How to Review and Correct Overshared Files in SharePoint and Teams

Summary

This guide explains how to review and correct files that have been shared too broadly - such as those accessible to everyone in our organization or external users.

Body

Overview

This guide explains how to review and correct files that have been shared too broadly - such as those accessible to everyone in our organization or external users.

These files may contain sensitive or regulated data (like Social Security numbers, financial data, or health information).  While sharing is often unintentional, it's important to correct it to keep our information secure and compliant.

Before You Start

Before reviewing shared files, we recommend viewing our quick training presentation to understand how sharing works in SharePoint and Teams.

These short presentations provide an end-to-end overview of SharePoint and Teams, including:

  • What SharePoint and Teams are and how they support collaboration
  • How to classify your data appropriately
  • Accessing and navigating SharePoint and Teams
  • Creating and managing Owners, Members, and Visitors
  • How sharing works
  • Best practices for reviewing and maintaining access

What You'll Do

You will:

  1. Identify files that are shared too broadly.
  2. Review who has access.
  3. Remove or limit access where necessary.
  4. Confirm that only authorized users can access sensitive data.

Estimated Time

Sites with a small number of shared files may take 10-15 minutes.  Sites with a larger number of shared files may take up to 60 minutes.  Access must be reviewed file by file.  We know this can be time-consuming, but your review is critical to maintaining data protection.

Step 1: Open the Site or Team

  1. In the email notification you received, select the Site URL link (or copy and paste the site directly in your browser).

Step 2: Review Your Site's Externally Shared Files

  1. Click the settings (gear icon) in the top-right corner.
  2. Click Site Usage.
  3. In the section named Shared with external users click Run report.
  4. Choose a folder in an existing document library to store the report.
  5. You will receive an email notification once your report has run.
  6. You can find files with Organizational or Anonymous links by reviewing Column H of the report.  Look for files that show a SharingLink, Everyone OU, or an individual who should not have access.

Step 3: Remove Access

  1. Browse to the files with links and click the … more options button.
  2. Select Manage Access. 
  3. Review the People tab.  If an individual has been granted access via a company-shared link, Click on a person’s name to edit/remove permissions.
  4. Review the Groups tab.  Click on a Group name to update their access.
  5. Review the Links tab.  Look for links shared externally (e.g., “Anyone with the link can view/edit” or “People in University of Oklahoma with the link can edit”).  Use the delete button to remove links granting access.

Step 4: Review Site Permissions

  1. Click the settings (gear icon) in the top-right corner.
  2. Click Site Permissions.
  3. Review:
    1. Site Owners, Members, and Visitors (internal users).
    2. External Users listed under “Guest” or “Advanced permissions.”
  4. Adjust or remove permissions as needed.
  5. Click Change how members can share.

Details

Details

Article ID: 3489
Created
Mon 11/3/25 9:03 AM
Modified
Mon 9/21/26 9:40 AM
Campus
This is strictly an internal field and not end user viewable.
Norman
Oklahoma City
Tulsa