logo
search
Security Policy Errors

How to Disable Anonymous Access to SharePoint lists.asmx Endpoint

Huda QurayshiHuda Qurayshi Sep 27, 2026 869 views

Question details

The administrator needs to understand and restrict anonymous access to the SharePoint /_vti_bin/lists.asmx web service endpoint when external sharing is already disabled.

How to Disable Anonymous Access to the SharePoint lists.asmx Endpoint
Product
Microsoft SharePoint
Device & OS
not provided
Scenario
Securing Microsoft 365 SharePoint web service endpoints against unauthorized programmatic access.
Observed behavior
Anonymous users may still be able to access the /_vti_bin/lists.asmx web service endpoint despite external sharing being disabled in Microsoft 365.
Before you start

Ensure you have global administrator or SharePoint administrator privileges in Microsoft 365 to modify external sharing configurations and site access policies.

Solution 1Recommended

Restrict Site-Level External Sharing Settings

Ensure the specific SharePoint site is configured to prevent anonymous access by limiting sharing strictly to people within your organization.

The /_vti_bin/lists.asmx address is a SharePoint SOAP web service endpoint used for programmatic list access. Securing it requires properly configuring site-level sharing rules.

1
Open SharePoint Admin Center

Log into the Microsoft 365 Admin Center and navigate to the SharePoint Admin Center.

2
Navigate to Active Sites

In the left navigation pane, expand 'Sites' and click on 'Active sites'.

3
Select the Target Site

Locate and click on the specific SharePoint site where the lists.asmx endpoint is being accessed.

4
Modify Sharing Settings

Click on the 'Sharing' tab for the selected site and set the external sharing configuration to 'Only people in your organization'.

5
Save Configurations

Save your changes and allow some time for the new policy to propagate across the tenant.

Restrict Site-Level External Sharing Settings
Verification: After applying the changes, test the lists.asmx endpoint without authentication to confirm that anonymous access is completely blocked.
Free Microsoft Office alternative

Looking for a Secure and Reliable Office Suite?

While resolving complex SharePoint and Microsoft 365 administrative settings, consider WPS Office as a lightweight, secure, and cost-effective alternative for your daily document processing needs. WPS Office offers robust tools for creating and editing documents with zero administrative overhead.

  1. 1. Download WPS Office: Visit the official WPS Office website and click the free download button.
  2. 2. Install the Software: Run the lightweight installer and follow the simple on-screen instructions.
  3. 3. Start Creating: Open WPS Office to seamlessly edit your Microsoft Office formatted documents locally.
Fully compatible with Microsoft Word, Excel, and PowerPoint formats (.docx, .xlsx, .pptx).Lightweight design ensuring fast installation and smooth operation on any device.Secure local document editing without complex cloud endpoint vulnerabilities.Familiar user interface for immediate productivity with zero learning curve.
microsoft office alternative - wps office

Frequently Asked Questions

What is the /_vti_bin/lists.asmx endpoint used for in SharePoint?

It is a legacy SOAP web service endpoint used by developers and third-party applications for programmatic access to read, create, and manage SharePoint lists and their underlying data.

Why can anonymous users access lists.asmx if external sharing is turned off?

This situation can occur if legacy authentication protocols are still enabled on the tenant, if specific site-collection features permit limited anonymous access, or if there is a conflict in tenant-level guest link policies overriding site settings.

How do I test if my SharePoint endpoint allows anonymous access?

You can test the endpoint by attempting to navigate to the site's /_vti_bin/lists.asmx URL in a private or incognito browser window where you are not logged into your Microsoft 365 account, or by using an API testing tool like Postman without passing any authentication headers.