewed.
  • Broken permission inheritance is invisible in normal use and permanent by default.
  • Version history and the recycle bin are not backup, and the distinction matters when a retention policy has acted.

Takeaway: every item above is a configuration decision, not a purchase.

V

Recommendation

For any organization past its migration, the sequence above is worth running once properly and then reviewing annually. Most of it costs nothing beyond the time to decide, which makes it unusually good value against almost anything else on a security roadmap.

Where a regulatory retention obligation exists, or where client contracts specify how material must be handled, the labelling and retention work stops being optional and should be scoped deliberately rather than approximated.

Takeaway: this is administration rather than expenditure, and it is usually overdue.

Next steps

Schedule the sharing readout

A short session producing the list of existing anonymous links and external guests, which is the fastest way to establish what is currently reachable from outside the organization.

Schedule the readout

Get in touch with Your Company

Questions about this solution? Reach us directly.