# SharePoint - External Sharing Scanner

> Detects externally shared files, folders and anonymous sharing links.

This free n8n template scans SharePoint sites and document libraries via the Microsoft Graph API to detect external sharing, guest users and anonymous access links. Ideal for security, audit and compliance use cases in Microsoft 365 environments.

- Area: n8n Automation
- Type: Free
- Category: IT Operations
- n8n template: https://n8n.io/workflows/12495-audit-sharepoint-online-external-sharing-and-anonymous-links-with-microsoft-graph/
- Source: https://www.sus-tech.com/en/solutions/sharepoint-external-sharing-scanner

## SharePoint External Sharing Scanner

Detect external SharePoint sharing before it becomes a risk  
Automatically identify files and folders in SharePoint that are shared with external users or via anonymous links. This workflow scans your SharePoint environment and provides a clear structured overview of all externally accessible items.

### What this workflow solves
External sharing in SharePoint often grows over time through collaboration project work or temporary access links. Without regular audits these shares can remain active long after they are needed. This workflow automates detection of external access and anonymous access to reduce security risk and support compliance.

### Key features
- Fetches all SharePoint sites via Microsoft Graph
- Fetches all document libraries
- Recursively scans drives folders files
- Retrieves permission metadata for each item
- Detects external sharing including
  - Anonymous sharing links
  - External users
  - Guest users based on login name or email domain
- Filters results to items with external access or anonymous access
- Normalizes results into a consistent structure including
  - Item name
  - Item type file or folder
  - Site ID
  - Library ID
  - Drive ID
  - Direct SharePoint URL
  - Last modified date
  - Sharing type anonymous or external user
  - Permission roles
  - Link details
- Produces clean data for reports exports follow-up workflows

### How it works
- Fetches all SharePoint sites via Microsoft Graph
- Retrieves document libraries for each site
- Recursively traverses folder and file structures
- Fetches permissions for every item
- Analyzes permissions for anonymous links or external users
- Outputs only externally shared items

### Setup requirements
Microsoft Entra ID app registration with Microsoft Graph Application permission
- Sites.Read.All

In n8n
- Create Microsoft Graph OAuth2 credentials Client Credentials flow recommended
- Assign credentials to all Microsoft Graph HTTP Request nodes
- Update the Set Variables node
  - tenantDomains list of internal domains used to identify external users

### Notes
- This workflow is read only and does not modify SharePoint permissions
- For continuous monitoring replace the manual trigger with a Schedule Trigger daily or weekly
- The workflow accesses metadata only permissions identities links and never reads file contents

## Related blog posts

- [Why Data and Identity Governance Is Critical for Every Business - and Why Starting Early Matters](https://www.sus-tech.com/en/blog/why-data-and-identity-governance-matters.md)

## Contact

Consulting and implementation: https://www.sus-tech.com/en/contact
