TechRam For IT Leaders

How do you find out what is shared outside your Microsoft 365 tenant?

Deploy the External Sharing Risk Scanner into your own tenant — under thirty minutes, with the permissions it needs named up front. It lists every file shared outside the tenant, who shared it, and whether the link still resolves. It reads only, and nothing leaves your environment.

A file passing through a scan that maps its connections outward, ending at a target

What the question really is

“What is shared outside our tenant” sounds like one question. It’s four, and most organisations can’t answer any of them.

Which files have been shared externally. Who shared them. Whether the link is still live. And whether the person on the other end still works at the company you shared it with.

The last one is the one that keeps auditors interested, and it’s the one nobody has ever checked.

Why nobody has the answer

Sharing in Microsoft 365 is designed to be easy, which is the right design decision and also the reason the estate drifts. A link takes two clicks, survives the project that created it, and gets forwarded.

The admin centre will tell you that sharing is enabled. It won’t hand you a list. Getting the list means walking every site, every library and every unique permission, and that isn’t something anyone does by hand twice.

What the scanner does

The External Sharing Risk Scanner walks the tenant and returns one row per externally shared item: the file, the site it lives in, who created the link, what kind of link it is, when it was created, and whether it still resolves.

It deploys into your own tenant, not ours. Nothing leaves your environment, and we don’t see the output unless you send it to us.

Before you run it

Three things to sort out first, none of which take long.

Get the right permissions. The scan reads across sites, so it needs an account that can. A global reader plus SharePoint administrator is enough, and read-only is the point: the tool changes nothing.

Tell your IT provider. A process walking every site in sequence looks exactly like the thing their monitoring is built to flag. A one-line heads-up saves an incident call.

Pick a quiet window. It’s read-only, so it won’t break anything, but on a large tenant it isn’t instant and it will show up in the audit log.

Reading the output

The instinct is to sort by date and start at the oldest. Don’t. Sort by what the link can reach.

Anyone links are first, always. An “Anyone with the link” URL needs no sign-in and no account. It works for whoever holds it, including whoever it was forwarded to. Every one of these is a decision somebody made, and most of them were made for a reason that expired.

Then links into sites that hold regulated content. Participant records, employee files, incident registers, anything a regulator would ask about. The volume here is usually low and the consequence is not.

Then stale links into anything. A link created three years ago for a project that closed isn’t serving anyone. These are the bulk of the list and the easiest to clear.

Last, current links to named people at organisations you still work with. These are usually fine. Leave them alone unless something above tells you otherwise.

What to actually do about it

Revoking everything is tempting and it’s a mistake. You’ll break something somebody is using today, they will find a worse way to share it, and the next scan will be longer than this one.

Work the first two categories properly. Revoke, and tell the person who created the link that you did and why. That conversation is what stops the same link being recreated next week.

For the stale bulk, set a cut-off date and clear everything older in one pass, with a note to site owners beforehand. Nobody will miss them.

Then decide the rule that stops the list regrowing: whether Anyone links are allowed at all, what the default expiry is, and which sites are exempt. That rule is the actual deliverable. The list is just what makes the case for it.

Where this leads

If the scan comes back clean, you have an answer you didn’t have yesterday and it cost you an afternoon.

If it comes back the way most do, the list is one slice of a bigger picture. Permissions, sharing, sprawl and storage all drift together, and the Environment Baseline reads all four against your tenant and ends in a prioritised plan you own.

Fixing them is Governance & Cleanup: access granted by group rather than by forwarded link, sharing under a policy your people can follow, and lifecycle rules so this doesn’t have to be done by hand again next year.

The tool this article is about External Sharing Risk Scanner Lists every file shared outside your tenant, who shared it and whether the link still works. Request access →

The service behind this: Environment Baseline →

Common questions

01. What do you need to sort out before running it?

An account that can read across sites — a global reader plus SharePoint administrator is enough — a one-line heads-up to your IT provider, because a process walking every site looks exactly like what their monitoring is built to flag, and a quiet window.

02. Which links should you act on first?

Anyone links, always: they need no sign-in and no account and work for whoever holds them. Then links into sites holding regulated content, then stale links into anything, and current links to named people at organisations you still work with last.

03. Should you just revoke every external link?

No. You'll break something somebody is using today, they will find a worse way to share it, and the next scan will be longer than this one. Work the first two categories properly and tell the person who created the link that you revoked it and why.

04. Does anything leave our tenant?

No. It deploys into your own tenant rather than ours, it reads only and changes nothing, and we don't see the output unless you send it to us.

Victor Khalil

Co-founder — CTO

LinkedIn

Run the External Sharing Risk Scanner on your own tenant first.

It deploys into the Microsoft 365 tenant you already pay for, on the licences you already hold, and nothing leaves your environment.

Request access →