Most Microsoft 365 tenants run on sharing settings someone accepted during setup and nobody revisited. None of these five take more than an afternoon to review — and each governs a different slice of how exposure gets created. A quarterly pass over them is cheap insurance.
1. The tenant-level external sharing level
The master dial (SharePoint admin center → Policies → Sharing) sets how far sharing can go: from "Anyone" links down to "only people in your organisation" — configured separately for SharePoint and OneDrive. Two review questions: is the level a decision or an inheritance from setup day? And is OneDrive at least as strict as SharePoint? OneDrive is personal, unreviewed space — there's rarely a reason for it to be more permissive.
2. The default link type
When a user clicks "Share", something is pre-selected — and defaults do most of the deciding in practice. A default of "specific people" makes deliberate sharing the path of least resistance; broader defaults make broad sharing the accident that keeps happening.
3. "Anyone" link expiration and permissions
If anonymous links are allowed at all, two sub-settings matter: a mandatory expiration (so links die instead of accumulating) and whether "Anyone" links can grant edit rather than view. Remember the limit of this control: expiry policies govern new links — the historical tail needs an inventory, not a setting.
4. Guest lifecycle controls
Guests accumulate; they don't clean up after themselves. Worth reviewing: who may invite guests at all, and whether guest access is put on a review cadence (Entra's access reviews can do this for group membership where your licensing includes it).
5. Per-site overrides for sensitive sites
The tenant dial is a ceiling; individual sites can be stricter. The sites holding HR, finance, legal, and board material usually should be — an "only your organisation" override on a handful of sensitive sites is one of the highest-value changes available, and it costs nothing.
The limit of all five
Settings govern the future. None of them tells you what is already shared — every "Anyone" link, guest grant, and inherited exposure created under the old settings keeps working under the new ones. Policy review and exposure inventory are two different controls, and you need both: here's the inventory route, and here's the tool that keeps it current.