Skip to content

Control 2.12: External Sharing and Guest Access Governance — Verification & Testing

Test cases and evidence collection for validating external sharing controls.

Test Cases

Test 1: External Sharing Block Verification

  • Objective: Confirm external sharing is blocked on Copilot-scoped sites
  • Steps:
  • Select a site on the Copilot RSS allowed list
  • Attempt to share a document with an external user
  • Verify the sharing is blocked by policy
  • Verify the block is logged in audit trail
  • Expected Result: External sharing blocked on Copilot-scoped sites
  • Evidence: Sharing block screenshot and audit log

Test 2: Guest Access Review Completion

  • Objective: Verify guest access reviews are completing on schedule
  • Steps:
  • Navigate to Entra ID > Identity Governance > Access Reviews
  • Verify active reviews are on schedule
  • Confirm completion rate exceeds 95%
  • Verify denied access has been removed from the reviewed resource
  • Verify alternate access paths through Microsoft 365 groups, security groups, Teams, applications, direct permissions, and sharing links are separately reconciled
  • Expected Result: Reviews complete on schedule, changes are applied to the reviewed resource, and surviving access paths are explicitly resolved or approved
  • Evidence: Access review completion records and access-path reconciliation record

Test 3: SharePoint/OneDrive Guest-Access Expiration

  • Objective: Verify the limited scope of SharePoint/OneDrive guest expiration without misrepresenting it as complete access removal or Entra guest-account deletion
  • Steps:
  • Review ExternalUserExpirationRequired and ExternalUserExpireInDays
  • Confirm site-level overrides are documented
  • Confirm the test uses direct site permission or sharing-link access granted after the policy was enabled
  • Inventory pre-existing direct or sharing-link access separately
  • Inventory Microsoft 365 group, security group, and Teams membership that can preserve access to a group-connected site or related content
  • Verify the renewal or removal process for each access path
  • Confirm the evidence states that SharePoint guest-access expiration does not alter or delete the Entra B2B account
  • Expected Result: Eligible direct or sharing-link access expires according to policy; surviving pre-existing, Microsoft 365 group, security group, and Teams access is separately identified and reconciled; the Entra account lifecycle remains governed independently
  • Evidence: Tenant setting export, policy enablement date, site override record, expiration notification or test record, and group/Teams membership reconciliation

Test 4: Guest Account Lifecycle Review

  • Objective: Verify any tenant-wide B2B guest-account action is decided separately from resource access reviews
  • Steps:
  • Confirm every Team, group, application, and other resource-scoped review is configured with no account-level denied-guest action: no sign-in block and no guest-account deletion
  • Confirm denial removes only the reviewed resource's membership or access
  • Confirm account blocking or deletion, if required, is handled through a separate dedicated guest-lifecycle review
  • Verify the lifecycle review checks direct permissions, sharing links, Microsoft 365 groups, security groups, Teams, SharePoint access, application assignments, and other active engagements
  • Confirm every access path and engagement is obsolete and required approvals are recorded before an account-level action
  • Expected Result: No tenant-wide account block or deletion is based solely on a resource-review denial
  • Evidence: Resource-review results, access-path reconciliation, guest-lifecycle review record, and account-action approval
  • Objective: Confirm anonymous sharing links cannot be created
  • Steps:
  • As a standard user, attempt to create an "Anyone with the link" sharing link
  • Verify the option is not available
  • Repeat on multiple site types
  • Expected Result: Anonymous link creation is blocked organization-wide
  • Evidence: Screenshot showing unavailable sharing option

Evidence Collection

Evidence Item Format Storage Location Retention
External sharing configuration CSV Compliance evidence repository 7 years
Guest user inventory CSV Compliance evidence repository 7 years
Access review records PDF Compliance evidence repository 7 years
Guest-access expiration configuration PDF/CSV Compliance evidence repository 7 years
Guest group, security-group, and Teams access reconciliation CSV/PDF Compliance evidence repository 7 years
Sharing block test results PDF Compliance evidence repository 7 years

Compliance Mapping

Regulation Requirement How This Control Supports It
SEC Regulation S-P Third-party information sharing External sharing controls support compliance with NPI sharing restrictions
GLBA §501(b) Access controls for NPI Guest access governance helps meet safeguards requirements
FINRA Rule 3110 Supervisory systems and WSPs External sharing restrictions support compliance with supervisory controls
- Back to Control 2.12