OneDrive & SharePoint (M365) - Collaborating with People Outside of Michigan Medicine


Introduction

Michigan Medicine supports secure collaboration with external partners through Microsoft 365 (M365) OneDrive and SharePoint. 

This article is intended for Michigan Medicine faculty, staff, site owners, and site collection administrators who need to share OneDrive or SharePoint content with people outside of Michigan Medicine. It explains what has changed, how external sharing works under the Microsoft Entra ID B2B guest collaboration model, and what responsibilities apply when granting or reviewing external access. 

When files, folders, or sites are shared with people outside Michigan Medicine, those external collaborators are added as Microsoft Entra ID B2B guest users. This model replaces the previous one-time passcode experience as the primary access method and allows invited users to authenticate with a supported work, school, or personal Microsoft account while Michigan Medicine manages guest access centrally. 

Before accessing shared content, external users must sign in with their organization's identity provider or another supported Microsoft account associated with the invitation. 

 

Key change: External collaborators no longer use one-time passcodes as the primary access method. Instead, invited users authenticate with a supported work, school, or personal Microsoft account, and their guest access is managed through Michigan Medicine's Microsoft Entra ID tenant. This provides stronger lifecycle management, access review, and auditing for external collaboration. 

Instructions

Before You Share 

Use this guidance when you need to share content with a named external collaborator for a business-related purpose. Do not use external sharing for anonymous access, broad public distribution, or content blocked by Michigan Medicine security or Data Loss Prevention policies. If you are unsure whether the content may be shared externally, confirm the appropriate policy or support path before sending the invitation. 

Before sharing content externally, confirm that the request meets all of the following requirements: 

  • External sharing must be business-related and comply with Michigan Medicine policies.
  • Users may only share content they are authorized to access.
  • Sensitive or restricted information may not be shared externally if blocked by Data Loss Prevention (DLP) policies.
  • The Anyone sharing option is not supported in the Michigan Medicine M365 environment.
  • Access is granted only to specifically identified individuals. 

 

Sharing Files, Folders, and Site Access with External Users 

External collaboration may involve sharing a specific file or folder, or granting access to an entire SharePoint site. Use the narrowest access needed for the collaboration. Share individual files or folders when the external user only needs specific content; grant site access only when the user needs ongoing access to multiple site resources. 

To share a file or folder securely with a specific person outside Michigan Medicine: 

  1. Open OneDrive or the SharePoint site containing the file or folder.
  2. Select the file or folder you want to share.
  3. Select Share.
  4. Enter the external user's email address.
  5. Verify the appropriate permission level: 
    1. Can Edit – Allows the recipient to modify content.
    2. Can View – Read-only access. (default)
  6. Optionally, enter a message.
  7. Select Send.

The external user will receive an email invitation to access the shared content. 

To grant external access to a SharePoint site, the site owner should use the site's permissions settings rather than sharing a single file or folder. 

  1. Navigate to the SharePoint site.
  2. Select Settings (gear icon), then select Site Permissions.
  3. Select Share site or Add members, depending on the site type and options available.
  4. Enter the external user's email address.
  5. Assign the least-privileged access level needed, such as Read for view-only access or Edit when contribution is required. Do not grant Full Control to guest users unless there is an exceptional, documented business need and the access has been approved through the appropriate support or governance process.
  6. Optionally, enter a message for the invitation.
  7. Select Add or Send, depending on the option shown. 

Important: Granting site access may expose more content than sharing an individual file or folder. Site owners should confirm that the external user has a business need for site-level access and should periodically review that access. Michigan Medicine strongly discourages assigning Full Control to guest users. Guest accounts assigned Full Control may be identified during routine reviews, and appropriate steps may be taken to reduce or remove that access. 

 

What External Users Can Expect 

When an external user receives a sharing invitation: 

  1. They select the link provided in the email.
  2. Microsoft validates their identity.
  3. They sign in using:  
    1. Their work or school account, or
    2. A personal Microsoft account, when applicable.
  4. If the external user does not already have a guest account in Michigan Medicine's tenant, one may be created automatically when the user accepts the invitation and completes the sign-in process.
  5. After successful authentication, the user gains access to the content that was shared with them. 

Important: Access is assigned to the invited individual. Forwarding the invitation email does not grant access to other people. 

 

Access Reviews and Guest Account Expiration 

Guest access is reviewed periodically, so Michigan Medicine can confirm that external collaboration remains appropriate and remove access that is no longer needed. 

As part of this governance process, Michigan Medicine plans to routinely check for guest accounts that have been assigned Full Control permissions. When this level of access is found and is not justified by an approved business need, appropriate steps may be taken to reduce or remove the access. 

External users may lose access when: 

  • Their guest account expires.
  • The sponsoring site owner does not renew access during an access review.
  • Their permissions are removed by a site owner.
  • Their guest account is disabled or removed from the Michigan Medicine tenant.

If access is removed and later needed again, an authorized site owner can re-share the content. 

 

Managing External User Access 

Site Owners and Site Collection Administrators can review external access within their SharePoint sites. 

To review external users: 

  1. Navigate to the SharePoint site.
  2. Select Settings (gear icon).
  3. Select Site Permissions.
  4. Review the site's guest and external user permissions.
  5. Remove access for users who no longer require collaboration privileges.
  6. Identify any guest users with Full Control permissions and reduce or remove that access unless it has an approved, documented business justification. 

Site owners are responsible for periodically reviewing external users, confirming that each person still has a business need for access, and removing access that is no longer appropriate. 

 

Sensitive Content and Data Loss Prevention (DLP) 

Michigan Medicine uses Microsoft Purview Data Loss Prevention policies to help prevent restricted or sensitive information from being shared externally when policy rules do not allow it. 

When sharing files externally: 

  • Content containing regulated or sensitive information may be restricted.
  • Sharing attempts may generate warning messages or be blocked entirely.
  • Some files may not be eligible for external sharing regardless of user permissions. 

If a sharing action violates a DLP policy, you may receive a message indicating the file cannot be shared outside the organization. 

 

Frequently Asked Questions 

Do external users need a Microsoft account? 

External users must authenticate through a supported identity provider. In most cases, users can sign in using their existing work or school account. Personal Microsoft accounts may also be supported where permitted. 

Can I share with anyone using a link? 

No. Michigan Medicine does not permit anonymous ("Anyone") sharing links. Access must be granted to specific individuals. 

Can external users edit documents? 

Yes. If granted Can Edit permissions, external users can collaborate on documents, subject to organizational policies and any applied restrictions. 

How do I remove an external user's access? 

Navigate to the SharePoint site's permissions management page and remove the user's permissions, or stop sharing the specific file or folder. 

What should I do if an external user cannot access shared content? 

Verify that: 

  • The correct email address was used.
  • The user completed the sign-in process with the account associated with the invitation.
  • Their guest account has not expired or been removed.
  • The content has not been restricted by a DLP policy. 

If the external user still cannot access the content after these checks, provide the HITS Service Desk with the external user's email address, the shared file or site location, the approximate time the invitation was sent, and any error message the user received. 

 

Additional Information 

For related guidance, refer to Michigan Medicine Knowledge Base articles and/or Microsoft Learning documentation about accessing SharePoint content as an external user, managing SharePoint site permissions, OneDrive file sharing, and Microsoft 365 collaboration best practices. 

 

Key Changes from the Previous Model 

Under the new Microsoft Entra ID B2B collaboration model: 

  • One-time passcodes are no longer used as the primary method of access.
  • External collaborators authenticate using their own organizational identity.
  • Guest accounts are created and managed within Michigan Medicine's Microsoft Entra ID tenant.
  • Access governance, lifecycle management, and auditing are improved through centralized guest account management. 

This model provides a more secure and seamless collaboration experience for Michigan Medicine employees and external partners.