
Collaboration suites like M365 offer unparalleled convenience. Millions of teams rely on them to quickly share documents with coworkers, clients and business partners. Yet when sharing is this easy, data security becomes a lot harder.
Cloud sharing is so integral to the modern workplace that it’s difficult to imagine how offices ever got by without it. Dropping files in one-on-one chats. Spreadsheets that live in Teams channels so everyone can see the latest figures. Throwing project folders on SharePoint and sending out invite links.
Yet for all the ways that cloud sharing has revolutionized office life, remote work and long-distance collaboration, there is a downside.
With the usage of cloud platforms exploding over recent years, visibility into sharing is falling further and further behind. Many organizations no longer have any idea who their users are sharing potentially sensitive information with.
Sharing moves fast. How security can keep up
Unmanaged cloud sharing is a shockingly common problem in enterprise environments. Anywhere organizations use Microsoft 365 to share access, security teams struggle to identify and rein in problematic cloud access.
In a survey by Wire, 61% of security leads reported that access to shared files often remains active longer than intended. Over a third acknowledge difficulties in even identifying who has access to sensitive shared files.
One factor that makes cloud sharing difficult to evaluate from a security perspective is how context-driven the use of sharing features is. Employees share files with a specific purpose in mind, whether it’s to coordinate with a coworker or get approval from a client on a design mockup.
The problem is that shared access often outlives or outgrows its original purpose: A freelancer could be taken off a project, but never removed from the project folder in SharePoint. Members may invite new users into a Teams channel, forgetting that they will get access to every file hosted within it.
The highly contextual nature of cloud sharing means the only way to know for certain whether shared access is still needed is to ask the person who originally provided it. Access reviews are an essential safeguard, and looping file or channel owners into the review process leads to faster and more accurate audits.
The challenge is in how to implement this process with the available tools of the platform.
The problem with built-in governance tools
The lack of control over shared data presents a growing and often underappreciated security risk in enterprise environments. At the same time, you can hardly blame teams for making full use of sharing features, the central pillar that cloud suites are built around. The problem of unmanaged cloud sharing is not so much about user behavior as it is insufficient governance features built into Microsoft 365.
Microsoft 365 provides two reporting options that offer visibility into shared data, but both come with major limitations.
You can generate a global report on sharing links using SharePoint Advanced Management, but this only tells you which sites had the most new links created in the last 28 days. By itself, that figure does not give you enough context to draw any useful conclusions. A high number of new links could point to misuse, or it could simply be due to a project with outside involvement, such as onboarding a new supplier.
Similarly, you can create site-level sharing reports to get a CSV table showing every shared file within a site and everyone who has access to it. However, running this report across every SharePoint and OneDrive in your organization is incredibly time-consuming. So is manually sifting through these files to identify problematic sharing.
Ultimately, both reporting options require you to do most of the legwork, whether it’s piecing together site-level reports into a cohesive whole or investigating the spike in sharing links you’ve seen in a global activity report.
What Microsoft 365 is missing is a centralized dashboard for access governance that gives you the full picture without all this added effort – allowing you to zoom in or out on the fly. This is where dedicated Identity & Access Governance solutions like tenfold bridge the visibility gap left by native reporting tools.
tenfold: Full visibility and central governance for shared files
As part of its deep integration with the Microsoft cloud and on-prem ecosystem, tenfold offers purpose-built reporting tools that provide full visibility into shared files across Teams, OneDrive and SharePoint. Two standout features put tenfold’s shared content governance ahead of other IGA platforms:
- A central breakdown of all shared content that gives you both high-level insights and object-level details in one place. Filter by app, user, site or more to quickly identify issues. Notable details, such as files being shared outside their Team or channel, are marked with icons to clearly distinguish potential issues.
- A streamlined access review process for shared content, prompting data owners to check and confirm who has access to files they shared. Each reviewer receives a personalized review dashboard of shared items and who currently has access to them. This lets reviewers quickly confirm or revoke access, making it easy to delegate the review process even to users in non-IT roles.
With in-depth visibility into cloud sharing and an effective review process to stop shared access from outliving its intended purpose, tenfold allows you to make full use of cloud collaboration features without putting your data at risk.
Regain control of shared files with the leading no-code IGA solution. Book a personal demo with our team to learn more.
Sponsored and written by tenfold Software.








English (US) ·