Microsoft 365 external domain monitoring
Your tenant talks to hundreds of domains. Name every one.
A guest joins a group, a file goes to an outside address, a partner firm shows up in the audit log - each of those is a relationship with an external organization, and most tenants have never seen the list. 1Security turns every domain observed anywhere in your tenant into one row: the real company behind it, the guests it holds, the mail it exchanges, the files its people can reach - next to what your own Microsoft controls say about it. Where the two disagree, you get a flag instead of a surprise.
- 1 rowper counterparty - guests, correspondents, files reachable, sensitivity exposure, first and last activity
- 4 sourcesmail flow, guest accounts, shared files and audit-log actors, joined on one key: the domain
- 3 controlsread and reconciled - SharePoint sharing lists, cross-tenant access partners, mail allow and block lists
The problem
Each admin center knows a piece. No screen knows the company.
A mid-sized tenant typically exchanges data with several hundred external domains - customers, vendors, agencies, auditors, and the personal addresses that arrive alongside them. No admin center shows that list in one place, which is why Microsoft 365 external domain monitoring usually lives in a spreadsheet someone started after the last incident and stopped updating before the next one.
The deeper mechanism: Microsoft ships several trusted-domain controls - the SharePoint and OneDrive sharing domain lists, cross-tenant access partners, the mail allow and block lists. They live in different admin centers, use different keys, and never check each other. A domain blocked in one control can hold live guests, working sharing links and daily mail flow through the others, and no screen puts those facts side by side.
Meanwhile the relationships drift on their own schedule. Guests outlive the projects that justified them, often by years. Trust configured for a partner nobody works with anymore stays configured. And the domains that matter most - the ones sensitive files actually flow to - are frequently the ones no control and no verdict covers at all.
What you get
One screen where domains become organizations.
Every signal source in Microsoft 365 speaks the same key - the mail domain - so that is the unit of the screen.
One row per counterparty
Every domain observed anywhere in the tenant - mail senders and recipients, guest accounts, shared files, audit-log actors - becomes one row carrying the whole relationship: guests, correspondents, messages exchanged, files reachable, sensitivity exposure, when it began and when it was last active.
Domains become companies
Each domain is resolved against the Microsoft Entra tenant directory: a real organization with its display name and sibling domains, freemail that belongs to a person rather than a company, or an unrecognized domain no organization stands behind. Your own verified domains stay out of the default view.
Configuration meets reality
Reading the trusted-domain controls it can reach - the tenant-wide SharePoint sharing lists, cross-tenant access partners, the mail allow and block lists - 1Security puts each domain configured standing next to its observed activity, one column beside the other.
Drift flags that alert
Blocked but active, trusted but unused, active but ungoverned, conflicting lists - each contradiction ships as a ready-made detection, so drift raises an alert instead of waiting for someone to browse the list.
A verdict that sticks
Each organization gets a decision - trusted, watched or blocked - with a note and a full who, when and why history. Blocking enforces straight into your tenant SharePoint sharing lists, working within whatever restriction mode you already run.
The whole relationship in one drawer
People lists the guests and the mail-only correspondents who exist in no directory at all. Files ranks everything the domain can reach by sensitivity. Emails shows the flow in both directions, Activity the audit events its people performed.
How deep it goes
One domain, followed from surprise to verdict.
The review most teams run in their first session.
Start from the chip row: blocked but active. An agency domain someone put on the SharePoint block list three years ago is still there - along with six guests who redeemed their invitations before the block, and a mail thread that never stopped. Blocking stops new sharing; it never evicts access that already exists, and this flag is where that surprise surfaces.
Open the row. Posture shows where the domain stands in every control 1Security reads: on the sharing block list, absent from cross-tenant access, clean on the mail lists. People names the six guests, Files ranks what they can still reach - two folders carrying payment data - and Activity shows one of them opening files last Tuesday.
Decide, and let it stick. Expire the surviving access through the staged actions, record the verdict as blocked with a note, and the drift detection keeps watching: if activity from that domain ever resumes, you get an alert with the history attached, not a mystery.
In practice
Four steps from domain strings to governed counterparties.
The chip row above the list is the review workflow in miniature, each chip with a live count.
- 01
Read the review queue
Open Domains and hit the active but ungoverned chip: sensitive data is flowing to these domains and no control or verdict covers them. The list is ranked by what is actually leaving, so the top rows are the meeting agenda.
- 02
Resolve who you are talking to
The unrecognized and freemail chips split the list by what stands behind each domain. A freemail address holding guest access is a conversation about a person; an unrecognized domain receiving sensitive files is a counterparty nobody has named yet.
- 03
Record verdicts
Work through unreviewed: trusted for the partners you know, watched for the ones you are not sure about, blocked for the ones that should never have appeared. Every verdict carries a note and lands in the history with a name and a date.
- 04
Enforce, and watch the drift
Block from the Posture tab - 1Security appends to your own sharing block list, or removes from your allow list, and never flips your restriction mode behind your back. The drift detections take it from there.
The difference
What the admin centers cannot put side by side
Every fact below exists somewhere in Microsoft 365. No screen there holds them together.
- One row per external organization across mail flow, guest accounts, shared files and audit-log actors
- Entra tenant resolution: display name, tenant identity and sibling domains - or freemail and unrecognized, stated plainly
- Configured standing from SharePoint sharing lists, cross-tenant access partners and mail allow and block lists, reconciled
- Four drift flags shipped as ready-made detections - blocked but active, trusted but unused, active but ungoverned, conflicting lists
- Verdicts with a who, when and why history that survives an audit
- Blocking that appends to your own lists and never changes your restriction mode
- Honest scope: the People and Files tabs show exactly what survives a block
- Sensitivity exposure per domain - what its people can actually reach, ranked
Licensing and scope
Standard licenses, optional permissions, honest gaps.
Discovery, the relationship rollups and verdicts work from data 1Security already collects - no premium Microsoft licensing and no extra permissions. Three optional read permissions light up the rest: resolving domains to Entra organizations, the tenant-wide sharing lists, and cross-tenant access partners. Blocking additionally needs the SharePoint settings write permission, consented separately. A missing permission is shown as exactly that, never as an empty screen.
- 4 flagsblocked but active, trusted but unused, active but ungoverned, conflicting lists - each a ready-made detection
- 90 dayswithout activity turns configured trust into the trusted but unused flag
- 0premium Microsoft licenses required - discovery and verdicts run on standard licensing
Related
Where this fits
Domains is the outbound half of the supply-chain answer - who do we hand data to. The pages below cover the people behind the domains, the sites the files leave from, and the software coming in.
Guest access reporting
Every guest account with what it can reach - the people behind the domains.
See guest reporting →SharePoint external sharing
The site-by-site view of what is shared outward, and the links that carry it.
See external sharing →App governance
The inbound half: every third-party app with a foothold in the tenant.
See app governance →
FAQ
Questions teams ask first
Does blocking a domain break existing collaboration?
No - and that is exactly the trap. Microsoft controls are forward-looking: blocking stops new sharing, while guests who already redeemed invitations and links that already exist keep working. The People and Files tabs show precisely what survives a block, the blocked but active flag keeps watching it, and the staged actions can then remove the surviving access deliberately.
Do we need Entra ID P1 or an E5 license?
No. Discovery, the relationship rollups and verdicts run on data 1Security already collects, on standard licensing. The optional read permissions that light up Entra resolution, the sharing lists and cross-tenant partners are Microsoft Graph permissions, not license tiers - and each one degrades gracefully when absent.
How is this different from the SharePoint sharing report?
The sharing report is file-centric and SharePoint-only. Domains is counterparty-centric and cross-source: one organization with its guests, its mail flow, its files, its audit activity and its standing in every trusted-domain control - including relationships that involve no sharing link at all.
What about domains we only email?
They get a row like everyone else, with correspondents and message counts in both directions. Mail-only relationships are where unnamed counterparties usually hide - sensitive attachments leave through them without a single guest or sharing link existing.
Where do the company names come from?
From the Microsoft Entra tenant directory: the organization display name behind the domain, its tenant identity and its sibling domains. When no organization stands behind a domain, the screen says so plainly - freemail, self-hosted mail or another cloud - because an unrecognized counterparty is a finding, not a formatting problem.
Put a name on every domain this week.
Connect read-only and the list builds itself from mail flow, guests, files and the audit log. Most teams find their first blocked but active flag in the first session.
Or keep trusting whatever the spreadsheet said last year.