Protect identifies guest users and common SharePoint sharing-link types in the permission explorer. It doesn't replace the tenant and site sharing policies that determine which link types SharePoint allows.
To grant access to a dedicated folder and send its direct link, see Share SharePoint folders with external users.
Understand sharing types
| Type | Typical behavior | Review focus |
|---|---|---|
| Guest | An external identity signs in and can receive direct or group-based access. | Sponsor, business purpose, access level, and continued need |
| Specific-people link | Named recipients use a link restricted to them. | Recipient list, item scope, and continued use |
| Organization link | Authenticated people in the tenant can use the link. | Whether tenant-wide discoverability is appropriate |
| Anyone link | The link can work without sign-in, subject to SharePoint policy. | Data sensitivity, purpose, reach, and expiration |
Find external access
- Open the target site in Protect.
- Enable Load nested sharing entries when child items are in scope.
- Under Shared with, select Guest, People you choose, and Anyone with the link.
- Under Access source, select Items with custom access if the review focuses on exceptions.
- Narrow by Access level and Location.
- Review the item, principal or link, capability icons, and source together.
- Export the loaded permission data when the review requires evidence.
Evaluate a guest assignment
Confirm:
- A current internal sponsor owns the relationship.
- The guest still has an active business purpose.
- The access level is no broader than required.
- The item or site scope is correct.
- Group membership isn't granting additional connected-Team or Microsoft 365 group resources unintentionally.
- Your organization has a defined review or expiration date.
Choose groups or direct access
Use a group when the same governed audience needs ongoing access. SharePoint groups keep site-specific membership maintainable. Microsoft 365 groups and Teams are appropriate when the person should also receive the connected group's other resources.
Use a direct assignment only when its narrow scope and ownership are clear. Repeated direct assignments become harder to review than a well-owned group.
Remediate an exception
- Record the workspace owner's decision.
- Identify whether access comes from a direct assignment, group, link, or inherited parent.
- Apply the change at the actual source.
- Refresh the Protect scope.
- Confirm that required collaborators retain access.
- Test sensitive removals with a representative account.
Protect displays and can remove supported permission entries; create or configure new SharePoint sharing links through your organization's approved SharePoint sharing workflow.
Run recurring reviews
Set a review interval appropriate to the data and collaboration model. Retain the filtered export, business decision, action owner, completion date, and exceptions that remain approved.
