Information
Control sharing of documents to external domains by either blocking domains or only allowing sharing with specific named domains.
Rationale:
Attackers will often attempt to expose sensitive information to external entities through sharing, and restricting the domains that users can share documents with will reduce that surface area.
Impact:
Enabling this feature will prevent users from sharing documents with domains outside of the organization unless allowed.
NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.
Solution
To remediate using the UI:
Navigate to SharePoint admin center https://admin.microsoft.com/sharepoint.
Expand Policies then click Sharing.
Expand More external sharing settings and check Limit external sharing by domain.
Select Add domains to add a list of approved domains.
Click Save at the bottom of the page.
To remediate using PowerShell:
Connect to SharePoint Online using Connect-SPOService.
Run the following PowerShell command:
Set-SPOTenant -SharingDomainRestrictionMode AllowList -SharingAllowedDomainList 'domain1.com domain2.com'
Default Value:
Limit external sharing by domain is unchecked
SharingDomainRestrictionMode: None
SharingDomainRestrictionMode: <Undefined>