Office 365 external sharing

Thousands of anyone links. Most never expire. Some point at sensitive files.

A typical tenant carries thousands of sharing links, and "anyone with the link" links have no expiry unless someone set one - so a proposal shared in 2023 is still public today. 1Security lists every link in your Office 365 tenant with its scope, type, password and expiration, crosses them with what the files contain, and removes the ones nobody would defend.

The problem

A sharing link is a permission that never shows up in a log.

Every deadline produces links. A proposal shared with "anyone" to skip the guest invitation, an edit link mailed to a contractor, a review link pasted into a chat. Each one made sense on the day it was created - and each one is still valid, because a link does nothing until someone uses it and writes no log line just for existing.

The scale is what surprises people. In a typical tenant we count thousands of active sharing links, a large share of them anyone links, most with no password and no expiration. Some are on files that hold card numbers, IDs, contracts or health data. Nobody decided those files should be public forever; nobody decided they should not be either.

Opening a file shows you the links on that file. The question that actually matters is tenant-wide: which of my millions of files carry an anyone link with no expiration and sensitive content inside? 1Security answers it as one filter across the whole tenant.

In practice

From every link in the tenant to the short list that must go.

One filterable pass in 1Security - most teams find in minutes what manual audits missed for years.

  1. 01

    List every link in the tenant

    Open Files and filter by link scope: anyone, organization, specific people. Split by link type (view, edit, review), links without a password, links past their expiration, disabled links. The whole tenant is one list.

  2. 02

    Run the public + sensitive + permanent filter

    Shared with anyone, contains sensitive information, no expiration. That is your genuine already-exposed list. In a mid-size tenant it is usually tens to a few hundred files - small enough to fix this week, and impossible to assemble by hand.

  3. 03

    Strip exactly the right grants

    Select the files and choose Remove access. 1Security lists every user, group and link with a path to each file - direct grants, links, groups, inheritance - and you pick which ones to strip. The change is pushed to Microsoft 365 through the separately consented write module.

  4. 04

    Keep it fixed

    Enable the link automation and links that outlived their purpose are retired as staged proposals behind a 72-hour review window. An instant alert fires the moment a new anyone link lands on a sensitive file, with the file and the detections attached.

What makes it work

Three parts of the platform behind the audit.

Link hygiene in 1Security is a standing filter, not a quarterly project.

  • SharePoint governance

    Link scope, type, password and expiration filters across the whole tenant - plus the sites whose sharing defaults keep producing risky links.

    Explore the feature
  • Access management

    Remove access resolves every path to a file - direct grants, links, groups, inheritance - so revoking a link never leaves a hidden door open.

    Explore the feature
  • Alerts

    The ongoing watch: an instant alert when a new public link appears on sensitive content, with the evidence attached.

    Explore the feature

FAQ

Common questions.

Will removing links break legitimate sharing?

You see every grant on a file before touching anything and choose exactly which ones to strip. Automated cleanup is staged behind a review window - 72 hours by default - and rejecting a proposal snoozes it instead of losing it. Every executed change is logged in Actions.

Can we see whether a link was ever used?

Yes. Up to three years of activity history ties access events to files, and the email trail on each file shows how many times it was uploaded or linked in mail and when it last left that way.

How is this different from checking sharing links site by site?

Checking site by site tells you which links exist on that site. 1Security lists links across the whole tenant, filters them by scope, password and expiration, and crosses them with sensitive-content detections - so the question "which public links point at sensitive files" has an answer.

What does 1Security need to run this?

Read-only consent and standard Microsoft 365 licenses - Business Basic upward, no E5. Write actions such as removing links ride a separate opt-in consent.

Find the links that never closed.

Connect read-only and see your public + sensitive + permanent list the same day - then remove it with a review window in front of every change.

Or keep trusting that nobody ever forwards a URL.