
Microsoft 365 access reviews needed as cloud sharing grows
Security leads say shared file access often stays open longer than intended, and Microsoft 365 built-in reports leave most of the work to administrators.
Microsoft 365 access reviews are the missing piece in many organisations that share files through Teams, SharePoint and OneDrive, according to a sponsored article published on BleepingComputer on September 18, 2026 and written by tenfold Software, a vendor that sells identity and access governance products. Microsoft 365 is the bundle of workplace services that includes Teams for chat and channels, SharePoint for team sites and document libraries, and OneDrive for individual file storage. The tenfold article describes how easily files move through those services and how that convenience creates a security problem. Staff drop documents into one to one chats. Spreadsheets sit in Teams channels so that everyone can see the latest figures. Project folders are uploaded to SharePoint and invite links are sent out. The article argues that as this kind of sharing has grown, visibility into who holds access has fallen further behind, and that many organisations no longer know who is able to open their sensitive files.
The sponsored piece points to a survey by Wire in which 61 percent of security leads reported that access to shared files often remains active longer than intended, and in which more than a third said they have difficulty even identifying who has access to sensitive shared files. Those numbers come from the tenfold article, not from any testing of our own, and the source text does not describe the survey's methodology, sample size or how the respondents were selected. They are still worth noting, because they match a pattern that many IT teams will recognise: sharing is easy to start and hard to keep track of.
One reason the problem is difficult to assess, the article explains, is that sharing is driven by context. An employee shares a file with a specific purpose in mind, whether that is coordinating with a colleague or getting a client to approve a design mockup. The difficulty is that shared access frequently outlives or outgrows that original purpose. A freelancer may be taken off a project but never removed from the project folder in SharePoint. Team members may invite new users into a Teams channel without realising that channel membership also grants access to every file stored inside that channel. Because the reasons for sharing are so specific and so local, the tenfold article argues that the only reliable way to know whether access is still needed is to ask the person who granted it in the first place. That is what an access review is: a periodic check in which the owners of files, folders or channels confirm who should still be able to see them. Bringing those owners into the process, rather than leaving it entirely to a central IT team, leads to faster and more accurate audits, according to the article.
The piece then examines the reporting options Microsoft already provides and describes their limits. SharePoint Advanced Management can produce a global report on sharing links, but it only shows which sites had the most new links created in the previous 28 days. On its own, the article says, that figure lacks the context needed to draw a useful conclusion, because a high number of new links might indicate misuse or might simply reflect a legitimate project with outside involvement, such as onboarding a new supplier. Separately, site level sharing reports can produce a CSV table, meaning comma separated values, a plain text table that opens in a spreadsheet program, listing every shared file within a site along with everyone who has access to it. Running that report across every SharePoint site and OneDrive account in an organisation is described as incredibly time consuming, and so is sifting through the results by hand to spot problematic sharing. In both cases, the tenfold article concludes, most of the legwork stays with the administrator, whether that means stitching site level reports into a coherent picture or investigating a spike in sharing link activity. What the article says is missing is a central dashboard for access governance that shows the whole picture and lets an administrator zoom in or out as needed.
That gap is where tenfold positions its own product. The article states that tenfold offers reporting tools for shared files across Teams, OneDrive and SharePoint, as part of what it calls a no-code identity and access governance suite with ready to use plugins for Microsoft cloud and on-premises environments. It highlights two features. The first is a central breakdown of all shared content that combines high level insights with object level detail, with filters by app, user or site, and with icons marking notable cases such as files shared outside their own team or channel. The second is an access review process in which data owners are prompted to check and confirm who has access to files they shared. Each reviewer receives a personalised dashboard of shared items and the people who currently hold access, so that access can be confirmed or revoked, which the article says makes it easier to delegate reviews even to users in non-IT roles.
It is important to be clear about what this is. The text is sponsored content, produced by tenfold Software and published by BleepingComputer, and it describes the vendor's own product in the vendor's own words. The source contains no independent test, no benchmark, no pricing, no customer case study and no comparison against other platforms, and we have not evaluated the tool ourselves. The underlying risk it describes, however, applies whatever software an organisation uses. Shared links and channel memberships accumulate quietly, they are rarely reviewed, and the person who knows whether access is still justified is usually the person who granted it. A simple review routine, run regularly and aimed at the file owners rather than only at IT, addresses the same problem without any purchase. For teams that want outside help tightening who can reach shared files and how that access is granted, AEU-I provides security first IT, infrastructure and consulting services, and its service page sets out what that covers.
How to Protect Yourself
- Go through the files and folders you have shared in OneDrive, SharePoint or Teams and remove anyone who no longer needs them, especially clients, suppliers or freelancers who have finished working with you.
- When you share a file or folder, choose the option that lets only specific named people open it instead of the option that lets anyone with the link open it, and set an expiry date if your app offers one.
- Check the member list of your Teams channels and shared folders every few months, and remember that anyone in a channel can usually open every file stored inside it.
- Put a reminder in your calendar to review your shared items two or three times a year, and ask the colleague who shared a file with you whether that access is still needed.
- If you leave a project, a team or your job, hand over the documents you own and ask the people who shared files with you to remove your access.
Terms Explained
- Microsoft 365 Microsoft's set of online workplace services, including email, chat, document editing and file storage, that organisations pay for by subscription.
- SharePoint The part of Microsoft 365 used to build team websites and shared document libraries where colleagues store files together.
- OneDrive The part of Microsoft 365 where an individual keeps their own files online and can share them with other people.
- Teams Microsoft's chat and meeting app, where conversations happen in channels and files can be shared inside those channels.
- sharing link A web address that gives whoever holds it access to a file or folder, sometimes without a password or a named account.
- access review A periodic check in which the person who shared a file or folder confirms who should still be allowed to open it.
- identity and access governance Software and processes that keep track of who is allowed to reach which company files and systems, and that check that these permissions are still justified.
- CSV Short for comma separated values, a plain list of data saved as text that opens in a spreadsheet program such as Excel.