logo
search
Data Protection Issues

How to Investigate an Unauthorized OneDrive File Share

Huma Ashraf ChHuma Ashraf Ch Sep 25, 2026 869 views

Question details

The user needs to investigate an unexpected anonymous sharing event for a confidential file in OneDrive and secure the potentially compromised account.

How to Investigate an Unauthorized OneDrive File Share
Product
Microsoft OneDrive
Device & OS
not provided
Scenario
A confidential OneDrive file was shared anonymously without authorization, requiring investigation and remediation.
Observed behavior
An unexpected anonymous sharing event occurred, raising concerns of a potential account security breach.
Before you start

Ensure you have Global Administrator or Compliance Administrator permissions in Microsoft 365, as standard users cannot access organization-wide audit logs.

Solution 1Recommended

Search Audit Logs and Secure the Microsoft 365 Account

Use the Microsoft 365 admin center to track down the sharing activity details and immediately lock down the affected user account.

Audit logs provide detailed insights into file-sharing activities, including timestamps, the user who triggered the event, the application used, and sometimes the device or operating system involved.

1
Access the Admin Center

Log in to the Microsoft 365 admin center and navigate to the Security or Compliance center.

2
Perform an Audit Log Search

Select 'Audit log search' and filter your search by the relevant date range, specific file-sharing activities, and the affected user.

3
Review the Activity

Analyze the search results to identify exactly when the sharing occurred, which application was used, and if any suspicious IP addresses or devices were involved.

4
Revoke Sharing Links

Go to the affected OneDrive file's settings and immediately revoke any unknown or anonymous sharing links to block unauthorized access.

5
Secure the Account

Review the user's recent sign-in activity, reset their password, and enforce Multifactor Authentication (MFA) to secure the account from further compromise.

Search Audit Logs and Secure the Microsoft 365 Account
Escalation: If the audit logs reveal highly suspicious or malicious activity, escalate the incident to your organization's IT or security team immediately.
Free Microsoft Office alternative

Secure Your Local Documents with WPS Office

While investigating Microsoft 365 cloud sharing requires enterprise admin logs, you can protect your local files securely with WPS Office. It provides robust built-in encryption and is a lightweight, free alternative to Microsoft Office.

  1. 1. Install WPS Office: Download and install WPS Office from the official website.
  2. 2. Open Your Document: Launch WPS Office and open the confidential document you wish to secure.
  3. 3. Encrypt the File: Navigate to 'Menu' > 'Document Encryption' and set a strong password to prevent unauthorized viewing or editing.
Fully compatible with Microsoft Office formats like Word, Excel, and PowerPoint.Built-in document encryption to protect confidential files from unauthorized access.Familiar, intuitive user interface for seamless migration without a learning curve.Lightweight and completely free to use on Windows, Mac, Linux, and mobile.
microsoft office alternative - wps office

Frequently Asked Questions

Who can access Microsoft 365 audit logs to investigate OneDrive sharing?

Only users assigned the Global Administrator or appropriate Compliance Administrator roles can search the Microsoft 365 unified audit logs.

How do I stop anonymous sharing in OneDrive entirely?

An administrator can disable 'Anyone with the link' (anonymous) sharing globally for the organization or specifically for SharePoint and OneDrive through the SharePoint Admin Center.

How long are audit logs kept in Microsoft 365?

By default, Microsoft 365 retains audit logs for 90 days for standard licenses. This can be extended up to one year or more depending on your organization's subscription tier, such as E5.

Can a standard user check who shared their OneDrive files?

Standard users can manage access and see who currently has links to their files via the 'Manage Access' pane in OneDrive, but they cannot view backend audit logs to investigate anonymous access events.