In Microsoft 365, there is setting to Allow only users in specific security groups to share externally. If this setting is enabled, Netskope policy action to remove external sharing from a document can fail. This issue is observed in Microsoft Office 365 OneDrive & SharePoint. This is a limitation in Microsoft graph API.
This issue is fixed in Next Generation API Data Protection. Consider migrating your Classic Microsoft Office 365 SharePoint instance to Next Generation API Data Protection. To learn more: Support Restrict Access Action on Files with Inherited Permissions (Netskope Release Notes Version 124.0.0 > What’s New > Next Generation API Data Protection > Support Restrict Access Action on Files with Inherited Permissions).


