---
title: How to reduce the risk of shared data in Microsoft 365
description: Our expert's advice on how to reduce the risks associated with dangerous shares (misconfigured, obsolete...) on your Microsoft 365 shared data.
image: https://blog.idecsi.com/hubfs/MicrosoftTeams-image%20(71)-1.png
---

[![Logo-Idecsi-Black-tagline](https://blog.idecsi.com/hs-fs/hubfs/LOGOS%20IDECSI/LOGOS%20OFFICIELS/Logo-Idecsi-Black-tagline.png?width=1010&height=319&name=Logo-Idecsi-Black-tagline.png)](https://www.idecsi.com/)

- Solutions
  
  
  
  
  
  DETOX® pour M365
  
  Audit, Remediation & ROI
  
  [Discover DETOX](https://info.idecsi.com/detox-m365?hsLang=en)
  
  ![Audit, Remediation & ROI](https://blog.idecsi.com/hubfs/ILLU-4.png)
  
  
  
  
  
  Solutions
  
  IDECSI gives security and IT teams full control over their data — across DSPM, Data Access Governance, Human Risk Management, and Data Volume Management.
  
  
  
    - [![download_done](https://blog.idecsi.com/hubfs/download_done.svg) M365 Data Security Platform](https://www.idecsi.com/solution/mydatasecurity/)
    - [![download_done](https://blog.idecsi.com/hubfs/download_done.svg) Data storage optimization](https://www.idecsi.com/solution/mydatamanagement/)
- Challenges
  
  
  
  
  
  M365 Checklist
  
  15 Warning Signs Your M365 Data Is at Risk
  
  [Get the checklist](https://info.idecsi.com/checklist-15-warningsigns?hsLang=en)
  
  ![Checklist risques M365](https://blog.idecsi.com/hubfs/Frame-2147255341.png)
  
  
  
  
  
  Your 2026 Challenges
  
  Address your most critical data security and governance challenges - across your M365 environment
  
  
  
    - [![download_done](https://blog.idecsi.com/hubfs/download_done.svg) Gain visibility accross M365](https://www.idecsi.com/challenges/visibility-microsoft-365)
    - [![download_done](https://blog.idecsi.com/hubfs/download_done.svg) Get Ready For Copilot M365](https://www.idecsi.com/challenges/m365-copilot/)
    - [![download_done](https://blog.idecsi.com/hubfs/download_done.svg) Control external user access](https://www.idecsi.com/challenges/external-access-microsoft-365/)
    - [![download_done](https://blog.idecsi.com/hubfs/download_done.svg) Prevent Sensitive Data Exposure](https://www.idecsi.com/challenges/sensitive-data-m365/)
    - [![download_done](https://blog.idecsi.com/hubfs/download_done.svg) Gain visibility across Microsoft 365](https://www.idecsi.com/challenges/visibility-microsoft-365/)
    - [![download_done](https://blog.idecsi.com/hubfs/download_done.svg) Ensure regulatory compliance](https://www.idecsi.com/challenges/compliance-m365/)
- Resources
  
  
  
  
  
  Is Your Tenant Ready for Copilot?
  
  A Security & Governance Playbook
  
  [Download](https://info.idecsi.com/whitepapper_copilot?hsLang=en)
  
  ![Copilot guide](https://blog.idecsi.com/hubfs/Frame-2147255339.png)
  
  
  
  
  
  Our resources
  
  Check out our useful resources for improving data protection
  
  
  
    - [![download_done](https://blog.idecsi.com/hubfs/download_done.svg) Blog](https://blog.idecsi.com)
    - [![download_done](https://blog.idecsi.com/hubfs/download_done.svg) Help Center](https://help.idecsi.com/)
    - [![download_done](https://blog.idecsi.com/hubfs/download_done.svg) Ressources & News](https://blog.idecsi.com/resources?hsLang=en)
    - [![download_done](https://blog.idecsi.com/hubfs/download_done.svg) About us](https://www.idecsi.com/about-us/)
- [Customers](https://blog.idecsi.com/resources-customer?hsLang=en)
- - [English](https://blog.idecsi.com/reduce-the-risk-of-shared-data-m365)
    - [Français](https://blog.idecsi.com/fr/reduire-risques-sur-les-donnees-partagees-m365)

Search

[Request a demo](https://info.idecsi.com/demo-idecsi?hsLang=en)

Microsoft 365

22 August 2023

# How to reduce the risk of shared data in Microsoft 365

![Illustration of a dangerous share in Microsoft 365](https://4272098.fs1.hubspotusercontent-na1.net/hubfs/4272098/MicrosoftTeams-image%20%2871%29-1.png)

- [Home](https://www.idecsi.com/)
- [Blog](https://blog.idecsi.com)
- How to reduce the risk of shared data in Microsoft 365

Document sharing is a common activity among Microsoft 365 users. Misconfigured shares, external and obsolete shares, guest access, inactive users, overly permissive rights: in companies, data shared via collaborative cloud applications raises questions relating to information system security, data protection, integrity and often increase the risk of cyberattacks. M365 solutions therefore offer great flexibility for sharing information both internally and externally, so [Microsoft 365 data protection and security](https://blog.idecsi.com/data-security-microsoft365?hsLang=en) are essential.

Indeed, managing access and sharing becomes more complex on cloud and collaborative environments such as Microsoft 365, so how do you identify misconfigured or risky shares, and eliminate dangerous shares for data?

## Shared data, what risks does this pose for the information system?

Open shares have always been considered problematic since they pose a risk, in particular, of data leaks. At Forvia (automotive equipment manufacturer), for example, 80% of industrial site compromises are linked to open sharing or uncontrolled access to file servers. And the information system is opened, the traditional perimeter increasingly dissolves.

According to a recent study, 10% of the average company's cloud data is accessible to each employee via SaaS\* solutions.

Identifying and reducing the scope of data exposure in the cloud is key. So what is the potential damage if a user is compromised? Where is sensitive data located? How is it shared? Who can access it?

## What is a "dangerous" share in M365?

Microsoft 365 link sharing can result in accidental data exposure, when a user sets too broad, inappropriate permissions while sharing. For example, an O365 account user can use the "Copy link" option to share a document with someone. If the link is forwarded to someone else or shared publicly, anyone with the link can edit the document.

Thus content sharing can be considered dangerous, when users share sensitive information with unauthorised people or when permissions are not appropriate or are no longer appropriate.

**5 risks posed by misconfigured shares:**

- Access to data that cannot be identified (anonymous user, non-nominative link)
- Access to data that cannot be traced (recipients)
- Access that is not suitable and too permissive (authorisation, legitimacy of access to a folder, a sharepoint site), for example a sharing link "to the whole company"
- External access to the company (access without expiration date)
- Authorised external access, which becomes obsolete over time: no precise tracking, expiration

What’s more, one share can hide another. Sharing has technical implications (adding guests, identities, objects, duration in time, etc.)

Each access, each right (sharing link, overly permissive rights, etc.) therefore becomes a potential entry point into digital environments containing strategic data. To minimise the risk, access rights should be regularly reviewed and reduced in the cloud according to the least privilege principle (principle of granting the minimum rights necessary).

## **How do I stay in control of sharing on Microsoft 365?**

8 steps to staying in control of shared data and M365 sharing links

- Set an expiration date for anonymous type links so that guest access is automatically reviewed.
- Restrict external shares (using PowerShell) to prevent a guest from accessing specific groups or block guests from a specific domain.
- [Labelling sensitive or confidential data](https://blog.idecsi.com/classify-protect-sensitive-data?hsLang=en), using Microsoft Purview Information Protection Sensitivity Labels and Azure AD's DLP tool helps define policies to map and identify where the data is located.
- Audit permissions that are overly permissive regularly
- Follow up on data shared with external parties and send reminders to owners to recertify access
- [Manage external access by the owner(s)](https://blog.idecsi.com/tips-admins-external-sharing-microsoft365?hsLang=en) of sharepoint sites, Teams groups (being able to track internal movements, guests over time)
- Launch access and rights review campaigns at company or user group level.
- Set up a remediation plan with the owners of data exposed internally or externally.

One of the main difficulties lies in the fact of not being able to have 100% control over security, compliance and governance policies, in particular due to deviant behaviour, which is often due to human error, poor configuration, poor knowledge of the environment and tools.

## **Managing shared data on a collaborative and cloud scale**

In each app, users can choose settings for shares, view or edit permissions, and grant these permissions to "Anyone with the link", "Specific people" or "Only people in your organisation" (only for professional account users).

**What is the user's role in controlling shared data?**

How can the user succeed in deleting these misconfigured, potentially dangerous shares, non-legitimate accesses, inappropriate permissions, in a "simple and effective" way on an environment in perpetual motion, and in which the user is almost the "master" of his own management?

After all, isn't the user the key?

Each employee should only be able to access the information they really need for their professional activity. At least that’s the ideal in this collaborative world. When information is shared, the responsibility for its protection is extended or distributed. Each collaborator should be made responsible for the sharing they make of the data, particularly over time, and should be involved in reviewing this sharing.

It is essential to make users aware of any of their shares that are too open, permissive, considered dangerous for the company with the possibility of correcting, modifying these shares.

Data must be at the heart of the security strategy. Traditional security approaches, however, have their limits. This is why security needs to be rethought. Cybersecurity can be collaborative, participatory, and so proactively involve the owners of shared data so as to limit these accidental exposures and the risks posed by shared data.

## **Auditing shared data and associated permissions**

IDECSI has launched DETOX for M365, a [device that allows you to audit data that is shared](https://info.idecsi.com/detox-m365?hsLang=en) internally and externally within the M365 tenant. The solution displays all the sharing, access and rights links and highlights to the owners any aspects that require correction thanks to MyDataSecurity technology.

 Recent articles

[Microsoft 365 Copilot Architecture: Technical Deep Dive (2026)](https://blog.idecsi.com/microsoft-365-copilot-architecture?hsLang=en)

[Securing AI Agents in Microsoft 365: Best Practices for 2026](https://blog.idecsi.com/securing-ai-agents-microsoft-365?hsLang=en)

[Data Exposure in Microsoft 365: Understanding the Risks and Taking Back Control](https://blog.idecsi.com/microsoft-365-data-exposure?hsLang=en)

[Copilot Cowork in Microsoft 365: What CIOs Need to Know](https://blog.idecsi.com/copilot-cowork-microsoft-365?hsLang=en)

 Best practices to improve Microsoft Teams security

[![Download the infographic ](https://no-cache.hubspot.com/cta/default/4272098/825ad7d1-e961-4a7a-a6b3-6e380b22285f.png)](https://cta-redirect.hubspot.com/cta/redirect/4272098/825ad7d1-e961-4a7a-a6b3-6e380b22285f)

 Share this article

<https://twitter.com/intent/tweet?text=https://blog.idecsi.com/reduce-the-risk-of-shared-data-m365> <http://www.facebook.com/sharer.php?u=https://blog.idecsi.com/reduce-the-risk-of-shared-data-m365> <https://www.linkedin.com/sharing/share-offsite/?url=https://blog.idecsi.com/reduce-the-risk-of-shared-data-m365>

Subscribe to our newsletter and receive new contents every month

 Our articles

These articles may   
interest you

![](https://4272098.fs1.hubspotusercontent-na1.net/hubfs/4272098/image%20%2858%29.png)

 Microsoft 365

 Security

 Securing AI Agents in Microsoft 365: Best Practices for 2026 

<https://blog.idecsi.com/securing-ai-agents-microsoft-365?hsLang=en> [Lire l'article](https://blog.idecsi.com/securing-ai-agents-microsoft-365?hsLang=en)

![](https://4272098.fs1.hubspotusercontent-na1.net/hubfs/4272098/Exposition%20des%20donn%C3%A9es%20dans%20Microsoft%20365%20_%20risques%20et%20controle%202.png)

 Security

 Data Exposure in Microsoft 365: Understanding the Risks and Taking Back Control 

<https://blog.idecsi.com/microsoft-365-data-exposure?hsLang=en> [Lire l'article](https://blog.idecsi.com/microsoft-365-data-exposure?hsLang=en)

![](https://4272098.fs1.hubspotusercontent-na1.net/hubfs/4272098/Architecture%20Copilot%20M365%20_%20Fonctionnement%20Technique%20&%20Flux%20de%20Donn%C3%A9es%20%282026%29%201.png)

 Security

 Copilot Cowork in Microsoft 365: What CIOs Need to Know 

<https://blog.idecsi.com/copilot-cowork-microsoft-365?hsLang=en> [Lire l'article](https://blog.idecsi.com/copilot-cowork-microsoft-365?hsLang=en)

![Partages externes des utilisateurs](https://4272098.fs1.hubspotusercontent-na1.net/hubfs/4272098/Blog%20Images/BLOG-PARTAGES-EXTERNES.png)

 Microsoft 365

 Workplace

 Microsoft 365 External Sharing: Best Practices Guide 2026 

<https://blog.idecsi.com/microsoft-365-external-sharing-best-practices?hsLang=en> [Lire l'article](https://blog.idecsi.com/microsoft-365-external-sharing-best-practices?hsLang=en)

### Data protection, let's discuss your project?

 

[![Contact us](https://no-cache.hubspot.com/cta/default/4272098/bea4f372-c84f-4ec4-980c-ca663747fbfe.png)](https://cta-redirect.hubspot.com/cta/redirect/4272098/bea4f372-c84f-4ec4-980c-ca663747fbfe)

![video background](https://idecsi2a-dev-idecsi.pf27.wpserveur.net/wp-content/uploads/2022/02/video-background-idecsi-responsive-1.png)

[![Logo-Idecsi-White-Ss-ES](https://blog.idecsi.com/hubfs/LOGOS%20IDECSI/LOGOS%20OFFICIELS/Logo-Idecsi-White-Ss-ES.svg)](https://www.idecsi.com/)

 +33 1 84 79 38 30

- <https://twitter.com/IDECSI>
- <https://www.facebook.com/IDECSI-306865969441428/>
- <https://www.linkedin.com/company/idecsi/>

- [Why choose IDECSI?](https://www.idecsi.com/user-security/)
- [About us](https://www.idecsi.com/about-us/)
- [Join the team](https://www.welcometothejungle.com/fr/companies/idecsi)

- Solutions 
    - [Visibility](https://www.idecsi.com/challenge-data-visibility/)
    - [Detection](https://www.idecsi.com/challenge-threat-detection/)
    - [User engagement](https://www.idecsi.com/challenge-involve-user/)
    - [Access review](https://www.idecsi.com/challenge-rights-review/)
    - [Remediation](https://www.idecsi.com/challenge-remediation/)
    - [Sensitive data](https://www.idecsi.com/challenge-sensitive-data/)

- [Products](https://www.idecsi.com/solution/) 
    - [MyDataSecurity](https://www.idecsi.com/solution/mydatasecurity/)
    - [Advanced Monitoring](https://www.idecsi.com/solution/advanced-monitoring/)
    - [MyDataManagement](https://www.idecsi.com/solution/mydatamanagement/)

- Resources 
    - [Resources & News](https://blog.idecsi.com/resources?hsLang=en)
    - [Blog](https://blog.idecsi.com)
    - [Customer success](https://blog.idecsi.com/resources-customer?hsLang=en)
    - [Extranet](https://extranet.idecsi.com?hsLang=en)

 © IDECSI

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Mona Piquet",
    "url" : "https://blog.idecsi.com/author/mona-piquet"
  },
  "dateModified" : "2023-08-22T10:00:00.385Z",
  "datePublished" : "2023-08-22T10:00:00.000Z",
  "headline" : "How to reduce the risk of shared data in Microsoft 365",
  "image" : [ "https://blog.idecsi.com/hubfs/MicrosoftTeams-image%20(71)-1.png" ],
  "mainEntityOfPage" : {
    "@id" : "https://blog.idecsi.com/reduce-the-risk-of-shared-data-m365",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://blog.idecsi.com/hubfs/Logo-Idecsi-Black-tagline.png"
    },
    "name" : "IDECSI"
  }
}
```