Secure enterprise sharing with access reviews for Microsoft 365

Cloud sharing has revolutionized modern office life, making it easier than ever to collaborate with coworkers, clients, and business partners. However, this convenience comes at a cost: millions of teams struggle to keep track of who has access to sensitive shared files, leaving them vulnerable to data security risks.

Unmanaged cloud sharing is a widespread problem in enterprise environments, particularly when using Microsoft 365. A recent survey found that 61% of security leads reported difficulty identifying and managing problematic cloud access. The issue lies not with user behavior but rather with the limitations of built-in governance tools within Microsoft 365. These tools fail to provide a clear picture of who has access to shared files, making it challenging for security teams to identify potential risks.

Cloud sharing is often driven by context-specific needs, such as coordinating with coworkers or obtaining approval from clients on design mockups. However, shared access frequently outlives its original purpose. For example, a freelancer might be removed from a project but remain connected to the project folder in SharePoint. Similarly, members may invite new users into Teams channels without realizing they will gain access to every file hosted within it.

To mitigate these risks, security teams need to implement regular access reviews. This process involves looping in the person who originally provided shared access and verifying whether it is still needed. Access reviews are an essential safeguard against unmanaged cloud sharing, allowing for faster and more accurate audits. However, implementing this process can be time-consuming, especially when using built-in reporting tools within Microsoft 365.

Microsoft 365 provides two reporting options to offer visibility into shared data: global reports on sharing links and site-level sharing reports. While these tools provide some insight into cloud access, they come with significant limitations. Global reports only show the number of new links created in the last 28 days, without providing context about whether this is a security risk or simply due to a legitimate project involving external partners. Site-level reports require manual sifting through CSV tables to identify problematic sharing.

What Microsoft 365 lacks is a centralized dashboard for access governance that offers a comprehensive view of cloud access without requiring extensive effort. Dedicated Identity & Access Governance solutions, such as tenfold, bridge this visibility gap by automating on- and offboarding processes, streamlining access reviews, and providing real-time insights into cloud access.

In summary, the convenience of cloud sharing has created a growing security risk in enterprise environments. While Microsoft 365 provides some reporting tools to help manage this issue, they fall short in offering a complete picture of shared access. To mitigate these risks, organizations need to implement regular access reviews and consider investing in dedicated Identity & Access Governance solutions that can provide real-time visibility into cloud access.

Practically speaking, organizations should prioritize implementing access reviews as part of their security protocols. This involves regularly reviewing shared access and verifying whether it is still necessary. By doing so, teams can reduce the risk of unmanaged cloud sharing and protect sensitive data from unauthorized access.


Source: Bleeping Computer — 2026-09-18