Information
External sharing of content can be restricted to specific security groups. This setting is global, applies to sharing in both SharePoint and OneDrive and cannot be set at the site level in SharePoint.
The recommended state is Enabled or Checked.
Note: Users in these security groups must be allowed to invite guests in the guest invite settings in Microsoft Entra. Identity > External Identities > External collaboration settings
Rationale:
Organizations wishing to create tighter security controls for external sharing can set this to enforce role-based access control by using security groups already defined in Microsoft Entra.
Impact:
OneDrive will also be governed by this and there is no granular control at the SharePoint site level.
NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.
Solution
To remediate using the UI:
Navigate to SharePoint admin center https://admin.microsoft.com/sharepoint
Click to expand Policies > Sharing.
Scroll to and expand More external sharing settings.
Set the following:
Check Allow only users in specific security groups to share externally
Define Manage security groups in accordance with company procedure.
Default Value:
Unchecked/Undefined