Do you want to share files with a customer, supplier, or other external person? You have several options: SharePoint or OneDrive, an email attachment, or an external file service such as WeTransfer. In this article, you will read which method is suitable when and why secure sharing is more than just sending a file.
Sharing files seems simple, but the chosen method partly determines:
- who gets access;
- how long that access lasts;
- whether you can revoke access later;
- whether different versions of the same document arise;
- whether you keep track of where the file ends up.
The three most used methods
1. SharePoint or OneDrive link
You share access to the file that remains in Microsoft 365.
2. Email attachment
You send a copy of the file to the recipient.
3. External file service
You upload the file to an external service and then send a download link.
Why SharePoint or OneDrive usually gets preference
When you share a file via SharePoint or OneDrive, the original document remains in your Microsoft 365 environment.
You do not necessarily send a new copy but give someone access to the existing file.
This has several advantages:
- you maintain one central version of the document;
- access can be revoked later;
- you can determine whether someone may view or edit;
- you can restrict access to specific persons;
- you do not have to email a new version after every change;
- the access remains part of your Microsoft 365 environment.
Choose specific persons for sensitive files
SharePoint and OneDrive can offer different types of sharing links.
For sensitive or business-related information, a link for specific persons is usually preferred.
In this case, the recipient must prove that he or she is the intended person.
You share a financial document with klant@example.com. A link intended only for that specific recipient offers more control than a link that anyone with the URL can open.
What is wrong with an email attachment?
An email attachment is not automatically unsafe.
For a small, non-sensitive file, an attachment can be perfectly practical.
The disadvantage is mainly that you have much less control after sending.
The recipient can, for example,:
- save the attachment locally;
- forward it;
- copy it;
- upload it to another service;
- keep it after you actually no longer want to share the document.
You have placed a copy of your document outside your own management environment.
The version problem of email attachments
Suppose you send an Excel file to three colleagues or customers.
They each make changes and send the file back.
Suddenly, there are different versions:
offer-final-Wim.xlsx
offer-final-new.xlsx
offer-final-final-v2.xlsx
With SharePoint or OneDrive, everyone, when allowed, can collaborate in the same document.
And what about WeTransfer or similar services?
External transfer services can be useful for sending very large files.
But for business information, you must first check whether using such an external service is permitted within your organisation’s policy.
After all, you bring the file outside your organisation’s Microsoft 365 environment and under the conditions and security measures of another provider.
This means you must consider, among other things:
- where the files are stored;
- how long they are retained;
- how the download link is protected;
- who can gain access;
- what logging is available;
- which contractual and privacy conditions apply.
For business data, it is usually better to first check whether SharePoint, OneDrive or another approved business solution can meet the same need.
But SharePoint links can also be forwarded, right?
That depends on the type of link.
An anonymous link intended for "anyone with the link" can indeed be easily forwarded.
That is why we prefer access for specific persons for confidential files.
Is the recipient allowed to download the file?
That depends on the purpose.
Sometimes the recipient must be able to save a file locally. In other situations, you want someone to only view the content.
Microsoft 365 offers possibilities in certain situations to restrict downloading.
Here too, technology can reduce risk but cannot guarantee absolute control over a human recipient.
Always check the recipient
The safest sharing technology does not help when you share a confidential file with the wrong person.
Therefore, check before sending:
- the name of the recipient;
- the full email address;
- whether the recipient really needs access;
- whether you have selected the correct file;
- which rights you grant: view or edit.
A perfectly configured sharing solution cannot prevent someone from deliberately sharing the wrong document with the wrong person.
How do we share sensitive information?
The more sensitive the information, the more control is needed.
Think, for example, of:
- personal data;
- contracts;
- financial information;
- salary information;
- medical information;
- strategic business information;
- passwords and other credentials.
For such information, it is wise to consciously determine:
- who gets access;
- how the recipient’s identity is verified;
- whether downloading is allowed;
- how long access is needed;
- whether access must be revoked afterwards;
- whether the document may be shared at all via this method.
Do not share passwords via ordinary email
Passwords and other sensitive credentials deserve a separate approach.
Preferably use a professional password manager that allows data to be securely shared with the right people.
Which method to choose?
SharePoint or OneDrive
Best choice for most business documents, collaboration and controlled external sharing.
Email attachment
Can be fine for small, non-sensitive files where control after sending is not important.
External transfer service
Can be useful for specific situations or very large files, but only when the service is approved by your organisation.
Technology must be correctly configured
SharePoint and OneDrive can be set up very securely, but the right settings are essential.
An organisation must, for example, determine:
- whether external sharing is allowed;
- which users may share externally;
- which types of links are available;
- whether anonymous links are allowed;
- how guests are managed;
- which information must be additionally protected;
- how old external access is monitored.
FLEXAMIT helps organisations to configure SharePoint, OneDrive, Microsoft Entra and external access so that users can easily collaborate without unnecessarily losing control over business data.
Our cybersecurity expertise has been recognised three years in a row by our Microsoft distributor with the Cybersecurity Partner of the Year award.
Would you like to know if external sharing is correctly and safely set up within your organisation?
Contact:
sales@flexamit.com
Accidentally shared something wrong?
Have you possibly shared a sensitive document with the wrong person or do you doubt whether an existing link is still safe?
Are you a FLEXAMIT customer? Contact our service desk so we can check whether access can still be revoked and what further steps are necessary.
support@flexamit.com
Summary
- For business documents, a managed SharePoint or OneDrive link usually has preference.
- With a link, access can often still be adjusted or revoked later.
- An email attachment is a copy over which you have much less control after sending.
- External transfer services must fit within your organisation’s policy.
- For sensitive files, prefer access for specific persons.
- Always check the recipient and the granted rights.
- Use a professional password manager for sharing credentials.
- The correct Microsoft 365 configuration is essential for secure external sharing.
- No technology can prevent a user from deliberately sharing information with the wrong person.
Comments
0 comments
Please sign in to leave a comment.