SharePoint external sharing
Dozens of your sites are shared outside. Nobody inside has opened them in a year.
In a typical tenant, 20-200 SharePoint sites have had no internal activity for a year while external users or guests still hold access - and IT usually knows about a handful of them. 1Security lists every site with its external users, guests and anyone links, ranks them by what is inside, and closes the ones nobody would defend behind a review window.
The problem
External access is granted per project. It is never revoked per project.
A site gets external access the week a project starts: a partner is invited, a channel is shared, a vendor gets a folder. Then the project ends, the team moves on, and nobody has "close what we opened" in their job description. Most tenants hold several times more sites than IT believes they have - subsites, hub members, private and shared channel sites and every personal OneDrive are all sites with their own sharing.
A site's sharing setting says what is allowed. Who can actually get in is a longer list: the external user added directly in 2023, the guest inside a Microsoft 365 group, the SharePoint-only guest who came in through a link or a site permission, the anyone link on a folder three levels down. 1Security resolves every one of those entrances per site, so the audit starts from who can get in, not from a setting.
That is why the dangerous pattern in most tenants is not "too much sharing". It is abandoned-but-shared: sites with no internal activity for a year that still have external users attached. In our experience the list is usually short, often shocking, and always immediately actionable.
In practice
One list, site by site, door by door.
How the SharePoint external sharing audit runs in 1Security - and how it stays done afterwards.
- 01
Rank sites by external exposure
Open Sites and sort by external users. Each row shows external users, SharePoint-only guests, anyone links, direct versus indirect access and the groups that grant it - so you see not just how many people can enter a site, but through which door. Subsites, hub sites, private and shared channel sites and OneDrives are all rows.
- 02
Apply the abandoned-but-shared filter
Filter to no activity in the last year and external users present. In a mid-size tenant this returns tens of sites; in a large one, hundreds. Every one of them is a finished project still open to someone outside.
- 03
Check what the open sites contain
Sensitivity labels and detected sensitive information are columns on the same list. Sort by sensitive detections and the order of work is obvious: an open archive of lunch menus and an open archive of contracts are different emergencies.
- 04
Close the doors and keep the receipt
Enable the suggested automation - remove external users from inactive sites, tighten sharing capability, set external-access expiry - and each site gets a staged proposal with a 72-hour review window and optional owner confirmation. Every executed change is logged in Actions.
What makes it work
Three parts of the platform behind the audit.
The site view is one end of every share. The link inventory on Files is the other - together they cover both.
SharePoint governance
Every site ranked by external exposure and abandonment, with per-site sharing settings automations to close what should be closed.
Explore the feature →Inventory
The full site count first - subsites, hubs, channel sites and OneDrives - because you cannot audit the sites you have not counted.
Explore the feature →Access management
Effective access resolved through groups, inheritance and links, so "who can get in" is a resolved answer for every site.
Explore the feature →
FAQ
Common questions.
Does the audit include OneDrive?
Yes. Every personal OneDrive is a row on Sites with the same exposure columns - and in most tenants a surprising share of external sharing lives there, not on team sites.
How is this different from reviewing sharing settings site by site?
A per-site sharing setting tells you what is allowed on that site. 1Security shows the effective external access on every site at once - external users, SharePoint-only guests, anyone links, group-granted access - next to last activity, owners and sensitive content, and lets you filter and act on the whole list.
Will closing sharing break active collaborations?
Changes are staged behind a 72-hour review window with owner review, so the people who actually use a site can object before anything closes. A rejected proposal is snoozed, not lost, and every executed change is logged.
Do we need write permissions or E5 to run the audit?
No. The audit runs on the read-only connection and standard Microsoft 365 licenses. Write actions are a separate opt-in module - and until you enable it, every suggested cleanup still shows its live match count.
Find the sites that forgot they are open.
Connect read-only and see your abandoned-but-shared sites the same day - then close them with a review window in front of every change.
Or let finished projects keep their doors open another year.