7.2.7 Ensure link sharing is restricted in SharePoint and OneDrive

Information

This setting sets the default link type that a user will see when sharing content in OneDrive or SharePoint. It does not restrict or exclude any other options.

The recommended state is Specific people (only the people the user specifies)

Rationale:

By defaulting to specific people, the user will first need to consider whether or not the content being shared should be accessible by the entire organization versus select individuals. This aids in reinforcing the concept of least privilege.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

To audit using the UI:

Navigate to SharePoint admin center https://admin.microsoft.com/sharepoint

Click to expand Policies > Sharing.

Scroll to Filer and folder links.

Set Choose the type of link that's selected by default when users share files and folders in SharePoint and OneDrive to Specific people (only the people the user specifies)

To remediate using PowerShell:

Connect to SharePoint Online using Connect-SPOService.

Run the following PowerShell command:

Set-SPOTenant -DefaultSharingLinkType Direct

Default Value:

Only people in your organization (Internal)

See Also

https://workbench.cisecurity.org/benchmarks/12934

Item Details

Category: ACCESS CONTROL, MEDIA PROTECTION

References: 800-53|AC-3, 800-53|AC-5, 800-53|AC-6, 800-53|MP-2

Plugin: microsoft_azure

Control ID: 28c51a422ce2deb72225d47125cea87b50595ef1aa2452a0a3dc9a53dc7ea361