Reference

File Sharing

All shared SharePoint files with their sharing information

Part of the SharePoint inventory.

Scan settings

Default scanning intervalAllowed scanning intervalsData removal during incremental scan
DefaultDaily, Weekly, Bi-Weekly, Monthly, Never, InitialNo

Properties

Property Type Description Automation placeholder
Shared by String SharePoint files shared with the user {{FileSharing.CreatedBy}}
Shared by Name String Specifies the name of the principal. {{FileSharing.CreatedByName}}
Initially Scanned DateTime Shows when this object was initially found in a scan. {{FileSharing.CreatedTime}}
Direct Access Boolean Indicates that the file was shared with the user directly, without a link. {{FileSharing.DirectAccess}}
Display Name String {{FileSharing.DisplayName}}
Shared File Id String {{FileSharing.DocId}}
Expiration DateTime A date/time string for which the format conforms to the ISO 8601:2004(E) complete representation for calendar date and time of day and which represents the time and date of expiry for the sharing. {{FileSharing.Expiration}}
SharePoint File File File Sharing {{FileSharing.File}}
Filename String Specifies the file name including the extension. {{FileSharing.FileName}}
SharePoint Folder Folder Folder Sharing {{FileSharing.Folder}}
Folder Name String Specifies the folder name. {{FileSharing.FolderName}}
Is External Boolean Indicating whether the link URL is a sharing that has any external guest invitees (external users explicitly invited by email address). {{FileSharing.HasExternalGuestInvitees}}
Invitation Expiration DateTime A date/time string for which the format conforms to the ISO 8601:2004(E) complete representation for calendar date and time of day and which represents the time and date of expiry for the sharing. A null value indicates no expiry. {{FileSharing.InvitationExpiration}}
Invited Group String Relation to the group the file has been shared with. {{FileSharing.InvitedGroup}}
Invited Group Name String Group name of the user the file has been shared with. {{FileSharing.InvitedGroupName}}
Invited User String Relation to the user the file has been shared with. {{FileSharing.InvitedUser}}
Invited User/Group Email String Specifies the e-mail address of the user {{FileSharing.InvitedUserEmail}}
Invited User Name String Name of the user the file has been shared with. {{FileSharing.InvitedUserName}}
Invited User Principal Name String User Principal Name of the user the file has been shared with. {{FileSharing.InvitedUserPrincipalName}}
Is Active Boolean Indicates whether the sharing is active. {{FileSharing.IsActive}}
Is Default Boolean Indicates whether a file sharing location is the site collections default sharing location. {{FileSharing.IsDefault}}
Is Folder Boolean Indicates whether the current selection is a folder. {{FileSharing.IsFolder}}
Item Id String {{FileSharing.ItemId}}
Sharing Changed by String Indicates the principal who last modified the sharing. {{FileSharing.LastModifiedBy}}
Modified By Name String Specifies the display name of the user. {{FileSharing.LastModifiedByName}}
Last scan update DateTime Shows when this object was last updated in a scan. If an object is found during a scan but no property has been changed this date will not change. {{FileSharing.LastModifiedTime}}
Link Kind String Specifies the kind of sharing. Allowed values: Anyone in the tenant with the link can edit, Anyone in the tenant with the link can view, Anyone with the link can edit, Anyone with the link can view, Specific people with the link can edit, Specific people with the link can view, Uninitialized. {{FileSharing.LinkKind}}
Share Url String Specifies the URL of the sharing. {{FileSharing.LinkWebUrl}}
List List/Library Relation to the parent list or library. {{FileSharing.List}}
SharePoint List Id String Specifies the identifier of the list in which the file belongs. {{FileSharing.ListId}}
List Name String Url of the parent list or library. {{FileSharing.ListName}}
Risk Score Int32 Stores risk score {{FileSharing.RiskScore}}
Risk Score Update DateTime Stores risk score update {{FileSharing.RiskScoreLastUpdate}}
Risk Score Value String Stores risk score value like Low_Low {{FileSharing.RiskScoreValue}}
FileShare Id String The unique share identifier of a sharing. {{FileSharing.ShareId}}
Share List Id String {{FileSharing.ShareListId}}
Shared anonymously Boolean True when shared with anonymous link {{FileSharing.SharedAnonymously}}
Sharing Creation Date DateTime The UTC date/time string with complete representation for calendar date and time of day which represents the time and date of creation of the sharing. {{FileSharing.SharingCreatedTime}}
Sharing Last Modified Date DateTime The UTC date/time string with complete representation for calendar date and time of day which represents the time and date of the last update of the settings for the sharing. {{FileSharing.SharingLastModified}}
SharePoint Site Collection Site Collection File Sharing in the site {{FileSharing.Site}}
SharePoint Site Id String Specifies the identifier of the site collection where the file is located. {{FileSharing.SiteId}}
SharePoint Site Collection Name String Specifies the full name of the site collection. {{FileSharing.SiteName}}
Site Site Relation to the parent site. {{FileSharing.Web}}
SharePoint Web Id String Specifies the identifier of the site where the file is located. {{FileSharing.WebId}}
Site Name String Name of the site. {{FileSharing.WebName}}
Site Url String Specifies the URL of the site. {{FileSharing.WebUrl}}

Relations

Relation Service Description
Group Microsoft 365 Group which was invited to use the file
Sensitivity Label Microsoft 365 Sensitivity label of the SharePoint Shared File
User Microsoft 365 User who was invited to use the file (direct or via security group)
User Microsoft 365 User who modified file sharing
User Microsoft 365 User who shared the file
List/Library SharePoint All SharePoint lists and libraries
File SharePoint All SharePoint files stored in a library of a SharePoint site
Folder SharePoint All SharePoint folders stored in a library of a SharePoint site
Site Collection SharePoint All SharePoint site collections in your tenant
Site SharePoint All root site and subsites of a SharePoint site collection

Segments

Segment Description
Expired SharePoint File Sharings Shows SharePoint File Sharings file sharings which have reached their expiration date

Actions

  • Add or remove link to/from a SharePoint File Sharing
  • Remove document sharing
Policy Severity Description
SharePoint file is shared with external users High Detects SharePoint files that have been shared externally, potentially exposing sensitive data.
SharePoint file is shared with inactive external user Medium Highlights SharePoint files shared with external users who have been inactive for over six months.

Last updated: 7/19/2026