5 Musts for Secure File Sharing With Clients on Microsoft 365 for SMEs
Microsoft 365 first steps for small businesses to share client files securely: five non negotiables, practical checklists and Hostme setup help.

The best approach for sending sensitive client files is a branded client portal or governed Microsoft 365 sharing using “specific people” links, never a plain email attachment or an open “anyone with the link” URL. Five things must be in place regardless of which method you choose: encryption in transit and at rest, some form of authentication before access is granted, an expiry or revocation option, an audit trail showing who accessed what and when, and access limited to the smallest group of people who genuinely need it. IT support providers can assist with setting this up on your existing Microsoft 365 tenant if you’d rather not do it alone.
TL;DR:
- Using “specific people” links with encryption, expiry, and audit logging is essential for secure file sharing, especially with sensitive client data.
- Default tenant-level sharing settings must be tightened, and site-specific controls should restrict overly permissive access, with regular access reviews.
- Branded portals and dropzones improve security and trust, particularly for frequent or large-volume document exchanges from clients without Microsoft 365 accounts.
- Email attachments remain vulnerable due to lack of revocation, expiry, and traceability, increasing risk of accidental exposure or unauthorized forwarding.
- Proper setup and regular audits of external sharing policies, combined with staff training, help small businesses avoid common risks and comply with data protection guidelines.
Table of Contents
- What is the most secure way to share files with clients?
- How do I set SharePoint and OneDrive external sharing safely for client files?
- Are client upload portals better than email for sensitive files?
- What’s a simple checklist for sharing files with clients securely?
- What will an auditor or the DPC expect to see?
- What are the most common file-sharing mistakes small businesses make?
- How Hostme approaches secure client sharing for small businesses
- Get your client file sharing set up properly
- Sources
- FAQ
What is the most secure way to share files with clients?
Small businesses generally choose from four practical routes: branded client portals, tenant governed Microsoft 365 sharing, secure transfer links, and controlled upload dropzones. Each suits a different mix of client type, file sensitivity, and how much fuss you’re willing to put up with day to day.
Branded client portals work well for accountants, solicitors, and consultants who receive a steady flow of documents from the same clients month after month. The client logs into a recognisable, branded space rather than digging through email threads, and every upload or download gets logged automatically. Friction for the client is low once they’re set up, and the audit trail is typically included from the start, which matters if a regulator or insurer ever asks you to prove who touched a file.
Tenant governed Microsoft 365 sharing through SharePoint, OneDrive, and Teams is the natural fit if your business already runs on Microsoft 365, which most Irish small businesses do. You’re not paying for a separate platform, and your admin can lock things down centrally. The trade off is that it takes some configuration effort up front, and if nobody in the business understands the settings, it defaults to looser permissions than you’d want.
Secure transfer links, the encrypted, one-off, expiring links some tools generate for a single file transfer, suit occasional, low-volume exchanges, such as sending a single contract to a new client. They’re quick to set up but offer little ongoing structure, so they’re a poor fit for anyone handling recurring sensitive files, like medical records or financial statements.
Controlled upload dropzones solve the opposite problem: getting files in from clients who don’t have Microsoft 365 accounts or don’t want one. A client drops a file into a branded, passcode-protected page without creating an account, and it lands directly in your governed storage.
For most small businesses already paying for Microsoft 365, the sensible default is tenant governed SharePoint or OneDrive sharing, layered with a branded portal or dropzone for specific clients who need a simpler, no-account way to send you things. That combination covers both directions of the relationship without asking you to manage a second piece of software for every use case.
- Accountants and bookkeepers: governed OneDrive/SharePoint links plus an upload dropzone for client receipts and statements.
- Designers and agencies: branded portal for delivering final assets, since clients expect a professional-looking handover.
- Solicitors and consultants: “specific people” SharePoint links for outbound documents, portal or dropzone for inbound signed paperwork.
How do I set SharePoint and OneDrive external sharing safely for client files?
Microsoft 365 external sharing is enabled by default at the tenant level, and many businesses do not adjust the settings after their initial setup. This default setting is more permissive than many small businesses expect, which can lead to accidental oversharing.
There are two layers of control worth understanding. Tenant level settings set the outer boundary for the whole organisation, the maximum level of sharing any site is allowed to use. Site level settings then narrow that further for individual SharePoint sites or OneDrive libraries. A confidential client site should be locked down tighter than a general company intranet, even though both sit inside the same tenant. Practitioner guidance on SharePoint governance recommends exactly this: keep the tenant reasonably open for productivity, then restrict sensitive sites individually rather than locking everything down and frustrating everyone.
Follow this sequence when reviewing or setting up external sharing for client work:
- Check your tenant-level ceiling first. In the SharePoint admin centre, confirm the organisation-wide sharing level isn’t set to “Anyone,” unless you have a specific, low-risk reason for it.
- Default to “Specific people” links for anything containing client data. This link type requires the recipient to be signed in as the exact person you named, which closes the gap that “Anyone” links leave wide open.
- Restrict “Anyone” links where you must use them. Microsoft’s own guidance lets admins force an expiry date on anonymous links and disable them entirely for specific sites holding sensitive files.
- Add domain restrictions so external sharing only works with named client domains, useful if you work with the same handful of firms repeatedly.
- Turn on verification codes or require sign-in for guest access, and enable multi-factor authentication for any account, staff or guest, that can reach client files.
- Set a recurring calendar reminder for a quarterly access review. Export a list of sites with active external guests and anonymous links, and close or reconfigure anything that shouldn’t still be open.
The SharePoint external sharing overview is worth bookmarking, since Microsoft updates these controls periodically and the exact menu locations shift between admin centre versions.
Pro Tip: Run the quarterly access review the same week you do your VAT return or payroll reconciliation. Tying it to an existing habit means it actually happens, rather than becoming the thing everyone means to get around to.
Admin hygiene matters as much as the initial setup. Microsoft’s documentation on turning sharing on or off points to admin reports and PowerShell exports as the practical way to find every site with an active anonymous link or a guest account nobody remembers adding. Without that visibility, permissions quietly drift wider over time as staff share files, forget to revoke access, and move on to other clients.
Are client upload portals better than email for sensitive files?
For many small businesses, yes, particularly once you’re handling the same type of document from multiple clients on a repeating basis. A branded portal or dropzone gives each client an isolated space, typically backed by pre-signed URLs that expire automatically, so nobody’s file sits accessible forever on a forgotten link.
Portals designed for this purpose, such as branded client portal platforms built for freelancers and agencies, generally isolate each client’s uploads into a separate storage bucket rather than one shared folder everyone can browse. That single design choice removes a surprising amount of risk: a client can’t stumble onto another client’s files, even by accident, because there’s no shared directory structure to wander into.
Look for these features before choosing a portal:
- Audit logs that record every upload, download, and view with a timestamp.
- Passcode or verification requirements so a leaked link alone isn’t enough to reach the files.
- Your own branding, since a portal that looks like your business builds more client trust than a generic file-sharing page.
- Expiry and revocation controls you can trigger manually, not just automatic timeouts.
- Exportable logs, so you can hand a clean record to an auditor, accountant, or insurer without stitching one together manually.
A dropzone-style portal makes the most sense when clients don’t have Microsoft 365 accounts of their own, when you’re collecting documents from many different individuals (think a solicitor gathering ID and proof of address from dozens of new clients), or when you want to remove the temptation for staff to just email a spreadsheet because it’s quicker. If your client base is a small, stable set of businesses who already work inside Microsoft 365, governed “specific people” links may cover you without the added cost of a separate platform.
Pro Tip: If you’re weighing up whitelabelled platforms for a client-facing portal, features like custom domains and branded login pages matter more than most people expect. A client is far more likely to trust and actually use a portal that looks like it belongs to your business rather than a third-party tool.
What’s a simple checklist for sharing files with clients securely?
Two short workflows cover almost every situation a small business runs into: sending files out to a client, and receiving files in from one.
Outbound workflow (you sending files to a client):
- Confirm the file needs to leave your systems at all, some requests can be answered by giving view-only access instead of a copy.
- Create a “specific people” SharePoint or OneDrive link, or package the file into your client portal if you use one.
- Set an expiry date on the link, even a generous one, rather than leaving it open indefinitely.
- Send the link through one channel and any passcode through a separate one, for instance the link by email and the passcode by text or a quick phone call.
- Log the share, who received it, when, and why, even a simple spreadsheet entry is better than relying on memory.
Inbound workflow (a client sending files to you):
- Point the client to your branded dropzone or upload portal rather than accepting attachments by email.
- Require a verification step, such as a passcode you’ve shared separately, before the upload completes.
- Confirm receipt with the client so they know the file landed and don’t resend it insecurely as a backup.
- Move the file into your governed, permanent storage promptly rather than leaving it sitting in the dropzone.
- Rotate or expire any temporary upload keys once the transfer is complete.
Keep a short standing checklist alongside both workflows: confirm the file is encrypted in transit and at rest, apply your firm’s retention policy so the file doesn’t linger past its useful life, use a consistent file naming convention so nothing gets lost, review access on a set schedule, and revoke access the moment a project or engagement ends.
What will an auditor or the DPC expect to see?
Auditors and data protection assessments generally look for records, not promises. The most common request is a straightforward one: show who accessed a given file, from where, and when.
That means keeping access logs with timestamps, and ideally the device or IP address involved, retention and deletion records showing files were removed once no longer needed, and a data map showing where client files actually live across your systems. If you work with subcontractors or processors who handle client data on your behalf, keep the relevant data processing agreements on file too.

Irish Data Protection Commission guidance is direct on one point that catches a lot of small businesses out: anonymous “anyone with the link” sharing should be the exception, not the default, and any public link should carry a technical limit such as an automatic expiry. The same guidance pushes businesses toward platforms with persistent, timestamped access logs rather than relying on email, precisely because an email attachment leaves no trace of who forwarded it on afterwards.
SharePoint and most client portals generate this evidence automatically, which is one of the strongest practical arguments for using them over email. Exporting that log is usually a matter of a few clicks in the admin centre or portal dashboard, turning what would otherwise be hours of guesswork into a clean report.
- Access logs with timestamp, IP address, and device where available.
- Retention and deletion records for each category of client file.
- A simple data map showing where client files are stored and processed.
- Documentation of where data physically resides, since this affects which regulations apply.
A five-point standard for what “secure” actually requires shows up consistently in current guidance on this topic: encryption, passcode protection, expiry, a full audit trail, and revocation. Most audit failures trace back to one of these five being missing, not to some more exotic gap.
What are the most common file-sharing mistakes small businesses make?
Email attachments remain the single most frequent source of accidental exposure, largely because there’s no way to revoke a file once it’s sent, no expiry, and no record of who forwarded it on afterwards. An accountant emailing a client’s full financial statement, only for the client to forward it to their own bookkeeper without telling anyone, illustrates how quickly control over a file disappears once it leaves as an attachment (a hypothetical example, not a specific incident).
Shadow IT creeps in when staff feel the sanctioned method is too slow or fiddly, so they start using personal Dropbox or WhatsApp to send files instead. The fix isn’t a stern memo, it’s making the approved method genuinely easier to use than the workaround, whether that’s a portal with no account required or a Microsoft 365 link that takes seconds to generate.
Watch for these recurring red flags:
- Stale “anyone with the link” URLs that were meant to be temporary but never got revoked.
- Guest accounts left active long after a project or client relationship ended.
- Access or revocation knowledge sitting with a single person, so nobody else can act if that person is unavailable.
- No record at all of which links or shares are currently active across the business.
Running the quarterly review covered earlier catches most of these before they become a real problem, but only if it’s actually scheduled and someone owns it.
How Hostme approaches secure client sharing for small businesses
A typical approach starts with your Microsoft 365 tenant configuration, since most small businesses already own the tools they need and simply haven’t set them up for client work. That usually means correcting the default sharing settings, setting up branded upload flows for clients who need a simple way to send files in, and running short staff training so people understand why the approved method beats the workaround they’ve been using.
A typical engagement runs through assessment, configuration, training, and a scheduled access review, so the setup doesn’t quietly drift back to loose defaults six months later. If you’d like a quick technical check on your current setup, message Hostme on WhatsApp and we’ll talk you through what’s involved.
— hostme.ie
Get your client file sharing set up properly
If you’ve read this far and recognised your own business in the email-attachment and stale-link mistakes above, you’re not alone, and fixing it usually takes less time than most owners expect. Hostme provides hands-on IT support for Irish sole traders and small businesses, with direct access to one technician who actually knows your setup rather than a ticket queue that starts from scratch every time.
For secure client sharing specifically, that means configuring your Microsoft 365 tenant and SharePoint sites correctly, setting up business email on your own domain so passcodes and confirmations go out through a channel clients trust, and reviewing your security and SSL setup so external access points are properly locked down. Backups and recovery are part of the same conversation, since a sharing setup is only as good as your ability to restore a file if something goes wrong.
If you’d rather talk it through than read another checklist, send a message on WhatsApp and Hostme will walk through your current setup with you, scope agreed clearly before any work begins.
Sources
- Data sharing in the public sector | Data Protection Commission (Ireland)
- Turn external sharing on or off for SharePoint and OneDrive | Microsoft Learn
- Secure File Sharing With Clients — Free Tools for Businesses (2026) | Strac
FAQ
How can I share files with clients securely?
Use a “specific people” link in SharePoint or OneDrive, or a branded client portal, rather than an email attachment or an open “anyone” link. Both approaches should include encryption, an expiry date, and a record of who accessed the file, matching the five non-negotiables covered earlier in this piece.
What’s the most secure way to share files?
There’s no single “most secure” method, it depends on the file’s sensitivity and who’s receiving it, but governed Microsoft 365 sharing with named recipients and a branded portal with audit logs both meet the standard most auditors expect. Microsoft’s external sharing guidance recommends “specific people” links as the safer default over anonymous “Anyone” links.
What are the legal implications of file sharing for a small business?
You’re responsible for demonstrating who accessed a client’s personal data and when, which is why access logs, retention records, and a data map matter for compliance. Data Protection Commission guidance treats anonymous link sharing as something that should be exceptional rather than routine, particularly for confidential files.
What are the security risks of file sharing?
The biggest risks are unrevoked “anyone with the link” URLs, forgotten guest accounts, and email attachments that can be forwarded on without any trace. A quarterly review of active links and guest accounts closes most of these gaps before they turn into an actual exposure.
Can hostme.ie help set up secure file sharing on Microsoft 365?
Yes, Hostme configures Microsoft 365 tenant and SharePoint settings for Irish small businesses, including external sharing controls, branded upload flows, and staff training. Current pricing for this work is available directly through Hostme’s IT support page.


