SharePoint Settings
Tenant-wide SharePoint Online and OneDrive settings deployed via the
deploySharePointSettings pipeline toggle.
Microsoft's defaults are permissive — CONFIG365 hardens them to prevent data leakage and accidental oversharing.
Why These Defaults Matter
Microsoft Defaults Are Too Permissive
Out of the box, Microsoft 365 allows anonymous "Anyone" sharing links, permits external sharing to anyone with an email address, and allows OneDrive sync on any device. These defaults optimize for ease of use, not security. CONFIG365 replaces them with sensible, auditable defaults that still allow legitimate collaboration.
SharePoint tenant settings are backed up and deployed through two complementary APIs, both under the
deploySharePointSettings toggle:
Microsoft Graph
sharepoint-settings/sharepoint-tenant.json Sharing levels, link defaults, guest expiration, OneDrive sync restrictions, and unmanaged device policies via the SharePoint admin settings API.
SharePoint Online PowerShell (PnP)
sharepoint-settings/tenant-configuration/*.json Full Set-SpoTenant property set — one JSON file per property. Requires a SharePoint-delegated token from the portal token API.
Graph settings and SpoTenant properties can be overridden per-site via site-level sharing settings or sensitivity labels for sites that require different collaboration patterns.
External Sharing Settings
Existing guests only Only users already in the directory as guests can access shared content. New external invitations are blocked by default.
Existing guests only Matches the SharePoint setting. Users cannot share OneDrive files with new external contacts without admin action.
Disabled Links that give access to anyone with the URL — without authentication — are disabled tenant-wide. These are the primary data leak vector.
Specific people When a user shares a file, the default link type is "Specific people" rather than "Anyone" or "Organization". Reduces accidental oversharing.
View only Default permission on new sharing links is View — not Edit. Users must explicitly choose to grant edit access.
30 days Guest sharing links expire after 30 days. Recipients must request renewal, ensuring stale external access is cleaned up automatically.
Enabled Site owners receive notifications when files in their sites are shared externally, enabling oversight without blocking sharing.
OneDrive Settings
Tenant domain only The OneDrive sync client only syncs to devices joined to the tenant domain. Unmanaged personal computers cannot sync company files.
Enabled Devices not Entra-joined or Intune-compliant cannot establish an OneDrive sync. Enforced via Conditional Access.
Configured via Intune Desktop, Documents, and Pictures are automatically redirected to OneDrive via Intune configuration profile.
500 versions OneDrive retains up to 500 versions of each file, providing ransomware recovery and point-in-time restore.
Unmanaged Device Access Controls
These controls work in conjunction with Conditional Access policies to restrict SharePoint and OneDrive access from non-compliant devices.
Browser-only (no download) Users on non-compliant or personal devices can access SharePoint/OneDrive via browser but cannot download files or sync. Enforced via Entra CA + Conditional Access policies.
1 hour warning, sign-out after 2 hours Inactive browser sessions on unmanaged devices are signed out to prevent session hijacking from unattended computers.
Enabled for Outlook Web, OneDrive web Microsoft apps in the browser respect device compliance state and enforce read-only or download-blocked experiences accordingly.
Enabled Sensitivity labels from Microsoft Purview can be applied to SharePoint sites, controlling guest access, download permissions, and external sharing per-site.
SpoTenant Configuration
Properties from Get-SpoTenant are exported nightly to
backups/sharepoint-settings/tenant-configuration/ and deployed from
baseline/baseline/sharepoint-settings/tenant-configuration/.
Promote individual property files through the policy viewer like any other backup resource.
DisableDocumentLibraryDefaultLabeling Configurable per baseline Controls whether SharePoint document libraries inherit a default sensitivity label. Often set to prevent automatic labeling conflicts with Purview publishing policies.
LegacyAuthProtocolsEnabled Backed up & deployable Tenant-level legacy authentication protocol settings applied via Set-PnPTenant / Set-SpoTenant.
All Set-SpoTenant properties One JSON per property Every property exposed by Set-SpoTenant is discovered at backup time and written as an individual JSON file under tenant-configuration/.