SOURCE-CHECKED GUIDE · SHARING WORKFLOWS

OneDrive or SharePoint for controlled client guest access

Choose a Microsoft 365 location where tenant, site, and personal sharing limits fit a client project.

Published September 29, 2026Checked September 29, 2026HowCurio editorial research
A document workflow checklist
Illustration of the topic. The article links to the source instructions.

Choose the guest policy boundary

Choose where the work lives by asking where external access should be allowed. SharePoint’s organization-level sharing setting is the ceiling: each site can use that level or a more restrictive one. OneDrive’s organization setting can be the same as or more restrictive than SharePoint’s, and an individual user’s OneDrive can be restricted further. A client-facing site therefore cannot override a tenant-wide ban on external sharing. Microsoft: external sharing overview · Microsoft: sharing settings · Microsoft: user OneDrive settings

Guest access needed Better fit Policy decision
A staff member needs to share a few selected files with a client Employee OneDrive may suffice Check both the OneDrive organization setting and that user’s setting before relying on external links.
A client needs continuing access to a defined project space Dedicated SharePoint site Set that site’s external sharing level within the organization ceiling, then decide whether guests need files or site membership.
Project material must stay internal Separate confidential SharePoint site Turn external sharing off for that site.

These choices follow Microsoft’s distinct controls for sites and OneDrive and its recommendation to keep confidential information in a site with external sharing turned off. Putting a client file in an employee’s OneDrive does not, by itself, give the client access to every file there. Access still depends on the sharing action and permissions granted. Microsoft: what happens when users share content

Suppose an agency prepares a client campaign while also keeping internal pricing notes and negotiation plans. Put client review files in a dedicated client-facing site whose guest policy permits the intended collaboration. Put pricing and negotiation material in a separate confidential site with external sharing off. The division gives administrators a site-level boundary they can inspect and change without requiring the same guest policy for both projects. It works only when the SharePoint organization setting permits the client site’s chosen sharing level. Microsoft: site and organization settings

Decide how much access the client needs inside the client-facing site. A link to one file is narrower than adding a guest to a Microsoft 365 group connected to the site. Group members are site members; a guest with site-member permissions can perform tasks such as editing or deleting site files and list items. Grant group or site membership only when those broader tasks are intended. Microsoft: group-connected sites and guest permissions

Before configuring either location, an administrator should open SharePoint admin center → Policies → Sharing and record the SharePoint and OneDrive organization levels. Then check the client and confidential sites’ individual sharing settings. For an employee OneDrive option, check Microsoft 365 admin center → Users → Active users → [user] → OneDrive → Manage external sharing. Also check whether Microsoft Entra B2B integration is enabled: it changes whether file-sharing invitations create guest accounts and whether Entra external collaboration settings apply. Microsoft: sharing administration and B2B · Microsoft: individual OneDrive setting

Finally, use an actual external guest account to test the configured route. Share a designated client file, sign in as the guest, and confirm the file opens with the intended permission. Check whether the guest can reach other client-site content, then verify that the confidential site remains inaccessible. Record the effective organization, site, and, where relevant, individual OneDrive settings alongside the results. That test checks the access the client will experience rather than assuming a setting alone proves the boundary.

How this guide was made

This guide explains a workflow using the linked primary sources. We did not independently run every step or verify the result for your files; check the current service screen and your own output.

Primary sources: