In this guide
Appearance
Appearance
By Scot, 10+ years in IT support and helpdesk ·How these guides are checked
In Microsoft 365, files are shared via OneDrive or SharePoint links. Choose People you specify for sensitive files or People in your organization for internal sharing. Always set the minimum permission level needed — use Can view unless editing is required.
Checked against Microsoft 365 Roadmap, Microsoft Learn - end of support and retirement and between 5 Aug 2026 and 12 Sep 2026. Nothing published in that period has been linked to this guide.
Sharing files in Microsoft 365 takes two clicks — but understanding how sharing works, what each link type does, and who can see what is critical to avoiding accidental exposure or access problems. This article explains the four sharing link types, permission levels, how to review and revoke access, inherited permissions, and common pitfalls.
In this guide
When you share a file or folder in OneDrive or SharePoint, you choose a link type. Each type controls who can access the file when they click the link. This article explains what each type does; for the click-by-click steps of creating the link itself, see How to Share Files and Folders via OneDrive.
| Link Type | Who Can Access | Sign-In Required? | Expiration Options | Security Level |
|---|---|---|---|---|
| Anyone | Anyone with the link — inside or outside your organization, no sign-in needed | No | Yes — expiration date and optional password | ⚠️ Lowest — link can be forwarded to anyone |
| People in your organization | Anyone in your company who has the link | Yes — must sign in with a work account | Yes — expiration date | 🔶 Moderate — limits to internal users but anyone internal can access |
| People with existing access | Only people who already have access to the file | Yes | No | ✅ Highest — does not grant new access, but generates a convenient link |
| Specific people | Only the exact people you name | Yes — must sign in with the specified account | Yes — expiration date | ✅ High — most precise control |
Key takeaway: Use Specific people for most sharing. Use People in your organization when the file should be broadly accessible internally. Use Anyone only when absolutely necessary (and if your organization allows it). Use People with existing access when you need to send a link to someone who already has permission.
After choosing a link type, you set what the recipient can do with the file.
| Permission | What They Can Do | What They Cannot Do |
|---|---|---|
| Can view | Open and read the file; download a copy (unless blocked) | Edit, delete, move, or rename the file |
| Can edit | Open, read, edit, delete, move, rename, and re-share the file | Change site-level permissions (SharePoint) |
| Can't download (optional) | View the file in the browser only | Download, print, or save a local copy |
Important: Can edit permission allows the recipient to delete the file. If you only want someone to contribute content, consider using Can edit on a copy or a specific folder rather than the original file.
Review files you have shared with others.
From OneDrive on the Web:
From File Explorer (Windows):
Remove access or change permission levels for files you own.
Your organization controls whether you can share files with people outside the company.
What your IT department typically controls:
If a sharing option is greyed out, your organization's policy does not allow it. Ask IT whether an exception is possible for that one file, and include the file name, who needs access, and the deadline the work depends on.
In SharePoint, files can inherit permissions from the library or site they belong to — meaning someone can access a file you never explicitly shared with them.
How it works:
Why someone can see a file you did not share with them:
How to check inherited permissions:
| Pitfall | Why It Is Risky | How to Avoid It |
|---|---|---|
| Sharing a folder shares everything inside it | Every file added to that folder in the future is automatically shared too | Share individual files when possible. If sharing a folder, only put files in it that need to be shared with that audience. |
| "Anyone" links can be forwarded | The recipient can send the link to anyone — there is no way to control who uses it | Use Specific people links when sharing sensitive content. Set an expiration date on Anyone links. |
| Edit permissions let people delete | A user with Can edit permission can delete the file (not only edit it) | Use Can view for read-only needs. For collaborative editing, use version history to recover deleted files. |
| Forgetting to revoke access | Former collaborators, vendors, or project members retain access indefinitely unless removed | Periodically review Shared by you in OneDrive. Remove access for completed projects. |
| Sharing from the wrong location | Sharing a personal OneDrive file when the file should be in SharePoint | Move the file to SharePoint first if the team needs ongoing access — then share from there. |
| Scenario | Recommended Link Type | Permission Level |
|---|---|---|
| Sharing a document with a specific colleague for review | Specific people | Can view |
| Collaborating on a document with a project team | Specific people | Can edit |
| Posting a reference document for the whole company | People in your organization | Can view |
| Sending a file to a client or external vendor | Specific people (external sharing must be enabled) | Can view (or Can edit if needed) |
| Sharing a link in a Teams channel where everyone already has access | People with existing access | N/A (inherits existing permissions) |
| Public-facing content (e.g., a downloadable form) | Anyone (if allowed by policy) | Can view |
DANGER
The most common sharing problem is "Access Denied" — and the most common cause is using the wrong link type. If a recipient reports Access Denied, check whether you used a Specific people link and entered their correct email address, or whether the link type requires sign-in and they are not signed in.
| Symptom / Error | Potential Cause | Solution |
|---|---|---|
| "Access Denied" when clicking a sharing link | Wrong link type or recipient not signed in | Verify the link type. If the link is for Specific people, ensure the recipient's email matches. If the link requires sign-in, ask the recipient to sign in with their work account. |
| "Request Access" page appears instead of the file | Recipient is not in the sharing scope | Approve the request, or re-share the file directly with the person using a Specific people link. |
| Sharing link expired | Expiration date passed | Generate a new sharing link from Manage access with an updated expiration date. |
| External recipient cannot access the file | External sharing disabled by IT policy | Contact IT to verify your organization's external sharing settings. Use alternative methods (email attachment) if external sharing is not allowed. |
| Recipient can view but not edit | Permission set to Can view | Open Manage access, change the recipient's permission to Can edit. |
| "You can't share this item" error | You do not own the file or lack resharing permission | Contact the file owner to share on your behalf, or ask them to grant you sharing rights. |
| File visible to people you did not share with | Inherited permissions from the SharePoint site | This is expected in SharePoint libraries. To restrict, ask a Site Owner to set unique permissions on the file or folder. See Section 6 above. |
IT Tip Tuesday
Get a short, actionable IT tip in your inbox every week.
Nothing loads from beehiiv until you click. Once it does, the form sets beehiiv's own cookies and loads beehiiv's own analytics.