SharePoint and OneDrive make it easy to send a document, collaborate with a customer or give a contractor access to a project folder. They also make it easy to leave access open after the work is finished.
The risk is usually not Microsoft 365 itself. It is an old sharing link, an external guest or a folder that inherited permissions nobody has reviewed.
Start with the link
Check what each SharePoint or OneDrive sharing link allows. A link that works for anyone who receives it is difficult to control once it has been forwarded. Use named people or groups when the file contains business or personal information.
- Prefer named access over anonymous links.
- Set an expiry date for temporary access where the service supports it.
- Use view-only access when editing is not required, but do not treat it as protection against downloading, copying or re-sharing.
- Use sensitivity labels or another tested control for sensitive files.
- Remove links that are no longer needed.

Review external guests
External guests can be useful for customers, suppliers and contractors. They should have a clear business reason and a person who owns the relationship.
Keep a record of who the guest is, what they can access and when the access should end. When a project finishes, remove the guest and review any links that were created for them.
Check inherited permissions
A person may have access to a file because they were added to a wider Microsoft 365 group, SharePoint site or team. That access can be easy to miss when you review one file at a time.
Start with the folders that hold contracts, customer records, finance information and operational documents. Check who can access them through groups, shared sites and inherited permissions. Avoid routine folder-level exceptions, which create permission sprawl.

Keep ownership with the business
For customer and contractor work, use a project SharePoint site with two business owners where practical. Do not make an employee’s OneDrive the permanent home for important shared files.
When a staff member leaves, move or copy important OneDrive content into a business-controlled SharePoint location where appropriate. Do not assume that deleting a user automatically cleans up every shared file or link.
A quick sharing review
- List the SharePoint sites and OneDrive folders that contain important business information.
- Review external guests and remove access that no longer has a clear purpose.
- Replace anonymous links with named access where practical.
- Check whether people can edit, download or reshare the files.
- Set expiry dates for temporary access and use sensitivity labels for sensitive files where appropriate.
- Confirm that important files have two business owners and are stored in a business-controlled location.
Review sharing quarterly and after staff or supplier changes. Record the owner, access list, exceptions and next review date.
Ask JCPIT to review your high-risk SharePoint sites and OneDrive folders, identify stale access and provide an approval-ready remediation list. The review can be planned around your normal work rather than forcing an unmanaged migration.