Ensure link sharing is restricted in SharePoint and OneDrive
Why This Matters
When sharing links default to broad access levels like "Everyone" or "People in your organization," users may unintentionally expose sensitive data beyond their intended audience. This misconfiguration increases the risk of data leakage and violates the least privilege principle, which requires that access be granted only to those who explicitly need it. By defaulting to "Specific people," you encourage thoughtful sharing decisions and reduce the surface area for accidental oversharing.
What Aether365 Checks
Aether365 verifies that the default sharing link type in SharePoint and OneDrive is set to "Specific people (only the people the user specifies)," as recommended by the CIS Microsoft 365 Foundations Benchmark. This check appears in the Aether365 dashboard under the microsoft-365 checks category.