Control 4.4: Guest and External User Access Controls - Portal Walkthrough
This playbook provides portal configuration guidance for Control 4.4.
Prerequisites
Before starting, ensure you have:
- SharePoint Admin role assigned
- Microsoft 365 E3/E5 license
- Current sharing settings documented
- Site inventory with governance classifications available
Step 1: Inventory Current Sharing State
Assess current external sharing:
- Navigate to SharePoint Admin Center
- Go to Reports > Data access governance
- View "Site permissions across your organization" report
- Identify sites with guest access enabled
- Export report for analysis
- Cross-reference with governance classification
Step 2: Configure Site-Level Restrictions
For Regulated/Sensitive Sites (Zone 3)
- Navigate to Sites > Active sites
- Select the site
- Open Settings tab
- Set "External file sharing" to Only people in your organization
- Repeat for all regulated/sensitive sites
For Collaborative Sites (Zone 2)
- Set "External file sharing" to Existing guests at most
- Document any approved guest access with business justification
Step 3: Configure Organization Policies
Set organization defaults:
- Navigate to Policies > Sharing
- Configure external sharing level:
- Baseline: "Existing guests" or more restrictive
- Regulated: "Only people in your organization"
- Enable guest access expiration (30 days recommended)
- Set default link type to Internal
- Enable link expiration requirements (30 days maximum)
Step 4: Configure Guest Access Expiration
- Navigate to Policies > Sharing
- Enable "Guest access to a site or OneDrive will expire automatically"
- Set expiration period:
- Zone 1: 90 days
- Zone 2: 30 days
- Zone 3: Not permitted (external sharing disabled)
Step 5: Configure Domain Restrictions (Optional)
For approved partner collaboration:
- Navigate to Policies > Sharing
- Under "Advanced settings for external sharing"
- Select "Limit external sharing by domain"
- Choose "Allow only specific domains"
- Add approved partner domains
Step 6: Implement Monitoring
Establish ongoing monitoring:
- Schedule weekly review of sharing reports
- Navigate to Reports > Data access governance
- Review "Sharing links" report
- Review "Site permissions across your organization"
- Document all guest access approvals
Governance Level Configurations
Baseline (Level 1)
| Setting | Value |
|---|---|
| Organization sharing | Existing guests or more restrictive |
| Sensitive sites | External sharing disabled |
| Monitoring | Monthly sharing report review |
Recommended (Level 2-3)
| Setting | Value |
|---|---|
| Guest expiration | 30 days |
| Link expiration | 30 days maximum |
| Default link type | Internal |
| Monitoring | Weekly sharing report review |
Regulated (Level 4)
| Setting | Value |
|---|---|
| Organization sharing | Existing guests only |
| Regulated sites | External sharing disabled |
| Conditional Access | MFA required for guests |
| Guest access reviews | Quarterly certification |
Validation
After completing the configuration, verify:
- Organization-level sharing settings configured appropriately
- Zone 3 sites have external sharing disabled
- Guest access expiration enabled with appropriate timeframes
- Default link type set to Internal
- Domain restrictions configured (if applicable)
- Sharing reports accessible and showing expected data
- Test external sharing attempt blocked on regulated site
Expected Result: External sharing is appropriately restricted based on site classification, guest access expires automatically, and sharing activity is visible in governance reports.
Back to Control 4.4 | PowerShell Setup | Verification Testing | Troubleshooting
Updated: January 2026 | Version: v1.2