Secure enterprise sharing with access reviews for Microsoft 365

Collaboration suites like M365 offer unparalleled convenience. Millions of teams rely on them to quickly share documents with coworkers, clients and business partners. Yet when sharing is this easy, data security becomes a lot harder.

Cloud sharing is so integral to the modern workplace that it’s difficult to imagine how offices ever got by without it. Dropping files in one-on-one chats. Spreadsheets that live in Teams channels so everyone can see the latest figures. Throwing project folders on SharePoint and sending out invite links.

Yet for all the ways that cloud sharing has revolutionized office life, remote work and long-distance collaboration, there is a downside.

With the usage of cloud platforms exploding over recent years, visibility into sharing is falling further and further behind. Many organizations no longer have any idea who their users are sharing potentially sensitive information with.

Unmanaged cloud sharing is a shockingly common problem in enterprise environments. Anywhere organizations use Microsoft 365 to share access, security teams struggle to identify and rein in problematic cloud access.

In a survey by Wire, 61% of security leads reported that access to shared files often remains active longer than intended. Over a third acknowledge difficulties in even identifying who has access to sensitive shared files.

One factor that makes cloud sharing difficult to evaluate from a security perspective is how context-driven the use of sharing features is. Employees share files with a specific purpose in mind, whether it’s to coordinate with a coworker or get approval from a client on a design mockup.

The problem is that shared access often outlives or outgrows its original purpose: A freelancer could be taken off a project, but never removed from the project folder in SharePoint. Members may invite new users into a Teams channel, forgetting that they will get access to every file hosted within it.

The highly contextual nature of cloud sharing means the only way to know for certain whether shared access is still needed is to ask the person who originally provided it. Access reviews are an essential safeguard, and looping file or channel owners into the review process leads to faster and more accurate audits.

The challenge is in how to implement this process with the available tools of the platform.

The lack of control over shared data presents a growing and often underappreciated security risk in enterprise environments. At the same time, you can hardly blame teams for making full use of sharing features, the central pillar that cloud suites are built around. The problem of unmanaged cloud sharing is not so much about user behavior as it is insufficient governance features built into Microsoft 365.

Microsoft 365 provides two reporting options that offer visibility into shared data, but both come with major limitations.

You can generate a global report on sharing links using SharePoint Advanced Management, but this only tells you which sites had the most new links created in the last 28 days. By itself, that figure does not give you enough context to draw any useful conclusions. A high number of new links could point to misuse, or it could simply be due to a project with outside involvement, such as onboarding a new supplier.

Similarly, you can create site-level sharing reports to get a CSV table showing every shared file within a site and everyone who has access to it. However, running this report across every SharePoint and OneDrive in your organization is incredibly time-consuming. So is manually sifting through these files to identify problematic sharing.

Ultimately, both reporting options require you to do most of the legwork, whether it’s piecing together site-level reports into a cohesive whole or investigating the spike in sharing links you’ve seen in a global activity report.

What Microsoft 365 is missing is a centralized dashboard for access governance that gives you the full picture without all this added effort – allowing you to zoom in or out on the fly. This is where dedicated Identity & Access Governance solutions like tenfold bridge the visibility gap left by native reporting tools.

Automate on- and offboarding, streamline access reviews and stay compliant – without complexity or custom scripting.

With a suite of ready-to-use plugins, tenfold provides seamless integration for Microsoft Cloud and on-prem environments.

As part of its deep integration with the Microsoft cloud and on-prem ecosystem, tenfold offers purpose-built reporting tools that provide full visibility into shared files across Teams, OneDrive and SharePoint. Two standout features put tenfold’s shared content governance ahead of other IGA platforms:

With in-depth visibility into cloud sharing and an effective review process to stop shared access from outliving its intended purpose, tenfold allows you to make full use of cloud collaboration features without putting your data at risk.

Regain control of shared files with the leading no-code IGA solution. Book a personal demo with our team to learn more.

Sponsored and written by tenfold Software.

Gyazo server flaw exploited to steal 23.6 million user records

Fake LastPass Authenticator GitHub repos push new Rapuncel infostealer

ShinyHunters hacks Clop leak site, threatens to extort ransomware gang

Find out how long recovery really takes — and what it costs. Read the 2025 BCDR Report.

Watch a working exploit hit live controls and see exactly what blocks, detects, or misses

Overdue a password health-check? Audit your Active Directory for free

Automate Onboarding and Access Reviews with No-Code IGA: See how it works

Patch automation needs more than speed. Action1 brings control into every stage of deployment.

Terms of Use – Privacy Policy – Ethics Statement – Affiliate Disclosure

Read our posting guidelinese to learn what content is prohibited.