---
name: Sharing Links Activity Audit
description: Analyse sharing-link creation and access activity over time across SharePoint and OneDrive to surface risk trends and stale links of every type.
lastReviewed: 2026-06-02
---

# Sharing Links Activity Audit

> **TL;DR:** This skill analyses activity and trends over time for Anyone, Company-wide and Specific People sharing links across SharePoint Online and OneDrive, then reports high-risk patterns and stale links that expand the Microsoft 365 Copilot exposure surface.

## What does the sharing links activity audit analyse?

This skill examines sharing-link creation and access activity across SharePoint Online and OneDrive, drawing on the SharePoint sharing-links reports and Microsoft Purview audit log activities. It distinguishes Anyone (anonymous), Company-wide (Organisation) and Specific People links, then surfaces high-risk patterns such as anonymous links to sensitive content and stale links no longer in use. Because every active link is a path Microsoft 365 Copilot and external recipients can follow, the audit highlights where least-privilege sharing has eroded. It reads activity data only and changes no links.

## When should you run this skill?

- "Audit our Anyone sharing links across SharePoint and OneDrive"
- "Find stale sharing links nobody uses anymore"
- "Show me Company-wide link trends over the last quarter"
- "Which anonymous links point at sensitive files?"
- "Analyse sharing-link activity for Copilot risk"
- "Where is link-based sharing growing fastest?"

## How this skill works, step by step

1. Connect read-only to SharePoint Online and the Microsoft Purview audit log.
2. Retrieve sharing-links reports for SharePoint Online and OneDrive.
3. Classify links by type: Anyone, Company-wide (Organisation) and Specific People.
4. Pull audit log activities for link creation, access and resharing events.
5. Identify stale links with no access activity over the review window.
6. Flag anonymous and Company-wide links pointing at sensitive content.
7. Score each link or trend by reach, anonymity and content sensitivity.
8. Aggregate link creation and access events by period to show trends, then group findings into high-risk trend groups and a stale-link list. Recipient identity and domain are not attributed here.
9. Output the audit without revoking or modifying any link.

## Output format

The skill returns a sharing-link audit table, one row per high-risk link or trend.

| Scope | Link type | Last accessed | Sensitivity | Risk | Recommended action |
| --- | --- | --- | --- | --- | --- |
| Finance Hub | Anyone | 6 months ago | Confidential | High | Revoke and reissue as scoped |
| Sales OneDrive | Company-wide | 2 days ago | General | Medium | Confirm business need |
| Project Atlas | Specific People | 14 months ago | General | Low | Expire stale link |

Summary:

- Total links reviewed: 4,820
- Anyone links: 612
- Company-wide links: 1,344
- Stale links (no recent access): 1,907
- High risk: 188

## Scope and safety

This skill is read-only by default and makes no changes to sharing links, policies or content.

This skill does NOT:

- Revoke, expire or modify any sharing link.
- Change tenant or site sharing policies.
- Alter audit log retention or configuration.
- Contact users who created or received links.

## Licensing and permissions

### Licences and add-ons

| Capability used | Minimum licence |
| --- | --- |
| SharePoint Online and OneDrive sharing-links reports | Microsoft 365 E3 or E5 |
| Sharing-link insights via Data Access Governance reports | SharePoint Advanced Management (included in E5 or as an add-on) |
| Microsoft Purview audit log activities for sharing events | Microsoft 365 E3 (E5 for extended retention) |

### Least-privilege roles

- Global Reader (read-only visibility across the audit data)
- SharePoint Administrator (read) for sharing-links reports, where Global Reader is insufficient

### Microsoft Graph permissions (read-only)

- `Sites.Read.All` — reads site and sharing-link metadata across SharePoint Online and OneDrive
- `Files.Read.All` — reads file-level sharing and sensitivity context for shared items
- `AuditLog.Read.All` — reads Purview audit log activities for link creation, access and resharing
- `Directory.Read.All` — resolves user and group identities on links

Note: SharePoint Advanced Management sharing-links reports are generated in the SharePoint admin centre or via SharePoint Online PowerShell rather than Microsoft Graph; the Graph scopes above apply to the supporting sharing and audit data this skill reads.

## When should I run this instead of the External Sharing Deep Audit?

Run this skill when you need to know how sharing links of every type, including Company-wide links, are created and used over time, and which links have gone stale. Run the [External Sharing Deep Audit](/sharepoint/external-sharing-deep-audit) when you need a point-in-time register of every externally shared item by recipient and domain, which this skill does not produce. If you need both, run the inventory first, then this audit to see which of those shares are actually in use.

## Related skills

- [SharePoint Oversharing Audit](/sharepoint/sharepoint-oversharing-audit): run first to review active sharing links and site permissions.
- [External Sharing Deep Audit](/sharepoint/external-sharing-deep-audit): run first to inventory externally shared items by recipient domain and risk.
- [Everyone Except External Users (EEEU) Sweep](/sharepoint/everyone-except-external-users-sweep): run after to sweep for broad-claim sharing.
- [Data Access Governance Report Review](/sharepoint/data-access-governance-report-review): run after to prioritise sharing-link signals into a remediation plan.
- [SharePoint Copilot Readiness Guide](/sharepoint/copilot-readiness-guide): the pillar guide that sequences these audits for Copilot readiness.

## Sources and compliance

- [Sharing links reports](https://learn.microsoft.com/en-us/sharepoint/sharing-reports)
- [Audit log activities for sharing](https://learn.microsoft.com/en-us/purview/audit-log-activities)
- Maps to Essential Eight: Restrict administrative privileges and limit unnecessary external data exposure.
- Aligns with ISM controls for access control and monitoring of data sharing.
- Reference: [ASD Essential Eight Maturity Model](https://www.cyber.gov.au/resources-business-and-government/essential-cyber-security/essential-eight/essential-eight-maturity-model)
