M365SPO-001: External sharing settings
- Plataforma
- Entra ID / M365
- Categoría
- SharePoint & OneDrive Security
- Severidad
- High
- Pilar de Zero Trust
- Data (peso 2)
- Fixtures de referencia
- 3
- Cobertura de ramas
- Observada: los fixtures prueban los veredictos que ejercitan
- Procedencia
- baseline
Qué comprueba
SharePoint Online external sharing settings control whether and how content can be shared with users outside the organization. Overly permissive sharing settings such as allowing anonymous sharing links can lead to uncontrolled data exposure and make it impossible to track who has accessed corporate content. Restricting external sharing to authenticated guests with verified identities is essential for maintaining data governance.
Valor recomendado
External sharing limited to existing guests or new and existing guests with authentication required; anonymous sharing links disabled
Remediación
Navigate to the SharePoint admin center sharing settings and configure the organization-level sharing to 'New and existing guests' or 'Existing guests only' based on your collaboration requirements. Disable anonymous access links (Anyone links) to ensure all external access requires authentication and can be tracked. Review site-level sharing overrides to ensure no individual sites have more permissive sharing settings than the organizational default.
Veredictos probados con fixtures
Cada veredicto de esta tabla está probado por un fixture de referencia en la suite de pruebas que valida el módulo. La tabla se deriva de la última ejecución en verde; no puede editarse a mano.
| Escenario | Veredicto esperado |
|---|---|
| clean | PASS |
| known-bad | FAIL |
| throttled | Not Assessed |
Mapeos a marcos de referencia
- CISA SCuBA
- MS.SHAREPOINT.1.1v1, MS.SHAREPOINT.1.2v1, MS.SHAREPOINT.1.3v1
- NIST SP 800-53
- AC-21
- CIS M365 Benchmark
- 7.2.1