Skip to the main content.

Microsoft Teams · File sharing in external chats

Teams turns on file sharing in chats with other organizations starting late October, even where you turned it off. Decide who can open those files first.

Starting in late October 2026, Microsoft Teams lets your staff attach files in chats with people at other organizations by default, and automatically grants everyone in the chat the permissions they need, within your OneDrive and SharePoint sharing settings. That saves a round of email with an outside auditor, a title company, or a vendor. Microsoft says the new default applies even where your administrators set file sharing in external chats to Disabled, so the settings that decide who can open those files deserve a look now.

  • Rollout begins in late October 2026 and is expected to complete by late November 2026 for all Microsoft 365 tenants, per Microsoft 365 Message Center post MC1479514
  • Attached files stay in the sender's OneDrive with an External label, and your existing OneDrive, SharePoint, and Microsoft Entra settings still decide who can open them
  • To keep it off, Microsoft says to reapply the Disabled setting after the rollout reaches your tenant
External chats Late 2026
Today
Off by default
Users can paste a link; the paperclip is hidden in external chats
Late October 2026
Rollout begins
The paperclip appears, and Teams sets permissions for the chat automatically
Expected by late November 2026
Default on in every tenant
Including tenants that set it to Disabled
Settle it before the late October rollout
Late Oct
Microsoft begins turning on file sharing in external Teams chats by default, and expects to finish by late November 2026.
Source: Microsoft 365 Message Center, MC1479514
All domains
Teams' default external access setting lets users chat with people in any external domain whose organization also allows it.
Source: Microsoft Learn, Manage external meetings and chat
48%
Breaches involving a third party now account for 48% of all breaches, with third-party involvement up 60%.
Source: Verizon, 2026 Data Breach Investigations Report

What is Microsoft changing about file sharing in external Teams chats?

Today, a Teams administrator has to switch file sharing on before anyone can attach a file in a chat with another organization. Microsoft is reversing that default and pairing it with automatic permissions.

Today

Off by default

Microsoft Learn says file sharing in external (federated) chats is turned off by default. Users can paste an existing link, and the paperclip stays hidden in external chats.

Late October 2026

The rollout begins

The paperclip appears in external 1:1 chats, group chats, and meeting chats, and Teams automatically grants the people in the chat the required permissions, within your OneDrive and SharePoint sharing settings.

Expected by late November 2026

Rollout expected to complete

Microsoft says the new default applies to all Microsoft 365 tenants, even where the setting was configured as Disabled, and expects the rollout to complete by late November.

After it reaches you

Your decision, reapplied

To keep file sharing in external chats off, Microsoft says to reapply the Disabled setting after the rollout reaches your tenant, then verify it.

"This change applies even if your organization previously configured the setting as Disabled. Organizations that want file sharing in external chats to remain disabled must reapply the disabled setting after rollout."

Microsoft 365 Message Center post MC1479514, Microsoft Teams: File sharing enabled by default in external (federated) chats, published September 25, 2026

Microsoft lists the rollout for Targeted Release and for General Availability in Worldwide, GCC, GCC High, and DoD, beginning in late October 2026 and expected to complete by late November 2026. It affects organizations that use Teams external access, also called federation, including organizations that previously disabled file sharing in external chats. It covers the Teams desktop app and the Teams web app.

Here is what users will see. The Attach file button, the paperclip, shows up in external chats, and people can attach a file or drag one into the message box. When they do, Teams automatically grants the required permissions to the participants in the chat. Senders can review, modify, or remove those permissions before sending, and can change or revoke access after the file is shared. A pasted file link works as it does today and keeps its existing permissions.

Microsoft answers the data question directly in the post's compliance section. Asked whether the change alters how existing customer data is processed, stored, or accessed, it says: "Yes. Uploaded files can automatically receive permissions for participants in external chats."

Timeline infographic, File sharing in external Teams chats: the late 2026 change, with the Microsoft four-square logo and Microsoft 365 and Microsoft Teams in the header. Today: off by default; admins must turn it on, users can paste links, and the paperclip is hidden in external chats. Beginning late October 2026: the rollout begins; the paperclip appears in external 1:1, group, and meeting chats, and Teams automatically grants chat participants the required permissions. Expected by late November 2026: the rollout is expected to complete, on by default in all Microsoft 365 tenants, including tenants that set it to Disabled. After the rollout reaches your tenant: want it off? Reapply the Disabled setting in Teams PowerShell, then verify it. Source: Microsoft 365 Message Center MC1479514.
Off by default today, on by default from late October, expected to complete by late November. A tenant that wants it off reapplies that choice after the rollout arrives.

Who can open a file your staff attach in an external Teams chat?

Start with five settings you already own. They are the priority checks, and they sit alongside sensitivity labels and your other protections, which Microsoft says continue to apply. Once the rollout lands, Microsoft's default for every one of the five allows sharing.

The five settings behind a file attached in an external Teams chat. Sources: Microsoft 365 Message Center MC1479514; Microsoft Learn pages on external chats, external access, SharePoint and OneDrive sharing, and Microsoft Entra external collaboration, read September 26, 2026. Microsoft's defaults are shown; step 1 below records your tenant's current values.
Setting Where you set it Microsoft's default What it decides for an attached file
Teams external access Teams admin center, Users, External access Allow all external domains Which outside organizations your staff can chat with at all. Microsoft notes the other organization must also allow external access.
File sharing in external chats Teams PowerShell, Set-CsTeamsFilesPolicy, FileSharingInChatsWithExternalUsers Disabled today; enabled by default as the rollout reaches each tenant Whether the paperclip appears in external chats.
Automatic sharing Teams PowerShell, Set-CsTeamsMessagingPolicy, AutoShareFilesInExternalChats Enabled Whether Teams grants the people in the chat the required permissions when a file is attached, within your sharing settings.
SharePoint and OneDrive external sharing SharePoint admin center, Policies, Sharing External sharing turned on Whether a file in a user's OneDrive can be shared outside the organization, at what level, and with which domains.
Guest invitations Microsoft Entra admin center, External Identities, External collaboration settings All users, including guests, can invite Who can bring an outside person into your directory as a guest.

External file sharing can add guest accounts to your directory.

Microsoft Learn says external recipients open attached files as Microsoft Entra B2B guests, if your policies allow it, and that a guest object is created on demand when one doesn't exist. Microsoft Learn also says that starting in May 2026 Microsoft enables SharePoint and OneDrive integration with Microsoft Entra B2B for all tenants, which gives each outside person you share with an account in your directory, subject to your Microsoft Entra ID policies such as multifactor authentication.

Plan the guest reviews for that growth now. Each chat partner who opens a file can become a guest account in your directory, and someone should decide how long each one stays.

A group chat can include people your external access list never approved.

Microsoft Learn says files attached in external chats are automatically shared with all participants. When one of your staff is added to an external group chat, Microsoft's default only requires a valid federation relationship between that person and the person who started the chat, and Message Center post MC1423114 notes that other people already in the chat might not meet your external access requirements.

Two controls answer that. MC1423114 describes EnableMutualFederationForChatParticipants, available September 30, 2026 and off by default, which requires every participant to meet the federation requirements. And your SharePoint, OneDrive, and Entra domain restrictions still apply to the file itself. Keep those lists in step with the domains your staff are allowed to chat with.

What happens when someone attaches a file in an external chat?

Microsoft documents the whole path, from the sender's OneDrive to the outside person's browser. Each step has a setting you already own.

It lands in the sender's OneDrive

Files uploaded to external chats are stored in the sender's OneDrive and display an External label. External recipients open them in the browser.

Permissions are set automatically

Teams grants the chat's participants the required permissions when a file is attached or dragged in, within your OneDrive and SharePoint sharing settings. The sender can change them before sending. Pasted links keep their existing permissions.

Recipients can sign in as guests

External recipients access files as Microsoft Entra B2B guests, if your policies allow it. Microsoft says they may see a consent prompt, and multifactor authentication depending on your tenant policy.

Your protections keep applying

Microsoft says existing sensitivity labels, domain restrictions, and security protections continue to apply, and that enabling file sharing in Teams doesn't override your OneDrive and SharePoint sharing settings.

"File access is governed by existing OneDrive and SharePoint sharing settings. Enabling file sharing in Teams doesn't override these controls."

Microsoft Learn, Share Files and Loop components in external (federated) chats, last updated March 12, 2026

That sentence is the reason to read your sharing settings before late October. The Teams change adds the paperclip and the automatic permissions. What an outside person can actually open still comes down to your OneDrive and SharePoint sharing level, your domain lists, and your Entra guest settings, the rows in the table above.

Microsoft adds two practical notes. If automatic permission assignment is turned off, users may need to grant access manually before external recipients can open a file. And people outside your organization who aren't federated with you can access and upload files during a meeting, then lose access after the meeting ends.

Diagram infographic, Who can open a file attached in an external Teams chat?, with the Microsoft four-square logo and Microsoft 365, Teams, SharePoint, OneDrive, and Microsoft Entra ID in the header. Your staff member attaches a file, and it passes four gates. Gate 1, Teams external access: which organizations can chat at all; default, all external domains. Gate 2, Teams file sharing and automatic sharing: paperclip on, permissions set automatically; default, on from the rollout. Gate 3, SharePoint and OneDrive sharing: sharing level and allowed domains; default, external sharing on. Gate 4, Microsoft Entra guest settings: who can invite guests; default, all users can invite. Outcome: the outside person opens the file in the browser, as a Microsoft Entra B2B guest where your policies allow it. The file stays in the sender's OneDrive, labeled External. Sources: Microsoft 365 Message Center MC1479514; Microsoft Learn.
One attached file, four gates you already own. The Teams change opens the second gate by default; the other three shape what happens next.

Find out how your five sharing settings are set before the rollout reaches you

ABT records Teams external access, both Teams file sharing policies, SharePoint and OneDrive sharing, and Microsoft Entra guest invitations in your Microsoft 365 tenant, as part of a free security assessment.

Request the free assessment

Should you keep file sharing in external chats on or turn it off?

Either answer can be right for a credit union, bank, or mortgage company. What matters is that the answer is yours, written down, and still true after the rollout.

On, with guardrails

A good fit when staff trade documents with the same outside partners every week.

  • Allow only the domains you work with in Teams external access. Microsoft says that once you list allowed domains, all other domains are blocked. For group chats, pair it with the mutual federation control described above.
  • Match those domains in SharePoint and OneDrive sharing, whose organization-level list accepts up to 5,000 domains.
  • Set OneDrive's sharing level and guest expiration, and consider limiting external sharing to specific security groups.
  • Narrow who can invite guests in Microsoft Entra, and review guest accounts on a schedule.
  • Choose automatic or manual permissions. AutoShareFilesInExternalChats Disabled keeps the paperclip and makes each sender grant access by hand.

Off, reapplied after the rollout

A good fit when files leave the institution through a secure portal or a managed transfer process.

  • Reapply the setting after the rollout reaches your tenant. Microsoft says the change applies even where the setting was configured as Disabled.
  • Check it weekly, or more often, until the expected finish. Microsoft gives a window, beginning in late October and expected to complete by late November. Between the rollout's arrival and your reapplied setting taking effect, the paperclip is available, so a shorter check interval means a shorter window.
  • Tell staff what still works. Pasted links keep working under each link's own permissions.
  • Mind Loop components. Microsoft notes they continue to be shared automatically even when file sharing in chats is disabled.
  • Keep the external access list tight anyway. It decides who can reach your staff in chat at all.

What should an administrator do before late October?

Seven steps. The first five hold whichever way you decide. The sixth applies if you choose off, and the seventh applies to everyone.

1

Record today's five settings

In the Teams admin center, open Users, then External access, and note which option is set for organizations. In Teams PowerShell, run Get-CsTeamsFilesPolicy | Select Identity, FileSharingInChatsWithExternalUsers and Get-CsTeamsMessagingPolicy | Select Identity, AutoShareFilesInExternalChats. In the SharePoint admin center, open Policies, then Sharing, and note the SharePoint and OneDrive levels and any domain limits. In the Microsoft Entra admin center, note the guest invite settings and collaboration restrictions under External collaboration settings.

Save the output with today's date as your baseline for comparison. Keep a dated record of every change your team makes from here, so a difference your team did not make stands out.

2

Decide on or off with your compliance officer

Put the two paths above in front of your information security officer and your compliance officer together. Record the decision, the reason, and who owns it. A written decision is far easier to explain later than an inherited default.

3

Limit external access to the organizations you work with

In Users, then External access, choose Allow only specific external domains and add the partners your staff actually chat with. Microsoft says that once you set up a list of allowed domains, all other domains are blocked. For external group chats, review EnableMutualFederationForChatParticipants, set with Set-CsTenantFederationConfiguration. Microsoft notes that turning it on can remove users from existing federated group chats that fall outside the federation requirements, so tell the help desk before you switch it on.

4

Set OneDrive's sharing level and domain limits

In the SharePoint admin center, under Policies, then Sharing, set the external sharing level for SharePoint and OneDrive. Microsoft says the OneDrive setting can be more restrictive than the SharePoint setting, but not more permissive. Limit external sharing by domain to match your Teams list, consider allowing only specific security groups to share externally, and set guest access to expire after a set number of days.

5

Decide who can invite guests

In the Microsoft Entra admin center, go to Entra ID, then External Identities, then External collaboration settings. Microsoft's default lets all users in your organization, including B2B collaboration guest users, invite external users. The options run down to only users in specific admin roles, and collaboration restrictions can allow or deny invitations by domain. Our guide to Microsoft 365 guest access for financial institutions covers what to prove about the guests you already have.

6

If you chose off, reapply it after the rollout

Once the rollout reaches your tenant, run Set-CsTeamsFilesPolicy -Identity Global -FileSharingInChatsWithExternalUsers Disabled, then verify it with Get-CsTeamsFilesPolicy | Select Identity, FileSharingInChatsWithExternalUsers. Microsoft says to allow several hours for policy changes to propagate. The verify command lists every Teams files policy in your tenant; if it returns custom policies, set each one the same way by its Identity.

Run that check weekly from late October until Microsoft's expected completion in late November, and have a test account open an external chat each time. If the verify command reports Enabled on a policy you set to Disabled, or the test account sees the paperclip, the rollout has reached you: reapply the setting that day. The paperclip stays available from the day the rollout arrives until your reapplied setting takes effect, so a shorter check interval means a shorter window. Watch MC1479514 itself too: Microsoft revises rollout timing inside the Message Center, as our page on how Microsoft changes Message Center dates shows.

7

Tell staff and the help desk

Microsoft recommends informing help desk and support teams and updating user training. Tell staff four things. If you keep automatic sharing on, files attached in an external chat are automatically shared with the chat's participants unless they change the permissions. Pasted links keep their existing permissions. Attached files stay in their own OneDrive with an External label. And they can change or revoke access after sharing. Pair it with the reporting button covered on our page about Teams user reporting turning on by default, so staff report a suspicious file request from outside to your security team.

Read the sources in two minutes

Open Message Center post MC1479514 in your Microsoft 365 admin center. Then read Microsoft Learn's Share Files and Loop components in external (federated) chats and Manage external meetings and chat for the external access options.

Why does this matter at a financial institution?

Institutions run on outside partners, and Teams is where much of that work already happens.

Start with the upside. A loan condition cleared with the title company in one chat, a policy draft sent to outside counsel without a second email thread, a vendor ticket with the log file attached. Institutions that already allowed file sharing in external chats have that today, and the rollout that begins in late October brings it to everyone else.

The same attachment can put member and borrower data in front of people outside the institution, who may sign in as guests of your tenant to open it. Verizon's 2026 Data Breach Investigations Report found that breaches involving a third party now account for 48% of all breaches, with third-party involvement up 60%. Verizon counts breaches of every kind, so read the figure as context for third-party risk in general. Every outside organization your staff chat with is part of that picture, and the five settings above shape how far into your files that relationship can reach.

Governance closes the loop. A written decision on this setting, the domain lists behind it, and a dated record that the setting held after the rollout belong in the evidence your information security program keeps. Our guide to Teams governance for financial institutions covers the settings around it, from guest access to retention.

People outside your institution get the paperclip too

Microsoft says file sharing in external chats will be enabled by default for all Microsoft 365 tenants. That includes the vendors, partners, and anyone else who can reach your staff in Teams chat, unless their own administrators turn it off. Microsoft says malicious link protection continues to apply in external chats, and your external access list decides which organizations can start that conversation in the first place. A file request from an unexpected outside contact is worth a report to your security team.

Why does a default matter more than a written policy?

Because a default reaches every user on the day it lands, and a written policy only reaches the people who read it. The Short from our channel argues a related point: much of the data risk an institution carries already has a badge. Firewalls, phishing filters, and multifactor authentication watch the door, and an employee who sends a borrower file to the wrong outside party is already inside it, trying to get the job done.

A paperclip in every external chat makes that easier. The Short points to Microsoft Purview Insider Risk Management for the behavior side. The five settings on this page are the configuration side, and they shape how far a well-meant attachment can travel.

Featured Short

A free security assessment

ABT is a Tier 1 Microsoft Cloud Solution Provider serving more than 750 financial institutions, and the external sharing check is part of this assessment.

We show you how your five sharing settings are set today, and what to decide before late October

The assessment is free and ends with written findings you keep. We work through your settings with an administrator on your team, and your team decides what changes in the tenant and who makes each change.

  • The five settings, recorded. Teams external access, both Teams file sharing policies, SharePoint and OneDrive sharing, and Microsoft Entra guest invitations, as they stand today.
  • The decision brief. On with guardrails or off, laid out for your compliance officer with what each path requires.
  • The domain lists. The organizations your staff can chat with, compared against the domains SharePoint, OneDrive, and Entra allow.
  • The guest picture. The guest accounts already in your directory and who can invite more.
  • The rollout check. The commands and a check schedule to confirm your Teams files policies still match your decision after the rollout reaches your tenant.

ABT also operates M365 Guardian, its managed security service for credit unions, banks, and mortgage companies. Learn about M365 Guardian

If this opened a bigger question

External chat file sharing sits between your Teams governance, your guest accounts, and the permissions on your files. These three pick up each thread.

Microsoft Entra ID External Identities panel showing four external guest accounts with MFA, beside an Anyone with the link card outside the directory perimeter

Microsoft 365 Guest Access for Financial Institutions

What banks and credit unions should be able to show about who outside the institution can reach their data, now that external sharing runs through Entra B2B.

Read the guide
Microsoft Teams governance for financial institutions: unmanaged Teams sprawl on the left, a structured Microsoft 365 governance foundation with Microsoft Entra ID and SharePoint on the right

Microsoft Teams Governance for Financial Institutions

Teams sprawl, guests that outlive the deal, and retention gaps, with what Business Premium already covers.

Read the guide
Microsoft 365 Copilot surfacing overshared files while a Microsoft Purview Data Access Governance shield protects financial institution data before a Copilot rollout

Microsoft 365 Copilot Oversharing for Financial Institutions

Copilot only surfaces what users can already open. How institutions find overshared files and tighten access before a Copilot rollout.

Read the guide

File sharing in external Teams chats, answered

Yes. Microsoft 365 Message Center post MC1479514 says Microsoft is changing the default for file sharing in external (federated) chats from Disabled to Enabled for all Microsoft 365 tenants, beginning in late October 2026 and expected to complete by late November 2026. Microsoft says the change applies even if your organization previously configured the setting as Disabled.
Microsoft gives a window. Targeted Release and General Availability in Worldwide, GCC, GCC High, and DoD begin in late October 2026 and are expected to complete by late November 2026. Watch MC1479514 in your Microsoft 365 admin center for changes to that timing, and check your setting weekly during the window.
After the rollout reaches your tenant, run Set-CsTeamsFilesPolicy -Identity Global -FileSharingInChatsWithExternalUsers Disabled in Teams PowerShell, then verify it with Get-CsTeamsFilesPolicy | Select Identity, FileSharingInChatsWithExternalUsers. If the verify command lists custom policies, set each one the same way by its Identity. Microsoft says to allow several hours for policy changes to propagate, and says the change applies even if your organization previously configured the setting as Disabled, which is why it says to reapply the setting after the rollout.
Yes. Microsoft says Set-CsTeamsMessagingPolicy -Identity Global -AutoShareFilesInExternalChats Disabled turns off automatic permission assignment while continuing to allow file attachments in external chats. Users may then need to grant access to a shared file manually before external recipients can open it.
In the sender's OneDrive. Microsoft says files uploaded to external chats are stored in the sender's OneDrive and display an External label, and Microsoft Learn says external recipients open them in the browser.
Yes. Microsoft says existing OneDrive and SharePoint sharing controls continue to govern access, and existing sensitivity labels, domain restrictions, and security protections continue to apply. Microsoft Learn adds that enabling file sharing in Teams doesn't override your OneDrive and SharePoint sharing settings.
If your policies allow it. Microsoft Learn says external recipients access files as Microsoft Entra B2B guests and that a guest object is created on demand when one doesn't exist. Your Microsoft Entra external collaboration settings decide who can invite guests, and by default all users in your organization, including guests, can.
They keep their existing permissions. Microsoft says pasted file links retain their existing permissions and are not automatically shared, because automatic permission assignment applies only to files uploaded through the attach or drag-and-drop experience.
Open Message Center post MC1479514, Microsoft Teams: File sharing enabled by default in external (federated) chats, in your Microsoft 365 admin center. On Microsoft Learn, read Share Files and Loop components in external (federated) chats. Every Microsoft statement on this page was read from those sources and the others listed below on September 26, 2026.

Where the facts on this page come from

Every Microsoft date, default, command, and quotation above was read from the sources listed here on September 26, 2026.

  • Microsoft 365 Message Center post MC1479514, Microsoft Teams: File sharing enabled by default in external (federated) chats, plan for change, major change, published September 25, 2026. Source for the change from Disabled to Enabled, the late October to late November 2026 rollout, the change applying to tenants that configured Disabled, reapplying the setting after rollout, the paperclip and automatic permissions, pasted links, the sender's OneDrive and External label, existing controls continuing to apply, the PowerShell commands, propagation time, the recommendations, and the compliance answer. Visible to administrators in your own Microsoft 365 admin center; a public archive copy is at mc.merill.net/message/MC1479514.
  • Microsoft Learn, Share Files and Loop components in external (federated) chats, last updated March 12, 2026. Source for today's off-by-default setting, sharing with all participants, browser access for recipients, Microsoft Entra B2B guests created on demand, consent and multifactor prompts, Loop components, meeting access for non-federated users, and settings that are not overridden.
  • Microsoft Learn, Set-CsTeamsFilesPolicy and Set-CsTeamsMessagingPolicy. Source for the FileSharingInChatsWithExternalUsers and AutoShareFilesInExternalChats parameters and their current default values.
  • Microsoft Learn, Manage external meetings and chat with people and organizations using Microsoft identities, updated August 7, 2026. Source for the Allow all external domains default and allowed-domain lists.
  • Microsoft Learn, External sharing overview and Manage sharing settings for SharePoint and OneDrive. Source for external sharing being on by default, the sharing levels, OneDrive never more permissive than SharePoint, domain limits of up to 5,000 domains, security-group limits, and guest expiration.
  • Microsoft Learn, SharePoint and OneDrive integration with Microsoft Entra B2B. Source for the May 2026 integration for all tenants and guest accounts subject to Microsoft Entra ID policies.
  • Microsoft Learn, Configure external collaboration settings for B2B in Microsoft Entra External ID. Source for the default that all users, including guests, can invite, the invite options, and domain collaboration restrictions.
  • Microsoft 365 Message Center post MC1423114, Microsoft Teams: Stricter external access controls for federated chats, updated August 4, 2026. Source for the default federation check in external group chats, EnableMutualFederationForChatParticipants and its September 30, 2026 availability, and participant removal. Visible to administrators in your own Microsoft 365 admin center; a public archive copy is at mc.merill.net/message/MC1423114.
  • Verizon, 2026 Data Breach Investigations Report news release, May 19, 2026. Source for breaches involving a third party accounting for 48% of all breaches and third-party involvement up 60%.

Your staff are about to get a paperclip in external chats.
Decide who can open what they attach.

Recording five settings and making one decision is a short piece of work before late October. Once it is settled, your five settings are recorded and your decision is written down.

Tell us a little about your environment and we will come back with what we would check first.

Tier 1 Microsoft CSP 750+ financial institutions SOC 1 Type 2 · Security Controls SOC 2 Type 1

What should we look at? Optional.

Teams external sharing settings
Guest account review
SharePoint and OneDrive sharing
Security assessment

Encrypted. Private.

Thank you. That is with us.

An ABT specialist will be in touch shortly. If you want your settings recorded before the late October rollout, say so in your reply and we will move it to the front.