The KAUST Information Technology Department blog
05 August, 2026
As KAUST IT prepares for the rollout of Microsoft Copilot, now is a good time to review how you have shared files and folders in OneDrive and SharePoint.
Many of us use broad sharing options because they are quick and convenient. A link that works for anyone who receives it, or for anyone at KAUST with the link, can be useful when circulating an event agenda, workshop materials, public guidance, or other information intended for a large audience.
The difficulty is that sharing permissions can remain in place long after the original event, project, or collaboration has ended. A file shared broadly several years ago may still be accessible today, even if you have forgotten that the link exists.
Copilot changes discovery, not permissions.
Copilot cannot bypass Microsoft 365 permissions or open files that someone is not authorized to access. It can, however, make it easier for people to find, summarize, or reference information they already have permission to see.
Today, someone may need to know that a document exists, remember where it was stored, or receive the original sharing link before they can find it.
With Copilot, someone may be able to ask a question such as:
“Find the workshop planning document and summarize the proposed activities.”
If that person already has access because the document was shared with a broad group, Copilot may be able to help them discover and use it. This is why it is important that your current sharing permissions still reflect what you intended.

You do not need to review every document you have ever created. Start with files and folders that are most likely to have been shared broadly:
For each item, ask one simple question: Do all of these people still need access?
SharePoint access may come from more than one place
A person may be able to open a file because it was shared with them directly, through a sharing link, through a SharePoint group, or because they are a member of the site or connected Team. Removing one link may not remove access received through another route.
Broad sharing is not automatically wrong. The right option depends on the information and why it is being shared.
| Sharing option | When it may be appropriate | What to keep in mind |
|---|---|---|
| Specific people | Documents intended for named colleagues, collaborators, or reviewers | Usually the safest choice when only a defined group needs access |
| SharePoint site or Team members | Ongoing work owned and managed by an established department, project, research group, or team | Site and Team owners should regularly review membership and remove people who no longer need access |
| People at KAUST with the link | Information that anyone in the KAUST community may legitimately need | The link may be forwarded to other KAUST community members |
| Anyone with the link | Public or temporary information that is appropriate to share without requiring sign-in | Anyone who receives or is forwarded the link may be able to open it |
| Department or team website | Information that should remain available to a large audience over time | Provides a clearer permanent home than a long-lived personal sharing link |
Check whether editing is really needed
When someone only needs to read a document, use Can view rather than Can edit. Editing access may allow people to change files and, when applied to a folder, may also allow them to add, move, rename, share, or delete its contents.
If access is only needed for a limited period, use an expiration date when that option is available for the type of link you are creating.
This can be useful when sharing:
After the expiration date, the link stops working automatically. This removes the need to remember to return later and disable it manually.
Learn how to configure sharing links, permissions, and expiration dates
OneDrive is designed primarily for files owned and managed by an individual. A personal sharing link may not be the best long-term home for information that a department, division, research group, or team needs to maintain indefinitely.
SharePoint and Teams are better suited to information owned by a group, but the site or Team still needs a clear owner and appropriate membership.
For information intended to remain available to a large audience, consider publishing it through an appropriate shared location, such as:
This gives the information a clear owner and a stable location, rather than leaving an important resource dependent on one person’s OneDrive account or an old sharing link.
Microsoft Copilot respects the access controls already used across Microsoft 365. It does not change your sharing settings, grant additional permission, or allow someone to bypass restrictions applied to a file or site.
If your permissions are correct, Copilot will continue to respect them.
The purpose of this review is simply to make sure that permissions applied in the past still match your intentions today.
A simple rule for future sharing
Share with the smallest audience that genuinely needs access, give people only the level of access they need, and use an expiration date when the access is temporary.
Microsoft provides illustrated guidance for checking who can access a file and changing or removing permissions: