Permission sprawl in SharePoint Online is fixed by giving access through groups at the site level, setting restrictive sharing link defaults in the SharePoint admin center, limiting who can share, and breaking inheritance only at library or folder level for a clear reason. Team sites are managed through their Microsoft 365 group, communication sites through the Owners, Members and Visitors SharePoint groups, and individual files through sharing links rather than hand-edited permissions. The rest of this guide turns those rules into concrete tenant and site settings, plus the reports that show whether they are holding.
Who this is for and what you will have
This guide is for SharePoint and Microsoft 365 administrators who inherited a tenant where nobody can say who has access to what, and for anyone setting up a new tenant who wants to avoid that state. At the end you will have:
- Organization-level sharing settings that make the safe choice the default.
- Site-level overrides for sensitive sites, applied in the admin center or with PowerShell.
- A membership model where people get access through groups, not one-off grants.
- Clear rules for member sharing, access requests and broken inheritance.
- A repeatable audit using PowerShell and the Data access governance reports.
If you are consolidating tenants or moving content in from another platform, apply these settings to the target before migrating content into it; the Microsoft 365 cross-tenant migration architecture and Google Workspace to Microsoft 365 migration guide cover the migration side.
How SharePoint Online permissions fit together
Access to content comes from three places, and sprawl happens when the third one is used for everything.
| Layer | What it grants | Where you manage it |
|---|---|---|
| Site membership | Access to everything in the site | Microsoft 365 group or Teams (team sites); Owners, Members, Visitors SharePoint groups (communication sites) |
| Unique permissions | Access to one library, folder or item that differs from the site | Advanced permissions on the library, folder or item |
| Sharing links | Access to one file or folder for the people the link allows | The Share and Copy link experience, governed by tenant and site sharing settings |
The site type decides where membership lives:
- Team sites are connected to a Microsoft 365 group by default. Group owners become site owners and group members become site members. Microsoft recommends managing permissions through the group, or through Teams when the site belongs to a team. You can add people directly to the site's SharePoint groups, but they then get the site without the group's other services, and Microsoft recommends against this for the simplest management.
- Channel sites (private and shared channels) are managed only in Teams. SharePoint shows their permissions as read-only.
- Communication sites have no Microsoft 365 group and use the Owners, Members and Visitors SharePoint groups.
- Hub sites follow the underlying site type. Associating sites to a hub needs separate permission granted by a SharePoint Administrator.
By default, Owners have Full Control, Members have Edit and Visitors have Read. Full Control and Limited Access are the two default permission levels you can't change.
Prerequisites
- The SharePoint Administrator role (or higher) for the admin center steps. Site-level sharing settings can't be changed by site owners.
- The SharePoint Online Management Shell for the PowerShell steps:
Install-Module -Name Microsoft.Online.SharePoint.PowerShell -Scope CurrentUser
Connect-SPOService -Url https://contoso-admin.sharepoint.comIn PowerShell 7, import the module with Import-Module Microsoft.Online.SharePoint.PowerShell -UseWindowsPowerShell first.
- For the Data access governance reports, the licensing in the SharePoint Advanced Management prerequisites. With Microsoft 365 E5 licensing but without SharePoint Advanced Management, administrators can use the activity reports (returning up to 10,000 sites) but not the snapshot reports or the remedial actions.
- Agreement on which sites hold content that must never be shared externally. Microsoft's guidance is to keep such content in sites with external sharing turned off and create separate sites for external collaboration.
Step 1: Set organization-level guardrails
In the SharePoint admin center, expand Policies and select Sharing. Under External sharing, choose the most permissive level any site needs; sites can be set to the same or a more restrictive level, never a more permissive one. The OneDrive slider can also be more restrictive than SharePoint, but not more permissive.
| Level | What users can do |
|---|---|
| Anyone | Share files and folders with links that work without sign-in; share sites with guests who authenticate |
| New and existing guests | Share with people outside the organization who sign in or verify with a code |
| Existing guests | Share only with guests already in the directory |
| Only people in your organization | No external sharing |
Then expand More external sharing settings and work through the options:
- Limit external sharing by domain to an allow list or block list (up to 5,000 domains).
- Allow only users in specific security groups to share externally if external sharing should be a privilege, not a default.
- Leave Allow guests to share items they don't own off unless there is a reason to change it. By default, guests need Full Control to share items externally.
- Guest access to a site or OneDrive will expire automatically after this many days to stop guest access from outliving the project.
Under File and folder links, set the default link type users see and the default link permission (the same settings as Set-SPOTenant -DefaultSharingLinkType and -DefaultLinkPermission). Specific people is the most restrictive. Only people in your organization suits organizations that share broadly internally. Anyone with the link is only available when external sharing is set to Anyone, and links of that type can be forwarded freely with no way to track who opened them. Set the default permission to View so that edit access is a deliberate choice.
If you allow Anyone links, use the advanced settings to require them to expire within a set number of days and to restrict them to view permission. When you shorten the expiration, existing links are updated to the new, shorter limit; when you lengthen it, existing links keep their current expiration.
Two behaviours to know before you change these settings on a live tenant: guests typically lose access within one hour when you restrict or turn off external sharing, and if you turn external sharing off for the organization and later turn it back on, guests regain access. To remove guests permanently from specific sites, turn off sharing on those sites first.
Remember that Microsoft Entra external collaboration settings also decide who can invite guests, and allowed or blocked domains in Entra ID affect SharePoint site sharing as well.
Step 2: Override sharing for sensitive sites
New sites do not all start in the same place:
| Site type | Default sharing setting |
|---|---|
| Communication | Only people in your organization |
| Modern site with no group | Only people in your organization |
| Classic | Only people in your organization |
| Group-connected (including Teams) | New and existing guests if group owners can add outside people, otherwise Existing guests only |
| OneDrive | Anyone |
The root communication site (contoso.sharepoint.com) defaults to Anyone, which is worth checking in every tenant.
To change a site in the admin center:
- Go to Active sites and select the site. For a channel site, select the link in the Channel sites column first.
- On the Settings tab, select More sharing settings.
- Choose the external sharing level.
- Optionally expand Advanced settings for external sharing and select Limit sharing by domain.
- To set a site-specific default link type, link permission or guest expiration, clear Same as organization-level setting and choose the values.
- Select Save.
The same changes in PowerShell, for a finance site that should allow only existing guests from one partner domain and default to view-only Specific people links:
$site = "https://contoso.sharepoint.com/sites/finance"
Set-SPOSite -Identity $site -SharingCapability ExistingExternalUserSharingOnly
Set-SPOSite -Identity $site -SharingDomainRestrictionMode AllowList -SharingAllowedDomainList "fabrikam.com"
Set-SPOSite -Identity $site -DefaultShareLinkScope SpecificPeople -DefaultShareLinkRole ViewSharingCapability accepts Disabled, ExistingExternalUserSharingOnly, ExternalUserSharingOnly and ExternalUserAndGuestSharing (the last one is the only value that allows Anyone links). DefaultShareLinkScope and DefaultShareLinkRole replace the older DefaultSharingLinkType and DefaultLinkPermission parameters. To change the default link type for a Teams private or shared channel site, PowerShell is the only option.
For sites where sharing should be more locked down than any slider allows, Set-SPOSite -Identity <url> -DisableSharingForNonOwners prevents non-owners from inviting new people. It is in a separate parameter set, so run it as its own command.
Step 3: Give access through groups
This is where most sprawl is prevented.
Team sites. Add people to the Microsoft 365 group (or the team) as owners or members. Do not add individuals to the site's SharePoint groups for routine access. Because Microsoft 365 groups have no view-only role, read-only users are the one exception: add them, or better a security group containing them, to the site's Visitors group.
Communication sites. Keep a handful of owners, a small Members group of content authors, and a large Visitors audience. Add security groups or Microsoft 365 groups rather than individuals; the Visitors group is the natural place for a large security group. If a team in Teams needs to author content on a communication site, add that team's Microsoft 365 group to the communication site's Members group. Microsoft notes that nested security groups can cause performance issues.
Everyone except external users. On public team sites, this built-in group is added to Members automatically, which gives every internal user edit access. On private team sites it can't be granted permissions. Treat public team sites as public, and use private sites for anything that isn't meant for the whole organization.
Step 4: Decide who can share and how requests are handled
Site owners control member sharing. In the site, go to Settings > Site permissions, then under Site Sharing select Change how members can share. The options under Sharing permissions are:
- Site owners and members can share files, folders, and the site. People with Edit permissions can share files and folders.
- Site owners, members and people with Edit permissions can share files and folders, but only site owners can share the site.
- Only site owners can share files, folders, and the site.
The middle option is a good default for most collaboration sites: content sharing still works, but site membership stays with the owners and the group. Use the last option for sites where owners must approve all access.
In the same panel, the Access requests section controls whether people without access can ask for it. Turn Allow access requests on and send requests to the site owners or to a specific mailbox that someone actually monitors. Pending requests appear under Settings > Site contents > Access requests, and only site collection administrators, SharePoint Administrators and members of the site's default Owners group can use that page.
Step 5: Break inheritance only where it pays for itself
By design, everything in a site inherits permissions from its parent: lists and libraries from the site, folders and files from their library. Each time inheritance is broken, the object gets its own permission list that no longer follows changes to the parent, and someone has to maintain it.
Use these rules:
- Prefer a separate site to a broken library. Content with a different audience usually belongs in its own site with its own group.
- If you must break inheritance, do it at library or folder level, never on individual files. One unique folder is easy to audit; hundreds of unique files are not.
- Grant the unique permission to a group, not to individual users.
- Act early on large libraries. You can't break or restore inheritance on a list, library or folder with more than 100,000 items, though individual items inside can still be changed.
- Watch the scope count. A list or library supports up to 50,000 unique permissions for items, but Microsoft's recommended general limit is 5,000.
Sharing is the most common source of unplanned unique permissions. When a user shares a file or item with someone who doesn't already have access, SharePoint automatically stops inheritance on that item. SharePoint then gives the recipient Limited Access on the parent library and site, so the interface can render around the shared item without granting access to anything else. Restrictive default link types and member sharing rules from steps 1 and 4 are what keep this under control.
Verify and audit
PowerShell
Get-SPOSite -Limit All is fast, but sharing properties such as SharingCapability, DefaultSharingLinkType and DefaultLinkPermission are not populated when you use -Limit or -Filter. Read each site by identity to get real values:
$report = Get-SPOSite -Limit All | ForEach-Object {
$s = Get-SPOSite -Identity $_.Url
[pscustomobject]@{
Url = $s.Url
Template = $s.Template
SharingCapability = $s.SharingCapability
DefaultLinkType = $s.DefaultSharingLinkType
DefaultLinkPerm = $s.DefaultLinkPermission
}
}
$report | Export-Csv -Path .\site-sharing.csv -NoTypeInformationSort the output by SharingCapability and check every site set to ExternalUserAndGuestSharing against your list of sites that are allowed Anyone links.
Data access governance reports
In the SharePoint admin center, expand Reports and select Data access governance. The reports most useful for sprawl are:
- Site permissions across your organization, a snapshot that identifies sites with the broadest access, including large user counts, guests and Everyone except external users.
- Sharing links, an activity report of sites where users created the most Anyone, People in your organization and Specific people links in the last 28 days.
- Shared with 'Everyone except external users', an activity report of sites where content was recently shared with all internal users.
Microsoft suggests running snapshot reports quarterly and activity reports monthly. Without SharePoint Advanced Management, you must enable data collection first; reports are available 24 hours later and only include data from that point. With SharePoint Advanced Management, you can act on the results by applying restricted access control, reviewing the change history report, or starting a site access review that asks owners to clean up their own sites.
Troubleshooting
Members say they can't share files or folders. Check the site's sharing permission. If it is set to Only site owners can share files, folders, and the site, members can't share; change it under Change how members can share if they should.
The Anyone link option is missing. Anyone links require the organization and the site to be set to Anyone. If the default link type is Anyone but the site only allows guests who sign in, the default falls back to Only people in your organization.
Guests of a group can't open site content even though the site allows external sharing. The Microsoft 365 group's guest settings may block guest members from group resources. Check guest access in Microsoft 365 Groups as well as the site sharing level.
You can't break or restore inheritance on a big library. The library, list or folder has more than 100,000 items. Break inheritance on a smaller folder or move the restricted content to its own location.
Data access governance reports don't generate. If the tenant is set to display concealed user, group and site names in reports, the reports might not work. A Global Administrator can clear Display concealed user, group, and site names in all reports in the Reports setting of the Microsoft 365 admin center.
Checklist
- Organization sharing level set to the most permissive level any site needs, not higher.
- Default link type set to Specific people or Only people in your organization, with View as the default permission.
- Anyone links, if allowed, set to expire and to view-only.
- Guest access expiration configured.
- Sensitive sites set to Existing guests or Only people in your organization, with domain restrictions where partners are known.
- Team site access managed in the Microsoft 365 group or Teams; read-only users in Visitors through a security group.
- Member sharing set to "only site owners can share the site" on collaboration sites; access requests routed to a monitored recipient.
- Inheritance broken only at library or folder level, granted to groups, and documented.
- Site sharing report exported quarterly; Data access governance sharing link reports reviewed monthly.
References
- Sharing and permissions in the SharePoint modern experience
- Manage sharing settings for SharePoint and OneDrive in Microsoft 365
- Change the sharing settings for a site
- Change the default sharing link for a site
- Understanding permission levels in SharePoint
- SharePoint limits
- Data access governance reports for SharePoint sites
- Set up and manage access requests
- Set-SPOSite
- Get-SPOSite
- Set-SPOTenant
- Get started with the SharePoint Online Management Shell