Review Who Can See Your Team's Files

Questions

  • Who can see the files in my department's Microsoft Team?
  • How do I check whether anyone outside Bowdoin can open our files?
  • Someone opened one of our files and they are not on my Team. How is that possible?
  • How do I find out who a folder is shared with?
  • Can guests in my Team see everything?
  • How do I review permissions on a Team's SharePoint site?
  • How often should I check who has access to our files?
  • A colleague who left the department can still open our files. How do I stop that?
  • As a Team owner, how do I check the membership of a private channel?
  • Why does someone have access when their name is not in the Teams member list?

Environment

Reviewing who can reach a Microsoft Team's files is a Team owner task from start to finish. Members of a Team can read the member list, but members cannot change it and cannot review SharePoint site permissions.

  • Applies to owners of a Microsoft Team at Bowdoin. Reviewing membership, sharing links, and SharePoint site permissions all require Team owner permissions.
  • Private channels and shared channels have their own membership, reviewed separately from the Team's membership. Looking inside a private channel requires membership in that private channel, even for a Team owner.
  • In some versions of Microsoft Teams, a channel's Shared tab is labeled Files. Both labels open the same place.
  • Menu names differ slightly between the Microsoft Teams desktop app, the web version, and SharePoint. Look for the same wording in a nearby menu if a label does not match exactly.
  • Supported on Bowdoin-issued computers running macOS Sequoia (15.x), macOS Tahoe (26.x), or newer, or Windows 11, and on the current version of iPadOS. Personal devices are best-effort only.
  • Sign in at office365.bowdoin.edu for the web version of Microsoft Teams or SharePoint.
  • Not in scope: setting a permission on one folder, which is covered by Give Someone Access to One Folder in the Related Articles section.

Resolution

The three layers that decide who can open a file

Three separate things combine to decide who can open a file in a Microsoft Team. Reviewing only the member list checks one of the three.

  1. Team membership. Everyone in the Team can open every file in every standard channel. A standard channel, or a folder inside one, cannot be hidden from a member of the Team.
  2. Channel type. Standard channels are open to all Team members. A private channel is visible only to the people invited to it. A shared channel is visible only to the people invited to it, and those people do not have to be in the Team at all. Private channels and shared channels each store their files on a separate SharePoint site.
  3. Individual sharing links. Any member can share a file or folder with a specific person, and that person may have no other connection to the Team. Sharing links keep working after membership changes.

Check Team membership and channel membership

  1. Select the Team name, then select Manage team.
  2. Open the Members tab.
  3. Review the owners, the members, and anyone marked Guest.
  4. Open each private channel and each shared channel and check its membership on its own, because channel membership is independent of the Team's membership.
  5. Confirm that the Team has at least two owners. If the only owner leaves the college, nobody can add members, renew the Team, or recover deleted files until an owner is restored.

For the steps to add and remove people, see Manage Membership of a Team or Channel in the Related Articles section.

Check the Team's SharePoint site permissions

Files in standard channels live in one SharePoint site connected to the Team. Team owners and Team members are placed in that site's owners and members permission groups automatically.

Note: Anyone added directly to a SharePoint permission group does not appear in the Microsoft Teams member list. A permission granted directly in SharePoint is the most common reason a person has access that a Team owner cannot account for.

To reach the site, open a channel's Shared tab and choose the option to open the folder in SharePoint. For the review itself, see Review User Permissions Inside a SharePoint Site in the Related Articles section, and to make changes, see Add and Remove Members to a SharePoint Permissions Group in the Related Articles section.

Find files shared with people outside Bowdoin

Sharing with people outside Bowdoin is the layer that most often surprises Team owners, because the person who created a link may have left the department. For the steps to produce the list for your Team's site, see List SharePoint or OneDrive Files Shared with External Users in the Related Articles section.

Spot individually shared files and folders inside a channel

Microsoft Teams puts no visible mark on a file or folder that has been shared with one individual, so individually shared items are hard to find by browsing.

  1. Open the channel's Shared tab.
  2. Select the file or folder you want to check.
  3. Select Share.
  4. Open Manage access.
  5. Read the People, Groups, and Links entries, which are the three things that grant access, then change or remove any entry that is no longer needed.

Checking every item in a channel is not realistic. Check the folders that hold sensitive or personnel-related material, and check anything a departing employee shared.

Guests and the 180 day expiry

Important: A guest added to the Team can see every standard channel and every file in it. Team owners routinely underestimate how much a single guest can see.

Guest access for people outside Bowdoin expires after 180 days, and only the file owner can renew it. For the renewal and removal steps, see Extend or Remove Guest Access in OneDrive and Teams in the Related Articles section. Expiry is not a substitute for housekeeping: remove a guest when their project ends rather than waiting for access to lapse. Before adding anyone new, see Invite a Guest to a Team or Channel in the Related Articles section.

A short quarterly review

Once a quarter, spend fifteen minutes on five checks.

  1. Read the Members tab and remove people who have changed roles or left Bowdoin.
  2. Confirm that the Team still has at least two owners.
  3. Open each private channel and each shared channel and check its membership.
  4. Produce the list of files shared with people outside Bowdoin, and remove links that are no longer needed.
  5. Open Manage access on the two or three most sensitive folders in the Team.

Manage access through membership and channels, not folders

Structure matters more than any single review. Decide access by who is in the Team and by which channel a file belongs in. Custom permissions on individual files and folders in a standard channel are invisible in Microsoft Teams, break when files move, and multiply until nobody can say who can see what. If a group of people needs its own space, give them a private channel or a shared channel instead. For the alternatives, see Give Someone Access to One Folder in the Related Articles section, and for Bowdoin's guidance on structure, see Best Practices and Limitations in Teams, SharePoint, and OneDrive in the Related Articles section.

Additional Help

If you need further assistance, you have several options:

  • Bowdoin Bot: Chat with Bowdoin Bot directly from any KB page for instant answers.
  • Phone: Call the Bowdoin College Service Desk at (207) 725-3030.
  • In person: Visit the Tech Hub in Smith Union during business hours.
  • Submit a ticket: Request assistance through the Service Catalog.

Additional Resources

 

 

AI-assisted content: This article was created with AI. It was verified and edited by a human.
Print Article

Related Articles (4)

This article is the starting point for anyone working with files in Microsoft Teams at Bowdoin, and it points to the knowledge base article that covers each task. It contains no procedures of its own, and every article it names is listed in the Related Articles section.
This article explains how to search for a file in Microsoft Teams, SharePoint, and OneDrive, and what each search box actually covers. It also lists the common reasons a file that exists does not appear in your search results, and what to do next when no search turns the file up.
This article explains how to give a Microsoft Teams channel its own email address, so that messages, scans, and automated reports arrive where the team already works instead of in one person's mailbox. It covers getting the address, limiting who may send to it, removing it, and when a different approach fits better.
This article explains how to give another person access to a file or folder stored in Microsoft Teams, SharePoint, or OneDrive with a Bowdoin account. It covers the link types available, the difference between edit access and view access, and when adding a person to the Team is a better choice than sending a link.