Sharing links in SharePoint Online do not expire by default. Without a configured expiry policy, a link shared with an external partner today will still work in five years - unless someone manually removes it. For most organisations, that gap between intended access duration and actual access duration is where external sharing risk accumulates quietly, one project at a time.
This guide covers how to configure link expiry at tenant level, what each setting controls, how users can set expiry when creating individual shares, and how to handle the links that existed before any policy was in place.
What happens without a link expiry policy
Microsoft 365 ships with no default expiry on sharing links. When a user creates an Anyone link or a Specific People link, SharePoint sets no end date. The recipient can bookmark the URL and return to the file indefinitely, even after the sharing relationship was intended to be temporary.
The business risk is straightforward: a contractor finishes a project in March, and the Anyone link to the project folder continues to work through the following year. The contractor may no longer be engaged, but their access has not been revoked because nobody removed the link and no policy enforced a cutoff. Multiply this across a tenancy with hundreds of active projects and the exposure surface becomes difficult to track manually.
Setting the default link expiry at tenant level
Tenant-level expiry is the foundation of a link governance policy. It ensures that new Anyone links created anywhere in the tenant automatically receive an expiry date, without relying on individual users to set one each time they share.
Using the SharePoint admin center
- Sign in to the Microsoft 365 admin center and navigate to SharePoint admin center.
- In the left sidebar, select Policies, then Sharing.
- Scroll to the section labelled Choose expiration and permissions options for Anyone links.
- Check the box for These links must expire within this many days.
- Enter your preferred number of days. Thirty days is a common starting point; fourteen days suits more sensitive environments such as legal or finance teams.
- Select Save. The setting takes effect for all new Anyone links created from that point forward.
Using PowerShell for finer control
For organisations managing settings programmatically or applying different policies to specific site collections, PowerShell gives more granular control:
# Set tenant-wide default expiry for Anyone links (in days)
Set-SPOTenant -RequireAnonymousLinksExpireInDays 30
# Apply a tighter expiry to a specific site collection
Set-SPOSite -Identity "https://contoso.sharepoint.com/sites/Partners" -OverrideTenantAnonymousLinkExpirationPolicy $true -AnonymousLinkExpirationInDays 14
# Give links for people in your organisation a maximum lifetime (7 to 720 days)
Set-SPOTenant -CoreOrganizationSharingLinkMaxExpirationInDays 365
The -RequireAnonymousLinksExpireInDays parameter accepts up to 730 days, and 0 removes the expiry requirement. The site-level -AnonymousLinkExpirationInDays value only takes effect when -OverrideTenantAnonymousLinkExpirationPolicy is $true on that site, and the override can be stricter or looser than the tenant.
Setting expiry when creating an individual share
Even without a tenant policy, individual users can set an expiry date when they create an Anyone link. Microsoft offers the option only for that link type:
- Open the file or folder in SharePoint Online and select Share.
- In the sharing dialog, open the link settings (the gear) and choose Anyone as the link type.
- Under More settings, use Set expiration date and pick a date from the calendar.
- Confirm the settings and copy or send the link.
If a tenant-level expiry is configured, users cannot set an expiry date that exceeds the tenant maximum. They can set a shorter date but not a longer one. If no tenant-level expiry is set, users have no upper limit unless a site collection policy is applied.
Link types and expiry: what the policy covers
| Link type | Tenant-level expiry available? | Per-share expiry available? | Default (no policy set) |
|---|---|---|---|
| Anyone (anonymous) | Yes - admin center and PowerShell | Yes | No expiry |
| Specific people (external) | No link expiry; guest access expiration covers external recipients (admin center or PowerShell) | No | No expiry |
| People in your organisation | Yes - PowerShell only, tenant or site, 7 to 720 days | Only through the policy | No expiry |
| People with existing access | No | No | No expiry (does not create new access) |
The practical takeaway: the admin center link setting enforces expiry on Anyone links only. External partners who receive a Specific People link are not covered by it. For them the control is guest access expiration (Guest access to a site or OneDrive will expire automatically after this many days on the same Sharing page), which removes the guest's access rather than expiring the link.
Auditing links that have no expiry or an expired date
Configuring an expiry policy does not clean up what already exists. Microsoft documents that changing the expiration time shortens existing Anyone links whose expiry is later than the new limit, but it does not spell out what happens to links created with no expiry before any policy existed, and the policy does nothing for other link types. Run an audit of existing links as the companion step to policy configuration.
ShareMaster's Share Link Finder reports the sharing links and unique permissions across the document libraries you select on a site, and with a paid licence can remove the sharing links in bulk. It does not show expiry dates. The ShareMaster V2 beta report does: it lists each link's type, scope and expiry date, and can be limited to expired links or to one link scope before you remove them.
For ongoing governance, run this audit on a quarterly schedule at minimum. External sharing tends to expand during project kick-offs and contract periods, and those contracts end on schedules that do not align with SharePoint's default of "no expiry". For the step-by-step removal process, see how to bulk remove SharePoint sharing links.
Frequently Asked Questions
Does the SharePoint link expiry setting apply to all link types?
The admin center expiry setting applies to Anyone (anonymous) links only. Links for people in your organisation can be given a maximum lifetime with PowerShell, tenant-wide or per site, of 7 to 720 days. Specific people links have no expiry of their own; for external recipients the control is guest access expiration, which removes the guest's access after a set number of days.
What happens when a SharePoint sharing link expires?
When a sharing link reaches its expiry date it stops working, and anyone who needs the file again has to be sent a new link. The file itself is not deleted, only the link.
Can site owners override the tenant-level link expiry?
People creating an Anyone link can choose an earlier expiry than the tenant maximum but not a later one, so with a 30-day maximum they can pick 7 days but not 60. Site owners cannot loosen it. A SharePoint admin can override the tenant setting for one site with Set-SPOSite and -OverrideTenantAnonymousLinkExpirationPolicy, and that override can be stricter or looser.
Do existing sharing links inherit the new expiry policy?
Partly. Microsoft says that when you change the expiration time, existing Anyone links keep their date if the new setting is longer and are updated to it if the new setting is shorter. The PowerShell reference for the tenant setting only promises it for links created after the policy is set, so treat links created with no expiry before the policy existed as unconfirmed and audit them.