Skip to content
akTeams
  • Home
  • Services
  • Articles
    • SharePoint
    • Microsoft Teams
    • Microsoft 365
    • Microsoft Viva
    • Machine Learning
  • About
    • Contact
akTeams
  • About
  • Articles
  • Attribution
  • Cart
  • Checkout
  • Contact Us
  • Cookie Policy (US)
  • Home
  • My account
  • Our Services
  • Privacy Policy
  • QuickBooks
  • Shop

SharePoint Online External Sharing Misconfiguration

/ Microsoft 365, SharePoint / By AKTeams

The is a discrepancy found in Microsoft 365 SharePoint external sharing configuration.

Let say, a sharing policy is configured at tenant level that restricts external sharing with “New and existing guests” and limits external sharing by domain:

 

But that is not enough. A site collection must be allowed to be shared also:

And when we are configuring Site Collection Sharing settings – we are not able to set “Site content can be shared with” higher that tenant level. But “Limit sharing by domain” still can be configured On or OFF (remember at tenant level it is set to ON).

So technically it is possible to not to limit site collection sharing by domains. 

Does that mean that external users from any domain can have access to this site? 
No. They will get an error message “Something went wrong. The organization that owns this resource has a policy that prevents access from people in the domain you’re currently signed in to. If you think you should have access, please contact the person who sent you the link to this resource“

References

  1. Policy that prevents access from people in the domain you’re currently signed in to
  2. Microsoft: External sharing overview


← Previous Post
Next Post →

Search

Categories

  • AI
  • eCommerce
  • Machine Learning
  • Microsoft 365
  • Microsoft Teams
  • Microsoft Viva
  • SharePoint
  • Uncategorized

Tags

Acer Aspire V5 AI App Secret Azure Certificate color scheme Custom Scripts diagnostics e-Commerce External Access External sharing Free Governance group privacy group visibility Guest Access Hints Information Security KBA m365 Metadata Management Microsoft Forms Microsoft Search Microsoft Teams ML OneDrive Permissions Phishing PowerShell Roadmap Search Search Answers Search Bookmarks sensitivity labels SEO SharePoint-Syntex SharePoint Search Site Pages SPO theme tips-and-tricks Troubleshooting Viva Viva Engage Yammer

Copyright © 2025 akTeams

Manage Cookie Consent
We use cookies to optimize our website and our service.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
Manage options Manage services Manage {vendor_count} vendors Read more about these purposes
View preferences
{title} {title} {title}