Baseline

SharePoint Settings

Tenant-wide SharePoint Online and OneDrive settings deployed via the deploySharePointSettings pipeline toggle. Microsoft's defaults are permissive — CONFIG365 hardens them to prevent data leakage and accidental oversharing.

SharePoint OnlineExternal SharingOneDriveSensitivity LabelsUnmanaged Devices

Why These Defaults Matter

Microsoft Defaults Are Too Permissive

Out of the box, Microsoft 365 allows anonymous "Anyone" sharing links, permits external sharing to anyone with an email address, and allows OneDrive sync on any device. These defaults optimize for ease of use, not security. CONFIG365 replaces them with sensible, auditable defaults that still allow legitimate collaboration.

SharePoint tenant settings are backed up and deployed through two complementary APIs, both under the deploySharePointSettings toggle:

Microsoft Graph

sharepoint-settings/sharepoint-tenant.json

Sharing levels, link defaults, guest expiration, OneDrive sync restrictions, and unmanaged device policies via the SharePoint admin settings API.

SharePoint Online PowerShell (PnP)

sharepoint-settings/tenant-configuration/*.json

Full Set-SpoTenant property set — one JSON file per property. Requires a SharePoint-delegated token from the portal token API.

Graph settings and SpoTenant properties can be overridden per-site via site-level sharing settings or sensitivity labels for sites that require different collaboration patterns.

External Sharing Settings

SharePoint external sharing level
Existing guests only

Only users already in the directory as guests can access shared content. New external invitations are blocked by default.

OneDrive external sharing level
Existing guests only

Matches the SharePoint setting. Users cannot share OneDrive files with new external contacts without admin action.

"Anyone" (anonymous) links
Disabled

Links that give access to anyone with the URL — without authentication — are disabled tenant-wide. These are the primary data leak vector.

Default link type
Specific people

When a user shares a file, the default link type is "Specific people" rather than "Anyone" or "Organization". Reduces accidental oversharing.

Default link permission
View only

Default permission on new sharing links is View — not Edit. Users must explicitly choose to grant edit access.

Expiration for guest access links
30 days

Guest sharing links expire after 30 days. Recipients must request renewal, ensuring stale external access is cleaned up automatically.

Email notifications for sharing
Enabled

Site owners receive notifications when files in their sites are shared externally, enabling oversight without blocking sharing.

OneDrive Settings

OneDrive sync client — allowed domains
Tenant domain only

The OneDrive sync client only syncs to devices joined to the tenant domain. Unmanaged personal computers cannot sync company files.

Block sync on unmanaged devices
Enabled

Devices not Entra-joined or Intune-compliant cannot establish an OneDrive sync. Enforced via Conditional Access.

Folder backup (Known Folder Move)
Configured via Intune

Desktop, Documents, and Pictures are automatically redirected to OneDrive via Intune configuration profile.

Version history retention
500 versions

OneDrive retains up to 500 versions of each file, providing ransomware recovery and point-in-time restore.

Unmanaged Device Access Controls

These controls work in conjunction with Conditional Access policies to restrict SharePoint and OneDrive access from non-compliant devices.

Unmanaged device access
Browser-only (no download)

Users on non-compliant or personal devices can access SharePoint/OneDrive via browser but cannot download files or sync. Enforced via Entra CA + Conditional Access policies.

Idle session sign-out
1 hour warning, sign-out after 2 hours

Inactive browser sessions on unmanaged devices are signed out to prevent session hijacking from unattended computers.

App-enforced restrictions
Enabled for Outlook Web, OneDrive web

Microsoft apps in the browser respect device compliance state and enforce read-only or download-blocked experiences accordingly.

Sensitivity label integration
Enabled

Sensitivity labels from Microsoft Purview can be applied to SharePoint sites, controlling guest access, download permissions, and external sharing per-site.

SpoTenant Configuration

Properties from Get-SpoTenant are exported nightly to backups/sharepoint-settings/tenant-configuration/ and deployed from baseline/baseline/sharepoint-settings/tenant-configuration/. Promote individual property files through the policy viewer like any other backup resource.

DisableDocumentLibraryDefaultLabeling Configurable per baseline

Controls whether SharePoint document libraries inherit a default sensitivity label. Often set to prevent automatic labeling conflicts with Purview publishing policies.

LegacyAuthProtocolsEnabled Backed up & deployable

Tenant-level legacy authentication protocol settings applied via Set-PnPTenant / Set-SpoTenant.

All Set-SpoTenant properties One JSON per property

Every property exposed by Set-SpoTenant is discovered at backup time and written as an individual JSON file under tenant-configuration/.