Secure enterprise sharing with access reviews for Microsoft 365

Cloud sharing has revolutionized office life, making it easier than ever to collaborate with coworkers, clients, and business partners. However, this convenience comes at a cost: many organizations are struggling to keep track of who has access to their sensitive data. In fact, 61% of security leads report that shared files often remain active longer than intended, while over a third admit they can’t even identify who has access to these files.

The problem lies in the highly contextual nature of cloud sharing. Employees share files with specific purposes in mind, but this context is easily lost as users come and go. A freelancer may be removed from a project, but still retain access to shared folders; new members may join Teams channels, granting access to sensitive files without anyone realizing it.

To mitigate these risks, access reviews are essential. These involve looping in the original file or channel owners to review who has access and whether it’s still necessary. However, implementing this process effectively is a challenge, especially with the available tools on Microsoft 365. The platform provides two reporting options that offer some visibility into shared data, but both come with significant limitations.

For example, SharePoint Advanced Management allows you to generate global reports on sharing links, but these only tell you which sites had the most new links created in the past 28 days. This figure can be misleading: a high number of new links might indicate misuse, or it could simply be due to a project with outside involvement.

Similarly, creating site-level sharing reports generates a CSV table showing every shared file and who has access to it. However, running this report across every SharePoint and OneDrive in your organization is a time-consuming task, not to mention manually sifting through these files to identify problematic sharing.

This is where dedicated Identity & Access Governance (IAM) solutions come into play. These tools provide a centralized dashboard for access governance, giving you the full picture without requiring manual effort or piecing together disparate reports. Tenfold Software’s no-code IGA solution, for instance, automates on- and offboarding processes, streamlines access reviews, and bridges the visibility gap left by native reporting tools.

The lack of control over shared data presents a growing security risk in enterprise environments. While teams rely heavily on sharing features to collaborate effectively, insufficient governance features built into Microsoft 365 exacerbate this issue. By implementing a dedicated IAM solution, organizations can regain control over their shared data and ensure that access is properly managed throughout the collaboration process.

Ultimately, securing enterprise sharing with access reviews requires more than just native reporting tools. It demands a centralized platform for managing access, one that can provide real-time visibility into who has access to sensitive files and when it’s time to revoke those permissions. By adopting such a solution, organizations can reduce the risks associated with cloud sharing and maintain a secure collaboration environment.


Source: Bleeping Computer — 2026-09-18