Skip to content

Data protection

Find and fix Anyone links in Google Drive and SharePoint

Build a dated inventory of anonymous file links, decide with owners, and verify changes in Drive, SharePoint, and OneDrive.

What to take away

An “anyone with the link” or “Anyone” URL can grant access without naming a collaborator. Native logs and sharing reports are useful leads, but they do not necessarily show every link that is open today. This guide gives a small team a no-script review: identify candidate items, inspect current permissions, ask the owner whether anonymous access is still needed, and verify the smallest safe change.

1. Identify the actual link audience

Anonymous or Anyone links differ from links for everyone in the organization, named external people, groups, or inherited folder access. Record the audience you found before deciding what to remove. A file can have more than one path to access; deleting one link does not prove every path is gone.

Focus this review on anonymous access. Keep organization-wide and named sharing as separate rows when they also need attention. Treat content DLP rules and Copilot discovery settings as complementary controls, not evidence that a public link has been removed.

1. Identify the actual link audience
AudienceWhat to verify
Anyone with the link / AnyoneAnonymous access and business need
People in the organizationWhether organization-wide reach is justified
Specific people or groupCurrent recipients and membership
Inherited accessThe parent or site granting the permission

2. Know what the native consoles can show

Google Workspace Drive log events show visibility and sharing changes in a chosen window; they are history, not a complete current-permission inventory. Google’s security-dashboard file exposure report is limited to supported higher editions and is not included with Business Plus. Check the edition and privileges of the tenant before relying on a feature.

SharePoint and OneDrive admin settings cap how open sharing can be. Where licensed, SharePoint Advanced Management Data access governance reports can identify SharePoint sites with the most new Anyone links in the last 28 days. They are activity reports, not a permanent list of every current anonymous file link. Microsoft’s prerequisites do not make Business Premium alone sufficient for Advanced Management; verify the tenant’s actual entitlement. Per-item Manage access remains the source check. Full tenant-wide OneDrive enumeration may require another supported tool.

References: Google Workspace — Drive log events · Google Workspace — File exposure report and editions · Microsoft Learn — Sharing-link activity reports · Microsoft Learn — SharePoint Advanced Management prerequisites

3. Build a bounded inventory without scripts

Begin with organization sharing defaults, then use recent Drive visibility events, licensed SharePoint activity reports, and known high-risk folders or recently shared files to identify candidates. For each candidate, open the live item and read its current General access or Manage access state. Ask the file owner to identify other temporary public links when native reporting cannot cover the whole tenant.

One row should contain the cloud and location, item reference, owner, link audience, evidence source and date, business purpose, proposed decision, and verification result. Store references and decisions, not file contents. Mark gaps explicitly: an event log that returned no recent public shares cannot establish that older links are closed.

3. Build a bounded inventory without scripts
FieldPurpose
Cloud and item referenceFind the same file again without copying its contents
Link audience and source dateSeparate current permission from historical activity
Owner and purposeSupport a proportionate access decision
Decision and verificationShow whether the source was actually changed

References: Google Workspace — Drive log events · Microsoft Learn — Sharing-link activity reports

4. Decide with the owner, then change the smallest permission

Keep anonymous access only for a current purpose, with an owner and next review date. If the work can continue with named recipients or an organization-only link, narrow the audience. Remove a link that no longer serves a need. Investigate ambiguous ownership, inherited permissions, or multiple links rather than changing a broad organization policy to solve one file.

After the change, reopen the item. Confirm anonymous access is gone where intended and required collaborators still work. A private-session check may help when allowed, but the source permission state remains primary. Record a failure or uncertain inheritance as unresolved.

5. Repeat checks as links change

Refresh recent Drive sharing events and licensed SharePoint activity reports monthly, and review retained exceptions quarterly. After a phishing event or vendor offboarding, check the files involved rather than relying on the last periodic export. Measure source-verified removals and open owner decisions, not just reports generated.

If native coverage cannot enumerate current public links across the tenant, state that limit and use a supported inventory connection or an explicit owner-led sample. Do not claim a complete inventory from an activity feed.

How Elba supports this review

With separate supported Data Protection connections, Elba can surface Google Drive, SharePoint, and OneDrive sharing exposures where each source reports them. Findings give the asset, audience, and owner context for investigation or distribution to the employee. Supported source-specific permission removal can complete some fixes; other changes happen in the source.

A Microsoft 365 directory sync alone does not inspect SharePoint or OneDrive documents. Check connection status, coverage, and a representative public-link finding before treating the inventory as complete. Verify any remediation in the source and keep unsupported cases open.

References: Elba — Data Protection

Anyone-link review checklist

0 of 7 checks complete

Your checks stay on this page and reset when you reload it.

Common questions

Can Business Plus list every public Drive file in one live view?

No general always-current inventory is provided by the Drive log events. The Google security-dashboard file exposure report is limited to other supported editions. Use current item checks, owner sampling, or a supported inventory connection and state the remaining coverage gap.

Does Business Premium include SharePoint Anyone-link activity reports?

Do not assume so. Data access governance reporting has separate SharePoint Advanced Management or other qualifying licensing conditions. Check the tenant’s actual entitlement before planning the review around those reports.

Should every anonymous link be banned?

Choose with the file owner. A deliberate public asset may need an anonymous link; sensitive or abandoned material usually does not. Keep a purpose and review date for exceptions and verify every removal in the source.

Sources & further reading

Primary documentation used to review this guide. Product settings and edition requirements can change; check the linked documentation before making changes.

Put it into practice

Google Workspace DLPSharePoint external sharingPost-click SaaS controls

From review to remediation

See sharing exposure across connected sources

Explore how Elba helps teams find supported broad links, involve owners, and verify fixes.

Request a demo