Information
Sway is a Microsoft 365 app that lets organizations create interactive, web-based presentations using images, text, videos and other media. Its design engine simplifies the process, allowing for quick customization. Presentations can then be shared via a link.
This setting controls user Sway sharing capability, both within and outside of the organization. By default, Sway is enabled for everyone in the organization.
Disable external sharing of Sway documents that can contain sensitive information to prevent accidental or arbitrary data leaks.
NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.
Solution
To remediate using the UI:
- Navigate to Microsoft 365 admin center
https://admin.microsoft.com
.
- Click to expand Settings then select Org settings
- Under Services select Sway
- Uncheck: Let people in your organization share their sways with people outside your organization
- Click Save
Impact:
Interactive reports, presentations, newsletters, and other items created in Sway will not be shared outside the organization by users.