Netwrix 1Secure 提供跨数据和身份的统一可见性——免费试用14天,享有完全访问权限。开始免费试用

资源中心博客

SharePoint 中的外部共享:明智实施建议

SharePoint 中的外部共享:明智实施建议

Mar 27, 2023

简介

Microsoft SharePoint 让用户只需几次点击就能与同事共享文件。然而,外部共享同样轻松——这会使您的敏感数据安全面临风险。

为帮助您在不干扰合法协作的情况下控制文件和文件夹的外部共享,本文详细介绍了 Microsoft 管理界面中可用的外部共享设置,并提供了配置这些设置的最佳实践。我们将介绍 Microsoft 365 Admin Center、SharePoint 和 OneDrive for Business 管理中心、经典 SharePoint Online Admin Center 以及现代 SharePoint Online Admin Center 中的相关设置。

Microsoft 365 Admin Center:外部共享的租户级设置

在 Microsoft SharePoint 中配置外部共享时,建议由您的管理员团队从租户(组织)级别开始。打开 Microsoft 365 Admin Center(原 Office 365),然后进入 Settings –> Services & add-ins –> Sites

然后,您可以指定用于控制租户级外部共享的选项:

Screenshot of SharePoint Online and OneDrive external sharing settings, showing sharing enabled for 'Anyone, including anonymous users' with anonymous links expiring in 7 days.

在大多数情况下,建议选择第二个选项“新用户和现有外部用户(需要登录)”,因为它在灵活性与控制之间提供了平衡。以下是关于如何为您的组织选择最佳选项的更详细建议:

Choose this option:

If your objective is to…

Let users share SharePoint Online and OneDrive content with people outside the organization

Enable external sharing at the tenant level, subject to the constraints you specify below.

Only existing external users (sign-in required)

Require external users (guests) to sign in with a Microsoft account before accessing content, and limit sharing to external users who already exist in your directory because they either have already been shared with or were manually imported.

New and existing external users (sign-in required)

Allow both existing and new external users to access shared content once they have signed in with a Microsoft account.

Anyone, including anonymous users

Allow use of anonymous links, which do not require sign-in to access

Set anonymous links to expire in these many days

If you allow anonymous access links, specify automatic expiration dates for them.

用于外部共享的站点集和 OneDrive for Business 设置

在配置了整个租户的共享设置之后,就该在各自的管理中心中开始配置 SharePoint Online 和 OneDrive for Business 的顶级外部共享设置了。

如您所见,在 SharePoint Online 中用于控制共享链接的选项与上文讨论的类似:

Choose this option:

If your objective is to

Anyone

Allow users to share files and other site content with anyone.

Allow users to share files and other site content with anyone.

Allow users to share content with external users, but require them to sign in with a Microsoft account to access it. This option is usually best for site collections with external collaborators, especially if you’re in the process of migrating to a newer version of SharePoint.

Existing external users

Allow external sharing only with users who already exist in your directory.

Only people in your organization

Do not allow any external sharing.

OneDrive 的外部共享选项也非常相似,只是文字说明略有不同:

A settings panel for default link sharing, with 'Shareable: Anyone with the link' selected, and advanced options for 7-day link expiration, 'View, edit, and upload' for files, and 'View' for folders.

再强调一次:允许用户与任何拥有该链接的人共享内容,会让你的文件面临重大风险。要求外部用户先登录,可以提供更强的控制。由于用户往往更倾向于在 OneDrive 中保存更敏感的信息,因此通常建议比 SharePoint 更严格地配置 OneDrive 的设置。

SharePoint 管理中心

经典版 SharePoint Online 管理中心可让你为每个 SharePoint 站点创建外部共享设置。进入“Site Collections(站点集合)”部分,然后点击 Sharing

Image

下图展示了可用的选项:

Image

默认情况下不允许外部共享,但你可以选择在指定的任意站点上启用外部共享,并选择允许的共享类型。例如,你可以为包含敏感数据的站点设置更严格的控制,而为更偏向协作的站点设置更宽松的控制。你也可以选择谁被允许向站点邀请新用户;不过,通常最好的做法是将这一决定交给站点所有者。

现代 SharePoint 管理中心

在现代 SharePoint 管理中心中,这些设置已更改为反映前面讨论的相同选项:

External sharing settings with the option

使用以下选项,您可以实现更强的访问控制:

  • 非受管设备 — 您可以限制来自不符合要求或未加入域的设备的访问。选项从允许完全访问、仅允许 Web 访问(不包含桌面或移动端),到完全阻止访问不等。
  • 空闲会话注销 — 您可以自动从处于非活动状态的浏览器会话中注销用户。
  • 网络位置 — 只能允许来自特定 IP 地址的访问。
  • 不使用现代身份验证的应用 — 您可以拒绝对依赖传统身份验证协议的应用的访问。

其他安全控制

其他安全控制可能会影响 SharePoint 和 OneDrive for Business 的外部共享。尤其是,以下控制可以阻止用户将某些文档和其他内容在外部共享:

  • 数据丢失防护(DLP)策略
  • 将记录保留策略应用到外部。
  • eDiscovery 要求
  • Microsoft Purview Information Protection(原为 Microsoft Information Protection)的安全控制

此外,以下审计和告警功能可以帮助管理员随时掌握文档向外共享的情况:

  • 与共享文件相关的所有用户活动都可在审计日志中查看。
  • 管理员可以选择在用户在 SharePoint 或 OneDrive for Business 中执行特定操作时收到通知。

使用 PowerShell 以深入了解外部共享

PowerShell 脚本可以帮助您深入了解外部共享。例如,下面的脚本将返回租户中的所有外部用户(需要 SharePoint 管理员权限):

PowerShell script to retrieve external users from a SharePoint Online tenant.

输出将如下所示:

Image

Netwrix 如何提供帮助

仔细配置上面详细说明的设置,可以让您的组织在内容如何向外部共享方面拥有显著的控制力。然而,第三方工具可以提供更好的可视性和控制能力,而这对于确保 data security 至关重要。

Netwrix 的数据访问治理软件可帮助您通过减少敏感数据的暴露来降低 data breach 的风险。它还可以帮助您遵从诸如 GDPR 之类的法规,因为该法规要求组织实施 data protection by design and default

尤其是,Netwrix 解决方案可帮助您:

  • 识别您最关键的数据。
  • 将对敏感数据的访问权限降低到所需的最低限度,以降低 insider threat 的风险,并将勒索软件和其他攻击造成的损害降到最低。
  • 通过数据所有者简化定期的权限证明(privilege attestations)。
  • 只要对内容进行准确且一致的标记(tagging),敏感数据在任何传输过程中都能得到保护。
  • 对整个 IT 生态系统中的活动进行审计,并快速发现与拦截威胁。

分享到

了解更多

关于作者

Asset Not Found

Farrah Gamboa

产品管理高级总监

Netwrix 产品管理高级总监。Farrah 负责制定并推进与 Data Security 以及 Audit & Compliance 相关的 Netwrix 产品与解决方案路线图。她拥有超过 10 年在企业级数据安全解决方案领域的经验,曾从 Stealthbits Technologies 加入 Netwrix。在加入 Netwrix 之前,她担任技术产品经理以及质量控制(QC)经理。Farrah 拥有 Rutgers University 的工业工程学士学位(BS)。