M365TEAMS-008: File sharing settings in Teams

Platform
Entra ID / M365
Category
Microsoft Teams Security
Severity
Medium
Zero Trust pillar
Applications & Workloads (weight 1)
Golden fixtures
3
Branch coverage
Observed: fixtures prove the verdicts they exercise
Provenance
baseline

What it checks

File sharing within Microsoft Teams is backed by SharePoint Online and OneDrive, and the sharing settings determine how files shared in channels and chats can be accessed by internal and external users. Misconfigured file sharing settings can result in sensitive documents being accessible to guest users or through overly permissive sharing links generated from Teams. Aligning Teams file sharing settings with organizational data protection policies prevents unintended data exposure.

Recommended value

File sharing with external users restricted to authenticated guests; cloud storage providers limited to OneDrive and SharePoint; external file sharing disabled in private channels

Remediation

Review the Teams file sharing configuration and ensure that files shared in channels and chats inherit the SharePoint Online sharing restrictions configured at the organizational level. Disable third-party cloud storage integration (Citrix Files, Dropbox, Box, Google Drive, Egnyte) in Teams to prevent data from being uploaded to unmanaged storage services. Configure sensitivity labels for Teams and associated SharePoint sites to enforce file protection policies that persist when documents are shared or downloaded.

Fixture-proven verdicts

Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.

Verdict scenarios for M365TEAMS-008
ScenarioExpected verdict
cleanPASS
known-badFAIL
no-dataNot Assessed

Framework mappings

NIST SP 800-53
AC-21