How to Provide External Liquidators Access to Company SharePoint Files
Navigating company data handoffs during liquidation can be complex, but providing secure and compliant access to your digital records doesn't have to be a roadblock.
Problem Description: Unattainable External SharePoint Access
External liquidators require access to sensitive corporate documentation stored in a company's SharePoint Online tenant. However, they cannot access these files independently because, by default, external users are blocked from internal Microsoft 365 environments without explicit administrative authorization and proper identity provisioning.
Quick Answer for Sharing Tenant Data with Liquidators
A Global Administrator or SharePoint Administrator must enable external sharing at the tenant and site level, invite the liquidators as Microsoft Entra guest users, and grant them specific permissions. If policies prohibit external sharing, an internal user must export the required files and transfer them via an approved secure channel.
Likely Causes Behind Blocked Third-Party File Access
- External Sharing is Disabled: The Microsoft 365 tenant or specific SharePoint site has external sharing disabled by default for security reasons.
- Lack of Guest Accounts: The liquidators have not been formally invited and authenticated as Microsoft Entra (formerly Azure AD) guest users.
- Insufficient Permissions: Even if sharing is on, specific read/view permissions haven't been assigned to the required document libraries.
- Conditional Access Policies: Existing IT security policies may block access from unrecognized IP addresses or non-company devices.
Recommended Solution: Provisioning Entra Guest Access
- Verify Company Policy: Confirm with your legal or compliance team that external sharing is permitted for the liquidation process.
- Enable Tenant-Level Sharing: Log into the SharePoint admin center as a Global or SharePoint Admin. Navigate to Policies > Sharing and adjust the external sharing slider to allow "New and existing guests."
- Enable Site-Level Sharing: In the active sites list, select the specific SharePoint site containing the records. Click Settings and ensure external sharing is enabled for that particular site.
- Invite Guests via Microsoft Entra ID: Go to the Microsoft Entra admin center, navigate to Users > All users, and select New guest user. Send an invitation to the liquidator's official email address.
- Grant Site Access: Once the liquidator accepts the invitation, navigate to the required SharePoint site. Click Share on the specific document library or folder, enter the guest's email, set permissions to "Can view" (or as required), and send the link.
Alternative Solutions for Restricted External Sharing Environments
- Manual Secure Export: If tenant-wide external sharing is strictly prohibited or no administrators are available, an authorized internal user can download the required folders as ZIP files. These files can then be transferred to the liquidators using an encrypted, third-party managed file transfer (MFT) service.
- Provisioning Internal Accounts: Temporarily create standard, licensed internal accounts within the company's Microsoft 365 tenant specifically for the liquidators. Enforce multi-factor authentication (MFA) and restrict their access only to the necessary SharePoint sites.
Working with WPS Office: Managing Exported Company Records
While WPS Office cannot directly modify SharePoint tenant permissions or Microsoft Entra settings, it is highly recommended as a lightweight, free alternative for managing exported records. If you must use the manual export method, liquidators and internal staff can use WPS Office to reliably open, edit, and convert Microsoft Word, Excel, and PDF documents. Its excellent cross-platform compatibility ensures that exported corporate financial logs, contracts, and inventories can be processed without requiring expensive, secondary Microsoft 365 subscriptions.
Prevention Tips for Secure External File Collaboration
- Apply the Principle of Least Privilege: Only grant access to the specific folders or document libraries the liquidator explicitly needs, rather than the entire site.
- Set Expiration Dates: When generating sharing links, configure an expiration date to ensure access is automatically revoked once the liquidation audit is complete.
- Audit Guest Activity: Use Microsoft Purview audit logs to monitor what files external liquidators are viewing or downloading.
- Enforce MFA for Guests: Ensure your conditional access policies require multi-factor authentication for all external guest accounts accessing company data.
FAQs About SharePoint Guest Privileges
Can standard SharePoint site owners invite liquidators without IT admin involvement?
Site owners can only invite external guests if the Global or SharePoint Administrator has previously enabled external sharing at both the tenant and site levels. If it is restricted globally, site owners cannot bypass this setting.
Do external liquidators need their own Microsoft 365 licenses to view the files?
No. When invited as a Microsoft Entra guest user, the liquidator can access and view the shared SharePoint files using their own email address without requiring a paid Microsoft 365 license from your company.
How do I immediately revoke a liquidator's access once they are finished?
An administrator can go into the Microsoft Entra admin center, locate the guest user's profile, and delete the account. Alternatively, the site owner can go to the SharePoint site's permission settings and remove the guest's access to the specific folders or libraries.




