Skip to content
DocumentationContact
Protect

Review guest access and sharing links

Find guest and link-based access, evaluate its source and scope, and choose the safest remediation.

Protect identifies guest users and common SharePoint sharing-link types in the permission explorer. It doesn't replace the tenant and site sharing policies that determine which link types SharePoint allows.

To grant access to a dedicated folder and send its direct link, see Share SharePoint folders with external users.

Understand sharing types

Type Typical behavior Review focus
Guest An external identity signs in and can receive direct or group-based access. Sponsor, business purpose, access level, and continued need
Specific-people link Named recipients use a link restricted to them. Recipient list, item scope, and continued use
Organization link Authenticated people in the tenant can use the link. Whether tenant-wide discoverability is appropriate
Anyone link The link can work without sign-in, subject to SharePoint policy. Data sensitivity, purpose, reach, and expiration

Find external access

  1. Open the target site in Protect.
  2. Enable Load nested sharing entries when child items are in scope.
  3. Under Shared with, select Guest, People you choose, and Anyone with the link.
  4. Under Access source, select Items with custom access if the review focuses on exceptions.
  5. Narrow by Access level and Location.
  6. Review the item, principal or link, capability icons, and source together.
  7. Export the loaded permission data when the review requires evidence.

Evaluate a guest assignment

Confirm:

  • A current internal sponsor owns the relationship.
  • The guest still has an active business purpose.
  • The access level is no broader than required.
  • The item or site scope is correct.
  • Group membership isn't granting additional connected-Team or Microsoft 365 group resources unintentionally.
  • Your organization has a defined review or expiration date.

Choose groups or direct access

Use a group when the same governed audience needs ongoing access. SharePoint groups keep site-specific membership maintainable. Microsoft 365 groups and Teams are appropriate when the person should also receive the connected group's other resources.

Use a direct assignment only when its narrow scope and ownership are clear. Repeated direct assignments become harder to review than a well-owned group.

Remediate an exception

  1. Record the workspace owner's decision.
  2. Identify whether access comes from a direct assignment, group, link, or inherited parent.
  3. Apply the change at the actual source.
  4. Refresh the Protect scope.
  5. Confirm that required collaborators retain access.
  6. Test sensitive removals with a representative account.

Protect displays and can remove supported permission entries; create or configure new SharePoint sharing links through your organization's approved SharePoint sharing workflow.

Run recurring reviews

Set a review interval appropriate to the data and collaboration model. Retain the filtered export, business decision, action owner, completion date, and exceptions that remain approved.

Was this page helpful?