Skip to main content

☁️ Lesson 4.2: Expiry, Passwords & Restrictions — Sharing Under Control

In the last lesson you learned to share on purpose — the right people, the right role. Now you'll learn to keep that share under control over time. A link, once created, can travel; the tools in this lesson let you put a clock on it, a lock on it, take away the download button, change your mind, or shut it off completely. By the end you'll have tightened a real share and then stopped sharing something entirely.

📚 What You'll Learn

By the end of this lesson, you will be able to:

  • Add an expiration date and a password to a shared link (and know which plans offer them)
  • Turn on block download so view-only really means view-only
  • Change someone's role — for example, drop an editor to a viewer
  • Stop sharing a link or a person entirely, and understand what that does
  • Know when to reach for each control, and build a habit of reviewing your shares periodically

⏱️ Estimated Time: 45 minutes

🎯 Project: Add an expiry or password to a shared link (or note honestly that it's a Microsoft 365 feature on your plan), then stop sharing something and confirm it's off.

In This Lesson

Why a Share Needs Ongoing Control

Here's the uncomfortable truth at the center of this lesson: a link can travel. The moment you create a shareable link, it becomes a little object that can be copied, forwarded, pasted into a chat, screenshotted, or saved in someone's browser history. You made it for one reason, for one moment — but it doesn't expire on its own, it doesn't know when your project ended, and it doesn't ask permission before it gets forwarded. The share you set up perfectly in Lesson 4.1 is only perfectly safe at the moment you made it. Time is the risk this lesson addresses.

Think of the shares you've made in your life. The budget you sent for last quarter's review — is that link still live? The photos you shared with a group before a trip — can everyone in that thread still open them a year later? Usually the answer is "I have no idea," and that's precisely the problem. Access you set up and forgot is access that keeps working long after it should. The controls in this lesson exist to close that gap: to make a share match how long you actually need it, and to give you clean ways to change your mind.

So this lesson adds a third question to the two from before. Lesson 4.1 asked who and what. Now we add for how long, and under what conditions — expiry, password, download control — plus the ability to revise or revoke access after the fact. Together these turn sharing from a one-time gamble into something you manage, like any other part of a tidy digital life.

🧠 Mindset

The safest share is one that cleans up after itself. If you can set a link to expire when your need ends, you never have to remember to turn it off — it just quietly stops working. Wherever you can, prefer controls that fail closed (access ends unless you renew it) over controls that fail open (access continues unless you remember to stop it). That single instinct — build in an expiry — prevents most of the "wait, that's still shared?" surprises.

Expiration Dates — Put a Clock on It

An expiration date is the most useful sharing control there is, because it makes a link temporary by design. You set a date; after it passes, the link simply stops working, and anyone who tries to open it is turned away. No cleanup, no remembering, no lingering access. For anything with a natural end — a document for a one-week review, files for an event, a link you're posting somewhere semi-public — an expiry is the difference between a share that closes itself and one that stays open forever.

You'll find it inside the link settings of the Share dialog (the same place you set the audience in Lesson 4.1). When you open link settings, look for Set expiration date and pick a date. On items you've already shared, you can add or change an expiry from Manage access on the existing link. The link keeps its audience and role; you're just adding a "works until" clock on top.

⚠️ Honest flag: this is largely a Microsoft 365 / business feature

Here's the honest part this course promises you. Expiration dates on links are primarily a paid Microsoft 365 and work/school feature. If you're on a free personal Microsoft account, you may not see the option at all, or you may see it only after upgrading to a Microsoft 365 personal or family plan; on work/school accounts your admin often requires expiry on certain link types. Whether it's available to you depends on your plan and, for organizations, on admin policy — and Microsoft changes what's bundled where over time. Check what your own account offers rather than assuming, and please don't take a hard price or tier from me: look at Microsoft's current plans page. If you don't have expiry, the fallback is simple and free — set a reminder to stop sharing manually, which we cover below.

When should you use an expiry? Any time the need has an end date, which is more often than people realize. A good rule: if you can name when you'll stop needing to share something, set the link to expire around then. Even for an ongoing share, a distant expiry (say, a review-it-again date) forces a healthy check-in rather than access that outlives its purpose by years.

Passwords — Add a Lock

A password on a link adds a second factor of control: even if the link travels, a person also needs the password to open it. It's especially valuable for the one setting that worries us most — an "Anyone with the link" style link — because it means the bare URL isn't enough on its own. You share the link one way (say, in an email) and the password another way (say, a text message), so intercepting one without the other gets nobody in.

Like expiry, you set it inside link settings: look for Set password, type one, and share it with your recipient separately from the link. The two should travel by different channels; emailing the link and the password together defeats the point entirely — anyone who sees that email has both.

⚠️ Honest flag: passwords are a Microsoft 365 / business feature too

Same honest caveat as expiry: password-protected links are generally a paid Microsoft 365 or work/school capability, not something every free personal account has. If you don't see Set password in your link settings, that's a plan or policy difference, not you doing something wrong. Availability shifts as Microsoft updates its plans, so verify on Microsoft's current pages rather than trusting a fixed answer. If passwords aren't available to you, lean harder on the free protections you do have: use People you choose (which requires sign-in and beats a password for most purposes), keep roles at Can view, and stop sharing when you're done.

💡 Password or "People you choose"?

If you have to choose, remember that "People you choose" is usually stronger than a password on an open link. A password protects a link that anyone could hold; "People you choose" makes the link only work for named identities in the first place, so there's no open door to lock. Use a password when you genuinely need a wider link (for example, a semi-public download) but want a barrier on it. Use "People you choose" when you can name your audience — which is most of the time, and which every free account supports.

Block Download — View-Only, Really

Here's a subtlety that surprises people: by default, Can view still lets someone download a copy. They can't change your file, but they can save their own copy to their device — and once it's downloaded, it's out of your control entirely. For most sharing that's fine. But when you're sharing something you want people to read but not keep — a sensitive report, a draft you'll revise, a document you want to stay the single source of truth — you want more than view-only. You want block download.

Block download (sometimes labeled as a "can view, can't download" option in link settings) does exactly what it says: recipients can open and read the file in their browser, but the download, print, and copy options are removed. The file stays in your cloud where you can still change or revoke it; nobody walks away with a permanent offline copy. It's the closest OneDrive gets to "look, don't take."

⚠️ Two honest limits

First, block download is generally a Microsoft 365 / business feature — like expiry and passwords, expect it on paid or work/school accounts, and check your own plan. Second, and just as important: block download is a deterrent, not a vault. It stops the easy Save and Print buttons, but a determined person can still take a screenshot or photograph their screen. Treat it as "raises the bar and signals intent," not "makes copying impossible." For truly sensitive material, the real protection is not sharing it widely in the first place — combine block download with a narrow audience, and don't rely on any single control.

The practical takeaway: block download pairs beautifully with Can view and a narrow audience. "People you choose — Can view — download blocked" is a tight, deliberate way to let a few named people read something without it leaking into a dozen downloaded copies. When the content matters, that combination is worth the extra click.

Changing Roles & Stopping Sharing

The most reassuring thing about OneDrive sharing is that nothing is permanent. Every share you make can be revised or revoked from one place — Manage access — which you reach by selecting the file or folder, opening the details pane (ⓘ), and choosing Manage access (it's also on the right-click menu and inside the Share dialog). This is your control room, and it holds three moves you'll use constantly.

Change someone's role

People's needs change. A colleague who was editing a document with you finishes their part and now only needs to reference it — so you drop them from Can edit to Can view. In Manage access, find the person (or the link), open their role, and pick the new one. The change is immediate. This is least privilege applied over time: as soon as someone no longer needs edit access, take it back to view. It costs nothing and closes a door you no longer need open.

Stop sharing a link or a person

When access should end, you have two levels of "off":

  • Remove a person — revokes that one individual's direct access while leaving everyone else untouched. Use it when one recipient shouldn't have access anymore.
  • Delete a link (turn off / stop sharing the link) — instantly kills that link for everyone who has it, including people who saved or forwarded it. This is the big red button for an "Anyone with the link" you regret: delete the link and it stops working everywhere, immediately.

There's also a "Stop sharing" action on some items that removes all sharing at once — every link and every person — returning the file to private. That's the cleanest way to fully close something down when a project ends.

📖 A note on ownership & transfers

Sharing grants access; it doesn't change ownership. On a personal account, your files are yours, and there's no true "transfer ownership to another person" for individual files — if you need someone else to own something long-term, they should have their own copy in their own OneDrive, or the content should live in a shared space (which is exactly what Lesson 4.3 is about). On work/school accounts, ownership and transfers are handled by the organization: when someone leaves, an admin can reassign their OneDrive, and team content ideally lives in SharePoint where the organization owns it, not one employee. If "who owns this?" is a real question for your files, that's a strong sign the content belongs in a shared library rather than one person's personal OneDrive — more on that next lesson.

The Escalation Ladder & Reviewing Shares

All these controls stack into a natural ladder, from the loosest, most convenient sharing up to the tightest, most locked-down. You climb the ladder as the sensitivity of what you're sharing rises. Most everyday sharing lives near the bottom; sensitive material climbs higher.

graph TD A["Start: I need to share something"] --> B["1. Narrow the audience
People you choose beats Anyone with the link"] B --> C["2. Lower the role
Can view, not Can edit, unless needed"] C --> D["3. Add an expiry
the link stops working on its own"] D --> E["4. Add a password
the link alone is not enough"] E --> F["5. Block download
read it, do not keep a copy"] F --> G["6. Stop sharing
remove people or delete the link entirely"] G --> H["Review periodically
a link can travel, so check Manage access"]

Notice how the ladder mirrors the two questions from Lesson 4.1 (audience, role) and then adds this lesson's controls (expiry, password, block download) before ending in the ultimate control — stopping the share. You don't need every rung every time; you climb only as high as the content demands. A family photo folder might stop at rung two. A confidential document shared outside the company might use every rung.

The final rung — review periodically — is the habit that ties it all together, and it flows directly from "a link can travel." Because shares don't clean themselves up (unless you gave them an expiry), it's worth opening Manage access on your important shared items every so often and asking: does this still need to be shared, with these people, at this level? Retire what's done. On a work/school account, admins have tools and reports for this at scale; on a personal account, a simple quarterly glance at what you've shared keeps your OneDrive honest.

✅ Pro Tip

Make "review my shares" a recurring calendar item — quarterly is plenty for most people. Open OneDrive's Shared view (which lists what you've shared and what's shared with you), spot-check the important ones in Manage access, and turn off anything that's outlived its purpose. Five minutes, four times a year, and nothing of yours stays shared by accident.

🎯 Project: Tighten, Then Stop

This project has two acts. First you'll tighten a share by adding a control (an expiry or a password — or, honestly, noting that your plan doesn't offer them and using a free alternative). Then you'll stop sharing something entirely and confirm it's truly off. Together they cover the two things every sharer needs to be able to do: add controls, and take access away.

🏋️ Add a control, then revoke a share

Objective: Practice the escalation ladder and the ultimate control — stopping a share — on real files, honestly adapting to what your plan supports.

Instructions (about 12 minutes):

  1. (2 min) Open onedrive.com. Use the file you shared last lesson, or share a fresh practice file with People you choose — Can view.
  2. (3 min) Open link settings and look for Set expiration date and Set password. If your plan offers them, add an expiry a week out (and, optionally, a password). If it doesn't, note in your journal: "Expiry/password are Microsoft 365 features not on my plan" — and instead set yourself a calendar reminder to stop sharing this file in a week. Both outcomes complete the step honestly.
  3. (2 min) If you saw a block download option, turn it on for a view-only link and notice how the share now reads: view, no download.
  4. (2 min) Now pick something you have shared — this file or an older share — and open Manage access. Practice the ultimate control: stop sharing it (remove the person, or delete the link).
  5. (3 min) Confirm it worked: the item should show no active sharing, and if you can, test the old link in a private/incognito window — it should refuse to open. Note in your journal how it felt to close a door completely.
💡 Hint — where each control lives
Adding controls (before/while sharing):
  Share  >  link settings  >
     Set expiration date     [365/business - may be absent]
     Set password            [365/business - may be absent]
     Can view, block download[365/business - may be absent]

Revising or ending a share (any time after):
  Select file  >  details pane (i)  >  Manage access  >
     change a role   (Can edit  ->  Can view)
     remove a person (revokes just them)
     delete a link   (kills it for EVERYONE who has it)
     Stop sharing    (removes all sharing at once)

No expiry/password on your plan? Free fallback:
  - Use "People you choose" + "Can view"
  - Set a personal reminder, then Stop sharing manually

The exact labels shift as Microsoft updates OneDrive, but every control lives in one of these two places: link settings to add, Manage access to revise or revoke.

✅ Project Completion Checklist

  • You tried to add an expiry (or password) — and either set one or honestly noted it's a 365 feature and set a manual reminder
  • You checked whether block download was available and understood what it does
  • You stopped sharing a real item via Manage access
  • You confirmed the item shows no active sharing (bonus: tested the dead link in a private window)
  • You noted your plan's sharing capabilities in your journal for future reference

🎯 Quick Quiz

Question 1: Why is an expiration date such a valuable sharing control?

Question 2: You're on a free personal Microsoft account and don't see Set expiration date or Set password. What's the honest situation?

Question 3: You created an "Anyone with the link" share and now regret it. What actually stops it working for everyone who already has the link?

Best Practices for Controlled Sharing

✅ Do's

  • Add an expiry whenever the need has an end. Let the link clean itself up.
  • Send a password by a different channel than the link, if you use one at all.
  • Pair block download with Can view + a narrow audience for sensitive reads.
  • Lower roles as soon as they're not needed — least privilege over time.
  • Review your shares periodically — a quarterly glance at Manage access and the Shared view.

❌ Don'ts

  • Don't email the link and its password together — that defeats the whole point.
  • Don't treat block download as a vault. It's a deterrent; screenshots still exist.
  • Don't assume expiry/password are available — they're mostly 365/business features; check your plan.
  • Don't leave old shares live "just in case." If it's done, stop sharing it.

💡 Pro Tips

  • Climb the escalation ladder only as high as the content demands — most everyday sharing stops at audience + role.
  • When in doubt, "People you choose" is free and stronger than a password on an open link.

📓 Learning Journal

Keep a learning journal as you work through this course — a separate document, a note, or a Word doc right in the OneDrive you're organizing. After each lesson, take a few minutes to write down:

  • Key concepts you learned
  • Techniques that clicked for you
  • Questions or confusion points to revisit
  • Ideas you want to try in your own OneDrive
  • Your progress and feelings about learning this — including where your confidence grew

✍️ This lesson's prompt: Which sharing controls does your plan actually offer — expiry, passwords, block download? Write them down so you know your real toolkit. Then think of one existing share you've forgotten about somewhere in your digital life. What would it take to go find it and decide whether it should still be live? That instinct — to go check — is the whole habit of "a link can travel, so review your shares."

📝 Lesson Summary

🎓 Key Takeaways

  • A share adds a third question to who and what: for how long, and under what conditions — because a link can travel.
  • Expiration dates make a link stop working on its own; passwords add a lock; block download lets people read without keeping a copy. All three are largely Microsoft 365 / business features — check your plan, and hedge on what's bundled.
  • Manage access is the control room: change a role, remove a person, or delete a link (which kills it for everyone who has it, instantly).
  • Sharing grants access, not ownership; content that needs a stable owner belongs in a shared library (next lesson), especially on work/school accounts.
  • Climb the escalation ladder only as high as the content demands, and review your shares periodically — the free fallback for any missing control is "People you choose + Can view + stop sharing when done."

🎉 What You've Accomplished

You can now keep a share under control from cradle to grave: add a clock, add a lock, take away the download, change your mind, and shut it off completely. You also know — honestly — which of these your own plan supports, and how to stay safe with the free tools if the paid controls aren't there. Most importantly, you've built the instinct that a link doesn't clean up after itself, so you do. That's the difference between sharing you manage and sharing that manages you.

❓ Common Questions at This Stage

If I stop sharing a file, do people who already downloaded it lose their copy?

No — and this is important to be honest about. Stopping sharing revokes future access: the link dies, and people can no longer open the file in your OneDrive. But any copy someone already downloaded is theirs; you can't reach into their device and delete it. That's exactly why block download (and, more fundamentally, not over-sharing sensitive things) matters — once a copy leaves, it's gone from your control. Revoking access is powerful, but it works forward, not backward.

Do expiry and password work on files shared with specific people, or only on links?

They're primarily properties of a link. When you invite specific people, the strongest protection is already built in — they must sign in as themselves, and you can remove any of them at any time from Manage access. Expiry and password shine on the more open "Anyone with the link" style shares, where you want a clock and a lock on a link that could otherwise travel freely. For named-people shares, "review and remove" is your main lever, and it's available on every account type.

My work/school account won't let me set some of these. Why?

Your IT admin sets sharing policies for the whole organization, and they may disable certain options, require others, or restrict external sharing entirely. For example, some organizations force an expiry on all "anyone" links, or block those links completely so you can only share with named people or the whole org. This isn't a limitation of your skill — it's your organization's security posture, and it's usually there for good reasons. Work within it, and when something you need is blocked, that's a conversation for your admin.

🔭 Looking Ahead

In the next lesson — Lesson 4.3: SharePoint & Shared Libraries, and Security Best Practices — we zoom out from single files to the bigger question of where shared content should live. You'll learn the difference between your personal OneDrive and SharePoint shared libraries (the team's files, owned by the organization, not one person), when to use each, and then a solid set of security best practices that ties Module 4 together — least privilege, reviewing access, watching "anyone" links, MFA, and admin policies, with an honest Google Drive parallel.

✅ Before the Next Lesson

  • Complete the project: add a control (or note it's a 365 feature) and stop sharing something
  • Write down which sharing controls your plan actually offers
  • Write your Learning Journal entry for this lesson

📚 Additional Resources

🌟 Encouragement for the Journey

You now hold the full sharing toolkit — not just how to open a door, but how to put a clock on it, a lock on it, and how to close it for good. That's real command over one of the most powerful (and easily misused) features in the cloud. Share generously where it helps, tighten where it matters, and never worry about a forgotten link again. ☁️