Every shared link created in SharePoint Online remains active until it expires or someone revokes it. Over months and years, most tenants accumulate hundreds or thousands of active links pointing to content that no longer needs to be shared. Clearing that backlog is a two-part job: audit what exists, site by site, then remove what should not. SharePoint Online gives you a CSV per site for the first part and no native tool for removing links across more than one item at a time.
Why Sharing Links Accumulate at Scale
The SharePoint sharing model is designed to make link sharing frictionless. A user right-clicks a file, selects "Share," picks a link type, and sends it in seconds. That ease is the feature, and it is also the source of the problem over time. In a tenant where a hundred employees each create a handful of sharing links per month, the tenant accumulates thousands of active links per year. Most of them are created with good intent and forgotten immediately after use, and SharePoint sends no reminder when a link has stopped being used.
Sharing links also sit outside the normal permission model. Someone holding a link can open the item it points to whether or not they are a member of the site, and an Anyone link needs no sign-in at all. Links tied to former employees are the sharpest example. When an account is disabled in Entra ID, SharePoint does not automatically revoke the sharing links that account created. A Specific people link sent to an external contractor survives the contractor relationship ending. An Anyone link emailed to a client before a project wrapped up continues to work after the client engagement closes. Without active management, the list of live links bears no relationship to the list of active business relationships.
An audit answers two questions: which content can be reached by people outside the expected permission model, and which of those links should be revoked now?
Sharing Link Types and Their Risk Profile
| Link type | Who can access | Sign-in required | Risk level | Expires by default |
|---|---|---|---|---|
| Anyone | Any person with the URL, including people outside your organisation | No; can be forwarded freely | High | Only if a tenant expiry is configured; not set by default in many tenants |
| People in your organisation | Any authenticated internal user who has the URL | Yes, a tenant account | Medium | No; persists until revoked |
| Specific people | Only the named individuals (internal or external) | Yes | Lower | No; persists until revoked |
For admin-centre defaults and a full breakdown of how each link type interacts with your tenant sharing policy, see the SharePoint sharing link types reference.
When Should You Remove Sharing Links in SharePoint Online?
Bulk link removal is the right action in several clear situations:
- An employee leaves the organisation and held libraries or files that were shared externally
- A project or client engagement ends and the associated content should no longer be reachable from outside the organisation
- A compliance audit or security review surfaces active Anyone links on sensitive content
- Your organisation is preparing to enable Microsoft 365 Copilot and wants to tighten the data-access perimeter before AI features reach the content
- A routine quarterly review shows the link count has grown beyond what your governance policy allows
- A site is being decommissioned or archived and all external access should be revoked before the content is locked
Even outside these specific triggers, a structured audit and cleanup two to four times a year reduces the residual exposure that builds between targeted removal events.
Step 1: Check Your Tenant and Site Sharing Settings
Before auditing existing links, note what your current sharing policy allows. It tells you which link types can exist in the report, and which policy changes will stop the backlog rebuilding after the cleanup.
- Sign in to the SharePoint admin centre and go to Policies > Sharing.
- Under External sharing, note the tenant-level setting. The options range from "Anyone" (most permissive) to "Only people in your organisation" (most restrictive).
- Under File and folder links, check the default link type and the default permission. The default link type is what SharePoint offers first when a user shares an item.
- Check the Anyone link expiry. If "These links must expire within this many days" is not ticked, Anyone links created without an explicit expiry date never expire.
For sites whose sharing differs from the tenant default, go to Active sites, select a site, and choose More sharing settings on its Settings tab. A site can be set more restrictively than the tenant, but not more permissively.
Step 2: Audit SharePoint Shared Links with a Sharing Links Report
Effective bulk removal starts with a complete, exportable inventory. Before removing anything, capture: the item being shared (file or folder), the site and library, the link type, who the link reaches, and whether an expiry is set. This export serves as both a baseline record and an audit trail showing the state of sharing before the cleanup took effect.
The native per-site sharing report
The SharePoint admin centre has no cross-site view of active sharing links. Each site has its own report: go to Settings > Site usage and, under Shared with external users, select Run report. It saves a CSV to the site with every shared item, user, permission and link type, internal shares included. You need to be a site admin, and it covers one site per run. For one small site that is workable; across a tenant with many sites and tens of thousands of shared documents, it is not.
A shared links report from the ShareMaster Share Link Finder
ShareMaster's Share Link Finder connects to a site and reads the document libraries you pick. In Report on shared links mode it changes nothing and writes an Excel workbook with a Sharing Links sheet listing every sharing link group on the site with the people in it (the group name carries the link type, such as anonymous, organisation or specific people, view or edit), and a sheet per library listing each file or folder that carries a link. Run it site by site across the sites in scope. The report is free on the Community licence.
If you need the link URL and expiry date as columns, the ShareMaster V2 beta has a Report shared links scan that writes the link type, scope, URL and expiry for each link in the sites or libraries you choose.
Who created each link: the Purview audit log
Neither the site report nor the Share Link Finder records who created a link or when. For that, search the audit log in Microsoft Purview, which needs the Audit Logs or View-Only Audit Logs role. Under the sharing and access request activities, select Created an anonymous link, Created a company shareable link and Created secure link; each result shows the date, the user who did it and the item. Used an anonymous link tells you whether an Anyone link is still being opened. Audit (Standard) keeps records for 180 days by default, so a link created before that window has no creation record left.
In the results, pay particular attention to content in libraries tagged with sensitivity labels, content owned by accounts that are now disabled, and folders shared to external domains you no longer have an active relationship with. These produce the highest-priority removal candidates.
Step 3: Prioritise Which Links to Remove
After clearing Anyone links, continue by context rather than link type alone:
- Organisation links on sensitive content: A budget document or HR folder shared with "People in your organisation" is open to every staff member who has the URL, even though a sign-in is required.
- Inactive sites: Links on sites with no recent activity are candidates for removal regardless of type. Inactive content is less likely to be actively managed, and its sharing settings may reflect a previous state of the organisation that is no longer valid.
- Former employee ownership: Content in libraries originally created or primarily managed by a departed user should be reviewed. Links from their account remain live after account deactivation unless explicitly revoked.
- External recipients: Specific people links to someone outside your organisation are worth a look even if the recipient was right at the time. Links shared with a single external domain from a former vendor or client can be scoped and removed as a batch rather than one at a time.
- Expired links: These no longer work, so removing them is tidying rather than an urgent security fix. Specific people links to current staff or partners who still need access can generally stay.
Step 4: Bulk-Remove Links with the ShareMaster Share Link Finder
Once the report has told you which libraries to clear, switch the Share Link Finder from Report on shared links to Remove shared links. That removes every sharing link on the items in those libraries as a single batch operation, after a confirmation, and writes the same Excel workbook with each removal marked. It does not choose between links within a library, so point it at libraries where no link should survive and revoke the exceptions individually. Removal needs a Recycle Master or Clone Master licence; the report runs on any licence.
If you need to remove only one kind of link, such as Anyone links or links that have already expired, or to take one departed person out of every link they were given, the ShareMaster V2 beta can narrow a removal by link scope, link type, expired links only, or recipient.
Removing a link does not delete files. The file or folder stays in its library with the same direct permissions it had before. Only the link-based access path is closed. Recipients who click a removed link see an access-denied message; recipients who have been explicitly granted direct permissions to the item are unaffected.
For large tenants, scope the first pass to the highest-risk areas: sites with the most active Anyone links, libraries containing labelled or sensitive content, and sites owned by accounts that have been disabled. Complete cleanup in batches to keep the change log manageable. A removed link cannot be restored, only re-shared as a new link, so keep the before-and-after workbooks for any access complaints that follow.
See how the Share Link Finder removes shared links
Removing an individual link in the browser
For the exceptions, or a site with only a few links, revoke them one at a time:
- Go to the file or folder in SharePoint and select it.
- Open the details pane with the information icon.
- Select Manage access.
- Find the link in the list of links (labelled Links giving access in older layouts).
- Open the link's options and remove it.
The link stops working straight away.
Step 5: Set Sharing Policies to Prevent Recurrence
Bulk removal addresses the existing backlog; policy is what keeps it from rebuilding. Configure the following in the SharePoint admin centre under Policies > Sharing:
- Anyone link expiry (days): Under the Anyone link options, tick "These links must expire within this many days" and set the number. A limit of 14 to 30 days is common for organisations that share externally for time-limited purposes like vendor reviews or client deliveries; sites holding confidential content can be given a shorter limit of their own in Active sites. Links created after this setting is applied will expire on schedule without additional admin action.
- Guest access expiration: "Guest access to a site or OneDrive will expire automatically after this many days" removes a guest's access a set number of days after it was granted, including access through Specific people links. Setting this to 90 days or fewer ensures that contractors and clients do not keep access indefinitely after a relationship ends.
- Default link type: Set it to "Specific people" rather than "Anyone" or "People in your organisation", so broad sharing takes a deliberate choice instead of accepting the pre-set option.
Do not rely on these settings to clear the backlog. Microsoft says that when you shorten the Anyone expiry, existing Anyone links with a later expiry are brought into line, but organisation and specific-people links are not covered at all, and guest expiration only removes guests, not the links. That is exactly why the cleanup pass comes first: the policy mostly governs what happens to new links going forward.
Organisations that need to restrict link creation altogether rather than just add expiry can lower the tenant-level external sharing setting. Moving from "Anyone" to "New and existing guests" removes the Anyone link option from the sharing dialog for all users. If only a few sites genuinely need anonymous sharing, such as an extranet or a client delivery site, set the tenant to "New and existing guests" and allow "Anyone" on those sites alone. Either is a significant operational change for organisations that rely on anonymous document distribution, so run it past your business process owners first.
Then repeat the audit every quarter with the same report. Once the first cleanup is done, each run only has to review the links created since the last one. Sharing links are one part of who can reach your content; the SharePoint permissions audit guide covers site membership, group inheritance and unique permissions alongside them.
Frequently Asked Questions
How do I get a SharePoint shared links report for every site?
There is no single native report for every site. Each site has its own sharing report (Settings, Site usage, Shared with external users, Run report) that writes a CSV of its links, and a site admin has to run it site by site. ShareMaster's Share Link Finder writes an Excel report of the sharing links in the libraries you pick on a site, free on the Community licence, which is much faster than reviewing items one at a time in the browser.
Can I see who created a sharing link?
Not from the site sharing report or the Share Link Finder report. Search the Microsoft Purview audit log for the Created an anonymous link, Created a company shareable link and Created secure link activities; each result shows the date, the user and the item. Audit (Standard) keeps records for 180 days by default, so older links have no creation record left.
What is an Anyone link in SharePoint?
An Anyone link, also called an anonymous link, gives access to a file or folder to anyone who has the URL, with no sign-in and no Microsoft 365 account needed. It is the broadest form of sharing in SharePoint Online and the highest oversharing risk when it has no expiry.
Does removing a sharing link delete the file or change other permissions?
No. Removing a sharing link closes the access pathway provided by that link. The file remains in its document library, unchanged. Users with access through site membership, group membership or direct item permissions keep it; only users who relied solely on that link lose access.
Can I remove sharing links for content I do not own?
SharePoint administrators can remove sharing links on any site once they make themselves a site admin there. Site owners can remove links within their own sites. Members and visitors do not have permission to remove links created by other users. ShareMaster works with the permissions of the account you connect with, one site at a time, so connect with an account that owns or administers each site you clean up.
What happens to someone using a link when it is removed?
Access through the removed link fails immediately. Any attempt to use the link after removal returns an access-denied error. There is no grace period and no automatic notification sent to recipients. If you need to inform users that access is changing, do so before running the removal.
How do I prevent users from creating new Anyone links after a cleanup run?
In the SharePoint admin centre under Policies > Sharing, lower the external sharing scope to "New and existing guests" or below. This removes the Anyone link option from the sharing dialog entirely. Alternatively, keep Anyone links permitted but require an expiry date, which prevents them from being created without a defined end date and stops the no-expiry backlog from rebuilding.