Secure corporate sharing with access reviews for Microsoft 365

Secure corporate sharing with access reviews for Microsoft 365

tenfold upload

Collaboration suites like M365 offer unparalleled convenience. Millions of teams rely on them to quickly share documents with colleagues, customers and business partners. But when sharing is so easy, data security becomes much more difficult.

Cloud sharing is so integral to the modern workplace that it’s hard to imagine how offices could ever function without it. Deleting files in individual chats. Spreadsheets stored in Teams channels so everyone can see the latest numbers. Throw project folders on SharePoint and send invitation links.

But for all the ways cloud sharing has revolutionized office life, remote work and long-distance collaboration, there is also a downside.

As the use of cloud platforms has exploded in recent years, transparency around sharing is falling further and further behind. Many companies no longer have any idea who their users share potentially sensitive information with.

Sharing is quick. How security can keep up

Unmanaged cloud sharing is a shockingly common problem in enterprise environments. Wherever organizations use Microsoft 365 for shared access, security teams struggle to identify and contain problematic cloud access.

In a Wire survey, 61% of security leaders said access to shared files often remains active longer than intended. More than a third admit they have difficulty even determining who has access to sensitive shared files.

One factor that makes cloud sharing difficult to evaluate for security reasons is the contextual use of sharing features. Employees share files for a specific purpose, whether it’s coordinating with a colleague or getting a client’s approval of a design mockup.

The problem is that shared access often outlives or outgrows its original purpose: a freelancer could be removed from a project, but never from the project folder in SharePoint. Members can invite new users to a Teams channel, forgetting that they gain access to every file hosted within it.

Due to the highly contextual nature of cloud sharing, the only way to know with certainty whether shared access is still required is to ask the person who originally provided it. Access reviews are an essential protection measure, and involving file or channel owners in the review process results in faster and more accurate reviews.

The challenge is to implement this process using the tools available on the platform.

The problem with integrated governance tools

Lack of control over shared data represents a growing and often underestimated security risk in enterprise environments. At the same time, teams can hardly be blamed for taking full advantage of sharing capabilities, the central pillar on which cloud suites are built. The problem with unmanaged cloud sharing isn’t so much user behavior, but rather the inadequate governance features built into Microsoft 365.

Microsoft 365 offers two reporting options that provide visibility into shared data, but both have significant limitations.

You can create a global link sharing report using advanced SharePoint management. However, this only tells you which websites created the most new links in the last 28 days. This number alone doesn’t give you enough context to draw useful conclusions. A high number of new links could indicate abuse or simply be due to a project with external involvement, such as onboarding a new supplier.

Likewise, you can create site-level sharing reports to get a CSV table that shows every shared file within a site and everyone who has access to it. However, running this report across all SharePoint and OneDrive devices in your organization is incredibly time-consuming. This also applies to manually searching through these files to identify problematic shares.

Ultimately, both reporting options require you to do the bulk of the work, whether it’s merging site-level reports into a cohesive whole or examining the spike in share links you saw in a global activity report.

What Microsoft 365 is missing is a centralized access management dashboard that gives you a complete picture without all that extra hassle – and that allows you to zoom in or out on the fly. Here, dedicated Identity & Access Governance solutions like tenfold close the transparency gap left by native reporting tools.

Automate onboarding and offboarding, streamline access reviews, and stay compliant without complexity or custom scripts.

With a suite of ready-to-use plugins, tenfold offers seamless integration for Microsoft cloud and on-prem environments.

Get a personal demo

tenfold: Full transparency and central governance for shared files

As part of its deep integration with Microsoft’s cloud and on-prem ecosystem, tenfold offers purpose-built reporting tools that enable complete visibility of shared files across Teams, OneDrive and SharePoint. Two outstanding features distinguish tenfold Shared content governance ahead of other IGA platforms:

  • A centralized breakdown of all shared content, giving you both high-level insights and object-level details in one place. Filter by app, user, website, or more to quickly identify issues. Important details, such as files shared outside of your team or channel, are marked with icons to clearly identify potential issues.
  • A streamlined access review process for shared content that requires data owners to review and confirm who has access to the files they share. Each reviewer receives a personalized review dashboard with shared items and who currently has access to them. This allows reviewers to quickly confirm or revoke access, making it easy to delegate the review process to users in non-IT roles.

With comprehensive visibility into cloud sharing and an effective review process that prevents sharing from exceeding its intended purpose, tenfold enables you to take full advantage of cloud collaboration capabilities without putting your data at risk.

Take back control of shared files with the leading no-code IGA solution. Book a personal demo with our team to find out more.

Sponsored and written by tenfold software.

Leave a Reply

Your email address will not be published. Required fields are marked *