Skip to content
Skip to main content
Cloud Services Technical Explainer

What is a shared link?

A shared link is a transferable web address that grants or requests access to a particular cloud object or folder under rules set by the service. The link identifies an access route; it does not inherently identify the person who uses it.

Its configuration may limit access to:

  • named accounts;
  • members of an organisation;
  • anyone who supplies a password; or
  • anyone who possesses the link.

It may permit viewing, download, editing or upload, and may have an expiry date. Some links merely lead to a sign-in page; others contain an unguessable token that acts as the authority to reach the object.

Useful sharing records include the link or share ID, target object, creator, creation time, permission, authentication requirement, expiry, later changes and revocation. The visible URL may be shortened or wrapped by another service, so the provider's stable share identifier can be important.

A simplified record might state:

share_id=SH-8F21
target_object=OBJ-4407
created_by=C-54119
access=anyone_with_link
permission=view_download
expires=2026-08-31T23:59:59Z

This establishes the route and its capability. It does not show that anybody used it.

Dave creates this link for budget.xlsx in OneDrive. A Teams message later contains a wrapped URL, but the provider's share ID SH-8F21 still points to object OBJ-4407. At 10:32 the provider records a successful download through that share route from connection 198.51.100.24; the creation record, message and access event answer three different questions.

Follow the stable share record through changing copies of the URL
EstablishedThe records can show the link's target and rules, its transport, and a successful request through that route.
Still openWho controlled an anonymous connection and whether an automated system made the request.

Use records depend on the access mode

If sign-in is required, an access event may include an account and session. Anonymous use may leave a time, connection address, browser details and action. Preview generators, security scanners and other automated systems may also request the link.

Attributing a shared-link event therefore depends on what authentication and corroborating records exist, not on the intended recipient's name.

Avoid opening a live evidential link unnecessarily. Doing so may add an access event, trigger a notification or retrieve material to the investigator's device.

The next useful comparison is the share ID and access event against authentication, message delivery, browser or device records. The transferable URL is not itself the user identity.

Current Microsoft sharing-link example - checked 3 September 2026

Microsoft Graph currently includes sharing-link information within a drive item's permission record, including link type, scope and the item to which the permission applies. Exact properties depend on how the link was created and accessed. Preserve the provider's permission or share identifier and returned settings rather than relying only on the visible URL.

The point to remember

Treat a shared link as a permission-bearing access route. Establish its target and rules first, then interpret use events according to the authentication and logging the service actually applied.

Reference: CLD-062Cloud Services