What it decides
- Rule
SPO-SHARE-004- Applies to
sharepoint·tenant- Default severity
- medium
- Basis
- documented-guidance
On what authority
Microsoft states the default and the alternative in the same section: "By default, Anyone links for a file allow people to edit the file, and Anyone links for a folder allow people to edit and view files, and upload new files to the folder. You can change these permissions for files and for folders, independently, to view-only." And then the recommendation: "If you want to allow unauthenticated sharing, but are concerned about unauthenticated people modifying your organization's content, consider setting the file permissions to View and folder permissions to View or View and upload." It is conditional guidance, and the condition is the ordinary case. The same page notes what is not lost by following it: Specific people links still grant edit, and those require the recipient to authenticate, which makes their activity auditable.
What it needs to decide
tenant_sharing.capabilitytenant_sharing.file_anonymous_link_type
Without these facts the rule answers unknown, which is not a pass and is not a failure: it is the rule saying the evidence could not settle the question.
Where the evidence comes from
tenant-sharing: what the organisation permits, which every site inherits by default · live-validated
What a pass does not establish
View-only is still unauthenticated read. This rule narrows what an anonymous holder can do; it does not make the content private, and a link that was passed on is still a link that was passed on.
- This reads the file permission and not the folder one. Microsoft names two acceptable values for folders, View and View and upload, because the second is what the Request Files feature needs. A rule comparing to a single value would fail organisations that are following the guidance, so the folder setting is deliberately not collected and not evaluated.
- This is the organisation setting. A site can be more restrictive, and this rule does not read sites.
Source
The rule as the Engine holds it, at the revision this page was generated from: 1.0.0b6@b4bf9c325233.
Generated from capability-manifest/1.0.0 at1.0.0b6@b4bf9c325233, contract1.0.0b6. Every fact on this page is the Engine's; this site publishes it and does not maintain it.