Cloud storage and file sharing SaaS apps bring several advantages to enterprises because of convenience and scale. However, when not managed properly, file sharing can have serious implications with respect to data security. File sharing is a necessity for today’s enterprises, as staff and business partners become increasingly globalized and need access to files and documents for efficient productivity and collaboration. However, to avoid data leaks, enterprises should take corrective steps toward achieving file sharing security.
Next Generation API Data Protection protects against data loss and theft due to file sharing. Next Generation API Data Protection supports various file sharing exposure for SaaS apps. Here is a definition of various file sharing options:
| Exposure Options | Definition | Exposure Value |
|---|---|---|
| Owner | Not shared with anyone | Owner |
| Internal | Shared between users and groups from one single domain defined in Internal Domains or defined as an internal user in the app instance. | Internal |
| All Internal Users | Shared between all users and groups organization-wide. | All Internal Users |
| External | Shared with external users and groups. | External |
| Anonymous | Shared with general public. Accessible by anyone. | Anonymous |
| SharePoint/OneDrive: All internal users via EEEU | Shared specifically via 'Everyone except external users' group in OneDrive and SharePoint. | SharePoint/OneDrive: All internal users via EEEU |
The table below lists the file sharing options supported by various SaaS apps:
| Apps/File Sharing Exposure | Owner | Internal | All Internal Users | External | Annonymous | SharePoint/OneDrive: All internal users via EEEU |
|---|---|---|---|---|---|---|
| Box | ✓ | ✓ | ✓ | ✓ | ✓ | - |
| Google Drive | ✓ | ✓ | ✓ | ✓ | ✓ | - |
| Microsoft OneDrive | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| Microsoft SharePoint | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
Understanding Exposure Discrepancies Between Netskope and Microsoft 365 Apps
You might notice a difference between the exposure level shown in Netskope and what appears in Microsoft 365 OneDrive or SharePoint.
This is expected. Netskope calculates exposure based on actual access permissions, while Microsoft’s UI labels (like Private) may not fully reflect who can access the content.
How Netskope Determines Exposure?
Netskope identifies all users and groups who have access to a file and assigns the highest exposure level among them.
For example:
-
If only internal users can access → Internal
-
If a guest user has access → External
-
If everyone can access → Anonymous
Why Microsoft 365 Apps Might Show “Private”?
Microsoft 365 OneDrive & SharePoint may display Private for files when all access to the site comes from Site Collection Administrator privileges. Site Collection Administrator access can include internal users, guests, groups, or special groups.
Site Collection Administrator Scenarios
| Who Is Added as Site Collection Admin | Netskope Exposure* | Microsoft 365 Exposure |
|---|---|---|
| Single internal user | Private (only one internal user can access the file) | Private |
| Multiple internal users | Internal (multiple internal userw can access the file) | Private |
| Guest (invited external user)^ | External | Private |
| Group | Group’s exposure value (a group’s exposure is determined by the highest exposure of its member, e.g., n internal user + 1 guest results to external) | Private |
| Special group: Everyone | Anonymous (all internal users & guest can access) | Private |
| Special group: Everyone except external users (EEEU) | Internal (shared with all users via EEEU) | Private |
Additional Notes
-
*The final exposure is determined by the most permissive entity (user or group with highest access level).
-
^Guest users may be treated as internal if their domain is defined as internal in Netskope or Microsoft 365.
-
When sharing a file directly or via a link, the Microsoft UI only shows Shared without displaying the actual exposure, while the details panel lists the users and groups who have access.

