Skip to main content

☁️ Lesson 4.1: Sharing — Link vs Specific People, and the Roles

Sharing is the feature that makes OneDrive genuinely powerful — and the one that can quietly get you into trouble. In this lesson you'll open the Share dialog, understand every choice it offers you (who can open it, and what they can do once they're in), and learn the single habit that keeps you safe: share on purpose, not by reflex. By the end you'll have shared a real file, view-only, with exactly one person — and checked who has access to it.

📚 What You'll Learn

By the end of this lesson, you will be able to:

  • Open the Share dialog and read every option it gives you
  • Choose the right link setting — Anyone with the link vs People in your organization vs People you choose
  • Set the right role — Can edit vs Can view (and Can review where it appears)
  • Decide between Copy link and inviting people by email, and between sharing a file and a whole folder
  • Use File Request to collect files from others into a folder without them seeing its contents
  • See who has access to something, and apply least privilege — the smallest access that does the job

⏱️ Estimated Time: 50 minutes

🎯 Project: Share one real file view-only with a single specific person (or with yourself at another address), then open "Manage access" and confirm exactly who can see it.

In This Lesson

Why Sharing Deserves Real Care

We've reached the fourth stage of our through-line — Store → Organize → Find → Share → Sync — and Share is the one that changes OneDrive from a private cabinet into a place other people can reach. That's enormous. Instead of emailing a heavy attachment that instantly becomes an out-of-date copy, you send a link to the one real file, and everyone works on the same thing. A family shares a folder of photos; a team edits a budget together; you send a landlord a signed lease without printing a page. Sharing is where the cloud finally pays off.

But that same power is exactly why sharing carries risk, and why this whole module treats it as a first-class skill rather than a button you tap without thinking. When you share a file, you are handing out access to something that lives in your cloud — and depending on how you share it, that access can travel much further than you intended. A link set to "anyone with the link" works for anyone who ever gets that link: the colleague you sent it to, the person they forwarded it to, someone who found it in a chat history a year later. Nothing about the file changed; the door you left open did.

So the spine of this entire module is a single sentence, and it's worth writing on a sticky note: share on purpose, not by reflex. Before you share anything, you'll ask two small questions — who needs this, and what do they need to do with it — and then choose the narrowest answer that still gets the job done. That habit, called least privilege, is the difference between sharing that helps and sharing you later regret. Everything else in this lesson is just the mechanics that let you act on those two questions.

🧠 Mindset

Sharing isn't a switch that's either "private" or "public." It's a set of dials — who can open it, what they can do, and (next lesson) for how long. Careless sharing usually isn't a disaster of intent; it's a disaster of the default. Someone clicks Share, grabs whatever link comes up, and pastes it. Learn to slow down for three seconds and set the dials on purpose, and you get all of the benefit with almost none of the risk. That three seconds is the whole skill.

The Share Dialog, Piece by Piece

Wherever you meet a file in OneDrive — the web at onedrive.com, File Explorer on Windows, an Office app, or the mobile app — sharing starts the same way: select the file (or folder), then choose Share. On the web you'll find it as a toolbar button when a file is selected, on the right-click menu, and in the details pane. In Word, Excel, and PowerPoint there's a Share button in the top-right corner. They all open the same core dialog, so once you can read it in one place you can read it everywhere.

The Share dialog has three parts, and they map exactly onto our two questions plus the send. From top to bottom you'll typically see:

  • The link settings line — usually a small bar or button near the top that tells you who the link currently works for (for example, "Anyone with the link" or "People you choose"). This is the who dial, and it's the most important thing on the screen. Click it to change the audience and, on many plans, the role and restrictions.
  • The "to:" field and role picker — a box where you type names or email addresses to invite specific people, with a pencil or role menu beside it that sets whether those people Can edit or Can view. This is where you invite by email and choose the what dial for named people.
  • Copy link and Send — a Copy link button that copies a shareable link to your clipboard so you can paste it anywhere, and a Send button that emails your invitation directly to the people you typed. Same access, two different delivery methods.

That's the entire anatomy. Everything else — expiry dates, passwords, "block download," managing who already has access — hangs off these three parts, and we'll get to the restrictions in Lesson 4.2. For now, hold the shape in your head: who can open it (link settings), what they can do (role), and how you deliver it (copy vs send).

⚠️ Personal vs work/school: the dialog differs

The exact options in the Share dialog depend on your account type — this is the account distinction showing up again. On a personal Microsoft account you'll typically see "Anyone with the link" and "People you choose," and the roles Can edit / Can view. On a work or school account you'll also see "People in your organization with the link," and your IT admin may have turned some options off entirely — for example, they might block "Anyone" links across the whole company. If an option described here is missing for you, that's normal: it's either a plan difference or an admin policy, not a mistake on your part.

Link Settings — Who Can Open It

This is the who dial, and getting it right is 80% of sharing safely. When you click the link settings line, you choose the audience — the set of people for whom the link will actually work. There are three settings you'll meet, and they run from most open to most controlled.

Link setting Who it works for Use it when…
Anyone with the link Anybody who has the link — no sign-in needed. It's forwardable, and it works for whoever it reaches. You genuinely mean "public" — something you'd be fine seeing posted anywhere. Rare. Handle with care.
People in your organization (work/school only) Anyone signed in with an account in your company or school. Outsiders can't open it. Internal documents that any colleague may see, but nobody outside the org should.
People you choose / Specific people Only the exact people you name. They usually must verify it's them by signing in. Forwarding the link to someone else does not let that person in. Almost always. This is the safe default — the link is tied to the people, not to whoever holds it.

Sit with that last row, because it's the heart of safe sharing. A "People you choose" link is bound to identities, not to the string of characters in the URL. If your recipient forwards it, the new person is asked to sign in as someone on your list — and they aren't, so they're turned away. An "Anyone with the link" link is the opposite: it trusts the link itself, so it trusts everyone the link ever reaches. The convenience is real (no sign-in, works instantly), and so is the danger (it travels). Prefer "People you choose" unless you have a specific reason to go wider.

⚠️ The big danger: "Anyone with the link"

This is the setting that causes the sharing horror stories. It's the easiest to reach — often the default on the Copy link button — and the least safe. An "anyone" link can be pasted into a chat, forwarded in an email thread, screenshotted, or indexed somewhere you'll never see. Once it's out, you can't call it back except by turning the link off. Use it only for things you'd be comfortable making genuinely public, and even then, prefer to add an expiry (Lesson 4.2). When in doubt, choose People you choose instead — it costs your recipient one sign-in and saves you the risk.

graph TD A["I want to share this"] --> B{"Who genuinely needs it?"} B -->|"A few named people"| C["People you choose
the safe default"] B -->|"Anyone at my company"| D["People in your organization
work or school only"] B -->|"Truly public, anyone at all"| E["Anyone with the link
use rarely, add an expiry"] C --> F{"What do they need to do?"} D --> F E --> F F -->|"Just read it"| G["Can view
least privilege"] F -->|"Change it with me"| H["Can edit"]

That diagram is the whole decision, and it runs in exactly the order of our two questions: who first (the link setting), then what (the role). Answer both narrowly and you've shared safely by construction. Now let's look closely at that second question.

Roles — What They Can Do

Once you've decided who can open something, the role decides what they can do once they're in. This is the what dial, and it's refreshingly simple — usually just two choices, with a third that appears in some places.

Role They can… They cannot…
Can view Open, read, and (usually) download the file. Read-only. Change the content, rename it, or delete it.
Can edit Open, read, and change the file — type in it, add or delete content, and in a shared folder add or remove files. Change your ownership of the file. (They can still do a lot — grant this deliberately.)
Can review (where available, e.g. Word) Add comments and tracked suggestions without changing the underlying text directly. Make untracked edits. A middle ground between view and edit.

The rule of thumb is least privilege: give the smallest role that still lets the person do what they actually need. If someone only needs to read a document, Can view is the right answer — not "Can edit, just in case." Extra access isn't a kindness; it's a liability, because an editor can accidentally delete a section, and everyone with edit access is one more way the file can change unexpectedly. When you genuinely are working on something together — a shared budget, a group document — Can edit is exactly right. Choose it because you mean it, not because it was already selected.

A subtle but important point: the role and the audience combine. "Anyone with the link — Can edit" means anyone who ever gets the link can change your file, which is almost never what you want. "People you choose — Can view" means only these named people can read it, which is a tight, deliberate share. When you set the link settings, the role picker usually lives right there beside the audience, so you set both dials in one place before you copy or send.

✅ Pro Tip

A quick sanity check before you share: read your two dials out loud as one sentence. "Anyone with the link can edit" should make you wince. "People I choose can view" should sound calm and boring — and boring is exactly what safe sharing feels like. If the sentence sounds scary, tighten a dial before you hit send.

Copy Link vs Invite, and File vs Folder

Copy link vs invite by email

Once the dials are set, you have two ways to actually deliver access, and they matter more than they look.

  • Copy link hands you a URL you can paste anywhere — a chat message, an email you write yourself, a document. It's flexible, but remember: a copied link carries whatever audience you set. A "People you choose" link is safe to paste because it still checks identities; an "Anyone with the link" URL is only as safe as everywhere it ends up.
  • Invite by email (Send) lets you type names or addresses right in the dialog, add a short note, and let OneDrive email each person an invitation. This pairs naturally with "People you choose," because you're naming the exact people and delivering to exactly them. For anything sensitive, this is the cleaner path: the access and the delivery are both scoped to named individuals.

They grant the same access; they differ in control of delivery. Inviting by email is the more deliberate, more traceable choice, and it's what we'll use in the project.

Sharing a file vs a whole folder

You can share a single file or an entire folder, and the difference is about scope and the future. Sharing a folder shares everything inside it — including files you add later. That's wonderful for a genuine shared space (a family photos folder, a team's project folder): add a file and it's automatically available to the group, no re-sharing needed. But it's a trap if you're careless, because a file you drop in "just to keep it handy" is now visible to everyone the folder is shared with. Share a folder when you mean "this whole area is a shared space"; share a file when you mean "just this one thing."

This connects straight back to the folder structure you designed in Module 2. If you keep a clean, purpose- built folder for things you intend to share — separate from your private areas — then folder-level sharing becomes safe and effortless. If your sharing folder is also your junk drawer, you'll leak things by accident. Structure and sharing safety are two sides of the same coin.

⚠️ Watch Out

Access to a shared folder flows down to everything in it. Before you share a folder, glance at what's inside — and remember that anything you move or save into it afterward inherits that same sharing. If you're ever unsure whether something belongs in a shared folder, keep it out and share the single file instead. It's much easier to share one more file than to discover you shared one too many.

File Request — Collecting Files From Others

Everything so far has been about sharing files out — giving other people access to something of yours. File Request is the mirror image: it lets other people upload files in, straight into a folder you choose, without ever seeing what else is in that folder or what anyone else uploaded. It's the clean answer to "everybody send me your…" — permission slips, event photos, résumés, signed forms, homework. Instead of a scattered pile of email attachments, every file lands tidily in one folder you control.

How it works

On onedrive.com, pick (or create) the folder you want files to land in, open its ⋯ (more) menu or the toolbar, and choose Request files. Add a short description of what you're collecting — "Upload your signed permission slip" — and OneDrive creates a special upload link. Send that link to anyone. When they open it, they see only a simple upload page: they add their files and their name, and that's it. They cannot see the folder's contents, open or edit anything already there, or see other people's uploads. Each file arrives in your folder with the uploader's name added to the filename, so you always know who sent what.

  Normal sharing (out) File Request (in)
The other person can… Open, read, or edit your file Only upload files to you
They can see… The file (and a folder's contents, if you shared a folder) Nothing — not the folder, not other people's uploads
Best for… Giving people something Collecting something from many people

💡 No account needed to upload

People you send a file request to can usually upload with just the link — they don't need a Microsoft account of their own, which is what makes it so handy for collecting from a whole class, team, or family. They type their name so the files are labeled, upload, and they're done. All the organizing happens on your side, automatically, in the folder you chose.

⚠️ Honest availability & a safety note

File Request is most dependable on work or school OneDrive when your admin has enabled it — some organizations turn it off by policy. On a personal OneDrive (a Microsoft account), availability has changed over time, so at the time of writing you may or may not see it. If you don't see "Request files," that's why. And treat the request link like any share link: anyone who has it can upload to that folder, so send it deliberately, and turn it off from Manage access (next section) once you've collected what you need.

Seeing Who Has Access

Sharing safely isn't only about the moment you share — it's about being able to look back and see the state of things. OneDrive keeps a record of every share, and you can review it any time through Manage access. On the web, select a file or folder, open the details pane (the ⓘ info button), and look for Manage access; you can also reach it from the right-click menu or from inside the Share dialog itself. On a shared item you'll also see small overlapping people icons that hint access exists.

The Manage access panel is your sharing dashboard for that item. It typically shows you:

  • Links that exist for the item, and what audience and role each one grants ("Anyone with the link — Can view," and so on). Each link can be copied again or turned off from here.
  • People who have direct access by name, with the role each one holds.
  • Controls to change a role (for example, drop someone from Can edit to Can view) or stop sharing entirely — which we'll practice properly in the next lesson.

Get in the habit of opening Manage access before and after you share something important. Before, so you know what access already exists; after, so you can confirm the share you just made looks exactly like you intended — the right people, the right role, and nothing extra. This one panel is where "share on purpose" becomes something you can actually verify, not just hope for.

💡 A quiet Google Drive parallel

If you've used Google Drive, all of this will feel familiar with different labels. Drive's "Share" dialog offers Restricted (specific people, like "People you choose") vs Anyone with the link, and roles Viewer / Commenter / Editor that line up neatly with OneDrive's Can view / Can review / Can edit. The concepts are the same everywhere: who can open it, and what can they do. Learn it once here and you can share safely on either service.

🎯 Project: Share One File Safely

Time to do the real thing — carefully. You'll share a single, harmless file view-only with one specific person (or with yourself at a second email address, which works perfectly for practice), then open Manage access to confirm exactly who can see it. This is "share on purpose" in miniature, and it's the pattern you'll reach for hundreds of times.

🏋️ Share a real file with one person, view-only

Objective: Make one deliberate, least-privilege share and verify it, using People you choose + Can view + invite by email.

Instructions (about 12 minutes):

  1. (2 min) Open onedrive.com and pick a low-stakes file — a photo, a practice document, anything you wouldn't mind a friend seeing. If you don't have one, upload or create a quick "Sharing test.docx."
  2. (2 min) Select the file and choose Share. Before doing anything else, click the link settings line and set the audience to People you choose (or Specific people).
  3. (1 min) Set the role to Can view. Read your two dials as a sentence: "People I choose can view." It should sound calm.
  4. (2 min) In the "to" field, type one person's email — a friend who agrees, or your own second address. Add a short note if you like, then choose Send (invite by email), not Copy link.
  5. (3 min) Now open the details pane (ⓘ) and choose Manage access. Confirm you see exactly that one person, with the Can view role, and no stray "Anyone with the link" that you didn't mean to create.
  6. (2 min) Note in your journal: was "People you choose" the default, or did you have to select it? That tells you how careful you'll need to be next time.
💡 Hint — a "share on purpose" checklist you can reuse
Before I click Send / Copy link, I set BOTH dials:

WHO can open it?  (link settings)
  [ ] People you choose   <- safe default, pick this
  [ ] People in my org    (work/school only)
  [ ] Anyone with the link (rare - only if truly public)

WHAT can they do?  (role)
  [ ] Can view            <- least privilege, pick this
  [ ] Can review          (comments/suggestions, where offered)
  [ ] Can edit            (only if we truly work on it together)

HOW do I deliver it?
  [ ] Invite by email (Send)  <- scoped + traceable
  [ ] Copy link               (only as safe as where it lands)

AFTER sharing:
  [ ] Open Manage access and confirm exactly who can see it

Keep this checklist somewhere handy — a note, or a Word doc in your OneDrive. Running through it takes three seconds and prevents almost every over-share.

✅ Project Completion Checklist

  • You shared a real file using People you choose, not "Anyone with the link"
  • You set the role to Can view (least privilege)
  • You delivered it by inviting one person by email, not a pasted public link
  • You opened Manage access and confirmed exactly who can see it
  • You noted whether the safe option was the default, for next time

🎯 Quick Quiz

Question 1: Why is a "People you choose" link safer than an "Anyone with the link" link?

Question 2: Someone only needs to read a document you're sharing. Following least privilege, which role do you pick?

Question 3: You share a whole folder with a colleague, then later drop a new file into it. What happens to that new file?

Best Practices for Sharing

✅ Do's

  • Default to "People you choose." Tie access to named people, not to whoever holds a link.
  • Apply least privilege. Give Can view unless the person genuinely needs to edit.
  • Invite by email for anything sensitive. Scoped access delivered to exactly the right people.
  • Open Manage access afterward. Confirm the share looks exactly as you intended.
  • Keep a clean "things I share" area. Folder-level sharing is safe only when the folder is purpose-built.

❌ Don'ts

  • Don't grab the default link and paste it. That's how "Anyone with the link" leaks out. Set the dials first.
  • Don't hand out edit access "just in case." Extra access is liability, not generosity.
  • Don't share a folder without glancing inside it first — access flows down to everything, now and later.
  • Don't assume the safe option is the default. It often isn't; check every time.

💡 Pro Tips

  • Read your two dials as one sentence before sending. If it sounds scary, tighten a dial.
  • For quick collaboration with a trusted colleague, "People you choose — Can edit" is a great everyday combo — deliberate access, real teamwork.

📓 Learning Journal

Keep a learning journal as you work through this course — a separate document, a note, or a Word doc right in the OneDrive you're organizing. After each lesson, take a few minutes to write down:

  • Key concepts you learned
  • Techniques that clicked for you
  • Questions or confusion points to revisit
  • Ideas you want to try in your own OneDrive
  • Your progress and feelings about learning this — including where your confidence grew

✍️ This lesson's prompt: Think about the last few things you shared — over email, in a chat, wherever. If you'd used the two-dial habit (who can open it, what can they do), would anything have changed? Was there a time you shared more widely than you needed to? Writing this honestly is how "share on purpose" becomes a reflex instead of a rule.

📝 Lesson Summary

🎓 Key Takeaways

  • Every share answers two questions: who can open it (link settings) and what can they do (role) — set both on purpose.
  • Link settings run from open to controlled: Anyone with the link (risky, forwardable) → People in your organization (work/school) → People you choose (the safe default, tied to identities).
  • Roles apply least privilege: Can view for reading, Can edit only when you truly collaborate, Can review for comments where offered.
  • Invite by email scopes delivery to named people; Copy link is only as safe as where the link ends up. Sharing a folder shares everything inside it, now and later.
  • File Request is the reverse of sharing: people upload files into a folder you choose without seeing its contents or each other's uploads — perfect for collecting forms, photos, or assignments.
  • Manage access lets you see and confirm exactly who has access — check it before and after important shares.

🎉 What You've Accomplished

You can now read the Share dialog with confidence and share a real file the safe way — the right people, the right role, verified afterward. More importantly, you've internalized the habit that anchors this whole module: share on purpose, not by reflex. That three-second pause to set two dials is the single skill that keeps sharing powerful instead of dangerous, and you just practiced it for real.

❓ Common Questions at This Stage

If I share with "People you choose," does my recipient have to have a Microsoft account?

Usually they'll be asked to verify it's them, which most often means signing in — and Microsoft can send a one-time verification code to their email even if they don't have a full account, depending on your settings and account type. On a work/school account, some organizations restrict sharing to people inside the company or to specific external guests. If a recipient can't get in, it's typically a policy or verification step, not a broken link. When in doubt, ask them what they see and check Manage access on your side.

Can I share differently with different people on the same file?

Yes. Access is layered: you can invite Person A as Can edit and Person B as Can view on the same file, and you can have a link with one setting and named people with another. Manage access shows you all of these together so you can see the full picture. This is exactly why checking Manage access matters — the real access is the sum of every share you've made, not just the last one.

I shared something and now regret it. Can I undo it?

Yes, and easily. Open Manage access, and you can change someone's role, remove a person, or turn off a link entirely — which instantly stops it from working, even for people who already have it. Nothing about sharing is permanent. We'll practice stopping sharing, plus adding expiry dates and passwords, in the very next lesson.

🔭 Looking Ahead

In the next lesson — Lesson 4.2: Expiry, Passwords & Restrictions — Sharing Under Control — we tighten the screws. You'll learn to put expiration dates and passwords on links (flagging honestly which of these need a Microsoft 365 or business plan), turn on block download for view-only-that-really-means-it, change someone's role, and stop sharing altogether. If this lesson was about sharing on purpose, the next is about keeping that share under control over time.

✅ Before the Next Lesson

  • Complete the project: one file shared view-only with one person, verified in Manage access
  • Save your "share on purpose" checklist somewhere you'll actually see it
  • Write your Learning Journal entry for this lesson

📚 Additional Resources

🌟 Encouragement for the Journey

Sharing is where OneDrive stops being a private drive and starts being a superpower — and you just learned to use it deliberately, which is what separates confident users from anxious ones. Two dials, three seconds, every time. Keep that habit and you'll never dread the Share button again. ☁️