Information
External sharing of content can be restricted to specific security groups. This setting is global, applies to sharing in both SharePoint and OneDrive and cannot be set at the site level in SharePoint.
The recommended state is Enabled or Checked
Note: Users in these security groups must be allowed to invite guests in the guest invite settings in Microsoft Entra. Identity > External Identities > External collaboration settings
Organizations wishing to create tighter security controls for external sharing can set this to enforce role-based access control by using security groups already defined in Microsoft Entra.
NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.
Solution
To remediate using the UI:
- Navigate to SharePoint admin center
https://admin.microsoft.com/sharepoint
- Click to expand Policies > Sharing
- Scroll to and expand More external sharing settings
- Set the following:
- Check Allow only users in specific security groups to share externally
- Define Manage security groups in accordance with company procedure.
Impact:
OneDrive will also be governed by this and there is no granular control at the SharePoint site level.