SharePoint External Sharing: The 4 Levels and Safe Settings for 2026
At a Glance
- Target Audience
- SharePoint administrators, Microsoft 365 security teams, and site owners operating external collaboration
- Problem Solved
- Separates site sharing levels from link types and corrects misinformation about the 2026 Entra B2B and one-time-passcode transition.
- Use Case
- Choose and test tenant and site sharing controls for customers, suppliers, partners, or internal-only sites.
SharePoint external sharing is often explained as a choice between “Anyone”, “guests” and “specific people”. That mixes up two different controls and leads to bad decisions.
There are four organisation and site sharing levels:
- Anyone
- New and existing guests
- Existing guests
- Only people in your organisation
There are also sharing-link types, including links for specific people and, where allowed, Anyone links. A “Specific people” link is not a fifth site sharing level.
This guide explains both layers, the 2026 Microsoft Entra B2B change and a safe configuration process without claiming that one setting is right for every site.
Fact-checked against Microsoft Learn on 7 August 2026.
The control model in one minute
SharePoint applies external sharing as a ceiling:
Organisation sharing level
-> maximum allowed for SharePoint and OneDrive
-> site sharing level can be the same or more restrictive
-> user chooses an available link type for an item
-> recipient must still pass identity and access checks
A site cannot be more permissive than the organisation-level setting. OneDrive's sharing level can be the same as or more restrictive than the SharePoint organisation setting, but not more permissive.
That means an administrator can allow external collaboration at the tenant level without making every site externally shareable. A confidential HR site can remain internal while a controlled client-project site allows new guests.
The four SharePoint sharing levels
| Level | What it allows | Use it when | Main control question |
|---|---|---|---|
| Anyone | Authenticated guest sharing plus anonymous Anyone links | A genuine anonymous-sharing requirement has been approved | Can the data safely be accessed by whoever obtains the link? |
| New and existing guests | Users can invite new external people or share with existing guests; recipients authenticate or verify identity | The site onboards changing customers, suppliers or partners | Who may invite guests, and how will stale access be reviewed? |
| Existing guests | Sharing is limited to people already represented as guests in the directory | Guest creation is centralised or pre-approved | Is there a fast, owned process for adding legitimate new collaborators? |
| Only people in your organisation | External sharing is disabled | The site is internal-only or holds data that must not be externally shared | Are users given a safe approved route when collaboration is genuinely needed? |
These levels describe what a site may permit. They do not, by themselves, prove that every link is safe, every guest is current or every document is suitable for sharing.
Anyone
Anyone links do not require the recipient to sign in. They can be forwarded, and anyone who obtains the link can use it until it expires or is revoked.
This can be appropriate for deliberately public or low-sensitivity material where ease of access is the requirement. It is not appropriate for information that relies on knowing who the recipient is.
If Anyone links are enabled, set a deliberate expiration policy and consider view-only plus download restrictions where the available controls and file type support them. Microsoft lets administrators configure expiry; it does not document a universal 30-day default that applies to every tenant. Check your actual setting.
New and existing guests
This is the normal level for a collaboration site that must invite new external participants. A recipient signs in or uses the identity-verification method provided by Microsoft Entra External ID.
The benefit is workable onboarding. The cost is guest lifecycle: someone must own invitation policy, access reviews, removal and what happens when a partner changes employer.
Existing guests
This level prevents ordinary sharing activity from creating or inviting a brand-new guest. It works well where the directory team pre-approves external identities.
It is not automatically “the best” setting. If the guest-creation process takes three weeks, users may bypass SharePoint or put documents in the wrong place. Choose the restriction together with an operable request path.
Only people in your organisation
Use this for sites with no valid external-collaboration purpose. It is the clearest boundary, but it should be an intentional classification rather than a tenant-wide reflex.
Blocking SharePoint sharing does not remove the business need. If a team must exchange files with a regulator or supplier, give it an approved collaboration site rather than leaving people to improvise.
Sharing level is not link type
Once the site permits sharing, the user sees link options allowed by the tenant, site and item context. The labels can vary slightly as Microsoft updates the interface, but the concepts include:
- Specific people / People you choose — only named recipients can use the link after identity verification.
- People in your organisation — anyone in your organisation with the link can use it; this is not an external-sharing link.
- People with existing access — sends a link without changing permissions.
- Anyone — anonymous access, only when the sharing level and policy allow it.
For ordinary partner collaboration, a named-recipient link is usually easier to justify than an anonymous link because access is tied to intended identities. But a specific-people link does not rescue a poorly governed site: recipients can still download or reshare content when policy and permissions allow it.
Set the default link type to the least permissive option that works for most users. The default is a nudge, not a substitute for the sharing ceiling and data controls.
The 2026 Entra B2B change—and the OTP claim to stop repeating
Microsoft says it began automatically enabling SharePoint and OneDrive integration with Microsoft Entra B2B for all tenants in May 2026. Under this model, authenticated external sharing uses Microsoft Entra B2B guest accounts rather than SharePoint's older standalone external-sharing mechanism.
The important correction is this:
One-time passcode authentication is not being retired.
Microsoft's own FAQ says exactly that. The transition is away from the old SharePoint-owned OTP path and towards Entra B2B. A guest may still authenticate with a one-time passcode through Microsoft Entra when that is the applicable method.
Why this matters:
- New external sharing is represented in the Microsoft Entra directory, improving identity visibility and governance options.
- Existing link behaviour needs review during the transition; old specific-people links and guests that do not map cleanly can produce access-denied reports.
- “OTP is dead” is both inaccurate and unhelpful to support teams diagnosing how a guest actually signed in.
Microsoft says the Entra B2B integration cannot be opted out of. Its transition FAQ explains the effect on existing shares and the repair steps for external users who lack the required guest access. Do not bulk reshare every item on speculation: inventory affected sites, test representative external users and follow the current Microsoft guidance for failures.
Anyone links are not affected by the authenticated-guest transition because they do not require sign-in.
Configure the organisation boundary
A SharePoint Administrator should open the SharePoint admin centre and review Policies → Sharing.
Before moving the slider, answer:
- Which site classes may collaborate externally?
- Is anonymous sharing a real requirement or simply a historical default?
- Who may create new guests?
- Should sharing be restricted to or blocked for named domains?
- What is the expiry policy for anonymous links and guest access?
- Which link type should users see by default?
- Who receives sharing and guest-lifecycle reports?
Microsoft supports domain allow or block lists in SharePoint sharing settings, with up to 5,000 domains. An allow list can be effective for a tightly defined partner estate, but it requires an owner and an exception process. A block list is not a complete defence; a partner may use another domain or a consumer identity.
Apply changes first to a pilot site and test as a real external recipient. An administrator's successful view proves very little about the guest journey.
Set each site's level from its purpose
In the SharePoint admin centre, open Active sites, select the site and change its external-sharing setting. Microsoft states that changing a site's sharing level requires at least the SharePoint Administrator role; a site owner cannot change that level merely because they own the site.
A useful site classification is:
| Site purpose | Starting position | Possible exception |
|---|---|---|
| HR, finance, board or security operations | Only people in your organisation | A separately designed external workspace, not a casual site exception |
| Long-running partner project with pre-approved members | Existing guests | New and existing guests if the project owner is accountable for onboarding |
| Customer or supplier workspace with changing participants | New and existing guests | Existing guests if central onboarding remains fast enough |
| Deliberate public distribution library | Anyone | Prefer a publishing surface if the content is truly public |
These are starting positions, not Microsoft mandates. Data classification, contractual duties, licensing and your threat model can change the answer.
Controls that make guest sharing maintainable
Restrict who can share
Decide whether site members can share, whether only owners should share the site, and whether guest-to-guest sharing is appropriate. Fewer sharers can reduce mistakes, but only if owners respond quickly.
Expire access deliberately
SharePoint provides controls for Anyone-link expiry and guest access expiry. Expiry is useful only when somebody handles renewal requests and verifies that access is still required. Treat a repeatedly extended guest as a signal to review the collaboration model.
Review permissions at the site and item levels
Do not review only the guest directory. A guest account can exist without access to a particular site, and a sharing link can grant item-level access that is easy to miss from the site's main members list.
Look for:
- Guests with direct site membership.
- Item- and folder-level sharing links.
- Anyone links.
- Broken permission inheritance.
- Former partner employees.
- Sites whose business owner has left.
Use data controls for the data problem
Sensitivity labels, Data Loss Prevention, Conditional Access and access reviews can add important controls, but their availability and behaviour depend on licensing and configuration. Do not write “DLP prevents external sharing” in a policy unless you have a tested policy that actually does so for the relevant locations and conditions.
External-sharing settings answer who may be given access. They do not classify the content for you.
A safe test script
For every externally shareable site, test these cases:
- An approved guest receives a specific-people link and can open the intended item.
- A different external identity cannot use that link.
- The approved guest cannot reach a sibling folder or site unless separately authorised.
- A new guest can or cannot be invited, matching the chosen site level.
- An Anyone link can or cannot be created, matching policy.
- An expired or removed guest loses access.
- The support team can identify the failed stage from sign-in and audit evidence.
Run the test in a private browser session as the external identity. Copying a link into another tab while still signed in as the administrator is not an external-access test.
Common questions
Should we disable Anyone links everywhere?
Disable them when there is no approved anonymous-sharing use case. If a team genuinely publishes low-sensitivity files to unknown recipients, a controlled Anyone-enabled site may be more honest and governable than repeated exceptions.
Is “Specific people” the most secure sharing level?
It is a link type, not a site sharing level. It limits a link to named recipients, which is often appropriate, but the site's level, recipient permissions, download controls and data sensitivity still matter.
Does a verification code mean the user is not an Entra guest?
No. Under Entra B2B, one-time passcode can be the guest's authentication method. Do not confuse the way a guest proves identity with where the guest relationship is governed.
Can a site owner make a site externally shareable?
Not by changing the site sharing level. Microsoft says that requires at least the SharePoint Administrator role. A site owner may be allowed to share content within the boundary administrators configured.
Keep the configuration tied to real tenant practice
The Teams, SharePoint & Intranet Mastery Space brings current Microsoft changes, admin patterns and practical checks into one maintained place.
If external collaboration is part of a tenant move, configure it after you understand what the migration preserves. This SharePoint migration-tools comparison explains where Microsoft's free tools end and paid migration products may add value.
Microsoft sources used
- External sharing overview
- Turn external sharing on or off
- Change the external sharing setting for a site
- SharePoint and OneDrive integration with Microsoft Entra B2B
- Frequently asked questions about the Entra B2B integration
Source boundary: Microsoft documents the four sharing levels, administrator controls and Entra B2B transition. The recommendations in this article are risk-based starting points, not a substitute for your organisation's data classification, legal obligations or tenant testing.
