Skip to content
Tech News
← Back to articles

Secure enterprise sharing with access reviews for Microsoft 365

read original more articles
Why This Matters

This piece highlights a growing enterprise security blind spot: the ease of sharing in Microsoft 365 and similar cloud platforms is outpacing organizations' ability to track and manage who has access to sensitive data. As collaboration tools become indispensable, unchecked or stale sharing permissions create real risks for data breaches and compliance failures, making access reviews a critical but often neglected security practice.

Key Takeaways

Collaboration suites like M365 offer unparalleled convenience. Millions of teams rely on them to quickly share documents with coworkers, clients and business partners. Yet when sharing is this easy, data security becomes a lot harder.

Cloud sharing is so integral to the modern workplace that it’s difficult to imagine how offices ever got by without it. Dropping files in one-on-one chats. Spreadsheets that live in Teams channels so everyone can see the latest figures. Throwing project folders on SharePoint and sending out invite links.

Yet for all the ways that cloud sharing has revolutionized office life, remote work and long-distance collaboration, there is a downside.

With the usage of cloud platforms exploding over recent years, visibility into sharing is falling further and further behind. Many organizations no longer have any idea who their users are sharing potentially sensitive information with.

Sharing moves fast. How security can keep up

Unmanaged cloud sharing is a shockingly common problem in enterprise environments. Anywhere organizations use Microsoft 365 to share access, security teams struggle to identify and rein in problematic cloud access.

In a survey by Wire, 61% of security leads reported that access to shared files often remains active longer than intended. Over a third acknowledge difficulties in even identifying who has access to sensitive shared files.

One factor that makes cloud sharing difficult to evaluate from a security perspective is how context-driven the use of sharing features is. Employees share files with a specific purpose in mind, whether it’s to coordinate with a coworker or get approval from a client on a design mockup.

The problem is that shared access often outlives or outgrows its original purpose: A freelancer could be taken off a project, but never removed from the project folder in SharePoint. Members may invite new users into a Teams channel, forgetting that they will get access to every file hosted within it.

The highly contextual nature of cloud sharing means the only way to know for certain whether shared access is still needed is to ask the person who originally provided it. Access reviews are an essential safeguard, and looping file or channel owners into the review process leads to faster and more accurate audits.

... continue reading