The extension is only part of the decision
Before attaching a file, consider what it contains, who needs it and how access will be controlled. An ordinary document can contain confidential information. A familiar extension does not prove a file is safe, and a cloud link does not make harmful content harmless.
Match the sharing method to the information
Ordinary documents
For an authorised recipient and information suitable for email, an attachment may be appropriate under your organisation’s policy. Check the address, the correct version and any comments or hidden information before sending. Use an approved shared document when several people need to work on the same version.
Confidential records
Use your organisation’s approved secure-sharing method. Check whether the recipient is entitled to see the information and whether an attachment would leave uncontrolled copies in mailboxes. Share only the information needed for the task and confirm access before sending the link.
Large media or project files
An approved OneDrive, SharePoint or other managed file-sharing service can avoid repeated attachments and version confusion. Confirm the recipient’s access and your storage entitlement. Mailbox limits vary, so there is no single attachment size that works for every sender and recipient.
Executables, scripts and macro-enabled documents
Files that run instructions need particular care. If a legitimate technical file is blocked, ask IT to agree the transfer method and validate the file. Do not rename extensions, disable filtering or package files to evade the controls. Microsoft documents attachment restrictions in Outlook; your organisation may apply additional restrictions.
A practical OneDrive or SharePoint sharing workflow
- Choose the approved location. Use the work account and library appropriate for the information, not a personal drive.
- Check the document. Confirm its contents, version and whether comments, metadata or additional sheets reveal information the recipient should not receive.
- Confirm the recipient. Verify the address through a known route when necessary, particularly for a new external contact.
- Choose the access. Where available and appropriate, use a specific-people link rather than an unrestricted link. Check whether viewing is sufficient or editing is necessary.
- Check sharing policy. External access, expiry and other controls depend on your licence and tenant settings. If the required option is unavailable, ask IT rather than moving the file elsewhere.
- Verify the link and permissions. Confirm that the intended recipient can use the approved method without expanding access to everyone.
- Review access afterwards. Remove access when no longer needed, following the organisation’s retention requirements. Revoking a link does not recall copies already downloaded.
Microsoft’s OneDrive sharing instructions explain the available controls. Check the options shown in your own organisation before promising password protection, download restrictions or expiry.
When receiving a file
Check whether you expected it, whether the sender and context make sense, and whether the link goes to the intended service. A message from a familiar account can still be suspicious. Do not enable macros or enter credentials simply because the message says this is necessary to view a document.
If a file has gone to the wrong person, contact your IT or data-protection lead promptly. Restrict further access where authorised and follow the incident process. Do not assume recalling an email or deleting your own copy has removed the recipient’s access.
For help with permissions and managed sharing, see Microsoft 365 support and cyber security.
About this guide
This guide replaces the earlier article at this address with freshly written practical guidance and current primary references.
Use this guidance alongside your organisation’s policies and agreed IT support arrangements. Product features and licence terms can change; check the linked supplier guidance before making a purchase or changing settings.
