Enabling External Sharing in Office 365,
SharePoint and OneDrive
London
SharePoint Saturday
01 June 2019
#spslondon @SPS_London
Chirag Patel @techChirag
Our Sponsors
Uranium
Diamond
Platinum
Chirag Patel
@techchirag
/techchirag
techchirag.comBlog
patelconsulting.co.ukwww
Office 365 & SharePoint
Consultant, Architect, Speaker
Session Overview
Getting started with External
Sharing and Collaboration
Sharing & collaboration coverage
• From OneDrive for Business, share with “Anyone."
• From OneDrive for Business, if collaboration isn't to be ongoing,
share with “Specific people.”
• For ongoing collaboration, use a new or existing Team or team site
and add members (including external members).
• Use a new or existing Communications site.
• Grant “everyone except external guests” permissions to a site,
folder, or file in your team shared library or OneDrive for Business.
• Share a file in OneDrive for Business (both for internal and external
sharing).
• Share a team/project file from a team site.
• Use a new or existing Team or team site and add members
(including external members).
• Save all team files into Teams document library or team site
• Share links to specific files from a team site.
• For ongoing collaboration, use a new or existing Team or team site
and add members (including external members), OR
• For specific content, grant access to a site or folder from your team
site shared library.
Share with no restrictions
Share externally
Share broadly with company
Share with my team + others
Share with my team
Share one-off file
End-user sharing experience
ANYONE
Easiest way to share files with anyone on the planet
Recipient has access if they have the link
Recipients decides who else gets access
PEOPLE in my COMPANY
Easiest way to share files within the company
Recipient has access if they have the link AND are in the company
Recipient decides who else in my company has access
PEOPLE with EXISTING ACCESS
Direct pointer, does not add permissions
Recipients who already have access via membership, or explicit
permission have access
Recipient cannot decide who else to share to
SPECIFIC PEOPLE
Sharer decides which specific people inside and outside have access
Only those people have access and prove their identity
Think about putting policies in place
Policy Examples
System will support external collaboration
Users cannot share content from OneDrive for Business Externally
Users can share content from SharePoint
External sharing should be disabled on sites by default
IT will restrict 3rd party / domains
Only users who have completed training are allowed to share content externally
External users are required to sign in
IT can enable / disable external sharing
Require external users to re-prove account ownership every 7 days
Prevent external users from sharing content they do not own
Only site owners can invite external users
External Sites should have naming convention
External access sites to be identifiable in sites list
IT can remove 3rd party access
Thinking about people and processes
External access
process with
roles and
responsibilities
Training -
including
compliance
requirements
Information
security policy
Information
classification
policy
Instructions for
3rd Parties –
Setup, access,
policies
Managing
external access
and removing
access
Sharing v Links v
Office 365
Groups User
Managing external sharing
Control WHO can share
to external users
Everyone
Only specific people
No one
Control WHICH external users
can be shared with
Anyone
Only authenticated users
Only authenticated users except
specific domains
Only authenticated users in specific domains
No one
External Sharing Governance
Support staff
Enable self service
creation
Use lifecycle
management
Detecting
valuable content
Use classification
for sites
Scan with data loss
prevention (DLP)
Protect content
Limit reach
Enforce policy
Use conditional
access
Use IRM
(Information Rights
Management)
Charge
Responsibility
Manage group /
site ownership
Review external
membership
Use IT services and
management
tooling
Accounts and Invitations
Look…I just want to share externally!
External User
(OneDrive/SharePoint)
• Someone from outside your
Office 365 tenant to whom
you have given access to one
or more sites, files, or folders.
• 3 types of users:
• Anonymous
• Authenticated without MSA
• Authenticated with MSA
Guest (Office 365 & Azure B2B)
• Also known as external user
that grants them access to all
apps within O365 group
(emails, calendar, notes, files,
and plans)
• Foundation for Microsoft
Teams, Planner, PowerBI,
Dynamics CRM and other
Enterprise Apps
OneDrive/SharePoint Online
• Separate invitation manager
to Azure AD
• Adds users to SPO directory
after users have redeemed
their invitations
• New invitations generated
every time you share
• Can pick external users from
Azure AD
Azure AD B2B
• Users are added immediately on
invitation so that they show up
everywhere
• OneDrive/SharePoint Online
invited users also show up in
Azure AD after they redeem
their invitations
• Guests in Office 365 Groups
already uses Azure AD B2B
invitation APIs for sharing
External Sharing Invitation Management
Microsoft Accounts and Anonymous users
External User Type Sharing Behaviours
Authenticated user with Microsoft account
(You’ll see them listed with #EXT# in their
username)
• Collaboration tasks aligned with site permission levels i.e. “Site
Member” – i.e. site libraries, subsites, etc.
• For files or folder: added as guests to Office 365 directory
• Can view and edit files in Office Online only
Authenticated user without
Microsoft account
• Can only share files and folders to email address with one-time
access code (email) for authentication each time they access
• Forwarded emails attempt will send one-time code to original
recipient
• Can’t share sites
Anonymous User • Free link - shareable link to file or folder and can view/edit without
log in with a username or password
• Can be forwarded and valid until you disable link or expire
• Can’t access site, nor assign licenses, nor verify identity – only IP
address.
https://docs.microsoft.com/en-us/sharepoint/external-sharing-overview (updated 06 May 2019)
SharePoint - Invitation Models
• User-initiated guest invitation model - This is the default for a new site
collection and the recommended model as it provides control to administrators
and at the same time flexibility of end users being able to collaborate with their
new business partner users without much intervention.
• Site-owner-initiated guest invitation model - If you want more control than the
default sharing model over who can invite new users to a site, you can configure
the site to only allow site owners to invite new users. This prevents ad-hoc
invitations from being sent out by site users.
• Admin-managed partner users model - In an admin-managed partner users
model, the Office 365 you pre-populate your organisation's directory with the
guest users who you'll be inviting to your site. This can be done by importing
users from other Office 365 or Azure AD.
DEMO: Tenant Level Sharing
DEMO: Azure External collaboration settings
Sharing Settings in OneDrive
and SharePoint
DEMO: SharePoint Admin - External Sharing
DEMO: SharePoint Admin – External Sharing
Who is the target audience?
Who can share externally?
What can external users do?
Limiting external sharing using domains
OneDrive Admin: External Sharing
• You give an external user
access to a Microsoft
SharePoint Online or
Microsoft OneDrive for
Business resource.
• The user accepts the invitation
but is signed in by using
another Microsoft account at
the time.
• The user browses to the
shared resource.
• User receives one of the
following error messages:
• Access Denied
• Let us know why you need
access to this site.
• User is not found in the
directory
• You need permission to access
this site.
Issues accessing files/folders, etc.
https://support.microsoft.com/en-gb/help/3026478/error-message-when-an-external-user-accepts-a-sharepoint-online-invita
Authorise guest access (Microsoft Teams)
• Azure Active Directory:
Controls the guest experience at
the directory, tenant, and
application level.
• Microsoft Teams: Controls
Microsoft Teams only.
• Office 365 Groups: Controls the
guest experience in Office 365
Groups and Microsoft Teams.
• SharePoint Online and
OneDrive for Business: Controls
the guest experience in
SharePoint Online, OneDrive for
Business, Office 365 Groups, and
Microsoft Teams.
https://docs.microsoft.com/en-us/microsoftteams/teams-dependencies
Getting Visibility to External
Sharing
Using Auditing
Awareness of activity
and anomalies
Audit log search
Rule based alerts
DLP Policy Matches
Tuning DLP
policies and
content
patterns
New SharePoint Admin Center
Dashboards
show Files
shared
externally
Sharing notifications
Be notified when your
content is shared
Managing access to shared content
Site Usage
Awareness when
content is externally
shared
Who is accessing my content
Give awareness when their content is accessed in OneDrive
Knowing why I am blocked
Policy Tips
Provide feedback to admin
Override the policy
Additional External Sharing
Considerations
Apps & Services and add-ins:
Office 365 Groups
Apps & Services and add-ins:
Calendar
Apps & Services and add-ins:
Integrated Apps
read their user profile details,
edit or delete their files (onedrive folder)
read items contained in site collections,
send email as that user
Apps & Services and add-ins:
Forms
Apps & Services and add-ins:
Sway
Microsoft Teams & Skype4B
Admin
Microsoft Teams & Skype4B
Admin
Power BI Admin
Sharing Dashboard
Secure Access
Secure Access: Keep it simple for everyone?
Device
Location
User
App
Tenant
Site
File
Conditional Access Different Scopes
Access and Sharing Policies
Limited browser-only access on
unmanaged devices
Prevents leakage of data on unmanaged devices
Allows users to be productive on any device
Scopes:
Tenant and site
Specific users
Controls:
Edit vs. View
Download non-previewable files
What’s new for users?
NEW! Smart people picker
NEW! Link open receipts
 Coming this year
NEW! Password-protected links
• Coming this year
NEW! Block downloads
• Keep your documents in the
cloud
• Avoid out-of-date copies
• Maintain access control
• Available for view-only links
SharePint
 Duke of Sussex
 23 Baylis Road
 London
 SE1 7AY
SharePint

More Related Content

PPTX
Power Saturday Paris 2019 - Enabling External Sharing in Office 365, SharePo...
PPTX
When SharePoint met Microsoft Teams - Oktoberfest 2019 #TeamsFest
PPTX
TeamsFest 2020 - Deep Dive Microsoft Teams integration with SharePoint
PPTX
How to implement SharePoint in your organization
PDF
SharePoint as an Intranet Portal for Business
PPTX
Administrators guide to managing Microsoft 365, SharePoint, Microsoft Teams a...
PPTX
Training – Introduction to SharePoint Online for Collaboration and Document M...
PPTX
SharePoint Benefits
Power Saturday Paris 2019 - Enabling External Sharing in Office 365, SharePo...
When SharePoint met Microsoft Teams - Oktoberfest 2019 #TeamsFest
TeamsFest 2020 - Deep Dive Microsoft Teams integration with SharePoint
How to implement SharePoint in your organization
SharePoint as an Intranet Portal for Business
Administrators guide to managing Microsoft 365, SharePoint, Microsoft Teams a...
Training – Introduction to SharePoint Online for Collaboration and Document M...
SharePoint Benefits

What's hot (20)

PPTX
10 SharePoint 2013 OOTB Solutions Every Power User Should Know
PPTX
Understanding Security and Compliance in Microsoft Teams - M365 Saturday Bang...
PPTX
Supporting third-party access and sharing in Microsoft Teams - Teams Day Onli...
PPTX
Guiding a Successful SharePoint Implementation
PPTX
10 Best SharePoint Features You’ve Never Used (But Should)
PPTX
Introduction to Intranet Planning
PPTX
SPSHEL18 - Microsoft Teams Deep Dive
PPTX
You got Microsoft Teams! Now let's build modern intranet on SharePoint - Team...
PPTX
Establishing a Collaboration Roadmap
PPTX
Share Point online
PPTX
A glance at share point 2013 social features
PDF
Introduction to Microsoft Teams
PPTX
A Business Users Guide to Getting the Most Out of SharePoint 2013
PPTX
Planeación de Intranet con SharePoint
PDF
Webinar: Deploy Microsoft Teams and stay in control
PPTX
SharePoint Online - Friend or Foe
PPTX
SharePoint Saturday Stockholm 2015 - SharePoint Online Friend or Foe
PDF
Introduction to SharePoint Information Architecture
PPTX
Microsoft Ignite Recap: Microsoft Teams & Yammer with Vlad & Drew
PPTX
Another attempt to demystify SharePoint Governance - SP Saturday Boston
10 SharePoint 2013 OOTB Solutions Every Power User Should Know
Understanding Security and Compliance in Microsoft Teams - M365 Saturday Bang...
Supporting third-party access and sharing in Microsoft Teams - Teams Day Onli...
Guiding a Successful SharePoint Implementation
10 Best SharePoint Features You’ve Never Used (But Should)
Introduction to Intranet Planning
SPSHEL18 - Microsoft Teams Deep Dive
You got Microsoft Teams! Now let's build modern intranet on SharePoint - Team...
Establishing a Collaboration Roadmap
Share Point online
A glance at share point 2013 social features
Introduction to Microsoft Teams
A Business Users Guide to Getting the Most Out of SharePoint 2013
Planeación de Intranet con SharePoint
Webinar: Deploy Microsoft Teams and stay in control
SharePoint Online - Friend or Foe
SharePoint Saturday Stockholm 2015 - SharePoint Online Friend or Foe
Introduction to SharePoint Information Architecture
Microsoft Ignite Recap: Microsoft Teams & Yammer with Vlad & Drew
Another attempt to demystify SharePoint Governance - SP Saturday Boston
Ad

Similar to SPS London 2019 Enabling External Sharing in Office 365, SharePoint and OneDrive (20)

PPTX
Everything you ever wanted to know about external sharing in Microsoft 365 - ...
PDF
Power Saturday 2019 F3 - Enabling external sharing in Office365 SharePoint an...
PPTX
Everything you need to know about external sharing in OneDrive, SharePoint, a...
PPTX
Deep Dive on Office 365 - External Sharing
PPTX
Working with External Partners in Office 365
PPTX
Everything you need to know about sharing files in SharePoint & OneDrive - SP...
PPTX
Everything you need to know about sharing files in SharePoint and OneDrive
PPTX
Making a real world sharing strategy for SharePoint, OneDrive & Teams
PPTX
SPS-NYC 2017: Managing external users in Office 365
PDF
O365Engage17 - Administer external users
PPTX
Paul Stork Collab365 SharePoint Summit slidedeck Going External with SharePoi...
PPTX
Enabling Sharing & Collaboration in OneDrive & SharePoint
PDF
SPUnite17 External Sharing in SharePoint Online
PPTX
SPUnite17 - External Sharing in SharePoint Online
PPTX
Options for Building a Modern Extranet
PDF
Office 365 External Collaboration - SharePoint Saturday Twin Cities Nov 2019
PDF
SharePoint External Sharing
PPTX
How Many Ways Can I Enable External Sharing for my Users?
PPTX
Sp expo one_drive_teams_sharepoint
PPTX
Sharing Nicely with Others - External Sharing in SharePoint Online
Everything you ever wanted to know about external sharing in Microsoft 365 - ...
Power Saturday 2019 F3 - Enabling external sharing in Office365 SharePoint an...
Everything you need to know about external sharing in OneDrive, SharePoint, a...
Deep Dive on Office 365 - External Sharing
Working with External Partners in Office 365
Everything you need to know about sharing files in SharePoint & OneDrive - SP...
Everything you need to know about sharing files in SharePoint and OneDrive
Making a real world sharing strategy for SharePoint, OneDrive & Teams
SPS-NYC 2017: Managing external users in Office 365
O365Engage17 - Administer external users
Paul Stork Collab365 SharePoint Summit slidedeck Going External with SharePoi...
Enabling Sharing & Collaboration in OneDrive & SharePoint
SPUnite17 External Sharing in SharePoint Online
SPUnite17 - External Sharing in SharePoint Online
Options for Building a Modern Extranet
Office 365 External Collaboration - SharePoint Saturday Twin Cities Nov 2019
SharePoint External Sharing
How Many Ways Can I Enable External Sharing for my Users?
Sp expo one_drive_teams_sharepoint
Sharing Nicely with Others - External Sharing in SharePoint Online
Ad

More from Chirag Patel (20)

PPTX
Data Lifecycle Management with Microsoft Purview in Microsoft Teams - Collabd...
PPTX
Deep Dive Microsoft Viva Insights - Collabdays Bletchley Park 2023
PPTX
Understanding Security and Compliance in Microsoft Teams M365 North 2023
PPTX
Microsoft Viva Essential in 45 minutes - Collabdays Bletchley 2022
PPTX
Building immersive and mixed reality experiences in SharePoint - Metaverse One
PPTX
Understanding Security and Compliance in Microsoft Teams - Scottish Summit 2022
PPTX
Working with templates in Microsoft 365 aMS Berlin 2022
PPTX
Deep Dive Microsoft Teams and Yammer integration - Teams Nation 2022
PPTX
Let's get rich and connected with Microsoft Viva Connections - Teams Nation M...
PPTX
Working with Security and Compliance in Microsoft Teams - Microsoft 365 Virtu...
PPTX
Understanding Security and Compliance in Microsoft Teams - M365 Saturday Pune...
PPTX
Administrators guide to managing Microsoft 365 and collaboration workloads - ...
PPTX
Deep dive on Microsoft Teams integration with SharePoint - M365 Saturday Ahme...
PPTX
Journey to the Centre of Microsoft 365 Groups - M365 Chicago 2020
PPTX
Building a Microsoft Teams team chat space to manage your project - M365 Chic...
PPTX
Navigating your way to different admin centres in Microsoft 365 - M365 Saturd...
PPTX
Building a Microsoft Teams Team Chat Space To Manage Your Project - Teams Com...
PPTX
Designing and Implementing Microsoft 365 Adoption Centre - M365 Philly Virtua...
PPTX
Microsoft 365 integration experiences with SharePoint, Microsoft Teams, Strea...
PPTX
Designing and Implementing Microsoft 365 Adoption Centre - Microsoft 365 Virt...
Data Lifecycle Management with Microsoft Purview in Microsoft Teams - Collabd...
Deep Dive Microsoft Viva Insights - Collabdays Bletchley Park 2023
Understanding Security and Compliance in Microsoft Teams M365 North 2023
Microsoft Viva Essential in 45 minutes - Collabdays Bletchley 2022
Building immersive and mixed reality experiences in SharePoint - Metaverse One
Understanding Security and Compliance in Microsoft Teams - Scottish Summit 2022
Working with templates in Microsoft 365 aMS Berlin 2022
Deep Dive Microsoft Teams and Yammer integration - Teams Nation 2022
Let's get rich and connected with Microsoft Viva Connections - Teams Nation M...
Working with Security and Compliance in Microsoft Teams - Microsoft 365 Virtu...
Understanding Security and Compliance in Microsoft Teams - M365 Saturday Pune...
Administrators guide to managing Microsoft 365 and collaboration workloads - ...
Deep dive on Microsoft Teams integration with SharePoint - M365 Saturday Ahme...
Journey to the Centre of Microsoft 365 Groups - M365 Chicago 2020
Building a Microsoft Teams team chat space to manage your project - M365 Chic...
Navigating your way to different admin centres in Microsoft 365 - M365 Saturd...
Building a Microsoft Teams Team Chat Space To Manage Your Project - Teams Com...
Designing and Implementing Microsoft 365 Adoption Centre - M365 Philly Virtua...
Microsoft 365 integration experiences with SharePoint, Microsoft Teams, Strea...
Designing and Implementing Microsoft 365 Adoption Centre - Microsoft 365 Virt...

Recently uploaded (20)

PDF
5-Ways-AI-is-Revolutionizing-Telecom-Quality-Engineering.pdf
PDF
IT-ITes Industry bjjbnkmkhkhknbmhkhmjhjkhj
PDF
NewMind AI Weekly Chronicles – August ’25 Week IV
PDF
Co-training pseudo-labeling for text classification with support vector machi...
PDF
Altius execution marketplace concept.pdf
PDF
giants, standing on the shoulders of - by Daniel Stenberg
PPTX
Build automations faster and more reliably with UiPath ScreenPlay
PDF
Aug23rd - Mulesoft Community Workshop - Hyd, India.pdf
PDF
Electrocardiogram sequences data analytics and classification using unsupervi...
PDF
Ensemble model-based arrhythmia classification with local interpretable model...
PDF
SaaS reusability assessment using machine learning techniques
PPTX
Module 1 Introduction to Web Programming .pptx
PPTX
Internet of Everything -Basic concepts details
PDF
The-2025-Engineering-Revolution-AI-Quality-and-DevOps-Convergence.pdf
PDF
zbrain.ai-Scope Key Metrics Configuration and Best Practices.pdf
PDF
Introduction to MCP and A2A Protocols: Enabling Agent Communication
PDF
CXOs-Are-you-still-doing-manual-DevOps-in-the-age-of-AI.pdf
PDF
Examining Bias in AI Generated News Content.pdf
PDF
“The Future of Visual AI: Efficient Multimodal Intelligence,” a Keynote Prese...
PDF
Auditboard EB SOX Playbook 2023 edition.
5-Ways-AI-is-Revolutionizing-Telecom-Quality-Engineering.pdf
IT-ITes Industry bjjbnkmkhkhknbmhkhmjhjkhj
NewMind AI Weekly Chronicles – August ’25 Week IV
Co-training pseudo-labeling for text classification with support vector machi...
Altius execution marketplace concept.pdf
giants, standing on the shoulders of - by Daniel Stenberg
Build automations faster and more reliably with UiPath ScreenPlay
Aug23rd - Mulesoft Community Workshop - Hyd, India.pdf
Electrocardiogram sequences data analytics and classification using unsupervi...
Ensemble model-based arrhythmia classification with local interpretable model...
SaaS reusability assessment using machine learning techniques
Module 1 Introduction to Web Programming .pptx
Internet of Everything -Basic concepts details
The-2025-Engineering-Revolution-AI-Quality-and-DevOps-Convergence.pdf
zbrain.ai-Scope Key Metrics Configuration and Best Practices.pdf
Introduction to MCP and A2A Protocols: Enabling Agent Communication
CXOs-Are-you-still-doing-manual-DevOps-in-the-age-of-AI.pdf
Examining Bias in AI Generated News Content.pdf
“The Future of Visual AI: Efficient Multimodal Intelligence,” a Keynote Prese...
Auditboard EB SOX Playbook 2023 edition.

SPS London 2019 Enabling External Sharing in Office 365, SharePoint and OneDrive

  • 1. Enabling External Sharing in Office 365, SharePoint and OneDrive London SharePoint Saturday 01 June 2019 #spslondon @SPS_London Chirag Patel @techChirag
  • 5. Getting started with External Sharing and Collaboration
  • 6. Sharing & collaboration coverage • From OneDrive for Business, share with “Anyone." • From OneDrive for Business, if collaboration isn't to be ongoing, share with “Specific people.” • For ongoing collaboration, use a new or existing Team or team site and add members (including external members). • Use a new or existing Communications site. • Grant “everyone except external guests” permissions to a site, folder, or file in your team shared library or OneDrive for Business. • Share a file in OneDrive for Business (both for internal and external sharing). • Share a team/project file from a team site. • Use a new or existing Team or team site and add members (including external members). • Save all team files into Teams document library or team site • Share links to specific files from a team site. • For ongoing collaboration, use a new or existing Team or team site and add members (including external members), OR • For specific content, grant access to a site or folder from your team site shared library. Share with no restrictions Share externally Share broadly with company Share with my team + others Share with my team Share one-off file
  • 7. End-user sharing experience ANYONE Easiest way to share files with anyone on the planet Recipient has access if they have the link Recipients decides who else gets access PEOPLE in my COMPANY Easiest way to share files within the company Recipient has access if they have the link AND are in the company Recipient decides who else in my company has access PEOPLE with EXISTING ACCESS Direct pointer, does not add permissions Recipients who already have access via membership, or explicit permission have access Recipient cannot decide who else to share to SPECIFIC PEOPLE Sharer decides which specific people inside and outside have access Only those people have access and prove their identity
  • 8. Think about putting policies in place Policy Examples System will support external collaboration Users cannot share content from OneDrive for Business Externally Users can share content from SharePoint External sharing should be disabled on sites by default IT will restrict 3rd party / domains Only users who have completed training are allowed to share content externally External users are required to sign in IT can enable / disable external sharing Require external users to re-prove account ownership every 7 days Prevent external users from sharing content they do not own Only site owners can invite external users External Sites should have naming convention External access sites to be identifiable in sites list IT can remove 3rd party access
  • 9. Thinking about people and processes External access process with roles and responsibilities Training - including compliance requirements Information security policy Information classification policy Instructions for 3rd Parties – Setup, access, policies Managing external access and removing access Sharing v Links v Office 365 Groups User
  • 10. Managing external sharing Control WHO can share to external users Everyone Only specific people No one Control WHICH external users can be shared with Anyone Only authenticated users Only authenticated users except specific domains Only authenticated users in specific domains No one
  • 11. External Sharing Governance Support staff Enable self service creation Use lifecycle management Detecting valuable content Use classification for sites Scan with data loss prevention (DLP) Protect content Limit reach Enforce policy Use conditional access Use IRM (Information Rights Management) Charge Responsibility Manage group / site ownership Review external membership Use IT services and management tooling
  • 13. Look…I just want to share externally! External User (OneDrive/SharePoint) • Someone from outside your Office 365 tenant to whom you have given access to one or more sites, files, or folders. • 3 types of users: • Anonymous • Authenticated without MSA • Authenticated with MSA Guest (Office 365 & Azure B2B) • Also known as external user that grants them access to all apps within O365 group (emails, calendar, notes, files, and plans) • Foundation for Microsoft Teams, Planner, PowerBI, Dynamics CRM and other Enterprise Apps
  • 14. OneDrive/SharePoint Online • Separate invitation manager to Azure AD • Adds users to SPO directory after users have redeemed their invitations • New invitations generated every time you share • Can pick external users from Azure AD Azure AD B2B • Users are added immediately on invitation so that they show up everywhere • OneDrive/SharePoint Online invited users also show up in Azure AD after they redeem their invitations • Guests in Office 365 Groups already uses Azure AD B2B invitation APIs for sharing External Sharing Invitation Management
  • 15. Microsoft Accounts and Anonymous users External User Type Sharing Behaviours Authenticated user with Microsoft account (You’ll see them listed with #EXT# in their username) • Collaboration tasks aligned with site permission levels i.e. “Site Member” – i.e. site libraries, subsites, etc. • For files or folder: added as guests to Office 365 directory • Can view and edit files in Office Online only Authenticated user without Microsoft account • Can only share files and folders to email address with one-time access code (email) for authentication each time they access • Forwarded emails attempt will send one-time code to original recipient • Can’t share sites Anonymous User • Free link - shareable link to file or folder and can view/edit without log in with a username or password • Can be forwarded and valid until you disable link or expire • Can’t access site, nor assign licenses, nor verify identity – only IP address. https://docs.microsoft.com/en-us/sharepoint/external-sharing-overview (updated 06 May 2019)
  • 16. SharePoint - Invitation Models • User-initiated guest invitation model - This is the default for a new site collection and the recommended model as it provides control to administrators and at the same time flexibility of end users being able to collaborate with their new business partner users without much intervention. • Site-owner-initiated guest invitation model - If you want more control than the default sharing model over who can invite new users to a site, you can configure the site to only allow site owners to invite new users. This prevents ad-hoc invitations from being sent out by site users. • Admin-managed partner users model - In an admin-managed partner users model, the Office 365 you pre-populate your organisation's directory with the guest users who you'll be inviting to your site. This can be done by importing users from other Office 365 or Azure AD.
  • 18. DEMO: Azure External collaboration settings
  • 19. Sharing Settings in OneDrive and SharePoint
  • 20. DEMO: SharePoint Admin - External Sharing
  • 21. DEMO: SharePoint Admin – External Sharing
  • 22. Who is the target audience?
  • 23. Who can share externally?
  • 24. What can external users do?
  • 25. Limiting external sharing using domains
  • 27. • You give an external user access to a Microsoft SharePoint Online or Microsoft OneDrive for Business resource. • The user accepts the invitation but is signed in by using another Microsoft account at the time. • The user browses to the shared resource. • User receives one of the following error messages: • Access Denied • Let us know why you need access to this site. • User is not found in the directory • You need permission to access this site. Issues accessing files/folders, etc. https://support.microsoft.com/en-gb/help/3026478/error-message-when-an-external-user-accepts-a-sharepoint-online-invita
  • 28. Authorise guest access (Microsoft Teams) • Azure Active Directory: Controls the guest experience at the directory, tenant, and application level. • Microsoft Teams: Controls Microsoft Teams only. • Office 365 Groups: Controls the guest experience in Office 365 Groups and Microsoft Teams. • SharePoint Online and OneDrive for Business: Controls the guest experience in SharePoint Online, OneDrive for Business, Office 365 Groups, and Microsoft Teams. https://docs.microsoft.com/en-us/microsoftteams/teams-dependencies
  • 29. Getting Visibility to External Sharing
  • 30. Using Auditing Awareness of activity and anomalies Audit log search Rule based alerts
  • 31. DLP Policy Matches Tuning DLP policies and content patterns
  • 32. New SharePoint Admin Center Dashboards show Files shared externally
  • 33. Sharing notifications Be notified when your content is shared
  • 34. Managing access to shared content
  • 35. Site Usage Awareness when content is externally shared
  • 36. Who is accessing my content Give awareness when their content is accessed in OneDrive
  • 37. Knowing why I am blocked Policy Tips Provide feedback to admin Override the policy
  • 39. Apps & Services and add-ins: Office 365 Groups
  • 40. Apps & Services and add-ins: Calendar
  • 41. Apps & Services and add-ins: Integrated Apps read their user profile details, edit or delete their files (onedrive folder) read items contained in site collections, send email as that user
  • 42. Apps & Services and add-ins: Forms
  • 43. Apps & Services and add-ins: Sway
  • 44. Microsoft Teams & Skype4B Admin
  • 45. Microsoft Teams & Skype4B Admin
  • 49. Secure Access: Keep it simple for everyone? Device Location User App Tenant Site File Conditional Access Different Scopes Access and Sharing Policies
  • 50. Limited browser-only access on unmanaged devices Prevents leakage of data on unmanaged devices Allows users to be productive on any device Scopes: Tenant and site Specific users Controls: Edit vs. View Download non-previewable files
  • 53. NEW! Link open receipts  Coming this year
  • 55. NEW! Block downloads • Keep your documents in the cloud • Avoid out-of-date copies • Maintain access control • Available for view-only links
  • 56. SharePint  Duke of Sussex  23 Baylis Road  London  SE1 7AY

Editor's Notes

  • #2: By default, Office 365 is turned for external sharing. However, without any planning and considerations some organisations turn this off and plan for later, but businesses can't wait after all collaboration is internal and external! There are plethora of settings and services to allow external sharing to your customers, partners and suppliers. With recent improvements in external sharing, this demo based session will cover the ins and outs for successful implementation of external sharing in Office 365.
  • #7: 6
  • #14: MSA = Microsoft Account (personal or work/school (Office 365))
  • #15: All external sharing (except OneDrive/SharePoint Online), including guests in Office 365 Groups, already uses the Azure AD B2B collaboration invitation APIs for sharing.
  • #16: - Can assign licenses to external users for more functionality. - Recipients who provide a verification code: If the recipient has a work or school account, they only need to enter the code the first time. Then they will be added as a guest and can sign in with their organization's user name and password.
  • #29: Manage Allow or Block list policy SharePoint Online policies independent to SharePoint – can migrate these to O365 Groups policy.