SlideShare ist ein Scribd-Unternehmen logo
1 von 57
FALL: Las Vegas, NV Dec 7–9, 2021 SPRING: Las Vegas, NV April 5–7, 2022
M365Conf.com
MICROSOFT 365 COLLABORATION CONFERENCE
Everything you need to know about external sharing in OneDrive, SharePoint, & Teams
Drew Madelung
2021/2022
April 5 – 7, 2021
MGM Grand
Las Vegas, NV
Dec 7 – 9, 2021
MGM Grand
Las Vegas, NV
In-Person – December and April
M365Conf.com
FALL: Las Vegas, NV Dec 7–9, 2021 SPRING: Las Vegas, NV April 5–7, 2022
Who am I
Drew Madelu n g
 Milwaukee, Wisconsin
 Associate Director @ Protiviti
 @dmadelung
M365 architecture to support sharing
Sharing for files, groups, sites
Sharing management
Everything you need
to know about
external sharing in
OneDrive, SharePoint,
& Teams
#M365Conf
Do you allow
external sharing?
Do you have email
turned off?
Access and Share
all your files
through OneDrive
Collaborate,
communicate, and
share in one spot
in Teams
Share content,
data and portals in
SharePoint
Global economies require cross company
collaboration
Users need to be able to safely share content
across company boundaries
Companies need to keep sensitive content
secure in a complex environment
Need to
understand
Microsoft 365
architecture
File Collaboration across Microsoft 365
All files stored in SharePoint
File sharing settings shared
Every OneDrive site is a SharePoint Site
Collection
SharePoint
Online
SharePoint
Communication
Sites
Teams
OneDrive for
Business
SharePoint Team
Sites
Yammer
Communities
Teams Chat
Microsoft 365 Groups are a
group of people
Single identity across workloads
Azure AD objects
Share at the group level
Different sharing settings
Teams Chat
SharePoint Files
Planner Tasks
Exchange Email
Microsoft 365 Groups
SharePoint Sites
not M365 Group
backed
(Communication/
Classic)
Teams Chat
The configuration & management
for sharing files is different than the
Microsoft 365 group
Adding external users to the group
grants them access to solutions the
group is granting access too
Sharing files grants them access to
just that content
SharePoint Files
Microsoft 365 Groups
Teams Chat Planner Tasks
Exchange Email
Teams Chat
SharePoint Files
Microsoft 365 Groups
Teams Chat
Adding external users to the Team
adds them to the Microsoft 365
Group
File sharing the same as the
content is still based on SharePoint
sharing rules
Someone from outside your Microsoft 365 subscription who has been
granted access to a site, file, or folder
Authenticated with
Microsoft account
Anonymous
Spreads across workloads
Added to Azure AD as Guest
Groups, Teams, SharePoint, OneDrive, Yammer, etc
Can’t be shared sites
IP tracked
External access enables
communication (chat) or content
available without using guest
accounts
• Sharing a file anonymously
Sometimes used synonymously but there are differences
Guest access enables non directory
users into your environment as guest
accounts which can grant them
access to content
• Adding a user to a team
Share files and folders
Request files
Add guests to
Teams (M365 group)
Share files and
folders
Add guests to site
Add guests to
M365 group
Share files and
folders
There are different external sharing
settings for containers vs files
M365 Group
Files
M365 Group
Site
Files
Files
File & folder
sharing
Specific People
People with existing access
People in the organization
Anyone
A non-transferrable, revocable secret key, only grants
access to the specific recipient
Won’t work if forwarded to others
Existing users get access via their account
New external users prove email ownership
Internal users granted access directly with
inheritance broken
Send link without sharing
Does not change permissions
Users have access and receive a link via email
Gets direct link to file
A transferrable, revocable secret key, only grants access
to internal users
Can be forwarded to others
Access can be revoked anytime
Users need link to gain access
Requires sign-in to an account in my
organization
Members (non-guests) in Azure AD
A transferrable, revocable secret key
Can be forwarded to others
Access can be revoked anytime
Users need link to gain access
Guarantees users can open, anywhere,
without signing in
Modern sharing UI is unified across platforms
OneDrive Mobile App
Office Mac
File Explorer with OneDrive sync
Mac Finder
Microsoft Teams (TBD)
SharePoint
OneDrive
Office Online
Office Desktop
Outlook on the Web
SharePoint tenant
settings checked for
external sharing
SharePoint site
settings checked for
external sharing
User shares file that
creates a link
External user
accesses link
B2B invitation
processes if non
anonymous
External user
accesses file
Guest access
expiration begins
Demo!
Group
sharing
Tenant settings
checked if guest
access available
Group settings
checked if guest
access available
User adds guest
to a Group (Team)
B2B invitation
sent
Guest user
accepts invitation
Guest added to
group and has
access to content
External sharing
settings enforced
for files
This is not how shared
channels will work
Demo!
Site
sharing
Tenant settings
checked if guest
access available
User adds guest to a
SharePoint site
B2B invitation sent
Guest user accepts
invitation
Guest added to
SharePoint site and
has access to
content
External sharing
settings enforced for
files
Demo!
Guest &
Sharing
Management
Members
Owners
Unauth’d
guests
Auth’d
guests
Admin
Inside Outside
Control
External sharing
Least Restrictive
Most Restrictive
Microsoft 365 admin center > Settings > Security &
Privacy
Turn on/off external sharing
 Tenant, per group, per user
Turn on/off per workload
 Teams, Power BI, SharePoint
Allow guests to invite
Access reviews
Powered by Azure B2B
Guest inviter role (no Teams)
Domain allow/block
 Different than SPO & OneDrive
 Configured in Azure AD
Terms of use
(some have extended licensing)
Allow OR Block, not both
One policy per organization
Works independently from SPO
Does not apply to already added
guest members
Powered by Azure B2B
https://go.microsoft.com/fwlink/p/?linkid=857710
Powered by Azure B2B
Microsoft 365 admin center > Settings
> Services & add-ins
> Microsoft 365 Groups
https://aka.ms/o365-groups-guests
• Azure Active Directory: Guest access in Microsoft Teams relies on the Azure AD
business-to-business (B2B) platform. Controls the guest experience at the directory,
tenant, and application level.
• Microsoft Teams: Controls Microsoft Teams only.
• Microsoft 365 Groups: Controls the guest experience in Microsoft 365 Groups,
Teams, Outlook, and more
• SharePoint Online and OneDrive for Business: Controls the guest experience in
SharePoint Online, OneDrive for Business, Microsoft 365 Groups, and Microsoft
Teams. Anywhere there are files.
https://aka.ms/teams-dependencies
Microsoft Teams > Org-wide settings > Guest access
https://aka.ms/teams-manage-guests
 Configure force privacy (public private)
 Manage ability to add new guests
 Configure external file sharing
 Control access from unmanaged devices or other CA
Demo!
Control WHO can share
to external users
• Everyone
• Only specific people
• No one
Control WHICH external users can
be shared with
• Anyone
• Only authenticated users
• Only authenticated users except specific domains
• Only authenticated users in specific domains
• No one
Control WHAT can be
shared externally
• Anything
• Only specific sites
• Only files without sensitive content
Control HOW externally shareable
links can be used
• Default
• Enabled, but not default
• Mandatory expiration date
• Block externally-shareable edit links
• Disabled
 Sharing for OneDrive can be MORE restrictive but not LESS restrictive than SharePoint
 If sharing turned off globally in SharePoint any shared links will stop working
Sharing Options
 No external sharing
 Only existing external users (sign-in required)
 New and existing external users (sign-in required)
 Anyone, including anonymous users (on by default)
Your SharePoint Online sharing
settings determine which OneDrive
sharing settings are available
Files hosted in Teams use these
permissions
Only effects files & sites
Can be set per site
Only for new shares after expiration put
in place
Demo!
Reporting
Usage logs
Audit log
Sharing reports
Data governance reports
OneDrive external sharing reports per OneDrive
Data governance reports for sharing links in tenant
Advice &
Examples
Copyright: DanielGlenn.com
Utilize specific SharePoint sites or Teams as extranet(s) and only allow external sharing there
• Only specific users can share to external users
• External users cannot share
• Only specific domains can be shared to
Allow anonymous by request for specific OneDrive sites
• Configure expiration policy
• Pull audit events out and retain for all anonymous shares
Allow external for all SharePoint sites and Teams
• External users cannot share
• Enable DLP to restrict access of sensitive info if shared
• Empower sensitivity labels for regulated users
• Enable monthly access reviews for external users
• Have external users accept terms of use
• Build sharing reports
Work with the business to understand sharing requirements, don’t just lock down
Utilize MFA for guests using conditional access
Setup DLP to remove guest access to sensitive content
Utilize terms of use for guests through Azure AD & conditional access
Use guest access reviews in Azure AD
Force web only access for guests using conditional access and sensitivity labels
Utilize sensitivity labels for sites, groups, & Teams to control external guest and file sharing
Questions?
Email: drew.madelung@protiviti.com
Twitter: @dmadelung
Website: drewmadelung.com
Slides: http://bit.ly/DrewSlides
M365Conf.com
FALL: Las Vegas, NV Dec 7–9, 2021 SPRING: Las Vegas, NV April 5–7, 2022
MICROSOFT 365 COLLABORATION CONFERENCE
Everything you need to know about external sharing in OneDrive, SharePoint, & Teams

Weitere ähnliche Inhalte

Was ist angesagt?

Was ist angesagt? (20)

Extending your Information Architecture to Microsoft Teams
Extending your Information Architecture to Microsoft TeamsExtending your Information Architecture to Microsoft Teams
Extending your Information Architecture to Microsoft Teams
 
Understand the SharePoint Basics
Understand the SharePoint BasicsUnderstand the SharePoint Basics
Understand the SharePoint Basics
 
OneDrive to Rule Them All
OneDrive to Rule Them AllOneDrive to Rule Them All
OneDrive to Rule Them All
 
Understanding Security and Compliance in Microsoft Teams M365 North 2023
Understanding Security and Compliance in Microsoft Teams M365 North 2023Understanding Security and Compliance in Microsoft Teams M365 North 2023
Understanding Security and Compliance in Microsoft Teams M365 North 2023
 
Advantages of SharePoint Online
Advantages of SharePoint OnlineAdvantages of SharePoint Online
Advantages of SharePoint Online
 
Labelling in Microsoft 365 - Retention & Sensitivity
Labelling in Microsoft 365 - Retention & SensitivityLabelling in Microsoft 365 - Retention & Sensitivity
Labelling in Microsoft 365 - Retention & Sensitivity
 
CollabDaysBE - Microsoft Purview Information Protection demystified
CollabDaysBE - Microsoft Purview Information Protection demystifiedCollabDaysBE - Microsoft Purview Information Protection demystified
CollabDaysBE - Microsoft Purview Information Protection demystified
 
Securing SharePoint, OneDrive, & Teams with Sensitivity Labels
Securing SharePoint, OneDrive, & Teams with Sensitivity LabelsSecuring SharePoint, OneDrive, & Teams with Sensitivity Labels
Securing SharePoint, OneDrive, & Teams with Sensitivity Labels
 
OneDrive for Business Best Practices
OneDrive for Business Best PracticesOneDrive for Business Best Practices
OneDrive for Business Best Practices
 
Training – Introduction to SharePoint Online for Collaboration and Document M...
Training – Introduction to SharePoint Online for Collaboration and Document M...Training – Introduction to SharePoint Online for Collaboration and Document M...
Training – Introduction to SharePoint Online for Collaboration and Document M...
 
Part 2 -Deep Dive into the new features of Sharepoint Online and OneDrive for...
Part 2 -Deep Dive into the new features of Sharepoint Online and OneDrive for...Part 2 -Deep Dive into the new features of Sharepoint Online and OneDrive for...
Part 2 -Deep Dive into the new features of Sharepoint Online and OneDrive for...
 
Content Collaboration And Protection With SharePoint, OneDrive & Microsoft Teams
Content Collaboration And Protection With SharePoint, OneDrive & Microsoft TeamsContent Collaboration And Protection With SharePoint, OneDrive & Microsoft Teams
Content Collaboration And Protection With SharePoint, OneDrive & Microsoft Teams
 
2 Modern Security - Microsoft Information Protection
2   Modern Security - Microsoft Information Protection2   Modern Security - Microsoft Information Protection
2 Modern Security - Microsoft Information Protection
 
OneDrive for Business 101
OneDrive for Business 101OneDrive for Business 101
OneDrive for Business 101
 
Deep Dive Microsoft Teams and Yammer integration - Teams Nation 2022
Deep Dive Microsoft Teams and Yammer integration - Teams Nation 2022Deep Dive Microsoft Teams and Yammer integration - Teams Nation 2022
Deep Dive Microsoft Teams and Yammer integration - Teams Nation 2022
 
Intro to Shared Channels
Intro to Shared ChannelsIntro to Shared Channels
Intro to Shared Channels
 
Microsoft OneDrive For Business
Microsoft OneDrive For BusinessMicrosoft OneDrive For Business
Microsoft OneDrive For Business
 
Azure AD connect- Deep Dive Webinar PPT
Azure AD connect- Deep Dive Webinar PPTAzure AD connect- Deep Dive Webinar PPT
Azure AD connect- Deep Dive Webinar PPT
 
ExpertsLive NL 2022 - Microsoft Purview - What's in it for my organization?
ExpertsLive NL 2022 - Microsoft Purview - What's in it for my organization?ExpertsLive NL 2022 - Microsoft Purview - What's in it for my organization?
ExpertsLive NL 2022 - Microsoft Purview - What's in it for my organization?
 
Things to know about One Drive
Things to know about One DriveThings to know about One Drive
Things to know about One Drive
 

Ähnlich wie Everything you need to know about external sharing in OneDrive, SharePoint, and Teams

Ähnlich wie Everything you need to know about external sharing in OneDrive, SharePoint, and Teams (20)

Everything you need to know about sharing files in SharePoint & OneDrive - SP...
Everything you need to know about sharing files in SharePoint & OneDrive - SP...Everything you need to know about sharing files in SharePoint & OneDrive - SP...
Everything you need to know about sharing files in SharePoint & OneDrive - SP...
 
Everything you need to know about sharing files in SharePoint and OneDrive
Everything you need to know about sharing files in SharePoint and OneDriveEverything you need to know about sharing files in SharePoint and OneDrive
Everything you need to know about sharing files in SharePoint and OneDrive
 
Everything you ever wanted to know about external sharing in Microsoft 365 - ...
Everything you ever wanted to know about external sharing in Microsoft 365 - ...Everything you ever wanted to know about external sharing in Microsoft 365 - ...
Everything you ever wanted to know about external sharing in Microsoft 365 - ...
 
SPS London 2019 Enabling External Sharing in Office 365, SharePoint and OneDrive
SPS London 2019 Enabling External Sharing in Office 365, SharePoint and OneDriveSPS London 2019 Enabling External Sharing in Office 365, SharePoint and OneDrive
SPS London 2019 Enabling External Sharing in Office 365, SharePoint and OneDrive
 
Working with External Partners in Office 365
Working with External Partners in Office 365Working with External Partners in Office 365
Working with External Partners in Office 365
 
How to Successfully Manage OneDrive for Business
How to Successfully Manage OneDrive for BusinessHow to Successfully Manage OneDrive for Business
How to Successfully Manage OneDrive for Business
 
Managing OneDrive for Business - SPSNYC
Managing OneDrive for Business - SPSNYCManaging OneDrive for Business - SPSNYC
Managing OneDrive for Business - SPSNYC
 
Taking OneDrive for Business administration to the next level
Taking OneDrive for Business administration to the next levelTaking OneDrive for Business administration to the next level
Taking OneDrive for Business administration to the next level
 
Life in the clouds: SharePoint and Office 365
Life in the clouds: SharePoint and Office 365Life in the clouds: SharePoint and Office 365
Life in the clouds: SharePoint and Office 365
 
Working securely with Microsoft Teams - Techorama 2021
Working securely with Microsoft Teams - Techorama 2021Working securely with Microsoft Teams - Techorama 2021
Working securely with Microsoft Teams - Techorama 2021
 
Supporting third-party access and sharing in Microsoft Teams - Teams Day Onli...
Supporting third-party access and sharing in Microsoft Teams - Teams Day Onli...Supporting third-party access and sharing in Microsoft Teams - Teams Day Onli...
Supporting third-party access and sharing in Microsoft Teams - Teams Day Onli...
 
OneDrive on Demand and Beyond
OneDrive on Demand and BeyondOneDrive on Demand and Beyond
OneDrive on Demand and Beyond
 
Sp expo one_drive_teams_sharepoint
Sp expo one_drive_teams_sharepointSp expo one_drive_teams_sharepoint
Sp expo one_drive_teams_sharepoint
 
OneDrive for Business for Administrators - SPS New York 2018
OneDrive for Business for Administrators - SPS New York 2018OneDrive for Business for Administrators - SPS New York 2018
OneDrive for Business for Administrators - SPS New York 2018
 
Introduction to Microsoft Teams
Introduction to Microsoft TeamsIntroduction to Microsoft Teams
Introduction to Microsoft Teams
 
Webinar: Building Your Document Management Strategy for Office 365
Webinar: Building Your Document Management Strategy for Office 365Webinar: Building Your Document Management Strategy for Office 365
Webinar: Building Your Document Management Strategy for Office 365
 
OneDrive for Business: Much More Than a File Share
OneDrive for Business: Much More Than a File ShareOneDrive for Business: Much More Than a File Share
OneDrive for Business: Much More Than a File Share
 
MindSurf 2013 - Improving Business Productivity with SharePoint 2013
MindSurf 2013 - Improving Business Productivity with SharePoint 2013MindSurf 2013 - Improving Business Productivity with SharePoint 2013
MindSurf 2013 - Improving Business Productivity with SharePoint 2013
 
Deploy Microsoft Teams with Success
Deploy Microsoft Teams with SuccessDeploy Microsoft Teams with Success
Deploy Microsoft Teams with Success
 
Governance in the Modern Workplace: SharePoint, OneDrive, Groups, Teams, Flow...
Governance in the Modern Workplace: SharePoint, OneDrive, Groups, Teams, Flow...Governance in the Modern Workplace: SharePoint, OneDrive, Groups, Teams, Flow...
Governance in the Modern Workplace: SharePoint, OneDrive, Groups, Teams, Flow...
 

Mehr von Drew Madelung

Mehr von Drew Madelung (20)

Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
 
Deep dive into Microsoft Purview Data Loss Prevention
Deep dive into Microsoft Purview Data Loss PreventionDeep dive into Microsoft Purview Data Loss Prevention
Deep dive into Microsoft Purview Data Loss Prevention
 
Introduction to Microsoft Syntex
Introduction to Microsoft SyntexIntroduction to Microsoft Syntex
Introduction to Microsoft Syntex
 
Breakdown of Microsoft Purview Solutions
Breakdown of Microsoft Purview SolutionsBreakdown of Microsoft Purview Solutions
Breakdown of Microsoft Purview Solutions
 
Deploying Viva Topics
Deploying Viva TopicsDeploying Viva Topics
Deploying Viva Topics
 
What's New with OneDrive
What's New with OneDriveWhat's New with OneDrive
What's New with OneDrive
 
Getting started with with SharePoint Syntex
Getting started with with SharePoint SyntexGetting started with with SharePoint Syntex
Getting started with with SharePoint Syntex
 
What's new with Security & Compliance for SharePoint, OneDrive, and Teams
What's new with Security & Compliance for SharePoint, OneDrive, and TeamsWhat's new with Security & Compliance for SharePoint, OneDrive, and Teams
What's new with Security & Compliance for SharePoint, OneDrive, and Teams
 
Microsoft Ignite 2021 Recap
Microsoft Ignite 2021 RecapMicrosoft Ignite 2021 Recap
Microsoft Ignite 2021 Recap
 
What's new with OneDrive - July 2021
What's new with OneDrive - July 2021What's new with OneDrive - July 2021
What's new with OneDrive - July 2021
 
Labelling in Microsoft 365 - Retention & Sensitivity
Labelling in Microsoft 365 - Retention & SensitivityLabelling in Microsoft 365 - Retention & Sensitivity
Labelling in Microsoft 365 - Retention & Sensitivity
 
Sensitivity for Groups, Teams, and SharePoint
Sensitivity for Groups, Teams, and SharePointSensitivity for Groups, Teams, and SharePoint
Sensitivity for Groups, Teams, and SharePoint
 
Wisconsin SharePoint User Group - November 2020 - Ignite News
Wisconsin SharePoint User Group - November 2020 - Ignite NewsWisconsin SharePoint User Group - November 2020 - Ignite News
Wisconsin SharePoint User Group - November 2020 - Ignite News
 
M365 Records Management Community Webinar
M365 Records Management Community WebinarM365 Records Management Community Webinar
M365 Records Management Community Webinar
 
Following the Evolution of Office 365 Groups to Microsoft 365 Groups
Following the Evolution of Office 365 Groups to Microsoft 365 GroupsFollowing the Evolution of Office 365 Groups to Microsoft 365 Groups
Following the Evolution of Office 365 Groups to Microsoft 365 Groups
 
Sensitivity labels for Teams, Microsoft 365 Groups & SharePoint Sites
Sensitivity labels for Teams, Microsoft 365 Groups & SharePoint SitesSensitivity labels for Teams, Microsoft 365 Groups & SharePoint Sites
Sensitivity labels for Teams, Microsoft 365 Groups & SharePoint Sites
 
Review of the new Managed Metadata experience in SharePoint Online
Review of the new Managed Metadata experience in SharePoint OnlineReview of the new Managed Metadata experience in SharePoint Online
Review of the new Managed Metadata experience in SharePoint Online
 
Getting Started with Site Designs and Site Scripts - SPSChi
Getting Started with Site Designs and Site Scripts - SPSChiGetting Started with Site Designs and Site Scripts - SPSChi
Getting Started with Site Designs and Site Scripts - SPSChi
 
Microsoft Ignite Recap: Microsoft 365 Security & Compliance with Vlad & Drew
Microsoft Ignite Recap: Microsoft 365 Security & Compliance with Vlad & DrewMicrosoft Ignite Recap: Microsoft 365 Security & Compliance with Vlad & Drew
Microsoft Ignite Recap: Microsoft 365 Security & Compliance with Vlad & Drew
 
Microsoft Ignite Recap: Microsoft Teams & Yammer with Vlad & Drew
Microsoft Ignite Recap: Microsoft Teams & Yammer with Vlad & DrewMicrosoft Ignite Recap: Microsoft Teams & Yammer with Vlad & Drew
Microsoft Ignite Recap: Microsoft Teams & Yammer with Vlad & Drew
 

Kürzlich hochgeladen

+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
?#DUbAI#??##{{(☎️+971_581248768%)**%*]'#abortion pills for sale in dubai@
 
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Victor Rentea
 

Kürzlich hochgeladen (20)

Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
 
Exploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with MilvusExploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with Milvus
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processors
 
MS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectorsMS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectors
 
presentation ICT roal in 21st century education
presentation ICT roal in 21st century educationpresentation ICT roal in 21st century education
presentation ICT roal in 21st century education
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
 
Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
Ransomware_Q4_2023. The report. [EN].pdf
Ransomware_Q4_2023. The report. [EN].pdfRansomware_Q4_2023. The report. [EN].pdf
Ransomware_Q4_2023. The report. [EN].pdf
 
DEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
DEV meet-up UiPath Document Understanding May 7 2024 AmsterdamDEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
DEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
 
DBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor PresentationDBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor Presentation
 
FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdf
 
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
 
AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of Terraform
 
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, AdobeApidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
 
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
 
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
 
Corporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptxCorporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptx
 

Everything you need to know about external sharing in OneDrive, SharePoint, and Teams

  • 1. FALL: Las Vegas, NV Dec 7–9, 2021 SPRING: Las Vegas, NV April 5–7, 2022 M365Conf.com MICROSOFT 365 COLLABORATION CONFERENCE Everything you need to know about external sharing in OneDrive, SharePoint, & Teams Drew Madelung
  • 2.
  • 3. 2021/2022 April 5 – 7, 2021 MGM Grand Las Vegas, NV Dec 7 – 9, 2021 MGM Grand Las Vegas, NV In-Person – December and April
  • 4. M365Conf.com FALL: Las Vegas, NV Dec 7–9, 2021 SPRING: Las Vegas, NV April 5–7, 2022 Who am I Drew Madelu n g  Milwaukee, Wisconsin  Associate Director @ Protiviti  @dmadelung
  • 5. M365 architecture to support sharing Sharing for files, groups, sites Sharing management Everything you need to know about external sharing in OneDrive, SharePoint, & Teams #M365Conf
  • 6. Do you allow external sharing? Do you have email turned off?
  • 7. Access and Share all your files through OneDrive Collaborate, communicate, and share in one spot in Teams Share content, data and portals in SharePoint
  • 8. Global economies require cross company collaboration Users need to be able to safely share content across company boundaries Companies need to keep sensitive content secure in a complex environment
  • 10. File Collaboration across Microsoft 365 All files stored in SharePoint File sharing settings shared Every OneDrive site is a SharePoint Site Collection SharePoint Online SharePoint Communication Sites Teams OneDrive for Business SharePoint Team Sites Yammer Communities
  • 11. Teams Chat Microsoft 365 Groups are a group of people Single identity across workloads Azure AD objects Share at the group level Different sharing settings Teams Chat SharePoint Files Planner Tasks Exchange Email Microsoft 365 Groups SharePoint Sites not M365 Group backed (Communication/ Classic)
  • 12. Teams Chat The configuration & management for sharing files is different than the Microsoft 365 group Adding external users to the group grants them access to solutions the group is granting access too Sharing files grants them access to just that content SharePoint Files Microsoft 365 Groups
  • 13. Teams Chat Planner Tasks Exchange Email Teams Chat SharePoint Files Microsoft 365 Groups Teams Chat Adding external users to the Team adds them to the Microsoft 365 Group File sharing the same as the content is still based on SharePoint sharing rules
  • 14.
  • 15. Someone from outside your Microsoft 365 subscription who has been granted access to a site, file, or folder Authenticated with Microsoft account Anonymous Spreads across workloads Added to Azure AD as Guest Groups, Teams, SharePoint, OneDrive, Yammer, etc Can’t be shared sites IP tracked
  • 16. External access enables communication (chat) or content available without using guest accounts • Sharing a file anonymously Sometimes used synonymously but there are differences Guest access enables non directory users into your environment as guest accounts which can grant them access to content • Adding a user to a team
  • 17. Share files and folders Request files Add guests to Teams (M365 group) Share files and folders Add guests to site Add guests to M365 group Share files and folders
  • 18. There are different external sharing settings for containers vs files M365 Group Files M365 Group Site Files Files
  • 20. Specific People People with existing access People in the organization Anyone
  • 21. A non-transferrable, revocable secret key, only grants access to the specific recipient Won’t work if forwarded to others Existing users get access via their account New external users prove email ownership Internal users granted access directly with inheritance broken
  • 22. Send link without sharing Does not change permissions Users have access and receive a link via email Gets direct link to file
  • 23. A transferrable, revocable secret key, only grants access to internal users Can be forwarded to others Access can be revoked anytime Users need link to gain access Requires sign-in to an account in my organization Members (non-guests) in Azure AD
  • 24. A transferrable, revocable secret key Can be forwarded to others Access can be revoked anytime Users need link to gain access Guarantees users can open, anywhere, without signing in
  • 25. Modern sharing UI is unified across platforms OneDrive Mobile App Office Mac File Explorer with OneDrive sync Mac Finder Microsoft Teams (TBD) SharePoint OneDrive Office Online Office Desktop Outlook on the Web
  • 26. SharePoint tenant settings checked for external sharing SharePoint site settings checked for external sharing User shares file that creates a link External user accesses link B2B invitation processes if non anonymous External user accesses file Guest access expiration begins
  • 27. Demo!
  • 29. Tenant settings checked if guest access available Group settings checked if guest access available User adds guest to a Group (Team) B2B invitation sent Guest user accepts invitation Guest added to group and has access to content External sharing settings enforced for files This is not how shared channels will work
  • 30. Demo!
  • 32. Tenant settings checked if guest access available User adds guest to a SharePoint site B2B invitation sent Guest user accepts invitation Guest added to SharePoint site and has access to content External sharing settings enforced for files
  • 33. Demo!
  • 37. Microsoft 365 admin center > Settings > Security & Privacy
  • 38. Turn on/off external sharing  Tenant, per group, per user Turn on/off per workload  Teams, Power BI, SharePoint Allow guests to invite Access reviews Powered by Azure B2B Guest inviter role (no Teams) Domain allow/block  Different than SPO & OneDrive  Configured in Azure AD Terms of use (some have extended licensing)
  • 39. Allow OR Block, not both One policy per organization Works independently from SPO Does not apply to already added guest members Powered by Azure B2B https://go.microsoft.com/fwlink/p/?linkid=857710
  • 40. Powered by Azure B2B Microsoft 365 admin center > Settings > Services & add-ins > Microsoft 365 Groups https://aka.ms/o365-groups-guests
  • 41. • Azure Active Directory: Guest access in Microsoft Teams relies on the Azure AD business-to-business (B2B) platform. Controls the guest experience at the directory, tenant, and application level. • Microsoft Teams: Controls Microsoft Teams only. • Microsoft 365 Groups: Controls the guest experience in Microsoft 365 Groups, Teams, Outlook, and more • SharePoint Online and OneDrive for Business: Controls the guest experience in SharePoint Online, OneDrive for Business, Microsoft 365 Groups, and Microsoft Teams. Anywhere there are files. https://aka.ms/teams-dependencies
  • 42. Microsoft Teams > Org-wide settings > Guest access https://aka.ms/teams-manage-guests
  • 43.  Configure force privacy (public private)  Manage ability to add new guests  Configure external file sharing  Control access from unmanaged devices or other CA
  • 44. Demo!
  • 45. Control WHO can share to external users • Everyone • Only specific people • No one Control WHICH external users can be shared with • Anyone • Only authenticated users • Only authenticated users except specific domains • Only authenticated users in specific domains • No one Control WHAT can be shared externally • Anything • Only specific sites • Only files without sensitive content Control HOW externally shareable links can be used • Default • Enabled, but not default • Mandatory expiration date • Block externally-shareable edit links • Disabled
  • 46.  Sharing for OneDrive can be MORE restrictive but not LESS restrictive than SharePoint  If sharing turned off globally in SharePoint any shared links will stop working Sharing Options  No external sharing  Only existing external users (sign-in required)  New and existing external users (sign-in required)  Anyone, including anonymous users (on by default) Your SharePoint Online sharing settings determine which OneDrive sharing settings are available Files hosted in Teams use these permissions
  • 47. Only effects files & sites Can be set per site Only for new shares after expiration put in place
  • 48. Demo!
  • 50. Usage logs Audit log Sharing reports Data governance reports
  • 51. OneDrive external sharing reports per OneDrive Data governance reports for sharing links in tenant
  • 53. Utilize specific SharePoint sites or Teams as extranet(s) and only allow external sharing there • Only specific users can share to external users • External users cannot share • Only specific domains can be shared to Allow anonymous by request for specific OneDrive sites • Configure expiration policy • Pull audit events out and retain for all anonymous shares Allow external for all SharePoint sites and Teams • External users cannot share • Enable DLP to restrict access of sensitive info if shared • Empower sensitivity labels for regulated users • Enable monthly access reviews for external users • Have external users accept terms of use • Build sharing reports
  • 54.
  • 55. Work with the business to understand sharing requirements, don’t just lock down Utilize MFA for guests using conditional access Setup DLP to remove guest access to sensitive content Utilize terms of use for guests through Azure AD & conditional access Use guest access reviews in Azure AD Force web only access for guests using conditional access and sensitivity labels Utilize sensitivity labels for sites, groups, & Teams to control external guest and file sharing
  • 56. Questions? Email: drew.madelung@protiviti.com Twitter: @dmadelung Website: drewmadelung.com Slides: http://bit.ly/DrewSlides
  • 57. M365Conf.com FALL: Las Vegas, NV Dec 7–9, 2021 SPRING: Las Vegas, NV April 5–7, 2022 MICROSOFT 365 COLLABORATION CONFERENCE Everything you need to know about external sharing in OneDrive, SharePoint, & Teams