File Sharing in Microsoft Teams: Complete Setup Guide
Set up efficient file sharing in Microsoft Teams. Learn about permissions, external sharing, and best practices for enterprise collaboration.
File sharing in Microsoft Teams happens through SharePoint under the hood — every Team has a linked SharePoint site, and every channel has a dedicated document library. Files uploaded to a channel land in that library; files in chats land in the sender's OneDrive. Setup runs through the Teams admin center and SharePoint admin center together, with external sharing, sensitivity labels, DLP, and retention policies layered in. For files over SharePoint's 250 GB per-file cap or for external deliveries under NDA, a transfer tool with client-side encryption fills the gap. This guide covers the setup that matters.
The SharePoint Backbone
Every Team = a Microsoft 365 Group + a SharePoint team site + a mailbox + a Planner. Channels inside the Team map to folders inside the SharePoint site's Documents library. Private channels get their own separate SharePoint site (not a folder), which has permission and compliance implications.
What this means in practice:
- Files uploaded to a channel tab are SharePoint files, fully indexed, version-controlled, subject to SharePoint DLP and retention.
- Files uploaded to a one-on-one or group chat are OneDrive files owned by the sender. When the sender leaves the org, those files need migration or they disappear.
- Link sharing inside Teams generates SharePoint sharing links with the permissions set in your tenant's sharing policy.
Treat Teams as the UI and SharePoint as the storage. Your file strategy is a SharePoint strategy.
Permissions Model
Four permission levels apply:
- Team owners: full control of the Team and its SharePoint site. Can add/remove members, change settings.
- Team members: can create channels (if allowed by Team settings), upload files, edit, delete.
- Guests: external users added via Azure AD B2B. Can be given full or restricted access.
- Shared channel participants: Teams shared channels allow outside users to collaborate without being full guests.
Set the baseline at the tenant level (Teams admin center → Teams policies) and override per Team when specific cases require. Don't let individual Team owners set arbitrary policies; drift becomes impossible to audit.
External Sharing Configuration
External sharing is where tenants get into trouble. SharePoint admin center → Policies → Sharing controls the tenant-wide ceiling:
- Anyone: link works for anyone, no sign-in. Maximum convenience, maximum risk.
- New and existing guests: recipient must authenticate, either as an existing guest or through a new guest creation flow.
- Existing guests: only current guests in your directory can access.
- Only people in your organization: no external sharing.
Most enterprises set "Existing guests" or "New and existing guests" as the tenant ceiling. Individual sites can be more restrictive. For one-off external deliveries that don't justify creating a guest account, a transfer tool with a short-lived password-protected link is often cleaner than guesting someone into your tenant.
Sensitivity Labels and DLP
Microsoft Purview (formerly Microsoft 365 compliance center) is where you configure sensitivity labels and DLP policies.
Sensitivity labels apply to documents: Public, Internal, Confidential, Highly Confidential. Labels carry settings — encryption, watermarking, access restrictions — that travel with the file wherever it goes.
Example: a document labeled "Confidential - External Partners" encrypts automatically, allows view/edit by the named partner domain, prevents download by anyone else, and expires access after 90 days.
DLP policies scan file content for patterns (credit card numbers, SSNs, health records) and enforce actions: warn, block, or require manager justification to share externally. Pre-built templates cover HIPAA, PCI DSS 4.0, GDPR, GLBA.
Roll out labels in three stages: publish with training, monitor in audit mode for 30-60 days, then enforce.
Retention and Legal Hold
SharePoint retention policies (Purview → Data lifecycle management) set how long files are kept after deletion or modification. Common settings:
- Keep all versions for 365 days.
- Retain files for 7 years from creation (common for SOX, HIPAA).
- Automatic deletion after 3 years from last modification (GDPR data minimization).
Legal hold preserves specific files or sites against deletion when litigation is anticipated. Set via Purview eDiscovery.
Teams-created Team sites inherit the default retention unless a specific label is applied. Review retention coverage quarterly; gaps here are where auditors find problems.
File Version History
SharePoint keeps up to 500 versions by default. Major and minor versioning can be enabled per library for more granular control. For any library containing contracts, policies, or regulated documents, enable versioning explicitly and set retention to match the document's compliance window.
Users restore prior versions via the file's version history in Teams or SharePoint. Admins can recover deleted files from the recycle bin (93 days by default).
Size Limits and What Lies Beyond
SharePoint's per-file cap is 250 GB. Teams upload through the client caps at 250 GB per file. The upload size is generous; the practical problems hit elsewhere:
- Upload speeds on consumer connections mean 250 GB takes many hours.
- Sync conflicts on large files with active editors.
- Search indexing limits for very large files.
- Backup and restore windows lengthen significantly.
For files near or over the cap — or for one-time external deliveries where the file shouldn't live in SharePoint at all — a transfer tool is the right tool. HexaTransfer's client-side AES-256-GCM encryption model keeps the contents opaque to any intermediate service, appropriate for files that shouldn't sit in SharePoint's retained history.
Shared Channels vs Guest Access
Shared channels (introduced broadly in 2022) let you collaborate with external organizations without making them guests in your tenant. The external org's users appear in the channel with their own tenant identity. Advantages:
- Less license and provisioning overhead.
- External users stay in their own MFA, password policy, and compliance regime.
- Cleaner exit when engagement ends.
Drawbacks:
- Not available for every feature; some Teams apps don't yet support shared channels.
- Permission models can confuse — files in a shared channel live in a SharePoint site with both-org access.
For steady-state multi-org collaboration, shared channels beat guest access. For one-off external sends, neither — use a transfer link.
Integrating Non-Microsoft Tools
Teams' app catalog includes integrations for Dropbox, Box, Google Drive, Adobe Acrobat, Figma, and more. Install these at the tenant level so users can attach files from those services instead of duplicating uploads.
For transfer services, most don't have dedicated Teams apps, but URL paste works. A pasted HexaTransfer link previews in the channel; recipients click through to download. Combine with a Power Automate flow that triggers on files dropped into a specific folder — auto-generate a transfer link for files tagged "send external."
Audit Logs and Compliance Reports
Audit logs for file activity (views, edits, deletes, shares) live in Purview Audit. Retention for logs depends on license tier:
- Microsoft 365 Business: 90 days.
- E3: 180 days.
- E5: 1 year standard, up to 10 years with add-ons.
For compliance regimes requiring longer retention, export logs to a SIEM (Sentinel, Splunk, Datadog) via the Microsoft Graph API.
Configuration Checklist
Before rolling out Teams file sharing to the org:
- Tenant-level external sharing policy set to the right ceiling.
- Sensitivity labels published and assigned to at least one mandatory label for all content.
- DLP policies in place for regulated data types applicable to your org.
- Retention policies configured per SharePoint site / per sensitivity label.
- Sync permissions tested on a sample of personal devices.
- Guest access flow documented for Team owners.
- Transfer tool approved for large files or sensitive one-offs, documented in the file-sharing policy.
Common Pitfalls
- Chat files owned by departing employees: they vanish unless retention catches them. Set OneDrive retention for departures.
- "Anyone" links leaking: audit sharing reports monthly and disable inherited "Anyone" links where not intentional.
- Permission inheritance confusion: breaking inheritance at a subfolder creates islands that Team owners forget about.
- Private channel sites ballooning: each private channel is a separate site; they don't show up in normal Team management.
Teams file sharing is capable, but it rewards setup discipline. Configure the controls, train the users, audit the outputs.
Try it at hexatransfer.com — free, no account, 10 GB max.
Send large files securely with end-to-end encryption
Transfer files up to 10 GB for free with end-to-end encryption. No account required. Your files are encrypted in your browser before upload — no one else can read them.
Send a file