External sharing in Office 365 and SharePoint Online makes collaboration between companies, clients, and partners easier than ever before. It allows unlimited collaboration, with people inside and outside your company. So it’s extremely important to set up your Office 365 external sharing right and avoid all the possible pitfalls.
Who are External Users in Office 365?
Before digging deep into configuration settings, you need to understand which types of external users exist in the Office 365 environment.
An external user is any user who is not a member of your organization. There are two main types of external users: authenticated external users and anonymous users.
1. Authenticated External Users
There are two main groups:
- Existing authenticated external users: Users who are already in your Office 365 user directory. For example, users who have previously accepted a sharing invitation or users who you have imported from another Office 365 or Azure Active Directory tenant. They are required to log into your system before accessing shared content.
- Ad-hoc external users: They are asked to verify their identity with a one-time code sent to their email. Since they are not required to log in, they don’t need a Microsoft account.
2. Anonymous External Users
These are external users who access your content via a link, so they don’t need to log in. Anonymous sharing is rather tricky since you can’t identify the person who opens up the link.
4 ways to configure Office 365 external sharing
When configuring external sharing you can choose between the four options below:
Each level includes all the levels above it. For instance, if you allow anonymous links, you are also allowing external users.
Different levels of Office 365 external sharing
You can granularly control how to apply the settings above to different services inside your Office 365:
- SharePoint Online
- Tenant level – settings located in the SharePoint admin center under Sharing
- Site collection level – settings located in the SharePoint admin center under Site collections
- OneDrive – settings located in the OneDrive admin center under Sharing
- Office 365 Groups – settings located in the Office 365 Admin center under Settings > Services & add-ins, where you will find the Office 365 Groups.
Be aware of a slippery slope when configuring external sharing for different services and levels. Sharing at the site collection level cannot be more permissive than at the tenant level, but it can be more restrictive.
For instance, if you disable anonymous links at the tenant level, you won’t be able to turn them on at the site collection level. But, if you allow anonymous links at the tenant level, you can disable them for specific site collections.
The same rules apply to OneDrive external sharing. Therefore, OneDrive external sharing also cannot be more permissive than the SharePoint tenant sharing settings.
Webinar Recording: Office 365 External Sharing
Recently we held a webinar in which we covered:
- What is Office 365 external sharing
- How you can configure your external sharing settings (SharePoint Online, OneDrive, Office 365 Groups) and some tips and tricks to follow
- How to report on external sharing and stay in control of security in your environment.
Free Whitepaper: Office 365 External Sharing
We hope we made some clarifications of how you can configure your external sharing settings. If you’d like to learn more about external users, and external sharing best practices read our in-depth Office 365 External Sharing Whitepaper. If you are keen to find out the latest Microsoft changes in external sharing read an external sharing blog post from our CEO and a Microsoft MVP, Toni Frankola.