Reference

File Sharing

All shared OneDrives items with their sharing information

Part of the OneDrive inventory.

Scan settings

Default scanning intervalAllowed scanning intervalsData removal during incremental scan
DefaultDaily, Weekly, Bi-Weekly, Monthly, Never, InitialNo

Properties

Property Type Description Automation placeholder
Created By String Shared files created by user {{FileSharing.CreatedByUser}}
Created By Name String Related user the sharing was created by. {{FileSharing.CreatedByUserName}}
Initially Scanned DateTime Shows when this object was initially found in a scan. {{FileSharing.CreatedTime}}
Direct Access Boolean Indicates that the file was shared with the user directly, without a link. {{FileSharing.DirectAccess}}
Display Name String {{FileSharing.DisplayName}}
Shared File Id String {{FileSharing.DocId}}
Drive OneDrive Sharings of files in this drive {{FileSharing.Drive}}
Drive Item File Sharings of a file {{FileSharing.DriveItem}}
Drive Item Folder Folder Sharings of a folder {{FileSharing.DriveItemFolder}}
Drive Item Folder Name String name of the shared drive item folder {{FileSharing.DriveItemFolderName}}
Drive Item Name String Name of the shared drive item {{FileSharing.DriveItemName}}
Drive Name String Display name shown for the OneDrive. This is usually the combination of the user's first name, middle initial and last name. {{FileSharing.DriveName}}
Expiration DateTime A date/time string for which the format conforms to the ISO 8601:2004(E) complete representation for calendar date and time of day and which represents the time and date of expiry for the sharing. {{FileSharing.Expiration}}
Invitation Expiration DateTime A date/time string for which the format conforms to the ISO 8601:2004(E) complete representation for calendar date and time of day and which represents the time and date of expiry for the sharing. A null value indicates no expiry. {{FileSharing.InvitationExpiration}}
Invited User/Group Email String Specifies the e-mail address of the user {{FileSharing.InvitedUserEmail}}
Is Active Boolean Indicates whether the sharing is active. {{FileSharing.IsActive}}
Is Default Boolean Indicates whether a document sharing location is the user's default sharing location. {{FileSharing.IsDefault}}
Is Folder Boolean Indicates whether the current selection is a folder. {{FileSharing.IsFolder}}
Item Id String {{FileSharing.ItemId}}
Modified By String Shared files modified by the user {{FileSharing.LastModifiedByUser}}
Modified By Name String Related user the sharing was last modified by. {{FileSharing.LastModifiedByUserName}}
Last scan update DateTime Shows when this object was last updated in a scan. If an object is found during a scan but no property has been changed this date will not change. {{FileSharing.LastModifiedTime}}
Link Kind String Specifies the kind of sharing. Allowed values: Anyone in the tenant with the link can edit, Anyone in the tenant with the link can view, Anyone with the link can edit, Anyone with the link can view, Specific people with the link can edit, Specific people with the link can view, Uninitialized. {{FileSharing.LinkKind}}
Share Url String Specifies the URL of the sharing. {{FileSharing.LinkWebUrl}}
OneDrive List Id String Specifies the GUID that uniquely identifies the list/document library containing the file. {{FileSharing.ListId}}
Risk Score Int32 Stores risk score {{FileSharing.RiskScore}}
Risk Score Update DateTime Stores risk score update {{FileSharing.RiskScoreLastUpdate}}
Risk Score Value String Stores risk score value like Low_Low {{FileSharing.RiskScoreValue}}
Sharing Creation Date DateTime The UTC date/time string with complete representation for calendar date and time of day which represents the time and date of creation of the sharing. {{FileSharing.ShareCreatedDate}}
Id String The unique share identifier. {{FileSharing.ShareId}}
Share List Id String {{FileSharing.ShareListId}}
Sharing Last Modified Date DateTime The UTC date/time string with complete representation for calendar date and time of day which represents the time and date of the last update of the settings for the sharing. {{FileSharing.ShareModifiedDate}}
Shared anonymously Boolean True when shared with anonymous link {{FileSharing.SharedAnonymously}}
External user Boolean True when shared with external user {{FileSharing.SharedWithExternalUser}}
Shared with Group String Files shared with the group {{FileSharing.SharedWithGroup}}
Shared with Group Name String Specifies the name of the group. {{FileSharing.SharedWithGroupName}}
Shared with User String Files shared with the user {{FileSharing.SharedWithUser}}
Shared with User Name String Specifies the display name of the user. {{FileSharing.SharedWithUserName}}
OneDrive Site Id String Specifies the GUID that identifies the site collection containing the file. {{FileSharing.SiteId}}
Site Url String Specifies the site URL of the sharing. {{FileSharing.SiteUrl}}
OneDrive Web Id String Specifies the GUID for the site containing the file. {{FileSharing.WebId}}

Relations

Relation Service Description
Group Microsoft 365 Group which the file sharing is shared with
Sensitivity Label Microsoft 365 Sensitivity label of the OneDrive Shared File
User Microsoft 365 User who created file sharing
User Microsoft 365 User who modified file sharing
User Microsoft 365 User with whom the file sharing is shared (direct or via security group)
OneDrive OneDrive All of your users OneDrives in your tenant
File OneDrive All OneDrive files stored in a library of a OneDrive
Folder OneDrive All OneDrive folders stored in a library of a OneDrive

Segments

Segment Description
Expired OneDrive File Sharings Shows OneDrive File Sharings file sharings which have reached their expiration date

Actions

  • Remove document sharing
Policy Severity Description
OneDrive file is shared with external users Medium Identifies OneDrive files that have been shared externally, increasing the risk of data leakage.

Last updated: 7/19/2026