M365SPO-001: External sharing settings
- Platform
- Entra ID / M365
- Category
- SharePoint & OneDrive Security
- Severity
- High
- Zero Trust pillar
- Data (weight 2)
- Golden fixtures
- 3
- Branch coverage
- Observed: fixtures prove the verdicts they exercise
- Provenance
- baseline
What it checks
SharePoint Online external sharing settings control whether and how content can be shared with users outside the organization. Overly permissive sharing settings such as allowing anonymous sharing links can lead to uncontrolled data exposure and make it impossible to track who has accessed corporate content. Restricting external sharing to authenticated guests with verified identities is essential for maintaining data governance.
Recommended value
External sharing limited to existing guests or new and existing guests with authentication required; anonymous sharing links disabled
Remediation
Navigate to the SharePoint admin center sharing settings and configure the organization-level sharing to 'New and existing guests' or 'Existing guests only' based on your collaboration requirements. Disable anonymous access links (Anyone links) to ensure all external access requires authentication and can be tracked. Review site-level sharing overrides to ensure no individual sites have more permissive sharing settings than the organizational default.
Fixture-proven verdicts
Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.
| Scenario | Expected verdict |
|---|---|
| clean | PASS |
| known-bad | FAIL |
| throttled | Not Assessed |
Framework mappings
- CISA SCuBA
- MS.SHAREPOINT.1.1v1, MS.SHAREPOINT.1.2v1, MS.SHAREPOINT.1.3v1
- NIST SP 800-53
- AC-21
- CIS M365 Benchmark
- 7.2.1