Skip to content
9 min read Recently reviewedBeginner
Quick Answer

In Microsoft 365, files are shared via OneDrive or SharePoint links. Choose People you specify for sensitive files or People in your organization for internal sharing. Always set the minimum permission level needed — use Can view unless editing is required.

Understanding File Sharing and Permissions in Microsoft 365

Applies to: Microsoft 365 (OneDrive, SharePoint, Teams)
Article Type: Informational
Last Updated: 2026-05-18

Summary

Sharing files in Microsoft 365 takes two clicks — but understanding how sharing works, what each link type does, and who can see what is critical to avoiding accidental exposure or access problems. This article explains the four sharing link types, permission levels, how to review and revoke access, inherited permissions, and common pitfalls.

Prerequisites

  • A Microsoft 365 account with OneDrive and/or SharePoint access.
  • Files must be stored in OneDrive or SharePoint to use sharing features (local files cannot be shared directly).

Instructions

When you share a file or folder in OneDrive or SharePoint, you choose a link type. Each type controls who can access the file when they click the link.

Link TypeWho Can AccessSign-In Required?Expiration OptionsSecurity Level
AnyoneAnyone with the link — inside or outside your organization, no sign-in neededNoYes — expiration date and optional password⚠️ Lowest — link can be forwarded to anyone
People in your organizationAnyone in your company who has the linkYes — must sign in with a work accountYes — expiration date🔶 Moderate — limits to internal users but anyone internal can access
People with existing accessOnly people who already have access to the fileYesNo✅ Highest — does not grant new access, but generates a convenient link
Specific peopleOnly the exact people you nameYes — must sign in with the specified accountYes — expiration date✅ High — most precise control

Key takeaway: Use Specific people for most sharing. Use People in your organization when the file should be broadly accessible internally. Use Anyone only when absolutely necessary (and if your organization allows it). Use People with existing access when you need to send a link to someone who already has permission.

2. Permission Levels — View, Edit, and More

After choosing a link type, you set what the recipient can do with the file.

PermissionWhat They Can DoWhat They Cannot Do
Can viewOpen and read the file; download a copy (unless blocked)Edit, delete, move, or rename the file
Can editOpen, read, edit, delete, move, rename, and re-share the fileChange site-level permissions (SharePoint)
Can't download (optional)View the file in the browser onlyDownload, print, or save a local copy

Important: Can edit permission allows the recipient to delete the file. If you only want someone to contribute content, consider using Can edit on a copy or a specific folder rather than the original file.

3. How to Check What You Have Shared

Review files you have shared with others.

From OneDrive on the Web:

  1. Open OneDrive in your browser (onedrive.com).
  2. Click Shared in the left navigation panel.
  3. Click Shared by you to see all files and folders you have shared.
  4. Click a file name to see who has access and what link types are active.

From File Explorer (Windows):

  1. Look for the people icon (👤) on synced files in your OneDrive folder — this indicates the file is shared.
  2. Right-click the file > Share > click the three-dot menu (⋯) > Manage access to view details.

4. How to Revoke or Change Sharing

Remove access or change permission levels for files you own.

  1. Open OneDrive in the browser or right-click the file in File Explorer.
  2. Click Manage access (or Share > Manage access).
  3. The Manage Access panel shows:
    • Links giving access — each active sharing link with its type and permissions.
    • Direct access — individual people with explicit permissions.
  4. To remove a link: Click the X or Remove link next to the link entry. Anyone using that link immediately loses access.
  5. To remove a person: Click the dropdown next to their name and select Stop sharing or Remove direct access.
  6. To change permissions: Click the dropdown next to a person's name and switch between Can edit and Can view.

5. Internal vs. External Sharing

Your organization controls whether you can share files with people outside the company.

  • Internal sharing — sharing with colleagues who have accounts in your organization. Always allowed.
  • External sharing — sharing with people outside your organization (clients, vendors, partners). May be restricted or require specific link types.
  • The "External" banner — When you receive a file shared from outside your organization, or when an external guest accesses your file, a yellow "External" banner appears at the top of the document. This is a reminder that someone outside your company can see the content.

What your IT department typically controls:

  • Whether Anyone links are allowed (many organizations disable them).
  • Whether external sharing is allowed at all, or limited to specific domains.
  • Whether external guests can re-share files they receive.

If a sharing option is greyed out, your organization's policy does not allow it. Ask IT whether an exception is possible for that one file, and include the file name, who needs access, and the deadline the work depends on.

6. Inherited Permissions (SharePoint)

In SharePoint, files can inherit permissions from the library or site they belong to — meaning someone can access a file you never explicitly shared with them.

How it works:

  • A SharePoint site has Site Members (can edit) and Site Visitors (can view).
  • Every document library in the site inherits those permissions by default.
  • Every file in the library inherits permissions from the library.
  • This means if someone is a Site Member, they can access all files in all libraries on that site — unless permissions are broken (customized) on a specific file or folder.

Why someone can see a file you did not share with them:

  • They are a member of the SharePoint site or Microsoft 365 Group that owns the library.
  • The file is in a SharePoint library with default inherited permissions.
  • A team owner added them to the Team, which automatically granted them SharePoint access.

How to check inherited permissions:

  1. Open the file in SharePoint.
  2. Click Share > Manage access.
  3. Look for entries labeled "Members of [Site Name]" or "[Group Name]" — these are inherited.
  4. To restrict access to a specific file, break inheritance by setting unique permissions (Site Owner action).

7. Common Sharing Pitfalls

PitfallWhy It Is RiskyHow to Avoid It
Sharing a folder shares everything inside itEvery file added to that folder in the future is automatically shared tooShare individual files when possible. If sharing a folder, only put files in it that need to be shared with that audience.
"Anyone" links can be forwardedThe recipient can send the link to anyone — there is no way to control who uses itUse Specific people links when sharing sensitive content. Set an expiration date on Anyone links.
Edit permissions let people deleteA user with Can edit permission can delete the file (not only edit it)Use Can view for read-only needs. For collaborative editing, use version history to recover deleted files.
Forgetting to revoke accessFormer collaborators, vendors, or project members retain access indefinitely unless removedPeriodically review Shared by you in OneDrive. Remove access for completed projects.
Sharing from the wrong locationSharing a personal OneDrive file when the file should be in SharePointMove the file to SharePoint first if the team needs ongoing access — then share from there.
ScenarioRecommended Link TypePermission Level
Sharing a document with a specific colleague for reviewSpecific peopleCan view
Collaborating on a document with a project teamSpecific peopleCan edit
Posting a reference document for the whole companyPeople in your organizationCan view
Sending a file to a client or external vendorSpecific people (external sharing must be enabled)Can view (or Can edit if needed)
Sharing a link in a Teams channel where everyone already has accessPeople with existing accessN/A (inherits existing permissions)
Public-facing content (e.g., a downloadable form)Anyone (if allowed by policy)Can view

Troubleshooting

DANGER

The most common sharing problem is "Access Denied" — and the most common cause is using the wrong link type. If a recipient reports Access Denied, check whether you used a Specific people link and entered their correct email address, or whether the link type requires sign-in and they are not signed in.

Symptom / ErrorPotential CauseSolution
"Access Denied" when clicking a sharing linkWrong link type or recipient not signed inVerify the link type. If the link is for Specific people, ensure the recipient's email matches. If the link requires sign-in, ask the recipient to sign in with their work account.
"Request Access" page appears instead of the fileRecipient is not in the sharing scopeApprove the request, or re-share the file directly with the person using a Specific people link.
Sharing link expiredExpiration date passedGenerate a new sharing link from Manage access with an updated expiration date.
External recipient cannot access the fileExternal sharing disabled by IT policyContact IT to verify your organization's external sharing settings. Use alternative methods (email attachment) if external sharing is not allowed.
Recipient can view but not editPermission set to Can viewOpen Manage access, change the recipient's permission to Can edit.
"You can't share this item" errorYou do not own the file or lack resharing permissionContact the file owner to share on your behalf, or ask them to grant you sharing rights.
File visible to people you did not share withInherited permissions from the SharePoint siteThis is expected in SharePoint libraries. To restrict, ask a Site Owner to set unique permissions on the file or folder. See Section 6 above.