Domain restrictions when sharing SharePoint & OneDrive content - SharePoint in Microsoft 365 (2024)

  • Article

If you want to restrict sharing with other organizations (either at the organization level or site level), you can limit sharing by domain.

Note

If you have enrolled in the SharePoint and OneDrive integration with Microsoft Entra B2B, invitations in SharePoint are also subject to any domain restrictions configured in Microsoft Entra ID.

Limiting domains

You can limit domains by allowing only the domains you specify or by allowing all domains except those you block.

To limit domains at the organization level

  1. Go to Sharing in the SharePoint admin center, and sign in with an account that has admin permissions for your organization.

    Note

    If you have Office 365 operated by 21Vianet (China), sign in to the Microsoft 365 admin center, then browse to the SharePoint admin center and open the Sharing page.

  2. Under Advanced settings for external sharing, select the Limit external sharing by domain check box, and then select Add domains.

  3. To create an allowlist (most restrictive), select Allow only specific domains; to block only the domains you specify, select Block specific domains.

  4. List the domains (maximum of 5000) in the box provided, using the format domain.com. If listing more than one domain, enter each domain on a new line.

    Note

    Wildcards are not supported for domain entries.

  5. Select Save.

You can also configure the organization-wide setting by using the Set-SPOTenant PowerShell cmdlet.

You can also limit domains at the site collection level. Note the following considerations:

  • In the case of conflicts, the organization-wide configuration takes precedence over the site collection configuration.

  • If an organization-wide allowlist is configured, then you can only configure an allowlist at the site collection level. The site collection allowlist must be a subset of the organization's allowlist.

  • If an organization-wide blocklist is configured, then you can configure either an allowlist or a blocklist at the site collection level.

  • For individual OneDrive site collections, you can only configure this setting by using the Set-SPOSite Windows PowerShell cmdlet.

To limit domains for a site

  1. Go to Active sites in the SharePoint admin center, and sign in with an account that has admin permissions for your organization.

    Note

    If you have Office 365 operated by 21Vianet (China), sign in to the Microsoft 365 admin center, then browse to the SharePoint admin center and open the More features page.

  2. Select the site name that you want to restrict domains to open the details panel.

  3. On the panel, select the Settings tab and select More sharing settings under External file sharing.

  4. Under Advanced settings for external sharing, select the Limit external sharing by domain check box, and then select Add domains.

  5. Select Allow only specific domains to create an allowlist (most restrictive), or to block only the domains you specify, select Block specific domains.

  6. List the domains (maximum of 500) in the box provided, using the format domain.com. If listing more than one domain, enter each domain on a new line.

    Note

    Wildcards are not supported for domain entries.

  7. Select Save, and then select Save again.

    Note

    To configure the site collection setting for site collections that do not appear in this list (such as Group-connected sites or individual OneDrive site collections), you must use the Set-SPOSite PowerShell cmdlet.

Sharing experience

After you limit sharing by domain, here's what you'll see when you share a document:

  • Sharing content with email domains that are not allowed. If you attempt to share content with a guest whose email address domain isn't allowed, an error message will display and sharing will not be allowed.

    (If the user is already in your directory, you won't see the error, but they will be blocked if they attempt to access the site.)

    Domain restrictions when sharing SharePoint & OneDrive content - SharePoint in Microsoft 365 (1)

  • Sharing OneDrive files with guests on domains that aren't allowed. If a user tries to share a OneDrive file with a guest whose email domain isn't allowed, an error message will display and sharing will not be allowed.

    Domain restrictions when sharing SharePoint & OneDrive content - SharePoint in Microsoft 365 (2)

  • Sharing content with email domains that are allowed. Users will be able to successfully share the content with the guest. A tooltip will appear to let them know that the guest is outside of their organization.

    Domain restrictions when sharing SharePoint & OneDrive content - SharePoint in Microsoft 365 (3)

User auditing and lifecycle management

As with any extranet sharing scenario it's important to consider the lifecycle of your guests, how to audit their activity, and eventually how to archive the site. See Planning SharePoint business-to-business (B2B) extranet sites for more information.

See also

External sharing overview

Extranet for Partners with Microsoft 365

Set-SPOTenant

Domain restrictions when sharing SharePoint & OneDrive content - SharePoint in Microsoft 365 (2024)
Top Articles
Determine Residency for Tax Purposes | The Office of International Affairs
How To Transfer Money From One Netspend Card To Another [Easy Methods]
Davita Internet
Ffxiv Palm Chippings
Research Tome Neltharus
Valley Fair Tickets Costco
Mohawkind Docagent
Emmalangevin Fanhouse Leak
Mndot Road Closures
Erskine Plus Portal
13 The Musical Common Sense Media
World Cup Soccer Wiki
Craigslist Heavy Equipment Knoxville Tennessee
Edible Arrangements Keller
Slag bij Plataeae tussen de Grieken en de Perzen
Oscar Nominated Brings Winning Profile to the Kentucky Turf Cup
Love In The Air Ep 9 Eng Sub Dailymotion
Leader Times Obituaries Liberal Ks
Committees Of Correspondence | Encyclopedia.com
Huntersville Town Billboards
Timeforce Choctaw
Ford F-350 Models Trim Levels and Packages
Routing Number For Radiant Credit Union
Bn9 Weather Radar
City Of Durham Recycling Schedule
Urbfsdreamgirl
Truvy Back Office Login
Table To Formula Calculator
Sandals Travel Agent Login
Orange Park Dog Racing Results
Neteller Kasiinod
Maths Open Ref
DIY Building Plans for a Picnic Table
Have you seen this child? Caroline Victoria Teague
Steven Batash Md Pc Photos
Tamil Play.com
Atlantic Broadband Email Login Pronto
Spinning Gold Showtimes Near Emagine Birch Run
Oreillys Federal And Evans
Asian Grocery Williamsburg Va
Afspraak inzien
Directions To 401 East Chestnut Street Louisville Kentucky
Academic important dates - University of Victoria
Gpa Calculator Georgia Tech
Housing Intranet Unt
T&Cs | Hollywood Bowl
St Vrain Schoology
Online College Scholarships | Strayer University
Nurses May Be Entitled to Overtime Despite Yearly Salary
Understanding & Applying Carroll's Pyramid of Corporate Social Responsibility
Unpleasant Realities Nyt
Tyrone Unblocked Games Bitlife
Latest Posts
Article information

Author: Terrell Hackett

Last Updated:

Views: 5958

Rating: 4.1 / 5 (72 voted)

Reviews: 87% of readers found this page helpful

Author information

Name: Terrell Hackett

Birthday: 1992-03-17

Address: Suite 453 459 Gibson Squares, East Adriane, AK 71925-5692

Phone: +21811810803470

Job: Chief Representative

Hobby: Board games, Rock climbing, Ghost hunting, Origami, Kabaddi, Mushroom hunting, Gaming

Introduction: My name is Terrell Hackett, I am a gleaming, brainy, courageous, helpful, healthy, cooperative, graceful person who loves writing and wants to share my knowledge and understanding with you.