HomeBlogMicrosoft 365

SharePoint Permissions Best Practices: Groups, Sharing Links and an Audit Checklist

Pixel-art illustration of a robot on a pirate ship's deck holding up a glowing blue shield against red bug-shaped threats above stormy waves

The SharePoint permissions best practices that matter most: grant access to whole sites through groups, not to individual files; leave inheritance intact; make Specific people the default sharing link and restrict or expire Anyone links; allow guests only on sites meant for outsiders, with access that expires; and audit sharing monthly and permissions quarterly. These settings matter more now that Microsoft 365 Copilot can surface anything a user is able to open.

This guide goes deeper than site setup, which our SharePoint setup guide covers, and wider than the pre-rollout cleanup in Fix SharePoint oversharing before Copilot. It explains the permission model, the settings to change and an audit you can repeat. Our SharePoint migration service rebuilds permissions from a written plan when files move.

How do SharePoint permissions work?

Access comes from three places: the site's groups, any unique permissions on a library, folder or file, and sharing links. Which groups apply depends on the type of site:

Site typeWhere access is managedBest practice
Team siteIts Microsoft 365 group: group owners become site owners and members become site membersManage membership in the group, or in Teams if the site belongs to a team; add read-only people to the site's Visitors group, because Microsoft 365 groups have no view-only role
Communication siteThe SharePoint Owners, Members and Visitors groupsA few owners, a small set of authors as members, and readers in Visitors through security groups
Private or shared channel siteThe channel in Teams; SharePoint shows these permissions read-onlyManage access only in Teams
Hub siteThe underlying site's groups; a SharePoint administrator decides who may associate sites with the hubRemember that each associated site keeps its own permissions

By default, Owners get Full Control, Members get Edit and Visitors get Read. Use those three levels, and add custom permission levels only for a requirement you can name. Microsoft also advises against nesting security groups inside SharePoint groups, which can cause performance problems.

Should you break permission inheritance?

Rarely. Everything in a site inherits the site's permissions until someone stops inheritance on a library, folder or file, and each break creates a separate access list someone has to remember. It also happens by accident: when someone shares a file with a person who lacks access, SharePoint automatically stops inheritance on that file.

When a set of files needs different access, give it its own site or library. Microsoft's own advice for confidential information is a site with external sharing turned off. Keep unique permissions for the few cases that truly need them, and list each one in your permissions record.

Which SharePoint sharing settings should you use?

Sharing links grant access to individual files and folders. There are three main types. Anyone links work for whoever holds the link, without signing in, and their use cannot be audited. People in your organization links work only for signed-in employees. Specific people links work only for the people named. External sharing is set at the organization level in the SharePoint admin center, and each site can match that level or be more restrictive, never less.

SettingWhereRecommended for a small business
Organization external sharing levelSharePoint admin center, Policies, SharingNew and existing guests, so guests must sign in or enter a verification code; Anyone only if clients truly need it
Default link typeOrganization level, which each site can overrideSpecific people
Anyone links, if allowedAdvanced settings for Anyone linksRequire expiration and limit them to view only
Site-level sharingEach site's sharing settingOnly people in your organization for HR, finance and leadership sites; guests only on sites built for outside collaboration
Who may share externallyOrganization sharing settingsMembers of a named security group, if outside sharing is rare
Allowed domainsLimit external sharing by domainAn allow list, if you work with a fixed set of client and partner firms

Two cautions when tightening. Guests typically lose access within an hour of a restriction. And if you turn external sharing off for the whole organization and later turn it back on, guests regain their old access, so restrict the specific sites first.

How should you manage external guests?

  • Guests authenticate. With SharePoint's Microsoft Entra B2B integration, guests without a work or Microsoft account sign in with a one-time passcode, and the guest invitation settings in Entra ID apply as well.
  • Access expires. Set guest access to expire after a set number of days. Site admins get a weekly email about guests expiring in the next two to three weeks and can extend those still needed. The policy applies only to guests given access after it is turned on, so older guest access needs a manual review.
  • Expiry is per site. A guest whose site access expires may still reach a team or security group they belong to elsewhere, so review group memberships too.
  • Guests should not reshare. By default, guests need Full Control to share items they do not own. Leave that default in place.

Who can share, and who approves access requests?

Each site has its own sharing permissions in its site permissions panel. Two settings suit most small businesses: site owners and members can share files and folders but only owners can share the whole site, or, for sensitive sites, only owners can share anything, which sends members' sharing requests to an owner for approval. Turn off access requests on sites where outsiders should never ask in.

Watch for one default. Public team sites add the Everyone except external users group to their members, which gives every employee edit access. Make sensitive team sites private, where that group cannot be granted permissions.

What does Copilot change about SharePoint permissions?

Copilot does not grant new access; it makes existing access easy to use. Anything a person can open can turn up in a Copilot answer, so oversharing that sat unnoticed becomes visible. Microsoft's SharePoint Advanced Management adds the tools to find and contain it:

  • Data access governance reports. A site permissions snapshot shows the sites with the broadest access, including those open to Everyone except external users. Activity reports cover the last 28 days of sharing links and broad sharing. Microsoft suggests running the snapshot quarterly and the activity reports monthly.
  • Site access reviews. An admin sends a flagged site to its owner to review and fix, for up to 100 sites at a time from the report.
  • Restricted Content Discovery. A temporary control that keeps a site out of organization-wide search and Copilot answers while its permissions are reviewed, without changing who can open it.
  • Restricted site access control. Limits a site to members of named groups; anyone outside them is blocked even if they hold permissions or a sharing link.

SharePoint admins get these tools once at least one person in the tenant has a Microsoft Copilot license (Microsoft lists SharePoint Advanced Management among the Copilot Business add-on's features), or through the SharePoint Advanced Management Plan 1 add-on. Microsoft's prerequisites page also lists the base subscriptions it supports, so confirm yours before you plan around these tools.

What goes on a SharePoint permissions audit checklist?

Monthly

  • Review Anyone and organization-wide links created in the last 28 days, and remove those that are not needed.
  • Check that guests added this month have a reason, a sponsor and an expiry.
  • Remove leavers from Microsoft 365 groups, SharePoint groups and Teams, and hand the files they owned to a manager.
  • Work through the expiring-guest emails: extend the guests still needed and let the rest lapse.

Quarterly

  • Run the site permissions snapshot, and fix any site open to Everyone except external users that should not be.
  • Have each site owner confirm the membership of the Owners, Members and Visitors groups.
  • Check sensitive sites for files and folders with unique permissions, and remove breaks that are no longer needed.
  • Compare organization and site sharing settings with your standard, including the default link type.
  • Review guests whose access predates your expiration policy.
  • Confirm HR, finance and leadership sites are private, with external sharing off.

Who maintains SharePoint permissions, and how do you validate them?

Site owners maintain membership and approve access requests for their sites. The SharePoint administrator owns organization-level settings, runs the reports and chases overdue reviews. A business owner approves who belongs on sensitive sites, and whoever handles leavers removes access the day someone goes.

Validate with evidence rather than settings screens. Sign in with test accounts at each level, member, visitor, guest and an employee with no access, and try to open restricted libraries. Run the site permissions for users report for a recent leaver and a new hire, and compare it with what their role should allow. Track the number of Anyone links and broadly shared sites each month; both should fall and then stay low.

How does NetSys help with SharePoint permissions?

When we move a file server or a sprawl of OneDrive folders into SharePoint, permissions are rebuilt from a written plan rather than copied: security groups instead of item-level exceptions, so access can be audited in one view, and external sharing rules set per site. The engineer who will manage the permissions reviews the plan, and pilot users verify access before the wider cutover. Afterward we manage SharePoint under Microsoft 365 management, on a month-to-month agreement.

Book a call with an engineer to review your sharing settings and the sites open to everyone in your tenant.

Frequently asked questions

What does the SharePoint permissions audit checklist cover?

Sharing links created in the last month, guests and their expiry, leavers' access, site group membership, sites open to Everyone except external users, unique permissions on sensitive sites, and the organization and site sharing settings. The monthly items catch new exposure, and the quarterly items reset the baseline.

Who maintains SharePoint permissions?

Site owners handle membership and access requests, the SharePoint administrator owns tenant settings and reports, and a business owner approves access to sensitive sites. In a small business the administrator is often your IT provider, but site owners should still confirm their own membership lists.

How do we validate that SharePoint permissions are right?

Test restricted content with accounts at each permission level, run the site permissions for users report for a leaver and a new hire, and track the count of Anyone links and broadly shared sites month over month.

What is the difference between SharePoint groups and Microsoft 365 groups?

A Microsoft 365 group is one membership list shared by a team site, a mailbox, a calendar, Planner and Teams. SharePoint groups (Owners, Members and Visitors) exist inside one site. Team sites use the Microsoft 365 group for owners and members and the Visitors SharePoint group for read-only access, while communication sites use SharePoint groups only.

Should we turn off Anyone links?

For most small businesses, yes, or at least require them to expire and limit them to viewing. Anyone links work without signing in and cannot be audited. If clients need to download files without an account, keep those files on one site that allows Anyone links, and keep every other site stricter.

How often should SharePoint permissions be reviewed?

Sharing activity monthly and the full permission baseline quarterly, which matches Microsoft's suggestion for its data access governance reports. Review again straight away after a merger or reorganization, and before turning on Copilot.

Sources and further reading

SharePoint & OneDrive Migration

Discuss sharepoint & onedrive migration for your business.

Tell us about your current systems, the result you need and your timeline. We will discuss the work, responsibilities and pricing before you decide on an engagement.

Explore SharePoint & OneDrive Migration 845-203-3914