Between an anonymous "Anyone with the link" share and a file no one outside can touch sits the most common external share of all: a link scoped to specific people, sent to someone outside your organisation. Because it authenticates a named recipient, it is genuinely safer than an anonymous link — and precisely because it feels safe, it piles up unwatched.
What a specific-people link grants
- Access tied to a named identity. The recipient has to sign in and verify who they are to open the file. The link is bound to the people it was issued to, not to whoever holds the URL.
- Forwarding it usually gets you nowhere. Pass the link to someone who wasn't named and they generally can't get in — they'd have to be one of the specified recipients. That is the single property that separates it from an anonymous link.
- It can carry more than one recipient. One link can name several external people, and that list tends to grow as "just add them too" requests arrive.
- Edit links are external write access. A specific-person link with edit rights is a named outsider who can change your business data, not just read it.
Why it's still worth auditing
- Safer is not the same as safe to forget. A named outsider can still open your content. The assurance is about who gets in, not about whether external reach exists.
- The recipient can go stale. The named person may be a personal address, or someone who has since left the partner organisation but whose link still resolves.
- Scale is the real problem. Hundreds of these across a tenant, each one individually reasonable, add up to an external surface no one has ever seen in one list.
Specific-people vs. anonymous links
The distinction is the whole reason these two finding types carry different severities. An anonymous link authenticates nobody — possession of the URL is the permission — so it ranks HIGH. A specific-people link resolves to a named, signed-in recipient, so it ranks MEDIUM. Both are external reach worth inventorying; the difference is how much stands between the link and a stranger. A good audit keeps them as separate finding types instead of lumping all "external links" together.
How TRACER365 surfaces it
TRACER365 treats a specific-people link that reaches outside your organisation as its own MEDIUM-severity finding type, across every SharePoint site and every OneDrive in one read-only scan. Every external recipient on the link is recorded individually, so the recipient set is tracked per person: adding or removing someone is a tracked change, not a silent one, and the finding resolves when the link is removed.
One honest boundary worth stating: this finding is about external reach. A specific-people link shared only with internal colleagues is a different, internal condition and is not flagged here — the page you're reading, and the detection behind it, are scoped to the outside-the-org case on purpose. We'd rather draw that line clearly than imply a complete map of internal sharing we don't yet produce.
What to do about it
- Inventory specific-people external links next to anonymous links and direct external grants — the complete how-to pulls all of them in one scan.
- Check the recipient on each: still the right person, still a work address, still needed?
- Prefer time-boxed links where your tenant allows expiry, and re-scan on a schedule.