Skip to content
Skip to main content
Cloud Services Operational Explainer

How do I identify whether cloud data was shared externally?

Separate two questions:

  1. Was external access made possible?
  2. Is there evidence that somebody actually used it?

Those are different propositions.

The key distinction
A sharing permission or link proves an access route existed. An access or download record is the stronger evidence that the route was actually used.

Reconstruct the historical permission path

Preserve the resource and every route that could have granted access:

  • resource ID and owner;
  • direct recipients;
  • guest accounts;
  • groups;
  • inherited folder permissions;
  • link ID and type;
  • creation and expiry;
  • authentication requirement;
  • allowed actions; and
  • connected applications.

A useful permission history might be:

09:03Resource private to Finance group.
10:18External link LNK-441 created.
10:21Link sent to external recipient.
10:44Provider records access to the resource.
11:02Link disabled.

That sequence supports more than simply finding a link in the current settings.

Current permissions may not describe the relevant period

A link may have been disabled later.

A guest may have been removed.

A parent-folder permission may have changed.

So use audit and permission history to reconstruct what access existed at the relevant time.

Test use separately from availability

Provider records may show:

  • link use;
  • file access;
  • preview;
  • download;
  • external account identity;
  • source address;
  • application; or
  • other request identifiers.

Absence of an access event needs careful wording because logging and retention vary.

What does a cloud record actually prove? is the useful companion when interpreting those fields.

Check other disclosure routes too

A file can leave the organisation without the original cloud object being directly shared.

Check for:

  • copies;
  • exports;
  • email attachments;
  • messaging platforms;
  • synchronised folders; and
  • third-party application access.
Permission evidence may establish

That external access was offered, to whom or through which link, and for what period.

It does not automatically establish

That the external recipient opened, downloaded or retained the data unless the provider or another source records use.

The practical point is: reconstruct the permission chain first, then test whether that route was actually used.

Reference: CLD-169Cloud Services