Can't configure external sharing per site basis for SharePoint site that is connected to O365 Group

%3CLINGO-SUB%20id%3D%22lingo-sub-2231211%22%20slang%3D%22en-US%22%3ESecurity%20Concern%20-%20can%20we%20configure%20external%20sharing%20per%20site%20basis%20for%20SharePoint%20Online%20sites%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2231211%22%20slang%3D%22en-US%22%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EMicrosoft%20recently%20enabled%20guess%20access%20as%20the%20default%20behavior%20for%20Microsoft%20Teams.%20As%20a%20result%20SharePoint%20online%20sites%20are%20configured%20for%20external%20sharing%20now.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EBecause%20of%20this%2C%20any%20SharePoint%20Online%20site%20that's%20connected%20with%20an%20Office%20365%20group%2C%20that%20gets%20created%20is%20configured%20for%20external%20sharing.%20These%20sites%20could%20be%20the%20sites%20associated%20with%20Microsoft%20365%20services%20e.g.%20Teams%2C%20Yammer%20etc.%20or%20just%20independent%20sites%20but%20connected%20with%20an%20O365%20group.%20Their%20external%20sharing%20is%20inherited%20from%20the%20SharePoint%20Online%20external%20sharing%20settings%20at%20the%20Tenant%20Org%20level.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ENoe%3A%26nbsp%3B%20If%20you%20create%20a%20SharePoint%20team%20site%20without%20a%20O365%20connected%20group%20or%20a%20communication%20site%20then%20the%20Tenant%20level%20external%20sharing%20settings%20do%20not%20get%20inherited%20to%20them%20and%20that%20is%20ideal%20so%20we%20can%20decide%20if%20we%20need%20to%20enable%20external%20sharing%20to%20them%20case%20by%20case.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EBut%20for%20those%20O365%20connected%20sites%20-%26nbsp%3B%20this%20is%20a%20huge%20security%20concerns%20as%20organizations%20and%20we%20don't%20want%20all%20these%20sites%20by%20default%20have%20the%20external%20sharing%20settings%20inherited%20to%20them%20from%20tenant%20org%20level.%20We%20want%20to%20enable%20external%20sharing%26nbsp%3B%20by%20request%20site%20by%20site%20by%20request.%20Now%20we%20can%20go%20in%20SharePoint%20admin%20center%20after%20the%20fact%20and%20reconfigure%20those%20sites%20one%20by%20one%20for%20not%20to%20be%20allowed%20for%20external%20sharing%20or%20set%20that%20to%20your%20desired%20settings%26nbsp%3Bbut%20that%20is%20very%20unproductive%20as%20users%20create%20sites%20left%20and%20right.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20understand%20for%20Teams%20guest%20access%20and%20collaboration%20purposes%20it%20is%20needed%20but%20that%20should%20not%20be%20applied%20to%20other%20SharePoint%20Online%20sites%20that%20is%20not%20associated%20with%20Teams.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ESo%20the%20question%20is%2C%20is%20it%20possible%20to%20set%20the%20O365%20group%20connected%20sites'%20external%20sharing%20settings%20not%20to%20inherit%20from%20the%20tenant%20SharePoint%20org%20level%20external%20sharing%20settings%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-2231211%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EPermissions%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ESecurity%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ESharePoint%20Online%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ETeams%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EYammer%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2239763%22%20slang%3D%22en-US%22%3ERe%3A%20Can't%20configure%20external%20sharing%20per%20site%20basis%20for%20SharePoint%20site%20that%20is%20connected%20to%20O365%20Gr%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2239763%22%20slang%3D%22en-US%22%3EYou%20ultimately%20received%20your%20answer%20from%20Microsoft%2C%20but%20ideally%20you'd%20place%20the%20most%20restrictive%20setting%20at%20the%20tenant%20level.%20You%20can%20then%20create%20a%20custom%20provisioning%20process%20that%20allows%20the%20end%20user%20to%20select%20their%20desired%20sharing%20setting%20and%20as%20part%20of%20the%20provisioning%20process%2C%20set%20the%20sharing%20setting%20at%20the%20site%20level%20appropriately.%3C%2FLINGO-BODY%3E
Contributor

 

Updates are given below the original post

 

Original post  ---

 

Security Concern - Not being able to configure external sharing per-site basis for any SharePoint Online site that is connected to an O365 Group. When you configure external sharing now at the SharePoint Admin Center at the tenant level, all O365 connected sites inherit the sharing settings from the Admin center, we can't configure a per-site basis for those O365 group connected sites.

 

Microsoft recently enabled guess access as the default behavior for Microsoft Teams. As a result, SharePoint online sites are configured for external sharing now. 

 

Because of this, any SharePoint Online site that's connected with an Office 365 group, that gets created is configured for external sharing. These sites could be the sites associated with Microsoft 365 services e.g. Teams, Yammer, etc., or just independent sites but connected with an O365 group. Their external sharing is inherited from the SharePoint Online external sharing settings at the Tenant Org level.

 

Noe:  If you create a SharePoint team site without an O365 connected group or a communication site then the Tenant level external sharing settings do not get inherited to them and that is ideal so we can decide if we need to enable external sharing to them case by case.

 

But for those O365 connected sites -  this is a huge security concern as organizations and we don't want all these sites by default to have the external sharing settings inherited to them from the tenant org level. We want to enable external sharing by request site by site by request. Now we can go in the SharePoint admin center after the fact and reconfigure those sites one by one for not to be allowed for external sharing or set that to your desired settings but that is very unproductive as users create sites left and right.

 

I understand for Teams guest access and collaboration purposes it is needed but that should not be applied to other SharePoint Online sites that are not associated with Teams.

 

So the question is, is it possible to set the O365 group connected sites' external sharing settings not to inherit from the tenant SharePoint org level external sharing settings?

 

Thanks 

 

-------------------------------------------------------------------

 

Updates:

 

I contacted Microsoft support for this issue. They acknowledge this is an issue but seems can't do anything on this now, which is really not acceptable. Support is limited to what they can do. Asked them to contact their development/engineering team to address this concern.

 

2 Replies
You ultimately received your answer from Microsoft, but ideally you'd place the most restrictive setting at the tenant level. You can then create a custom provisioning process that allows the end user to select their desired sharing setting and as part of the provisioning process, set the sharing setting at the site level appropriately.
That was not an answer but just acknowledging the issue. The issue is - when you set the sharing setting for SharePoint at the tenant level, then those settings are inherited for any O365 Group connected SPO site and you can't apply users desired sharing settings per-site basis via custom provisioning. If the site is NOT an O365 Group connected SPO site then customer provisioning would work. Give it a try.