Skip to content
  • Home
  • About
Search
Close

Nathan Wells

SharePoint | Office 365

Tag: azure b2b

New Office 365 Feature: Per-Group Sharing Controls

June 12, 2017 nathanwells20141 Comment

When you’re thinking about enabling collaboration with external/third party users in your organisation’s Office 365 tenant, there are a lot of things you need to think through, agree, and design around. These include:

  • Which applications will you allow external sharing in (SharePoint Online, OneDrive for Business, Office 365 Groups)?
  • Will you enable member sharing, or require site owner approval when content is externally shared?
  • Will you enable or disable anonymous links?
  • How/where will you use domain restrictions?
  • Is there anywhere you’ll disable external sharing completely?
  • How will you encourage users not to share content with consumer identities?
  • What processes will you put in place to manage/maintain external user permissions and guest invites?
  • How will you tweak your IA (information architecture) to encourage good practices for external sharing/permissions management, e.g. sharing at the site/library level rather than per document?
  • Will you enforce MFA (multi-factor authentication) on guest users?
  • And lastly, but perhaps most importantly, will you use Azure AD B2B Collaboration or the traditional SharePoint Online external sharing model?

Now though, there’s one more thing you can add to that list: Per-Group Sharing Controls.

This new feature – which hits first release tenants in June 2017 – will give Office 365 administrators a little bit of extra control over who and how information can be shared with external/third party users in SharePoint Online and OneDrive for Business.

There are two new settings, the details of which I’ve lifted from Microsoft’s blog post on the subject:

  1. Let only users in selected security groups share with authenticated external users – With this option, you can specify one or more Office 365 security groups which contain the users who you want to allow to share with authenticated external users. Users in these security groups will not be able to send anonymous links.
  2. Let only users in selected security groups share with authenticated external users and using anonymous links – With this option, you can specify one or more Office 365 security groups which contain the users who you want to allow to share with authenticated external users and by using anonymous links. (This option doesn’t appear unless you have enabled anonymous access links for the tenant.)

pgsc

The current set of options that the Per-Group Sharing Controls build upon are relatively coarse. The options available are: external sharing is disabled completely; external sharing with anonymous links is enabled; external sharing with only authenticated users is enabled; and sharing with users who already exist in your organisation’s directory (AKA the Azure B2B option). These options are available at both the tenant scope and site collection scope, though the site collection settings cannot be less restrictive than those defined at the tenant level (i.e. most restrictive setting wins).

The new functionality gives some extra granularity on top of these existing settings. You now have three separate audiences of users that can have different levels of external sharing ability:

  1. Users who are unable to share content externally (by virtue of not belonging to a group specified for either option);
  2. Users who can share authenticated links; and
  3. Users who can share authenticated links and anonymous links.

But unfortunately, the feature can only be defined at the tenant scope, not per site collection. How it’s going to play with the existing set of options is also slightly unclear at the time of writing, but I’ve been informed that the site collection settings will take precedence. For example, if anonymous sharing is disabled at the site collection level, even users in the security group that can share anonymous links will not be able to do so in that site collection. This suggests that the best way to get set-up for these new controls is to allow anonymous sharing in each site collection in all but exceptional circumstances, and control who is actually allowed to undertake this action via the new Per-Group Sharing Controls.

Also worth noting here that this new feature only covers security groups (i.e. the thing that would once have been defined as a mail-enabled distribution list). It doesn’t cover Groups, as in, Office 365 groups. Confusing, but an important distinction.

It will be interesting to have a play with these new settings when they start rolling out, but for now, it’s one more thing to consider when you’re setting up your organisation for collaboration with third parties.

Recent Posts

  • How and When to Adopt the Modern UI in SharePoint – Part 2/2
  • How and When to Adopt the Modern UI in SharePoint – Part 1/2
  • New Office 365 Feature: Per-Group Sharing Controls
  • Planning for the Azure CDN Capabilities in Office 365
  • Tinfoil Hat Predictions for SharePoint and Office365 in 2021

Recent Comments

Chad on How and When to Adopt the Mode…
Mike Strubbe on How and When to Adopt the Mode…
JSW on How and When to Adopt the Mode…
Damien on Planning for the Azure CDN Cap…
Antoine Troost (@apr… on New Office 365 Feature: Per-Gr…

Archives

  • September 2017
  • July 2017
  • June 2017
  • May 2017
  • January 2016
  • September 2015
  • August 2015
  • July 2015
  • June 2015
  • March 2015
  • February 2015
  • January 2015
  • December 2014

Categories

  • Extranets
  • Governance
  • Hybrid
  • Migration
  • Modern UI
  • Office365
  • OneDrive for Business
  • Operating Model
  • Performance
  • SharePoint 2013
  • SharePoint 2016
  • SharePoint Online
  • strategy

Tags

adoption avepoint business case Cal change management content E1 E3 enhancements experiences external sharing Follow foreign governance groups Group Site housekeep housekeeping Impact Assessment incident management intranet language language packs license licensing Localisation localise Machine Translation Service map mapping metalogix microsoft migrate migration Modern Experience Modern Library Modern List Modern Site Modern UI move MTS MUI multilingual o365 OD4B ODFB office365 Office 365 on-prem onedrive onedrive for business operating model operations policies problem management procedures roadmap roi search sharegate sharepoint sharepoint 2013 SharePoint 2016 sharepoint online source SP2016 SPOL strategy support taxonomy translate Translation Variations vision yammer

Blogroll

  • Discuss
  • Get Inspired
  • Get Polling
  • Get Support
  • Learn WordPress.com
  • Theme Showcase
  • WordPress Planet
  • WordPress.com News
Blog at WordPress.com.
Back to top
  • Follow Following
    • Nathan Wells
    • Already have a WordPress.com account? Log in now.
    • Nathan Wells
    • Customize
    • Follow Following
    • Sign up
    • Log in
    • Report this content
    • View site in Reader
    • Manage subscriptions
    • Collapse this bar
 

Loading Comments...