External Sharing Policy change all existing sites

Silver Contributor

One of my customers recently enabled external sharing at the tenant level, and almost all of the existing sites are now showing "This site can be shared with new and existing external users who sign in". We were expecting that each site would have remained "This site can’t be shared with external users" until we specifically change the setting on a site by site basis.

Has anyone else seen this behavior? Was there a change in functionality deployed by Microsoft that I missed?

6 Replies
It’s always been that way. The sharing will go to “specific users” if you want anonymous links thou you have to explicitly set it per site but all sites not manually set will go up to specific users.

Ok, thanks. I guess now we have to go turn it off on a bunch of sites, ugh.

 

@Chris Webbi have done some more investigation and I'm not seeing consistent behavior, there are some group enabled sites that were not changes and many that did change. Any idea why that would have happened?

Some were manually changed at some point and others not? Possible that one of the site template types, (Group, Team etc.) may have this property explicitly set. The problem is it's really hard to tell because they all say what they are and don't really tell you if it inherits or not from what I'm finding.

@Chris Webb is correct. An example:

 

1) Tenant is set to allow anyone links. Site is set to allow anyone links.

2) Tenat is restricted to authenticated sharing only. By policy, site can now only offer authenticated sharing too (and so will show up as such in admin UI) even though it's saved value is "anyone" links.

3) Tenant is set to allow anyone links again. Site now allows anyone links again (because it's value never changed).

 

Hope that helps!

 

Stephen Rice

OneDrive Program Manager II

@Stephen Ricethanks for the information, it was my understanding that enabling an external sharing option would only make each site eligible for sharing, but that sharing would have to be activate on a site by site basis. I am quite sure that this is the way that it used to work. I am very concerned that many site collections just had external sharing enabled without the site owners knowledge.

The tenant setting was changed to "Allow users to invite and share with authenticated external users" and now, many  sites are set to "This site can be shared with new and existing external users who sign in" but some are still set to "This site can’t be shared with external users", which is what they were before the tenant setting change. Why did some sites change and some not?

Hi @Dean Gross, what likely happened is that, for the sites that didn't change, at some point in the past someone modified or explicity set the external sharing value for those sites. If it happened in the last 90 days, you should be able to see it in the audit log. Hope that helps!

 

Stephen Rice

OneDrive Program Manager II