M365: Protecting Data in SharePoint and OneDrive

Summary

Protecting university data in SharePoint and OneDrive is a shared responsibility. By following established guidelines and being proactive about access and sharing, all members of the university community can help maintain data privacy, security, and compliance. These guidelines apply to all USNH faculty, staff, and students using SharePoint Online or OneDrive for Business. For additional guidance, please review SharePoint: USNH SharePoint Usage Guidelines and Governance

Protecting Data with Thoughtful Sharing
USNH Sharing Defaults
Risk Awareness
Suspicious Activity and Access Revocation
Least Privilege Mindset
Sensitivity Labels 
Regular Site Access Review
Additional Microsoft Resources

 

Content


Protecting Data with Thoughtful Sharing

With thousands of files shared across USNH each month, it’s important to remain mindful of what is being shared, with whom, and how. Taking a moment to review permissions and sharing methods helps protect sensitive information and supports responsible data stewardship. Before sharing files or sites, it’s important to define roles, assign responsibilities, and clearly communicate expectations to those managing shared resources. Resource owners should consider the full lifecycle of access:

  • Who needs access?
  • What level of access do they need?
  • How long should access be available?

Site owners remain responsible for ensuring that access and sharing settings continue to align with the intended use of the site throughout its lifecycle. Define clear roles and responsibilities, especially for those managing collaborative resources. A well-planned approach to sharing reduces the need for cleanup later and helps avoid oversharing. Site and file owners are encouraged to:

  • Provide basic training or guidance on how to access and use shared content.
  • Monitor activity and storage to ensure the space is being used as intended.
  • Audit permissions regularly to confirm they align with current collaboration needs.
  • Use tools like SharePoint Sharing reports to identify oversharing or unused content.

Back to top

 

USNH Sharing Defaults

Sharing defaults provide a secure starting point, but they do not replace the responsibility of site and file owners to verify permissions before sharing content. Users should always confirm who will receive access and whether the selected sharing option is appropriate for the information being shared

Site owners are responsible for understanding the types of information stored within their sites and ensuring appropriate safeguards are in place. When a site contains confidential, regulated, restricted, or otherwise sensitive university data, owners should evaluate whether additional controls, such as a Sensitivity label, are necessary. Sensitive information is not automatically classified or protected simply because it resides within Microsoft 365.

USNH uses different sharing defaults for SharePoint and OneDrive:

  • OneDrive: Allows sharing with “Anyone with the link” anonymous sharing by default. Users are encouraged to set link expiration dates when using this option.
     
  • SharePoint: USNH SharePoint sites are invite-only, and default to “Specific people” for sharing. If broader or anonymous access is needed (e.g., “Anyone with the link”), a request must be submitted to the SharePoint Admin team for review: Request Anonymous Sharing for SharePoint

Note: USNH SharePoint sites are part of the university’s internal intranet. While it’s possible to share content with specific external collaborators, SharePoint sites cannot be made publicly accessible for anonymous viewing (i.e., they cannot function as a public-facing website).

These settings are periodically reviewed and updated to align with USNH security and data governance standards.
Back to top
 

Risk Awareness

Improper sharing practices can expose sensitive, confidential, or regulated information to unintended audiences. Risks often arise not from malicious activity, but from simple oversights such as granting broader permissions than intended, sharing content with the wrong audience, or leaving access in place long after a project or collaboration has ended.

Examples of higher-risk sharing practices include:

  • Sharing files using unrestricted or permanent links.
  • Granting edit access when view-only access is sufficient.
  • Sharing sites or folders with large groups without reviewing permissions.
  • Retaining access for former project members, contractors, or external collaborators after work has concluded.
  • Storing sensitive information in locations that are shared more broadly than intended.

The impact of oversharing can include unauthorized disclosure of university information, violations of privacy or compliance requirements, and increased risk of data loss. Taking a few moments to review permissions, select the most appropriate sharing option, and periodically validate access can significantly reduce these risks.
Back to top
 

Suspicious Activity and Access Revocation

Protecting university data sometimes requires immediate action when potential security concerns are identified. In coordination with USNH Cybersecurity, SharePoint and Microsoft 365 administrators may temporarily suspend, restrict, or revoke access to SharePoint sites, OneDrive content, Teams, or other Microsoft 365 resources when suspicious, unauthorized, or prohibited activity is reported or detected.

Access restrictions or revocation may apply to both internal and external users, including guest collaborators. In some situations, access may be removed without prior notice while a security concern is reviewed and addressed.

These actions are taken to protect university information, systems, and users and may remain in place until the matter has been evaluated by the appropriate USNH security and administrative teams.
Back to top

 

Least Privilege Mindset

Always assign the most restrictive (minimum necessary) permissions that still allow a collaborator to complete their work.

Many collaboration scenarios only require view access rather than edit access. Site owners should also consider whether permissions should be assigned directly to individuals, existing Microsoft 365 groups, or SharePoint groups to simplify ongoing management and reduce the risk of inappropriate access over time.

Permissions should be reviewed whenever project membership changes, employees leave the university, or external collaborations conclude.
Back to top
 

Sensitivity Labels

Sensitivity labels help site owners apply additional protections based on the nature of the information being stored. Depending on the assigned label, controls may include restrictions on external sharing, requirements for managed access, enhanced privacy settings, or additional compliance protections. Labels should be considered whenever a site contains confidential, regulated, or otherwise sensitive university information.

For added protection, Sensitivity Labels can be applied to SharePoint sites and Teams to restrict access, limit sharing, and enforce compliance policies. Learn more about requesting a label for your site:

Back to top
 

Regular Site Access Review

Access reviews should be performed regularly and whenever significant changes occur, such as project completion, staff turnover, departmental reorganizations, or the conclusion of external partnerships. Reviewing access during these transitions helps ensure permissions continue to reflect legitimate business, academic, and research needs.

Make a habit of reviewing site access, shared links, and group membership. Remove outdated or unnecessary permissions to reduce risk. You can use built-in tools like Site Permissions, Access Reviews, or OneDrive’s Manage Access panel to assist in this process.
Back to top
 

Additional Microsoft Resources

Set "Anyone" shared link expiration dates to prevent unauthorized access. 

Share SharePoint files or folders following Microsoft Support guidelines. 

Back to top

Further Readings

SharePoint: Requesting a Sensitivity Label for your SharePoint Site

Microsoft Support - Share SharePoint files or folders 

Microsoft Support - See who a file is shared within OneDrive or SharePoint 

Microsoft Support - Stop sharing OneDrive or SharePoint files or folders, or change permissions 

 

Need additional help?

For assistance concerning site creation, content sharing, file synchronization, or other common SharePoint, OneDrive, Teams, or Office app activities, we recommend our Microsoft 365 Learning sites:

Learn more about the great tools our Microsoft 365 Learning sites offer!

Visit the Technology Help Desk Support page to locate your local campus contact information or to submit an online technology support request.  For password issues you must call or visit the Help Desk in person.