How to Share a File Safely
The difference between a private link and a public one, in plain terms, and how to pick the right one.
Sharing a file is easy. Sharing it with exactly the people you meant is the part worth two minutes of your time.
The idea to hang on to. A share link is a key, not an invitation. If you post a key through somebody's door and they hand it to a friend, it still opens the lock. Links behave the same way.
Start with one question
Does it matter who opens this?
If the answer is yes, and for anything with client details, staff details, money or contracts in it the answer is yes, then send it to named people rather than handing out a key.
The two kinds of link
| Who can open it | Use it for | |
|---|---|---|
| Specific people | Only the people you name, and only after they sign in. Forwarding it to somebody else does not work. | Anything that matters. This should be your normal choice. |
| Anyone with the link | Anybody at all who has the link. No sign-in, no name, no record of who they were. | Things you would be happy to see on a noticeboard. A flyer, a photo, a public price list. |
There is no third clever option. Everything else is a variation on those two.
Sharing with specific people
- Right-click the file. Choose Share. On some computers it sits under a OneDrive entry first.
- A box opens. Near the top it tells you who the link currently works for. Click that line to change it.
- Choose Specific people.
- Type the email address of each person who should have it.
- Decide whether they get Can edit or Can view. If they only need to read it, pick Can view.
- Click Send to email it, or Copy link if you would rather paste it into your own message.
That is it. If somebody forwards that email, the new person still cannot open the file.
When "anyone with the link" is the right call
Sometimes it genuinely is the right tool, usually when the other person cannot sign in and the content is not sensitive. If you use it, two small things make it much safer:
- Set an expiry date. In the sharing box, open the settings and give the link an end date. A link that stops working next Friday cannot come back to bite you in two years.
- Make it view-only unless they really do need to change it.
You may find your organisation has turned this option off. That is deliberate rather than a fault, and it is worth a quick message to us if you think you need it for something specific.
Three things worth knowing
Links get forwarded. Not usually out of mischief. Somebody helpfully passes it to a colleague who needed it. With a "specific people" link that simply does not work, which is the point.
Sharing a folder shares everything in it. Including anything you or anybody else puts in it later. If you only meant to send one spreadsheet, send the spreadsheet rather than the folder it lives in.
"Can edit" means exactly that. They can change the file, and they can delete what is in it. If in doubt, Can view is the kinder default. You can always upgrade someone later.
Checking who already has access
Worth doing occasionally on anything important, and always before you assume something is private.
- Right-click the file, choose OneDrive, then Manage access.
- You will see the people who have been given access, and any links that exist.
- Remove anybody who should not be there, or delete a link entirely to switch it off.
If you find a link you do not remember creating, that is not necessarily a problem. Links are easy to make and easy to forget. Delete it and move on.
If it is genuinely sensitive
Payroll, medical, banking details, anything covered by a client agreement: talk to us before sending it. We have ways of getting a file to somebody that expire on their own and do not sit in an inbox forever. It takes us a minute and it is much easier than unpicking it afterwards.
Nobody has ever been told off for asking first.
