November 13, 2013

Critical Office 365 External Sharing Security Gotcha

232 Views

In an Office 365 Tenant, you must be careful with External Sharing in a few different scenarios:

1) If your organization has migrated from an existing on premise Farm in which you used “NT AuthorityAuthenticated Users” to grant permissions

2) If your organization is making use of External sharing via “Everyone” (including external users) in Office 365

If your organization’s Office 365 Admin has allowed External Sharing for Authenticated Users:

1

And has also enabled External Sharing on 1 or more External Site Collections:

1

If a Site user shares anything (a document, folder, library, site etc.) with an external user:

3

That user become part your Organization’s Office 365 Tenant Directory.

Once part of this Directory, Any Site Collection that is configured for External Sharing and has permissions granted to securables via “NT AuthorityAuthenticated Users” or “Everyone” will now be available to all External Users (as well as organization users) with whom anyone at your company has shared anything with

5Be extremely careful to review your permissions before opening up external sharing!

Leave a Reply

Your email address will not be published. Required fields are marked *