Microsoft 365 OneDrive anonymous link created

Goal

Detect when a user creates an anonymous link for a Microsoft 365 document in OneDrive. This would allow any unauthenticated user to access this document, if they had the link.

Strategy

This rule monitors the Microsoft 365 logs for the event name AnonymousLinkCreated.

Triage and response

Determine whether this document should be available anonymously.

Changelog

4 October 2022 - Updated severity.