2.11 Ensure that Sways cannot be shared with people outside of your organization

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Sway is a new app from Microsoft Office that allows users to create and share interactive reports, personal stories, presentations, and more.

This setting controls user Sway sharing capability, both within and outside of the organization. By default, Sway is enabled for everyone in the organization.

Rationale:

Disable external sharing of Sway documents that can contain sensitive information to prevent accidental or arbitrary data leak.

Impact:

Interactive reports, presentations, newsletters and other items created in Sway will not be shared outside the organization by users.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

To ensure Sways cannot be viewed outside of your organization:

Navigate to Microsoft 365 admin center https://admin.microsoft.com.

Click to expand Settings then select Org settings.

Under Services select Sway

Let people in your organization share their sways with people outside your organization.

Click Save.

Default Value:

Let people in your organization share their sways with people outside your organization - Enabled

See Also

https://workbench.cisecurity.org/benchmarks/10751