When someone shares a file and picks "People in your organization with the link", they create an organisation-wide link: anyone signed in to your tenant can open the file by following the URL. No guest, no invitation, no named recipient — just every internal account, via a link that can be forwarded around inside the company. It's the internal cousin of the anonymous link, and TRACER365 flags it as its own low-severity condition.
What an org-wide link grants
- Internal, but broad. The link works for any authenticated tenant user — potentially everyone in the organisation — rather than a chosen person.
- Forwardable inside the tenant. Unlike a named grant, an org link is a URL; forward it to an internal distribution list and the whole list can open the file.
- It authenticates an identity. Following an org link still requires signing in as a tenant user. That's the honest line between it and an anonymous link.
Org-wide vs. anonymous links
This distinction is exactly why org links are LOW and anonymous links are HIGH:
- An anonymous link authenticates nobody. Possession of the URL is the whole permission, and it works for anyone on the internet.
- An org-wide link authenticates an internal identity. The reader has to be a signed-in member of your tenant, so the exposure stays inside the organisation.
Same shape — a forwardable URL — very different blast radius. Treating them as one thing over- or under-states the risk, so TRACER365 keeps them as separate finding types.
Where org links deserve a second look
On a communication site, an org-wide link can be a deliberate publishing choice — "everyone should be able to open this". On a personal OneDrive it's a different story: an org link on OneDrive content quietly distributes one person's files to the entire tenant, which is rarely the intent. Same finding type, different likelihood of being deliberate — LOW severity reflects the internal-only reach, not a verdict that it's always fine.
How TRACER365 surfaces it
TRACER365 emits the organisation link as its own LOW-severity finding type across both SharePoint and OneDrive. As with every internal condition, this is one specific named signal — an org-scoped link on an item — not a claim to map everyone's internal access. The link is tracked over time, so a new org link, or one that changes, surfaces as a change; and because it's internal by definition it stays out of the external-sharing totals, flagged clearly in its own internal category.
What to do about it
- Separate the comms-site "publish to everyone" links (often fine) from OneDrive org links (usually worth a closer look).
- Consider whether a specific-people link would do the job — one that names its audience instead of opening to the whole tenant.
- Re-scan on a schedule — org links accumulate, and OneDrive is where the unintended ones tend to appear.