Expiration Times for Guest Access to a Site SHOULD Be Determined by specific needs
Last updated
Last updated
SharePoint allows sharing with users who are outside the agency, which is convenient but may pose a data loss or other information security risk. This working group recommends setting an expiration time for guest access to the site or OneDrive
Expiration timers for ‘guest access to a site or OneDrive’ and ‘people who use a verification code’ SHOULD be set.
Expiration timers SHOULD be set to 30 days.
Any tenant with SharePoint online licensing can access this setting.
To limit external sharing by domain, in the SharePoint admin center:
Select Policies -> Sharing.
Expand More external sharing settings.
Select Guest access to a site or OneDrive will expire automatically after this many days.
Enter “30” days.
Select People who use a verification code must reauthenticate after this many days.
Enter “30” days.
• Users may have to reshare new links if the existing ones expire before the interaction with external users is complete.
None Currently