Microsoft 365 safe links
Every "Copy link" click creates a permission. Nobody ever reviews it.
A typical tenant has thousands of sharing links, most without a password or an expiry, and no access review ever lists them. 1Security keeps every Microsoft 365 sharing link in one inventory - scope, type, password, expiration and the sensitive data behind it - retires the unsafe ones behind a review window, and sets the site defaults so the backlog does not grow back.
The problem
Nobody decided the file should be public forever.
A proposal shared with a vendor in 2023. A spreadsheet posted to a Teams channel with an anyone link because it was faster that day. A folder link forwarded outside the company by someone who was allowed to see it. Each was reasonable in its moment; none has an expiry, an owner, or a second look - and anyone links do not expire unless the tenant or the user set a limit.
Most access reviews cover users and groups. Links are neither, so they rarely make it onto one: the same tenant that certifies group membership every quarter typically carries thousands of live links it has never listed once. In our experience a large share of them are anyone links, most without a password, and some point at files with card numbers, IDs, contracts or health records.
1Security keeps the whole picture as one filterable inventory: link scope (anyone, organization, specific people), type (view, edit, review), password present or not, expired or permanent, disabled or active - crossed with 300+ sensitive-information detectors. The list that matters most is one filter away: public, sensitive, permanent.
In practice
The link hygiene pass most tenants run in their first week.
From every link ever created to a short, defensible cleanup - and defaults that keep it that way.
- 01
Surface the unsafe set
Open Files and filter: anyone links + files with sensitive detections + no expiration. Add "no password" for the edit links. This is your genuine already-exposed list - typically tens to a few hundred files, and most teams find in minutes what manual audits missed for years.
- 02
Read the evidence per file
Each row shows what the link reaches, which detections fired (card numbers, national IDs, credentials, health data), which users came in through the link, and the email trail - how many times the file also left by mail and when it last did.
- 03
Retire links behind a review window
Enable the link automation - anonymous links first, then links without a password or past their expiration - and each link becomes a staged proposal with a 72-hour review window. Owners see what is about to change; anything still needed is one click to reject.
- 04
Change the defaults so it stays clean
Site-level automations set the default link scope, require expiry on anyone links and set external-access expiry per site, so new links are born safe. An alert fires the moment a new public link lands on a sensitive file.
What makes it work
Links, sensitivity and remediation on one graph.
Three parts of the platform carry this workflow.
Site and link governance
Every site's links, sharing defaults and external exposure in one ranked view - including links without passwords and past expiration.
Explore SharePoint governance →Effective access, resolved
A link is one of many doors. The permission graph shows every path to a file, so removing the link never leaves a hidden one open.
Explore access management →Alerts on new exposure
A prebuilt policy watches for fresh public-and-sensitive links and mails you the moment one appears - with the file and the detections attached.
Explore the alerts tool →
FAQ
Common questions.
Is this Microsoft Defender's "Safe Links" feature?
No. Defender's Safe Links rewrites URLs in inbound mail and Teams messages to check them at click time. This page is about the sharing links your own users create on files and folders - standing permissions on your own files, which is a different job. The two complement each other and run side by side.
Can removing links break legitimate collaboration?
That is what the review window is for. Cleanup runs as staged proposals with a 72-hour default grace period (instant, 24 hours and 7 days are presets), owners can reject anything still needed, and every executed change is logged in Actions - reversible by restoring access, never by guesswork.
Do we need an E5 license for the sensitive-data part?
No. The 300+ detection types, including OCR of scans and screenshots, run in 1Security's own engine on standard Microsoft 365 licenses - Business Basic is enough. Purview sensitivity labels, if you have them, are imported and shown right next to our detections.
How fast do we see our own numbers?
The read-only connection starts listing links the same day. Sensitive-content detection runs across the tenant over the following days, and the public + sensitive + permanent filter fills in as it goes.
Find the links nobody would defend.
Connect read-only and see your public + sensitive + permanent list the same day - then retire it behind a review window and set the defaults so it does not come back.
Or let 2023's links keep deciding what is public.