Which SharePoint Online guest access settings matter
SharePoint Online guest access is controlled by several layers: organization-level SharePoint and OneDrive sharing settings, site-level sharing settings, link defaults and restrictions, Microsoft Entra external collaboration settings, and—in connected scenarios—Microsoft 365 group or Teams settings. The effective path is shaped by their interaction. No single toggle describes every guest's actual access.
Review the settings as policy context, then collect resource and identity evidence separately. A permissive setting does not prove a guest has access. A restrictive setting does not prove old links, groups, or directory objects were reviewed. Any change can affect live collaborators and needs account-specific testing and authorization.
Microsoft's official SharePoint and OneDrive sharing-settings guide, last updated 30 June 2026 when reviewed, says administrators configure organization-level settings and may apply more restrictive settings to individual sites.
The organization-level sharing setting
In the SharePoint admin center, the organization-level sharing setting establishes the broadest external-sharing level available to SharePoint sites. Microsoft's current guide describes four options:
- Anyone: permits unauthenticated Anyone links for files and folders and also supports authenticated guest scenarios.
- New and existing guests: permits authenticated sharing with existing directory guests and people added through the sharing flow.
- Existing guests: limits sharing to guests already in the directory.
- Only people in your organization: turns off external sharing.
These descriptions are platform behavior, not recommendations. The right setting depends on the organization's collaboration model, data classification, risk decisions, and other controls.
Microsoft also documents that the OneDrive organization setting can be more restrictive than SharePoint but not more permissive. Record both values, because “SharePoint allows guests” does not fully describe OneDrive.
The site-level sharing setting
Each site has its own setting within the organization ceiling. A site can be more restrictive than the organization, but not more permissive. That creates a simple review rule:
effective site maximum = the more restrictive of organization and site
The rule is only a policy maximum. It does not enumerate current users, groups, links, or item permissions.
For every site in scope, record:
- site URL and ID;
- site type and connected group or Team where relevant;
- organization-level value;
- site-level value;
- observation date;
- person or process that collected it;
- exceptions, labels, or governance rules that may also constrain sharing.
Do not infer that all sites share the same value. Site owners, administrators, templates, provisioning rules, and later changes can create different configurations.
Link settings and sharing paths
Microsoft's current guide distinguishes Anyone, organization, and Specific People link behavior and lets administrators choose default link types and permissions under supported settings. It also documents controls such as Anyone-link expiration and view-only restrictions.
For a preflight, capture:
- whether Anyone links are allowed;
- default link type;
- default link permission;
- expiration rule for Anyone links;
- domain restrictions;
- whether only selected security groups can share externally;
- guest expiration policy;
- verification-code reauthentication behavior where applicable;
- relevant site-specific restrictions.
A default is not an inventory. Users may have created links under an earlier default, selected a different allowed type, or received direct access instead. Use the official sharing report and other approved evidence to understand actual sharing in the defined sites.
The how to audit SharePoint guest access guide provides that evidence workflow.
Microsoft Entra external collaboration settings
SharePoint and OneDrive integrate with Microsoft Entra B2B in supported sharing flows. Microsoft notes that Entra external collaboration controls—such as who can invite guests and domain restrictions—apply depending on the sharing model.
The official Entra external collaboration settings, last updated 24 April 2026 when reviewed, documents:
- guest directory-access restrictions;
- who can invite guests;
- self-service sign-up configuration for relevant applications;
- allow or block domain restrictions;
- external-user leave settings;
- cross-tenant access settings that should also be reviewed for B2B collaboration.
These settings govern directory collaboration behavior. They are not a list of SharePoint resources a person can access. Likewise, a SharePoint sharing setting does not tell you every Entra group or application assignment.
Group and Teams context
Microsoft's SharePoint settings guide says the SharePoint organization setting applies to sites connected to Microsoft 365 groups and Teams, while group and Teams guest settings also affect connected sites. Record those relationships before changing a site.
A connected Team can involve:
- a Microsoft 365 group;
- a SharePoint team site;
- Team membership and guest controls;
- channels with different collaboration models;
- links or direct permissions on files and folders.
This page does not attempt to prescribe Teams or cross-tenant configuration. The preflight should identify the connected components and route them to the correct official configuration guide and authorized owner.
Synthetic settings preflight
Assume an invented tenant has:
- SharePoint organization sharing: New and existing guests;
- OneDrive organization sharing: Existing guests;
- site
Project Alpha: Existing guests; - default file link: Specific People;
- Anyone links: not available under the selected maximum;
- Entra invitation rule: only members and selected administrators can invite;
- supplier domain: allowed by the supplied collaboration-restriction evidence;
- guest expiration: 60 days for the site;
- one external collaborator using current project files.
A safe preflight would say:
- The site is configured no more permissively than the organization and currently limits new sharing to existing directory guests.
- The OneDrive setting is more restrictive than the SharePoint organization setting.
- The default link narrows the normal user path, but it does not prove every existing permission uses that link type.
- Entra invitation restrictions affect who can create supported guest relationships.
- The current collaborator's actual access, expiration state, directory object, and planned sign-in path require evidence.
It should not say “guest access is secure” or “the collaborator will keep access after migration.” Those conclusions require more than configuration values.
A configuration review checklist
SharePoint and OneDrive organization level
- Record the current SharePoint external-sharing value.
- Record the current OneDrive value.
- Confirm the OneDrive value is not being described as a site setting.
- Capture domain restrictions and selected sharer restrictions.
- Record link defaults and Anyone-link controls.
- Record guest expiration and reauthentication rules.
- Preserve the observation time and collector.
Site level
- Inventory every site in the defined scope.
- Record the site's external-sharing value.
- Identify connected Microsoft 365 groups and Teams.
- Note sensitivity labels or other approved controls that affect sharing.
- Identify site owners and the person authorized to approve changes.
- Compare the setting with actual sharing evidence.
Microsoft Entra
- Record who can invite guests.
- Record guest directory-access restrictions.
- Record domain allow or block rules.
- Identify relevant cross-tenant access configuration.
- Record the email one-time-passcode or other identity path only from current approved evidence.
- Keep
UserType, identities, and invitation state as distinct fields.
Evidence and decisions
- Generate sharing reports for the sites and OneDrive locations in scope.
- Obtain the approved directory snapshot.
- Separate links, groups, named users, and directory objects.
- Identify sponsors and resource owners.
- Test planned changes with representative collaboration paths.
- Require authorization and a rollback plan before changing live settings.
For the full review boundary, see the Microsoft 365 guest access review.
Common interpretation errors
“Existing guests” means every guest is approved
It means the sharing flow is limited to guests already present in the directory under the documented setting. It does not prove each existing object has a current sponsor or legitimate need.
A Specific People default means no broad links exist
A default guides link creation. Existing links, prior settings, direct access, groups, and user-selected allowed options require evidence.
A guest object proves SharePoint access
An Entra object can exist because of another application, group, Team, invitation, or past collaboration. Join it to resource evidence before making a SharePoint statement.
No guest object means no external sharing
Microsoft documents multiple sharing models and link types. Link evidence and report limitations matter. Do not turn an unmatched row into a tenant-wide conclusion.
One tenant setting can be copied to another
Tenants differ in data, collaboration patterns, licensing, labels, identity providers, domains, and cross-tenant relationships. Verify the intended outcome in the actual tenant.
Limitations and change safety
This checklist does not discover every access path, evaluate every Conditional Access policy, expand every group, or prove a future sign-in result. It does not recommend a universal setting. Microsoft features, terminology, admin interfaces, and licensing can change after the update date.
Before changing a live setting:
- identify affected sites and collaborators;
- collect current evidence;
- document the intended outcome;
- test supported scenarios;
- obtain authorization;
- define rollback and communication;
- verify post-change access and sharing behavior;
- retain a decision record.
Never bulk-remove guests or tighten tenant settings solely from a generic checklist. Access and business continuity decisions belong to authorized owners.
For a focused explanation of why configuration and identity evidence differ, read SharePoint sharing report vs Entra guests.
Official sources reviewed
Microsoft platform facts were checked on 23 July 2026 against the SharePoint and OneDrive sharing-settings guide, Entra external collaboration settings, and SharePoint sharing-report documentation.
To test a bounded settings-and-evidence join without changing the tenant, review the GuestPreflight sample and request one paid migration feasibility audit. It does not invite or remove guests and does not modify sharing settings.
