7.2.8 (L2) Ensure external sharing is restricted by security group

Information

External sharing of content can be restricted to specific security groups. This setting is global, applies to sharing in both SharePoint and OneDrive and cannot be set at the site level in SharePoint.

The recommended state is Enabled or Checked

Note: Users in these security groups must be allowed to invite guests in the guest invite settings in Microsoft Entra. Identity > External Identities > External collaboration settings

Organizations wishing to create tighter security controls for external sharing can set this to enforce role-based access control by using security groups already defined in Microsoft Entra.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

To remediate using the UI:

- Navigate to SharePoint admin center

https://admin.microsoft.com/sharepoint

- Click to expand Policies > Sharing
- Scroll to and expand More external sharing settings
- Set the following:
- Check Allow only users in specific security groups to share externally
- Define Manage security groups in accordance with company procedure.

Impact:

OneDrive will also be governed by this and there is no granular control at the SharePoint site level.

See Also

https://workbench.cisecurity.org/benchmarks/17682

Item Details

Category: ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

References: 800-53|AC-2, 800-53|AC-3, 800-53|AC-6, 800-53|AC-6(1), 800-53|AC-6(7), 800-53|AU-9(4)

Plugin: microsoft_azure

Control ID: 43a766fd2e16dd37d96ff6a58fc74405750c8c65dd78f9a178fece26a55f4724