Control 2.12: External Sharing and Guest Access Governance — Verification & Testing
Test cases and evidence collection for validating external sharing controls.
Test Cases
Test 1: External Sharing Block Verification
- Objective: Confirm external sharing is blocked on Copilot-scoped sites
- Steps:
- Select a site on the Copilot RSS allowed list
- Attempt to share a document with an external user
- Verify the sharing is blocked by policy
- Verify the block is logged in audit trail
- Expected Result: External sharing blocked on Copilot-scoped sites
- Evidence: Sharing block screenshot and audit log
Test 2: Guest Access Review Completion
- Objective: Verify guest access reviews are completing on schedule
- Steps:
- Navigate to Entra ID > Identity Governance > Access Reviews
- Verify active reviews are on schedule
- Confirm completion rate exceeds 95%
- Verify denied access has been removed from the reviewed resource
- Verify alternate access paths through Microsoft 365 groups, security groups, Teams, applications, direct permissions, and sharing links are separately reconciled
- Expected Result: Reviews complete on schedule, changes are applied to the reviewed resource, and surviving access paths are explicitly resolved or approved
- Evidence: Access review completion records and access-path reconciliation record
Test 3: SharePoint/OneDrive Guest-Access Expiration
- Objective: Verify the limited scope of SharePoint/OneDrive guest expiration without misrepresenting it as complete access removal or Entra guest-account deletion
- Steps:
- Review
ExternalUserExpirationRequired and ExternalUserExpireInDays
- Confirm site-level overrides are documented
- Confirm the test uses direct site permission or sharing-link access granted after the policy was enabled
- Inventory pre-existing direct or sharing-link access separately
- Inventory Microsoft 365 group, security group, and Teams membership that can preserve access to a group-connected site or related content
- Verify the renewal or removal process for each access path
- Confirm the evidence states that SharePoint guest-access expiration does not alter or delete the Entra B2B account
- Expected Result: Eligible direct or sharing-link access expires according to policy; surviving pre-existing, Microsoft 365 group, security group, and Teams access is separately identified and reconciled; the Entra account lifecycle remains governed independently
- Evidence: Tenant setting export, policy enablement date, site override record, expiration notification or test record, and group/Teams membership reconciliation
Test 4: Guest Account Lifecycle Review
- Objective: Verify any tenant-wide B2B guest-account action is decided separately from resource access reviews
- Steps:
- Confirm every Team, group, application, and other resource-scoped review is configured with no account-level denied-guest action: no sign-in block and no guest-account deletion
- Confirm denial removes only the reviewed resource's membership or access
- Confirm account blocking or deletion, if required, is handled through a separate dedicated guest-lifecycle review
- Verify the lifecycle review checks direct permissions, sharing links, Microsoft 365 groups, security groups, Teams, SharePoint access, application assignments, and other active engagements
- Confirm every access path and engagement is obsolete and required approvals are recorded before an account-level action
- Expected Result: No tenant-wide account block or deletion is based solely on a resource-review denial
- Evidence: Resource-review results, access-path reconciliation, guest-lifecycle review record, and account-action approval
Test 5: Anonymous Link Prevention
- Objective: Confirm anonymous sharing links cannot be created
- Steps:
- As a standard user, attempt to create an "Anyone with the link" sharing link
- Verify the option is not available
- Repeat on multiple site types
- Expected Result: Anonymous link creation is blocked organization-wide
- Evidence: Screenshot showing unavailable sharing option
Evidence Collection
| Evidence Item |
Format |
Storage Location |
Retention |
| External sharing configuration |
CSV |
Compliance evidence repository |
7 years |
| Guest user inventory |
CSV |
Compliance evidence repository |
7 years |
| Access review records |
PDF |
Compliance evidence repository |
7 years |
| Guest-access expiration configuration |
PDF/CSV |
Compliance evidence repository |
7 years |
| Guest group, security-group, and Teams access reconciliation |
CSV/PDF |
Compliance evidence repository |
7 years |
| Sharing block test results |
PDF |
Compliance evidence repository |
7 years |
Compliance Mapping
| Regulation |
Requirement |
How This Control Supports It |
| SEC Regulation S-P |
Third-party information sharing |
External sharing controls support compliance with NPI sharing restrictions |
| GLBA §501(b) |
Access controls for NPI |
Guest access governance helps meet safeguards requirements |
| FINRA Rule 3110 |
Supervisory systems and WSPs |
External sharing restrictions support compliance with supervisory controls |
| - Back to Control 2.12 |
|
|