7.2.4 Ensure OneDrive content sharing is restricted

Information

This setting governs the global permissiveness of OneDrive content sharing in the organization.

OneDrive content sharing can be restricted independent of SharePoint but can never be more permissive than the level established with SharePoint.

The recommended state is Only people in your organization.

Rationale:

OneDrive, designed for end-user cloud storage, inherently provides less oversight and control compared to SharePoint, which often involves additional content overseers or site administrators. This autonomy can lead to potential risks such as inadvertent sharing of privileged information by end users. Restricting external OneDrive sharing will require users to transfer content to SharePoint folders first which have those tighter controls.

Impact:

Users will be required to take additional steps to share OneDrive content or use other official channels.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

To remediate using the UI:

Navigate to SharePoint admin center https://admin.microsoft.com/sharepoint

Click to expand Policies > Sharing.

Locate the External sharing section.

Under OneDrive, set the slider bar to Only people in your organization.

To remediate using PowerShell:

Connect to SharePoint Online service using Connect-SPOService.

Run the following cmdlet:

Set-SPOTenant -OneDriveSharingCapability Disabled

Default Value:

Anyone (ExternalUserAndGuestSharing)

See Also

https://workbench.cisecurity.org/benchmarks/12934

Item Details

Category: ACCESS CONTROL, MEDIA PROTECTION

References: 800-53|AC-3, 800-53|AC-5, 800-53|AC-6, 800-53|MP-2

Plugin: microsoft_azure

Control ID: 1157454f70e85ff0b35189f4b917ddadc870ab708b3480486358cd7c81b18a66