How to Investigate an Unauthorized OneDrive File Share
Question details
The user needs to investigate an unexpected anonymous sharing event for a confidential file in OneDrive and secure the potentially compromised account.

- Product
- Microsoft OneDrive
- Device & OS
- not provided
- Scenario
- A confidential OneDrive file was shared anonymously without authorization, requiring investigation and remediation.
- Observed behavior
- An unexpected anonymous sharing event occurred, raising concerns of a potential account security breach.
Ensure you have Global Administrator or Compliance Administrator permissions in Microsoft 365, as standard users cannot access organization-wide audit logs.
Search Audit Logs and Secure the Microsoft 365 Account
Use the Microsoft 365 admin center to track down the sharing activity details and immediately lock down the affected user account.
Audit logs provide detailed insights into file-sharing activities, including timestamps, the user who triggered the event, the application used, and sometimes the device or operating system involved.
Log in to the Microsoft 365 admin center and navigate to the Security or Compliance center.
Select 'Audit log search' and filter your search by the relevant date range, specific file-sharing activities, and the affected user.
Analyze the search results to identify exactly when the sharing occurred, which application was used, and if any suspicious IP addresses or devices were involved.
Go to the affected OneDrive file's settings and immediately revoke any unknown or anonymous sharing links to block unauthorized access.
Review the user's recent sign-in activity, reset their password, and enforce Multifactor Authentication (MFA) to secure the account from further compromise.

Secure Your Local Documents with WPS Office
While investigating Microsoft 365 cloud sharing requires enterprise admin logs, you can protect your local files securely with WPS Office. It provides robust built-in encryption and is a lightweight, free alternative to Microsoft Office.
- 1. Install WPS Office: Download and install WPS Office from the official website.
- 2. Open Your Document: Launch WPS Office and open the confidential document you wish to secure.
- 3. Encrypt the File: Navigate to 'Menu' > 'Document Encryption' and set a strong password to prevent unauthorized viewing or editing.

Frequently Asked Questions
Who can access Microsoft 365 audit logs to investigate OneDrive sharing?
Only users assigned the Global Administrator or appropriate Compliance Administrator roles can search the Microsoft 365 unified audit logs.
How do I stop anonymous sharing in OneDrive entirely?
An administrator can disable 'Anyone with the link' (anonymous) sharing globally for the organization or specifically for SharePoint and OneDrive through the SharePoint Admin Center.
How long are audit logs kept in Microsoft 365?
By default, Microsoft 365 retains audit logs for 90 days for standard licenses. This can be extended up to one year or more depending on your organization's subscription tier, such as E5.
Can a standard user check who shared their OneDrive files?
Standard users can manage access and see who currently has links to their files via the 'Manage Access' pane in OneDrive, but they cannot view backend audit logs to investigate anonymous access events.




