M365 SharePoint | Next Generation of File and Folder Sharing

M365 SharePoint | Next Generation of File and Folder Sharing

A single file in SharePoint accumulates a dozen sharing links over months: one for the project team, one for the external contractor, one anonymous from the previous year that no one can trace anymore. Each of these links carries its own permissions, and if you want to know who can actually open a file, you have to check each one individually.

Starting at the end of August 2026, Microsoft will phase out this model. The rollout of the third generation of file sharing will run through the end of October 2026 and will simultaneously cover Worldwide, GCC, GCC High, and DoD.

At the core is the hero link: a primary sharing link per file or folder, whose target audience can be changed retroactively. The URL remains stable. If a recipient cannot open the file, you expand the target audience of the existing link instead of creating a new one and sending it again. Technically, this shifts the permission logic from the URL to the object.

For you as an administrator, this means: There is no single switch for the rollout. Preparation involves taking inventory and making a deliberate decision for each site collection, as there is currently no tenant-wide setting for the Hero Link audience.

Verify Prerequisites

According to roadmap item 492622, the affected products include SharePoint, OneDrive, Word, Excel, PowerPoint, and Microsoft 365, with platforms spanning web, desktop, Mac, iOS, and Android. Neither the roadmap entry nor the Message Center notification specifies any licensing requirements; instead, the notification states that all users who share or manage files and folders in Microsoft 365 are affected.

Configuration is performed via the SharePoint Online Management Shell. Update the module to the latest version and connect to your tenant's admin URL:

Update-Module -Name Microsoft.Online.SharePoint.PowerShell -Force
Connect-SPOService -Url https://contoso-admin.sharepoint.com

Next, check whether your module version actually supports the parameter. If it doesn’t, any further configuration will be ineffective, and you’ll need to update first.

(Get-Command Set-SPOSite).Parameters.Keys | Where-Object { $_ -like 'DefaultMainLink*' }

Related: M365 Organization Settings via PowerShell demonstrates how to script-read and set tenant-wide policies, which you’ll need for the inventory in the next step.

Step 1: Document current sharing defaults

Before making any changes, you document the current state. After the rollout, the existing default values for sharing links remain valid, but they will only control legacy links and additional links, not the hero link. Without a documented initial state, you won’t be able to distinguish later which deviations stem from the rollout and which originate from your own configuration.

Get-SPOTenant | Select-Object *

The sharing parameters controlled by Set-SPOTenant are relevant here: SharingCapability, DefaultSharingLinkType, DefaultLinkPermission, CoreDefaultShareLinkScope, CoreDefaultShareLinkRole, OneDriveDefaultShareLinkScope, OneDriveDefaultShareLinkRole, and RequireAnonymousLinksExpireInDays. To see which of these your module version actually returns, use Get-SPOTenant | Get-Member.

At the website level, you pull the same values for all active sites into a CSV, which later serves as evidence. Personal sites are excluded here because Get-SPOSite only includes them with the -IncludePersonalSite parameter.

Get-SPOSite -Limit All |
    Select-Object Url, SharingCapability, DefaultSharingLinkType, DefaultLinkPermission |
    Export-Csv .\sharing-defaults-vorher.csv -NoTypeInformation -Encoding UTF8

Related: Data Protection in Microsoft SharePoint Online classifies sharing settings in terms of data protection law and helps you assess the documented current state rather than just exporting it.

The default value is OnlyPeopleAdded. The hero link does not grant access on its own. It reflects the individuals who have been explicitly authorized. Forwarding the link does not provide the recipient with access. This is the restrictive option and the correct starting point for most environments. After the Message Center announcement, the permission level begins with view access, not edit.

For site collections where internal collaboration is the norm (such as an intranet site or an internal project archive), you can switch to Organization.

Set-SPOSite -Identity https://contoso.sharepoint.com/sites/projekt-alpha `
    -DefaultMainLinkScope Organization

The Learn reference for Set-SPOSite also lists the value Anyone. This only applies if anonymous links are permitted at the tenant level. If this is not the case or the site blocks anonymous links, the effective default falls back to the next most restrictive level. Message Center announcement MC1454378 does not mention Anyone, only OnlyPeopleAdded and Organization. You should verify this discrepancy in your pilot tenant before incorporating it into your internal documentation.

Every risk assessment should include two key points: The parameter only sets the default value. It does not prevent users from expanding the target audience in the dialog, as long as the sharing policy allows it. And it applies to items in the root of the document library. It does not replace a global lock for the entire site collection.

Further information can be found in the German-language article.

Share:
Noch keine Kommentare

Sei der Erste und starte die Diskussion mit einem hilfreichen Beitrag.

Leave a comment

Dein Beitrag wird vor der Veröffentlichung kurz geprüft — fachlich, respektvoll und auf den Punkt ist hier genau richtig.

E-Mail Adresse wird nicht veröffentlicht.