Document Sharing Security Tips

Body

Overview

Online document-sharing tools make it easy to collaborate, collect feedback, and provide access without sending multiple copies of a file. The same features can expose information when a link is too broad, the wrong person is selected, a folder contains more than expected, or access remains in place after it is no longer needed.

Share documents only with people who need them and only for as long as they need them. Use the least-permissive access that will support the work. A person who needs to read a document may not need to edit, download, reshare, or view the entire folder that contains it.

A sharing restriction can reduce risk, but it cannot guarantee that information will remain controlled. A recipient may be able to download, copy, photograph, summarize, or forward content. Before sharing, consider whether the recipient is authorized to receive the information and whether the selected service is appropriate for the type of data involved.

How It Works

Document-sharing services commonly provide several ways to grant access:

  • Direct access to named people. The owner selects specific recipients, who may be required to sign in.
  • Group or team access. Everyone in a selected group, team, site, or workspace receives access based on membership.
  • Organization-wide links. Anyone in the organization who obtains the link may be able to open the item, depending on the settings.
  • Public or “anyone with the link” access. The link may work without sign-in and can be forwarded beyond the intended recipients.
  • View or edit permissions. Edit access may allow recipients to change, delete, upload, rename, or reshare content.
  • Folder access. Sharing a folder may expose existing files and files added later, not just the one document you intended to share.

Some services also allow expiration dates, download restrictions, password protection, access requests, or limits on resharing. The available controls depend on the service and the account's configuration.

A document can contain information that is not immediately visible. Comments, tracked changes, document properties, hidden rows or worksheets, revision history, embedded files, notes, and previous versions may disclose information that was not intended for the recipient.

Before You Share

Ask these questions before sending a link or granting access:

  1. Is this the correct document or folder? Open it and confirm the contents, file name, version, comments, attachments, and hidden information.
  2. Is the service approved for this information? University records and sensitive data may require a UM-approved storage or collaboration service.
  3. Does the recipient need the information? Confirm that each person is authorized and that the email address or account is correct.
  4. What is the narrowest access that will work? Prefer named recipients over broad links, and view access over edit access when editing is not required.
  5. Does the recipient need the whole folder? Share an individual file or a separate working folder when broader folder access is unnecessary.
  6. Should access expire? Use an expiration date when available and appropriate for temporary collaboration.
  7. Will the recipient be able to download or reshare? Understand what the selected permission allows. Do not assume that “view only” prevents every form of copying.
  8. Is an external recipient involved? Verify the person's identity, organization, and need before granting access outside UM.
  9. Could the link be forwarded? Avoid public or anonymous links unless that level of access is intentional and approved.
  10. Will the document reveal more than intended? Remove unnecessary personal information, comments, tracked changes, hidden content, and metadata before sharing.

How to Protect Yourself

  • Use approved services. Do not move UM information to a personal email account, personal cloud-storage account, or unapproved collaboration service merely because it is convenient.
  • Share with specific people when possible. A named-recipient link is easier to control than an anonymous or public link.
  • Use least privilege. Grant view access unless the recipient needs to edit. Avoid allowing resharing or download when the tool and business need permit a narrower setting.
  • Check addresses carefully. Autocomplete can select the wrong person, especially when names are similar.
  • Add context without exposing data. In the notification message, describe why the document is being shared, but do not repeat sensitive information unnecessarily.
  • Review access regularly. Remove people, groups, guests, and sharing links that are no longer needed.
  • Remove access when work ends. Do not rely on the recipient to stop using a link after a project, class, committee, or employment relationship ends.
  • Be careful with shared folders and teams. Membership changes can give new people access to older content. Review the contents before adding members.
  • Do not approve unexpected access requests automatically. Verify who is requesting access and why.
  • Treat unexpected document invitations as possible phishing. Open the known collaboration service directly and look for the document there rather than signing in through an unfamiliar link.
  • Do not enter a password or MFA code into a page reached through an unexpected sharing notice. A legitimate sharing service should not require you to disclose an MFA code to another person.
  • Keep a controlled source copy when appropriate. For high-value work, maintain an authoritative version and understand how version history and deletion work in the service.

What You Should Do at UM

Use UM-approved storage and collaboration services for university information. Follow applicable UM requirements for data classification, records management, privacy, contracts, research, and regulated information.

Before sharing confidential, restricted, regulated, or otherwise sensitive university information:

  1. Confirm that the service and sharing method are approved for the data.
  2. Confirm the recipient's identity, authorization, and business need.
  3. Use named recipients and the least access required.
  4. Consult the appropriate data owner, steward, UM Information Security Office, or other responsible UM office when the permitted sharing method is unclear.

If you accidentally share a UM document with the wrong person or create a link that is broader than intended:

  1. Remove the recipient's access or disable the sharing link immediately, if you can do so safely.
  2. Do not redistribute the document while trying to correct the problem.
  3. Contact the UM IT Helpdesk or UM Information Security Office promptly. Provide the file or folder name, service used, type of information involved, intended and unintended recipients, sharing settings, and approximate time of exposure.
  4. Preserve relevant notices, access information, and audit details. Do not delete the document, account, or other evidence unless UM support directs you to do so.

If you receive an unexpected document-sharing email in your UM mailbox, do not use the link to sign in. Verify the sender through a separate, trusted method or open the known UM collaboration service directly. If the message appears fraudulent, use Outlook's Report Message tool and report it as phishing. Delete the message after reporting it. The Report Message tool may remove it automatically.

If you entered your UM password on a fake sharing page, shared an MFA code, or approved an unexpected MFA prompt, change your UM password through the normal UM account-management process and contact the UM IT Helpdesk or UM Information Security Office.

For a personal document-sharing problem that does not involve UM, use the cloud or document-sharing provider's official security, sharing, and account-recovery tools.

Additional Questions

For document sharing involving UM information, a UM account, a UM device, or a university collaboration service, contact the UM IT Helpdesk and the UM Information Security Office. Involve the appropriate UM data owner, steward, privacy, records, research, or compliance office where applicable.

For a personal document-sharing concern:

  • Use the cloud-storage or document-sharing provider's official help and security process to review permissions, disable links, remove access, and recover an account.
  • Contact the email provider if a fraudulent sharing notice was delivered to a personal mailbox.
  • Contact affected people promptly when personal information was shared with the wrong recipient and additional protective action may be needed.
  • Use IdentityTheft.gov only when identifying information has been used or is at meaningful risk of misuse. A mistakenly shared ordinary document does not automatically require an identity-theft report.

Additional Resources

Details

Details

Article ID: 172462
Created
Wed 8/5/26 8:07 PM
Modified
Wed 8/5/26 8:08 PM