How should you share files with clients securely?
Share a link rather than an attachment, restrict it to specific people rather than anyone with the link, and set an expiry. For ongoing work, add the client as a guest to a dedicated Team or site instead. Then review guest access when engagements end, which is the step nearly everyone skips.
Most businesses share client files the way they always have, by attaching them to an email, and it is worth being precise about why that is the weakest option. The moment it sends, you have lost control of that copy: you cannot revoke it, cannot see who opened it, and cannot correct it if the version was wrong. If the address was mistyped, client material is now sitting in a stranger's inbox permanently. And the copy immediately begins diverging from yours as people edit and reply.
A link solves all four problems at once. The file stays in your SharePoint or OneDrive, so there is one authoritative version. Access can be revoked. You can see who has opened it. And if the wrong person receives the link, a properly configured one will not let them in. That last clause is doing the work, because a badly configured link is not much better than an attachment.
Microsoft 365 offers a few link types and the distinction matters. Anyone with the link works for whoever holds it, with no sign-in, which is convenient and is precisely the setting that turns a forwarded email into an exposure. Specific people requires the recipient to verify who they are, which is the sensible default for client material. People in your organisation is for internal use and is a common accidental choice when sharing outward, producing the confused client who cannot open anything.
Two settings turn good intentions into a system. Expiry, so links do not outlive the engagement, since an unexpired link from 2023 still works and nobody remembers it exists. And permission level, meaning view rather than edit unless collaboration is genuinely intended. Both can be set as tenant-wide defaults, which is far more effective than instructing people, because the safe option becomes the one that requires no thought.
For ongoing client work, guest access is the better model. Add the client to a dedicated Team or site for their engagement, and they get a proper shared workspace with conversation, files and history in one place, under permissions you control. The important caveat is scope: a guest sees the whole Team, not one folder, so the Team needs to be built for that from the start rather than being an internal space you later invited someone into. That mistake is common and quietly exposes internal discussion.
The step almost everyone skips is the review. Engagements end, projects finish, and the guest account remains, still able to reach the site months or years later. Quarterly, list your guests and confirm each still needs access. This is usually the single most productive half-hour in a small business's security year, because it reliably finds several people who should have been removed long ago, occasionally including someone who now works for a competitor.
Receiving files from clients deserves as much thought as sending them, and it gets almost none. The usual arrangement is that clients email documents, which puts sensitive material into a mailbox rather than into managed storage and leaves it there indefinitely. A request link that lets someone upload directly into the right library without seeing anything else solves it, and it also removes the size limits that push people toward personal file-sharing accounts you have no visibility of at all.
Some material warrants more than a link. Anything highly sensitive, health records, financial documents, legal material, deserves consideration of sensitivity labels, which can restrict what recipients may do with a document, and in some industries a purpose-built portal rather than general file sharing. Check your professional obligations before assuming a link is sufficient, because in regulated fields it sometimes is not.
The honest caveat is that the secure path must also be the convenient one or it will not be used. If sharing properly takes six clicks and emailing an attachment takes two, people will email the attachment, and no policy survives that gap. Set the defaults so the right thing happens automatically. If you want yours configured that way, call 1800 456 567.
Make secure sharing the easy option
We configure sharing defaults, expiry and guest access so the convenient path and the safe path are the same one.
Frequently asked questions
Questions? Let's talk.
Call 1800 456 567 or fill out the form.
- 30-minute discovery — no jargon, no pressure
- Plain-English Essential Eight Cyber Security Scorecard
- A clear plan tailored to your business