---
name: External Sharing Deep Audit
description: Point-in-time inventory of every externally shared item across SharePoint, OneDrive and Teams, grouped by recipient domain and ranked by recipient risk.
lastReviewed: 2026-06-02
---

# External Sharing Deep Audit

> **TL;DR:** This skill takes a point-in-time inventory of every externally shared item across SharePoint Online, OneDrive, and Teams, attributes each share to a recipient domain, and ranks it by recipient risk so data stewards can decide what to revoke.

## What does the external sharing deep audit do?

The audit inventories every externally shared item across SharePoint Online, OneDrive, and Teams, reading sharing links and direct permissions through Microsoft Graph. It attributes each share to a recipient domain, captures share type, expiry, and last access date, and ranks results by external recipient risk so the data steward can revoke stale or unsafe shares. External exposure is one of the biggest blind spots for Microsoft 365 Copilot readiness: content reachable by external principals can widen the effective grounding surface, so closing stale and unapproved shares keeps Copilot answers least-privilege and trustworthy. Cross-reference findings with Microsoft Purview sensitivity labels to prioritise revocation of classified content.

## When should you run this skill?

- "Audit external sharing across the tenant"
- "Find externally shared SharePoint content"
- "List which external recipients and domains can reach our content"
- "Build an external recipient register for our review board"

## How this skill works, step by step

1. Enumerate all sharing links and direct permissions where the principal is external.
2. For each shared item capture: item path, share type (Anyone, Specific people, Existing access), recipient identity, recipient domain, expiry, last access date.
3. Group recipients by domain.
4. Cross-reference domains against the approved external partner list.
5. Record last access date per share (no access in last 90 days counts as stale for risk scoring only; link-level stale analysis and trends belong to the Sharing Links Activity Audit).
6. Flag Anyone links regardless of recency.
7. Compute risk: High (Anyone or unapproved domain), Medium (approved domain, stale), Low (approved domain, recent).
8. Produce the table below.

## Output format

| Item | Share Type | Recipient Domain | Recipient | Expiry | Last Access | Risk | Action |
| --- | --- | --- | --- | --- | --- | --- | --- |

Followed by a summary:

- Externally shared items: N
- Distinct external recipients: N
- Domains outside the approved list: N
- Anyone links: N
- Recommended revocations: N

## Scope and safety

This skill is read-only by default and takes no destructive actions. It does NOT:

- Revoke shares or modify links (read-only)
- Email external recipients
- Inspect file contents

## Licensing and permissions

### Licences and add-ons

| Capability used | Minimum licence |
| --- | --- |
| Read sharing links and external permissions across SharePoint, OneDrive, and Teams via Microsoft Graph | Microsoft 365 E3 or E5 |
| Data Access Governance reports for oversharing and Anyone-link insights | SharePoint Advanced Management |

### Least-privilege roles

- Global Reader (read-only tenant-wide visibility)
- SharePoint Administrator (read) where Data Access Governance reports are reviewed

### Microsoft Graph permissions (read-only)

- `Sites.Read.All` — read site collections and their sharing permissions
- `Files.Read.All` — read drive items and sharing links across SharePoint and OneDrive
- `Group.Read.All` — resolve Teams and Microsoft 365 group membership behind shares
- `Directory.Read.All` — resolve recipient identities and external (guest) principals

## When should I run this instead of the Sharing Links Activity Audit?

Run this skill when you need a register of who outside the organisation can reach what, by item and recipient domain. Run the [Sharing Links Activity Audit](/sharepoint/sharing-links-activity-audit) when you need to see how sharing links of every type, including internal ones, are created and used over time, and which links have gone stale. If you need both, run this inventory first, then the activity audit to see which of those shares are actually in use.

## Related skills

- [Sharing Links Activity Audit](/sharepoint/sharing-links-activity-audit): run after to analyse sharing-link activity, trends and stale links across all link types.
- [SharePoint Oversharing Audit](/sharepoint/sharepoint-oversharing-audit): run first to flag external or Anyone access that breaches policy.
- [Teams External Access Audit](/sharepoint/teams-external-access-audit): run after to review Teams external access, guest access and sharing settings.
- [Stale and Guest Account Audit](/purview/stale-and-guest-account-audit): run after to find guest accounts with no sponsor in Microsoft Entra.
- [SharePoint Copilot Readiness Guide](/sharepoint/copilot-readiness-guide): the pillar guide that maps each oversharing step to a read-only skill.

## Sources and compliance

- Pair with Broken Permission Inheritance Audit for a complete external-exposure picture
- Run monthly as part of the sharing governance cadence
- [External sharing overview for SharePoint and OneDrive](https://learn.microsoft.com/en-us/sharepoint/external-sharing-overview)
