Skip to main content
CybersecurityCloud Security

Microsoft 365 Sharing Risks Exposed in Enterprise Environments

Empty office corridor with a laptop and scattered papers on a desk.

“61% of security leads reported that access to shared files often remains active longer than intended.” That stark figure, from a Wire survey cited in vendor material, frames a common tension: cloud collaboration is effortless — and that very ease leaves persistent, invisible access across Teams, SharePoint and OneDrive.

Wire survey: access outliving its purpose

The source material cites a survey by Wire showing 61% of security leads believe shared-file access frequently remains active beyond its intended timeframe. It also reports that “over a third” of those respondents said they have trouble identifying who has access to sensitive shared files. Those two data points underpin the piece’s central claim: sharing in Microsoft 365 environments is happening faster than current governance can track.

How context-driven sharing defeats blunt reporting

The report emphasizes that cloud sharing is highly contextual. Examples used in the source include one-on-one chats, spreadsheets embedded in Teams channels and project folders on SharePoint shared via invite links. That context — sharing for a specific purpose, with a particular recipient or for a discrete interval — is precisely what makes automated, untargeted reporting insufficient. A file shared for a temporary contractor, or a channel open to collaborators for a single project, may continue to grant access long after the business reason has passed.

Limitations of Microsoft 365’s built-in governance, as described

The material identifies two native reporting options in Microsoft 365 and sets out their limits. SharePoint Advanced Management can produce a global report on sharing links, but that output “only tells you which sites had the most new links created in the last 28 days,” a metric the source says lacks context — a spike could reflect legitimate project work or misuse. Site-level sharing reports can yield CSV listings of every shared file and current access, but running those reports across every SharePoint site and OneDrive tenant, then manually reviewing rows of data, is described as “incredibly time-consuming.” The conclusion presented is that both options transfer most of the investigative work back onto the organization.

tenfold’s proposed fixes: centralized dashboards and owner-driven reviews

Positioning itself as a supplement to Microsoft 365, tenfold — the vendor behind the piece — highlights two “standout features” it says set its Identity & Access Governance (IGA) platform apart. First is a centralized breakdown of shared content across Teams, OneDrive and SharePoint that the vendor describes as combining high-level insights with object-level detail and filters by app, user or site. The source claims the interface flags “notable details, such as files being shared outside their Team or channel” with icons.

Second is a streamlined access-review workflow that prompts the data owners who originally shared content to confirm who should still have access. According to the material, each reviewer receives a personalized dashboard showing the items they shared and current access lists, enabling reviewers to confirm or revoke access quickly — and allowing the process to be delegated “even to users in non-IT roles.” The write-up also notes tenfold provides ready-to-use plugins, integrates with Microsoft Cloud and on-prem environments, and advertises itself as a “no-code IGA solution.”

What this means for security teams, data owners, and procurement leaders

  • Security teams: The source frames security teams as struggling with visibility and manual effort; it implies teams will use central dashboards and automated reviews to reduce investigation time and to address links and access that persist beyond their purpose.
  • Data owners and non-IT reviewers: The material stresses looping file and channel owners into reviews, suggesting these individuals are best placed to judge whether shared access remains necessary and that personalized review dashboards simplify their task.
  • Procurement leaders and IT buyers: The vendor copy urges action — automating on- and offboarding, streamlining access reviews and booking a “personal demo” — positioning tenfold as a turnkey add-on for organizations seeking a centralized governance layer over Microsoft 365 sharing.

The source makes a clear, focused argument: the convenience of Microsoft 365 sharing is creating a governance gap that native reports do not close, and access reviews driven by the people who shared content are the proposed antidote. tenfold’s pitch is that centralized visibility and owner-led reviews will let organizations “make full use of cloud collaboration features without putting [their] data at risk.” Whether that approach suits a given organization depends on how much weight they place on the survey findings and on the tradeoff between built-in reporting and adopting an external IGA layer.

Read the original sponsored piece on BleepingComputer