How-to guide

How to stop external sharing in SharePoint — find it first

"How do we stop external sharing?" usually rolls two different jobs into one: turning off the ability to share externally, and cleaning up what's already shared. Microsoft gives you real controls for the first. The second — knowing exactly what is currently exposed, so you remove the right things and don't break legitimate access — is where most of the work actually is. This guide covers both, and is honest about which part TRACER365 does: it's the read-only discovery step, not a switch that changes your tenant.

Turning external sharing off — the native controls

These are the levers that change tenant state, all in Microsoft's own admin surfaces:

  • Tenant-level sharing policy. The SharePoint admin center sets the most-permissive external sharing allowed for the whole tenant — from "Anyone" down to "Only people in your organization".
  • Per-site sharing policy. Each site can be set more restrictively than the tenant default.
  • Link defaults and expiry. Default link type, expiration days, and view-vs-edit can all be tightened.
  • Removing existing access. Individual links and grants are removed in SharePoint and OneDrive themselves, or in bulk via PowerShell.

Turning the policy down stops new external sharing. It does not, on its own, tell you what's already out there — and that's the gap.

Why "turn it off" isn't the whole job

  • Policy is forward-looking. Setting the tenant to "existing guests only" stops new anonymous links; it doesn't enumerate or remove the ones created before today.
  • Blanket bans push sharing sideways. If people can't share the sanctioned way, they fall back on email attachments and personal cloud accounts. A precise cleanup usually beats an absolute ban.
  • You have to remove the right things. Yanking access indiscriminately breaks the legitimate external collaboration your business runs on. To remove surgically, you first have to see exactly what's shared, with whom, and why.

The discovery step: know exactly what's exposed (read-only)

This is the part TRACER365 is built for, and the boundary is worth stating exactly: TRACER365 reads your tenant and reports. It never changes a permission, removes a link, or alters a setting — the scan is 100% read-only. What it gives you is the precise, deduplicated inventory you need before you remediate:

  • Every external exposure, across all SharePoint sites and every OneDrive, as severity-ranked finding types — anonymous links, direct grants to guests, specific-people external links, pending invitations, and inherited guest access.
  • The noise removed. Inherited duplicates collapse under the single grant that causes them — in our testing, roughly 91% of raw findings collapsed as duplicates — so you review causes, not thousands of repetitions.
  • A list you can act on. Take the findings into SharePoint and OneDrive (or your PowerShell cleanup) and remove exactly what shouldn't be there, leaving what should.

Then re-scan: because a finding resolves when the access behind it is gone, the next scan confirms your cleanup actually landed — and keeps confirming it stays gone.

Putting it together

  1. Discover first. Run a read-only scan so you know precisely what's externally shared and why. The complete how-to walks every native route too.
  2. Remediate deliberately. Remove the specific links and grants that shouldn't exist, in Microsoft's tools — surgically, not with a blanket switch.
  3. Tighten policy to prevent recurrence. Set tenant and site sharing and link defaults to match your actual intent.
  4. Re-scan to verify. Confirm the exposure is gone, and watch for it coming back.

Remove the right things — know exactly what's shared first

TRACER365 is the read-only discovery step before remediation: the precise, deduplicated inventory of what's externally shared, so you clean up surgically. Free 30-day trial at launch.