{"id":89918,"date":"2026-09-17T12:22:55","date_gmt":"2026-09-17T05:22:55","guid":{"rendered":"https:\/\/itsystems.vn\/control-google-drive-sharepoint-sharing-permissions\/"},"modified":"2026-09-17T12:22:59","modified_gmt":"2026-09-17T05:22:59","slug":"control-google-drive-sharepoint-sharing-permissions","status":"publish","type":"post","link":"https:\/\/itsystems.vn\/en\/control-google-drive-sharepoint-sharing-permissions\/","title":{"rendered":"Controlling Google Drive and SharePoint sharing permissions: where should SMEs start?"},"content":{"rendered":"<style id=\"its-five-new-post-clean-layout-en\">\nbody.postid-89918 #brxe-eshixv { display: none !important; }\nbody.postid-89918 #brxe-c544ff { display: block !important; max-width: 1120px !important; margin-left: auto !important; margin-right: auto !important; padding-left: 24px !important; padding-right: 24px !important; }\nbody.postid-89918 #brxe-oxprhc { width: 100% !important; max-width: 920px !important; margin-left: auto !important; margin-right: auto !important; }\nbody.postid-89918 #brxe-bbjupk { width: 100% !important; max-width: 860px !important; height: auto !important; margin-left: auto !important; margin-right: auto !important; display: block !important; }\n@media (max-width: 767px) { body.postid-89918 #brxe-c544ff { padding-left: 16px !important; padding-right: 16px !important; } }\n<\/style>\n<p><strong>Quick answer:<\/strong> Google Drive and SharePoint help teams collaborate quickly, but sharing permissions can expand quietly. A folder that started as a sales workspace may later include accounting, partners, former employees or public links. SMEs should start with critical folders, data owners, permission groups, external sharing, edit rights and leaver access.<\/p>\n<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_88 counter-hierarchy ez-toc-counter ez-toc-light-blue ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">The content of the article<\/p>\n<span class=\"ez-toc-title-toggle\"><a href=\"#\" class=\"ez-toc-pull-right ez-toc-btn ez-toc-btn-xs ez-toc-btn-default ez-toc-toggle\" aria-label=\"Toggle Table of Content\"><span class=\"ez-toc-js-icon-con\"><span class=\"\"><span class=\"eztoc-hide\" style=\"display:none;\">Toggle<\/span><span class=\"ez-toc-icon-toggle-span\"><svg style=\"fill: #999;color:#999\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" class=\"list-377408\" width=\"20px\" height=\"20px\" viewBox=\"0 0 24 24\" fill=\"none\"><path d=\"M6 6H4v2h2V6zm14 0H8v2h12V6zM4 11h2v2H4v-2zm16 0H8v2h12v-2zM4 16h2v2H4v-2zm16 0H8v2h12v-2z\" fill=\"currentColor\"><\/path><\/svg><svg style=\"fill: #999;color:#999\" class=\"arrow-unsorted-368013\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"10px\" height=\"10px\" viewBox=\"0 0 24 24\" version=\"1.2\" baseProfile=\"tiny\"><path d=\"M18.2 9.3l-6.2-6.3-6.2 6.3c-.2.2-.3.4-.3.7s.1.5.3.7c.2.2.4.3.7.3h11c.3 0 .5-.1.7-.3.2-.2.3-.5.3-.7s-.1-.5-.3-.7zM5.8 14.7l6.2 6.3 6.2-6.3c.2-.2.3-.5.3-.7s-.1-.5-.3-.7c-.2-.2-.4-.3-.7-.3h-11c-.3 0-.5.1-.7.3-.2.2-.3.5-.3.7s.1.5.3.7z\"\/><\/svg><\/span><\/span><\/span><\/a><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/itsystems.vn\/en\/control-google-drive-sharepoint-sharing-permissions\/#Why_cloud_sharing_gets_out_of_control\" >Why cloud sharing gets out of control<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/itsystems.vn\/en\/control-google-drive-sharepoint-sharing-permissions\/#Permission_types_to_check\" >Permission types to check<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/itsystems.vn\/en\/control-google-drive-sharepoint-sharing-permissions\/#Monthly_review_checklist\" >Monthly review checklist<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/itsystems.vn\/en\/control-google-drive-sharepoint-sharing-permissions\/#What_should_the_report_say\" >What should the report say?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/itsystems.vn\/en\/control-google-drive-sharepoint-sharing-permissions\/#How_this_connects_with_DLP_and_backup\" >How this connects with DLP and backup<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"https:\/\/itsystems.vn\/en\/control-google-drive-sharepoint-sharing-permissions\/#Frequently_Asked_Questions\" >Frequently Asked Questions<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-7\" href=\"https:\/\/itsystems.vn\/en\/control-google-drive-sharepoint-sharing-permissions\/#Should_external_sharing_be_disabled_completely\" >Should external sharing be disabled completely?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-8\" href=\"https:\/\/itsystems.vn\/en\/control-google-drive-sharepoint-sharing-permissions\/#Are_permission_groups_better_than_individual_sharing\" >Are permission groups better than individual sharing?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-9\" href=\"https:\/\/itsystems.vn\/en\/control-google-drive-sharepoint-sharing-permissions\/#Do_Google_Drive_and_SharePoint_need_separate_backup\" >Do Google Drive and SharePoint need separate backup?<\/a><\/li><\/ul><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-10\" href=\"https:\/\/itsystems.vn\/en\/control-google-drive-sharepoint-sharing-permissions\/#Need_to_standardize_cloud_data_access\" >Need to standardize cloud data access?<\/a><\/li><\/ul><\/nav><\/div>\n<h2><span class=\"ez-toc-section\" id=\"Why_cloud_sharing_gets_out_of_control\"><\/span>Why cloud sharing gets out of control<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Traditional file servers are often permissioned by IT at the folder level. Drive and SharePoint let users share files, create links, invite outsiders and move data into personal spaces. That speed is useful, but without rules, quotations, contracts, HR files, finance data and project documents can become over-shared.<\/p>\n<p>The risk rarely appears on day one. It accumulates after months of department changes, completed projects, copied folders and ownership changes. When an incident occurs, nobody can quickly answer who has access to what.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Permission_types_to_check\"><\/span>Permission types to check<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<table>\n<thead>\n<tr>\n<th>Permission type<\/th>\n<th>Question to answer<\/th>\n<th>Better operating practice<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Owner<\/td>\n<td>Who is accountable for this folder?<\/td>\n<td>Assign ownership by department or process<\/td>\n<\/tr>\n<tr>\n<td>Editor<\/td>\n<td>Who can change or delete files?<\/td>\n<td>Use groups instead of adding individuals<\/td>\n<\/tr>\n<tr>\n<td>Viewer<\/td>\n<td>Who only needs to read?<\/td>\n<td>Separate view-only and edit access<\/td>\n<\/tr>\n<tr>\n<td>External sharing<\/td>\n<td>Are outsiders included?<\/td>\n<td>Limit by project and review date<\/td>\n<\/tr>\n<tr>\n<td>Public links<\/td>\n<td>Are any anyone-with-link URLs active?<\/td>\n<td>Require approval and owner review<\/td>\n<\/tr>\n<tr>\n<td>Former users<\/td>\n<td>Do leavers still own files?<\/td>\n<td>Transfer ownership and remove access<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2><span class=\"ez-toc-section\" id=\"Monthly_review_checklist\"><\/span>Monthly review checklist<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>The company does not need to inspect every file every day. Start with important data groups: finance, contracts, quotations, HR, customers, projects and technical documents. For each group, identify the owner, root folder, viewers, editors, external links and files owned by former employees.<\/p>\n<ul>\n<li>List business-critical folders by department.<\/li>\n<li>Check public or external sharing links.<\/li>\n<li>Transfer ownership from departed employees.<\/li>\n<li>Prefer groups over individual permissions.<\/li>\n<li>Document exceptions and next review dates.<\/li>\n<li>Add the result to the monthly IT or security report.<\/li>\n<\/ul>\n<h2><span class=\"ez-toc-section\" id=\"What_should_the_report_say\"><\/span>What should the report say?<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>A useful access report should not only list the number of files scanned. It should show folders with external users, links that allow anyone-with-link access, owners who no longer work at the company, sensitive folders without a named owner and exceptions that need management approval. This turns a technical permission review into a business decision list.<\/p>\n<p>For SMEs, this report can be short. The important part is that each risky permission has an owner, a reason to keep it, or a planned removal date. Without that owner, the same risky shares will remain open after every review.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"How_this_connects_with_DLP_and_backup\"><\/span>How this connects with DLP and backup<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Permission control does not replace <a href=\"\/en\/data-loss-prevention-software-for-business\/\">Data Loss Prevention<\/a>, but it reduces exposure before DLP rules are needed. DLP detects or controls sensitive data movement; permission governance limits who can access the data in the first place. For cloud documents, the business should also consider backup if accidental deletion, ransomware sync or compromised accounts are real risks.<\/p>\n<section class=\"its-post-faq\">\n<h2><span class=\"ez-toc-section\" id=\"Frequently_Asked_Questions\"><\/span>Frequently Asked Questions<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<h3><span class=\"ez-toc-section\" id=\"Should_external_sharing_be_disabled_completely\"><\/span>Should external sharing be disabled completely?<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Not always. Many businesses need to collaborate with customers or partners. The key is ownership, scope, reason and review date.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"Are_permission_groups_better_than_individual_sharing\"><\/span>Are permission groups better than individual sharing?<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Yes. Groups make onboarding and offboarding easier and reduce scattered access from former users.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"Do_Google_Drive_and_SharePoint_need_separate_backup\"><\/span>Do Google Drive and SharePoint need separate backup?<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Consider it for important data, especially if retention, accidental deletion or ransomware recovery requirements exceed the platform defaults.<\/p>\n<\/section>\n<section class=\"its-post-cta\">\n<h2><span class=\"ez-toc-section\" id=\"Need_to_standardize_cloud_data_access\"><\/span>Need to standardize cloud data access?<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>IT Systems can review users, groups, Drive, SharePoint, leaver access and data-sharing risks as part of recurring IT administration.<\/p>\n<p><a href=\"\/en\/it-system-administration\/\">View IT system administration<\/a><\/p>\n<\/section>\n","protected":false},"excerpt":{"rendered":"<p>Google Drive and SharePoint sharing can expand quietly. Start with public links, owners, permission groups, external access and leaver data.<\/p>\n","protected":false},"author":34,"featured_media":89773,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"rank_math_focus_keyword":"Google Drive SharePoint sharing permissions","rank_math_title":"Controlling Google Drive and SharePoint sharing permissions: where should SMEs start? | IT Systems","rank_math_description":"Google Drive and SharePoint sharing can expand quietly. Start with public links, owners, permission groups, external access and leaver data.","rank_math_robots":"","rank_math_canonical_url":"https:\/\/itsystems.vn\/en\/control-google-drive-sharepoint-sharing-permissions\/","rank_math_schema":"","footnotes":""},"categories":[32],"tags":[],"class_list":["post-89918","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-tin-tuc-it-hang-ngay"],"wpml_current_locale":"en_US","wpml_translations":{"vi_VN":{"locale":"vi_VN","id":89818,"slug":"kiem-soat-quyen-chia-se-google-drive-sharepoint","post_title":"Ki\u1ec3m so\u00e1t quy\u1ec1n chia s\u1ebb Google Drive v\u00e0 SharePoint: SME n\u00ean b\u1eaft \u0111\u1ea7u t\u1eeb \u0111\u00e2u?","href":"https:\/\/itsystems.vn\/kiem-soat-quyen-chia-se-google-drive-sharepoint\/"}},"_links":{"self":[{"href":"https:\/\/itsystems.vn\/en\/wp-json\/wp\/v2\/posts\/89918","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/itsystems.vn\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/itsystems.vn\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/itsystems.vn\/en\/wp-json\/wp\/v2\/users\/34"}],"replies":[{"embeddable":true,"href":"https:\/\/itsystems.vn\/en\/wp-json\/wp\/v2\/comments?post=89918"}],"version-history":[{"count":1,"href":"https:\/\/itsystems.vn\/en\/wp-json\/wp\/v2\/posts\/89918\/revisions"}],"predecessor-version":[{"id":89919,"href":"https:\/\/itsystems.vn\/en\/wp-json\/wp\/v2\/posts\/89918\/revisions\/89919"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/itsystems.vn\/en\/wp-json\/wp\/v2\/media\/89773"}],"wp:attachment":[{"href":"https:\/\/itsystems.vn\/en\/wp-json\/wp\/v2\/media?parent=89918"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/itsystems.vn\/en\/wp-json\/wp\/v2\/categories?post=89918"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/itsystems.vn\/en\/wp-json\/wp\/v2\/tags?post=89918"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}