How to Block or Control Inbound External OneDrive Sharing
Question details
The user wants to prevent external tenants from sharing files or folders with internal Microsoft 365 users via OneDrive.
- Product
- Microsoft 365 / OneDrive
- Device & OS
- not provided
- Scenario
- Securing an internal Microsoft 365 environment by restricting inbound collaboration and file sharing from external domains.
- Observed behavior
- While outbound external sharing is successfully restricted, there is no simple or obvious tenant-wide switch to block inbound external sharing from other organizations.
Ensure you have Microsoft 365 Global Administrator or Security Administrator permissions, as managing inbound sharing controls requires modifying tenant-wide Entra ID and compliance policies.
Configure Microsoft Entra Cross-Tenant Access Settings
Use Microsoft Entra (formerly Azure AD) cross-tenant access settings to explicitly block inbound B2B collaboration from all external tenants or specific domains.
Because Microsoft 365 does not offer a simple toggle for inbound OneDrive sharing, configuring Cross-Tenant Access settings is the most effective way to block external organizations from collaborating with your internal users.
Navigate to the Microsoft Entra admin center and log in with your Global Administrator or Security Administrator credentials.
In the left-hand navigation menu, expand 'Identity', go to 'External Identities', and select 'Cross-tenant access settings'.
Click on the 'Default settings' tab, then click 'Edit inbound defaults' under the B2B collaboration section.
Set the access status to 'Block access' for external users and groups, and save your changes. This prevents external tenants from initiating new sharing or collaboration invitations with your users.
Implement Defender for Office 365 and Conditional Access Controls
Apply a layered security approach to protect internal users from malicious external links if complete inbound blocking is not feasible.
Looking for a Secure and Free Office Suite? Try WPS Office
While managing complex Microsoft 365 tenant settings can be challenging and requires extensive administrative oversight, WPS Office provides a lightweight, highly compatible alternative for everyday document editing. It offers robust local file management and security without the overhead of cloud tenant configurations.
- 1. Download WPS Office: Visit the official WPS website and download the free installation package for your operating system.
- 2. Install the Application: Run the installer and follow the on-screen instructions to set up WPS Office on your device.
- 3. Open and Protect Documents: Launch WPS Office, open your existing Microsoft Office files, and use the built-in encryption tools to secure your data locally.

Frequently Asked Questions
Is there a single switch to block all inbound external sharing in Microsoft 365?
No, Microsoft 365 does not offer a simple, single tenant-wide toggle exclusively for inbound sharing. Administrators must rely on a combination of Entra cross-tenant access settings, Conditional Access, and Defender policies to mitigate inbound sharing risks.
Does disabling outbound external sharing automatically block inbound sharing?
No. Outbound sharing policies only prevent your internal users from sharing files with external parties. They do not stop external users from generating and sending sharing links to your internal tenant users.
Can I block inbound sharing from specific domains while allowing others?
Yes. Using the Microsoft Entra admin center, you can configure Cross-Tenant Access Settings to set a default block for all external organizations, and then add specific domains to an allowlist under 'Organizational settings'.




