Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchPC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11SharePoint Online data security combines normal site permissions with identity controls, sharing restrictions, content protection, and monitoring. For especially sensitive sites, Restricted site access control adds a second access condition: users must have normal SharePoint permission and belong to an approved Microsoft 365 or Microsoft Entra group.
This guide covers practical controls for SharePoint in Microsoft 365, including restricted site access, sensitivity labels, permissions, sharing, and governance reports. The cited controls and paths apply to SharePoint Online; do not assume the same features or UI paths are available in SharePoint Server on-premises.
What SharePoint Data Security Actually Means
SharePoint data security is about preventing unauthorized access and accidental exposure, limiting unwanted changes, protecting sensitive files, detecting suspicious activity, and responding to incidents.
For a security review, answer these questions:
- Who can access which content? Review permissions, inheritance, group membership, and external access.
- Can users share it outside the organization? Review link types, guest access, and domain restrictions.
- How is sensitive content protected? Review file labels, encryption, retention, and access enforcement.
- Can the organization detect risky behavior? Review audit logs, alerts, and DLP coverage.
- What happens during an incident? Plan how to revoke access, contain exposure, and preserve evidence.
Core Security Model in SharePoint (Microsoft 365)
SharePoint Online security uses Microsoft 365 identity and authorization controls. The main layers are:
#1 Best Overall
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
- Identity: Microsoft Entra ID authentication, MFA, and Conditional Access.
- Authorization: SharePoint permissions and group membership.
- Content controls: Sensitivity labels, encryption, and retention.
- Governance: DLP, retention policies, and lifecycle management.
- Monitoring: Audit logs and investigation tools in Microsoft Purview.
Permissions determine who can open content. File labels can apply protection to supported content, while auditing and DLP help detect or respond to risky activity. A site label is a container setting; it does not automatically label every file in the site.
Prerequisites Before You Change Anything
Before tightening SharePoint, confirm your deployment and existing settings. Aggressive permission changes can disrupt legitimate access or integrations.
Know your deployment and tenant settings
- Confirm that you use SharePoint Online rather than an on-premises SharePoint Server farm.
- Identify existing sensitivity labels, DLP policies, and retention policies.
- Inventory site owners, SharePoint administrators, and third-party apps with permissions.
Get the right admin roles
You may need access to the SharePoint admin center and Microsoft Purview. Use least privilege when assigning administrative roles.
Decide your acceptable sharing stance
Set a policy for tenant and site external sharing, guest invitations, link types, partner domains, sign-in requirements, and expiration. Validate the effective settings on important sites.
Secure Sharing: External Access, Links, and Invitations
External sharing can expose data when misconfigured. Decide which users and link types are appropriate for each category of content rather than relying on one setting for every site.
Choose the right external sharing model
- Prefer named guest accounts for higher-risk content so access can be tied to an identity.
- Allow sharing links only where needed, with sign-in, domain, or expiration controls consistent with policy.
- Consider Restricted site access control for sites where access should be limited to a defined group of already-authorized users.
Configure sharing settings in SharePoint admin center
- Review tenant-level external sharing settings.
- Review whether users can create Anyone links and whether those links are appropriate.
- Set permitted external domains if your policy uses a partner allowlist.
- Set link expiration and sign-in requirements according to policy.
- Check site-level settings as well as tenant settings, then test access with representative accounts.
Important: Restricted site access control does not, by itself, block sharing outside its control groups. That is a separate tenant setting, described below.
Restricted Site Access Control
Restricted site access control adds an access condition to a site. A user must both have normal SharePoint permission to the site or content and belong to one of the site’s specified Microsoft 365 or Microsoft Entra security groups. Adding someone to the restricted-access group does not grant SharePoint permissions.
Configure restricted site access
- Open the SharePoint admin center, expand Sites, and select Active sites.
- Select the target site and open the Settings tab in its details panel.
- Under Restricted site access, select Edit.
- Select Restrict SharePoint site access to only users in specified groups.
- Add or remove the approved Microsoft Entra security groups or Microsoft 365 groups, then select Save.
Users outside those groups cannot access the site or content even if they had prior permission or a shared link. A site can have up to 10 groups in this policy, including dynamic Microsoft Entra security groups. On a Microsoft 365 group-connected site, the connected group is the default restricted-access group.
Private-channel and shared-channel sites are not connected to the parent team’s Microsoft 365 group, so configure them separately. For shared-channel sites, manage Teams channel membership and SharePoint restricted-access membership consistently.
Optional sharing restriction and administration
To also prevent users outside the control groups from sharing the site or its content, a SharePoint administrator can use SharePoint Online Management Shell:
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Set-SPOTenant -AllowSharingOutsideRestrictedAccessControlGroups $false
When enabled, sharing is blocked with groups not included in the site’s restricted-access list, including Everyone except external users and SharePoint groups. Groups included in the list, and nested security groups that are part of them, remain allowed for sharing.
Delegation of restricted-access management to site administrators is off by default. An administrator can enable it with Set-SPOTenant -DelegateRestrictedAccessControlManagement $true and check it with Get-SPOTenant | Select-Object DelegateRestrictedAccessControlManagement. In Microsoft 365 Multi-Geo, run the command separately for each required geo-location.
Permissions and Access Control
Broad groups, unnecessary direct assignments, and complicated inheritance make access difficult to review. Use groups aligned to job functions and periodically check who can reach sensitive libraries.
Use groups and minimize permission exceptions
Prefer group-based access over individual assignments where practical. Review libraries, folders, and files with unique permissions and consolidate exceptions that are no longer needed.
Understand common roles
- Read: View access; downloading may still be possible depending on controls and client behavior.
- Contribute or Edit: Allows changes, with capabilities depending on the role and context.
- Design or Full Control: Broad capabilities within the assigned scope; grant sparingly.
Practical permission design pattern
- Separate major data domains, such as HR, Finance, and Legal, into appropriately governed sites.
- Use libraries for clear content boundaries where appropriate.
- Create groups that map to job functions rather than relying on individual assignments.
- Grant only the access required and remove obsolete membership promptly.
- Review permissions on sensitive sites on a cadence that fits risk and user churn.
Sensitivity Labels, Encryption, and Content Protection
Sensitivity labels can classify files and, depending on configuration, apply encryption and usage restrictions. File labeling must be configured separately from a sensitivity label applied to a SharePoint site: a site label does not automatically label all documents inside it.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Enable processing for SharePoint and OneDrive files
In the Microsoft Purview portal, go to Solutions > Information Protection > Sensitivity labels. If prompted to process Office online files, select Turn on now. A SharePoint administrator can also enable processing with SharePoint Online Management Shell version 16.0.19418.12000 or later using Set-SPOTenant -EnableAIPIntegration $true. Tenant changes generally take about 15 minutes to take effect.
For Microsoft 365 Multi-Geo, connect to and configure each geo-location separately for supported commands. OneNote label support uses Set-SPOTenant -EnableSensitivityLabelforOneNote $true with shell version 16.0.26914.12004 or later; this command does not support Multi-Geo.
Supported scenarios and limitations
SharePoint and OneDrive can process supported Office files and, when PDF support is enabled, supported PDF files encrypted with a sensitivity label using a cloud-based key. HYOK and Double Key Encryption files are unsupported for SharePoint content processing. Password-protected documents cannot have labels read or applied by SharePoint and OneDrive. Files encrypted by directly applying a Rights Management template rather than a sensitivity label cannot be opened in Office for the web.
For an encrypted file uploaded to SharePoint to be recognized and processed, the uploader needs at least the View usage right. External users can access label-encrypted files through guest accounts. Supported label-encrypted files can be inspected by DLP and searched in eDiscovery.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Rank #3
- NIST Certification: FIPS 140-3 validated for government and regulated organizations (Overall Level 2, Physical Security Level 3).
- Works with 1000+ Accounts: Supported by Google and Microsoft accounts, Identity Access Managers, password managers and 1000+ popular services. It works with operating systems and browsers including Windows, macOS, Chrome OS, Linux, Chrome, and Edge.
- Fast & convenient login: Plug in your YubiKey via USB-A and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required.
- Most secure passkey: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
- Built to last: Made from tough, waterproof, and crush-resistant materials. Made in Sweden with the highest security standards.
PDF support
PDF support can be enabled in Microsoft Purview under Solutions > Information Protection > Sensitivity labels > Policies > Auto-labeling policies, using the Protect PDFs with Auto-labeling banner when it is shown. The PowerShell alternative is Set-SPOTenant -EnableSensitivityLabelforPDF $true, requiring SharePoint Online Management Shell version 16.0.24211.12000 or later. Signed PDFs are not supported. Auto-labeling policies support a maximum of 100,000 files per day.
Test labels before broad rollout
Existing encrypted files do not automatically gain all newly enabled SharePoint capabilities; they may need to be downloaded and uploaded again or edited. Microsoft recommends publishing new labels to a small test group, waiting at least one hour to verify behavior, and waiting at least one day before broad publication.
Encrypted Office files larger than 12 MB copied or moved to another site may no longer be processed by SharePoint. Office for the web does not support printing, downloading, exporting, or copying encrypted documents, and it cannot prevent screen captures. Test supported file types, clients, and workflows before relying on a label for a specific control.
Extend Permissions to Downloaded Files
SharePoint Online has an optional feature to extend protection to certain files downloaded, copied, or moved from a library. It requires tenant enablement and library configuration, and it has important usage limitations.
- Use SharePoint Online Management Shell version 16.0.25430.12000 or later and enable the feature with Set-SPOTenant -ExtendPermissionsToUnprotectedFiles $true. The feature may not yet be available in a tenant during rollout; Multi-Geo tenants must run the command separately for each geo-location.
- In the library’s sensitivity-label settings, select Extend protection on download, copy or move. This option appears only after tenant enablement.
- Use a label with encryption and user-defined permissions, configured to let users assign permissions or prompt users to specify permissions in Office apps. In the library scenario, SharePoint applies permissions automatically.
| SharePoint permission | Resulting rights |
|---|---|
| Owner | Full content and label control; mapped to Owner |
| Edit | Can control content but cannot change the applied label; mapped to Editor |
| Read | Can view and copy but cannot edit content or change the label; closest equivalent is Viewer |
Files protected this way cannot be opened offline or if the original site, folder, or file is deleted. They cannot be copied or moved to another site. Copying or moving within the same site has additional permissions requirements and does not retain the label. The feature is incompatible with a non-encrypting default library label and with admin-defined Assign permissions now labels. Review Microsoft’s limitations before deploying it to a workflow.
Data Loss Prevention (DLP) for SharePoint
Microsoft Purview DLP policies can detect sensitive information and apply configured actions such as notification, restriction, or blocking. Confirm that the policy covers the SharePoint locations and file types that matter, and test with representative content.
- Start in audit mode to assess detections and false positives.
- Review policy matches and tune conditions and exceptions.
- Apply enforcement to higher-risk data categories when the results are understood.
- Maintain a documented exception and approval process.
Auditing, Reports, and Investigation Workflows
Audit logs help reconstruct sharing, access, and administrative activity. For organization-wide permission exposure analysis, Data access governance reports provide a separate view of site permissions.
Use Data access governance reports
SharePoint Advanced Management is required for the Data access governance snapshot reports. From the Data access governance landing page, under Site permissions across your organization, select View reports, then Create report for the first report. Later, select Run reports when enabled and use View report under SharePoint or OneDrive.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →SharePoint and OneDrive reports are separate. The first report can take up to 5 days; later reports complete within 24 hours, and data may be up to 48 hours old. Reports can be run again every 30 days. NoAccess sites and archived sites are excluded; unlocked and ReadOnly sites are included.
Reports cover permissioned users and groups, broken inheritance, guest and external participant permissions, Anyone and organization-wide links, and Everyone permissions. The detailed view shows the top 100 sites by number of users with permissions; CSV export supports offline analysis of up to 1 million sites. Link and Everyone except external users counts indicate potential exposure, not necessarily users who have accessed content.
Restricted-access reports
SharePoint Online Management Shell can generate restricted-site and access-denial reports using Start-SPORestrictedAccessForSitesInsights -RACProtectedSites and Start-SPORestrictedAccessForSitesInsights -ActionsBlockedByPolicy. The denial reports can show recent denials, top users, top sites, and distribution by site type. The downloaded report supports up to 10,000 denials; on-screen views are limited to documented top-100 results.
Rank #4
- NIST Certification: FIPS 140-3 validated for government and regulated organizations (Overall Level 2, Physical Security Level 3).
- Works with 1000+ Accounts: Supported by Google and Microsoft accounts, Identity Access Managers, password managers and 1000+ popular services. It works with operating systems and browsers including Windows, macOS, Chrome OS, Linux, Chrome, and Edge.
- Fast & Convenient Login: Plug in your YubiKey via USB-C and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required.
- Most Secure Passkey: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
- Built to Last: Made from tough, waterproof, and crush-resistant materials. Made in Sweden with the highest security standards.
Build an investigation runbook
- Identify the affected site, library, folder, or file.
- Determine who accessed or shared it and when using available records.
- Check whether access came from inherited or unique permissions, a guest, or a link.
- Check the content’s label and whether DLP triggered.
- Contain exposure by revoking access or restricting site sharing as appropriate.
- Preserve relevant records and address the underlying permission, sharing, labeling, or identity issue.
Network, Device, and Identity Controls That Affect SharePoint
SharePoint security is also affected by authentication and device posture. Use Entra ID Conditional Access and MFA in line with organizational risk and policy, and review risky sign-ins and sessions. If you use Microsoft Defender for Cloud Apps or similar monitoring, include SharePoint activity in your visibility scope.
Free tools Windows power users keep installed
One-click scans. No signup required.
Protection Against Ransomware and Malware
Malware and ransomware risks can involve malicious files or compromised accounts uploading content. Combine endpoint and email protection with least-privilege SharePoint access. Limit write access to users who need it and keep administrative actions restricted.
Operational Security for Admins and Power Users
Govern who creates sites, who administers them, and which applications can access content. Set appropriate naming, ownership, permission, and lifecycle practices. Review third-party app permissions and separate business content ownership from security administration where practical.
Incident Response: When Something Goes Wrong
When you suspect exposure, contain access, preserve evidence, and remediate the root cause.
- Restrict external sharing on the affected site if emergency policy allows.
- Revoke access for affected users or guests and remove suspicious permissions.
- Identify affected files and preserve relevant audit and activity records.
- Determine whether the cause was a permission, sharing, labeling, DLP, or identity gap.
- Correct the cause and verify the effective access settings.
Common Misconfigurations and How to Fix Them
Anyone links enabled for sensitive content
Review whether anonymous links are appropriate. Where policy requires it, disable their creation and require sign-in for external access.
Recommended Free Tools
Unique permissions spread across many folders
Consolidate permissions and use group-based site or library access where practical.
Assuming a site label labels all its files
A sensitivity label on a site controls container settings; configure file labeling separately.
Assuming restricted access control grants permissions or blocks every share
Users still need normal SharePoint permission as well as membership in an allowed group. Blocking sharing outside those groups is a separate tenant option.
Assuming encrypted files always work in Office for the web
Unsupported encryption modes, direct Rights Management templates, password protection, processing delays, or file limitations can prevent web processing. Test the actual labels and file types in use.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problemsComparison: SharePoint vs OneDrive vs Teams File Storage
SharePoint, OneDrive, and Teams files are connected but have different governance contexts. Align controls rather than assuming one setting covers every use.
Best Value
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
| Storage | Primary use | Security emphasis |
|---|---|---|
| SharePoint | Shared team and department content | Site and library permissions, external sharing, and labeling |
| OneDrive | Personal work content | Sharing links, permissions, and device or session controls |
| Teams files | Collaboration within Teams | Channel/site permissions, retention, and governance alignment |
Teams channel files are stored in SharePoint, but channel type and site structure affect how access is managed. In particular, private- and shared-channel sites require separate attention when configuring restricted site access control.
FAQ
Can I prevent users from downloading SharePoint documents?
Available controls depend on the label, permissions, file type, and client. The optional Extend protection on download, copy or move feature can extend certain label protections, but it has limitations: protected files may require connection to the original site and cannot be copied to another site. Validate the specific behavior your policy requires.
Does a sensitivity label on a SharePoint site label every file inside it?
No. A label applied to a site is a container label and does not automatically label documents. Configure file labeling separately.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallOutdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchDoes restricted site access control give its group members access?
No. Members must also have normal SharePoint permission. Restricted site access control is an additional condition that limits which already-authorized users can access the site.
Does restricted site access control automatically block sharing outside its groups?
No. Blocking sharing outside the groups is a separate tenant setting. Configure it only if required by your sharing policy.
Why might an encrypted file not open in Office for the web?
HYOK or Double Key Encryption, directly applied Rights Management templates, unsupported label settings, password protection, processing delays, or certain file limitations can prevent processing. Test the relevant files and workflows before relying on web access.
How current are Data access governance reports?
Report data may be up to 48 hours old when generated. The first report can take up to 5 days, later reports within 24 hours, and reports can be run again every 30 days.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Bottom Line
SharePoint Online security works best as a layered system: strong identity controls, least-privilege permissions, deliberate sharing settings, correctly configured file labels, and monitoring with a response plan. Restricted site access control can add a valuable group-based access condition, but it neither grants normal SharePoint permissions nor blocks all sharing by itself.
Start by reviewing external sharing and sensitive-site permissions, configure file labeling separately from site labels, and use Data access governance reports to identify potential exposure. Test protection and enforcement with the file types and clients your organization actually uses.
Quick Recap
Sources
- Microsoft: Restricted site access control
- Microsoft: Sensitivity labels for SharePoint and OneDrive files
- Microsoft: Extend SharePoint permissions to downloaded files
- Microsoft: Data access governance site permissions report
- Microsoft: Secure access with sensitivity labels
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




