The best way to share files with external users

    · 7 min read

    The best way to share files with external users is almost never the thing people are actually searching for. They think they have a file delivery problem. What they have is a permissions problem wearing a file delivery costume.

    I know this because I have made both mistakes in the same week. Once by dropping an Anyone-with-the-link URL to a pricing folder into an email thread that got forwarded twice. Once by trying to be careful, sending a proper invite, and watching a client bounce off a sign-in wall for a Microsoft account they did not have and did not want.

    Neither of those was about file size. Both were about not deciding, up front, who this person is and how long they should have access.

    Work out which kind of external user you are dealing with

    Skip this and every tool choice below is a coin flip. Take a real case. A prospective client's finance lead needs to see one proposal PDF and a supporting cost model, for about two weeks, and will probably forward it internally to someone whose name you do not yet know. That person should never get a Google account invite, because they will forward the link and the invite will not travel with it. They want an unauthenticated link that expires, and you want to know whether the forwarded copy got opened.

    Now change one detail. A contractor is joining your team for six months and needs the whole marketing folder, including write access. That person absolutely should be a named guest with a login, because you need to be able to revoke one human's access in November without breaking anything else.

    Same phrase, "external user". Completely different answer. The tools all handle the second case well and the first case badly, which is why the first case is where the leaks happen.

    Your admin has already made this decision for you

    If you are on Microsoft 365, the range of what you can do was set by someone else before you opened the file. SharePoint and OneDrive external sharing runs on four organisation-level settings: Anyone, New and existing guests, Existing guests, and Only people in your organisation.

    Anyone links are the unauthenticated kind, the ones that work for the forwarded-to-finance case. The setting worth knowing about is that an admin can require every Anyone link to expire within a set number of days, and can force them to view-only. If you are the person who gets to configure this, turn that on. An external link with no expiry is a permanent one, and permanent was almost never what anyone meant.

    One trap: if Anyone links are enabled at the tenant level but the site itself is set to require sign-in, your default link type quietly reverts to people in your organisation only. That is the setting behind most "but I definitely shared it with them" conversations.

    Google Drive, done properly

    For a one-off document going to someone outside your company, Drive is still the lowest-friction option and I use it constantly.

    Select the file, hit Share, open General access, change Restricted to Anyone with the link, set the role to Viewer rather than Commenter or Editor, copy, done. Google's own documentation flags the thing people forget: your name and email are visible as the owner to anyone who opens it. Fine for a proposal, less fine when you are sharing something on behalf of a client.

    The bigger catch is that a work or school account may have external sharing switched off by an admin, and you will discover this at the exact moment you are trying to send something. Test it once on a throwaway file before you need it for real.

    Drive has no expiry on Anyone-with-the-link sharing the way a paid link tool does, so if the two-week window matters, put a calendar reminder on yourself to revoke it. That is a manual process and I have no better answer inside Drive.

    None of them tell you whether it landed

    Every option above solves access, and access is not the same as a document someone actually read. That gap is what I kept running into in growth roles before this, sending decks and proposals out on a Thursday and then guessing all weekend.

    The honest rundown of what fills it, then, my own product included, because leaving it out would be a bit precious.

    DocSend is the established name for document tracking with access controls attached, and if what you need is watermarking or an NDA gate before someone can view, that is where I would point you. LiveDocument does not do either of those, and I would rather say so than pretend.

    LiveDocument is the one I build. It takes a PDF or an image, lets you record a walkthrough that plays alongside it, shares it as one link with nothing to download, gives you clickable highlights that jump the video to the section you are discussing, and shows page-level engagement so you can see where someone lingered and what they went back to. Access control is link expiration and revocation, and that is the whole list. It is not storage, not a data room, not an editor, and it will not help you send a folder.

    Which is the honest boundary. If your external user needs a folder, use Drive, SharePoint or Dropbox with the settings above. If your external user needs to understand one document and you will not be in the room when they open it, a folder link is a strange way to deliver that, and a walkthrough sitting on the document is a better one. Most teams need both, and I would rather you got the folder part right than pretended one tool covers it. There is more on how the two fit together in the file sharing software breakdown and in the rundown of PDF sharing sites.

    FAQ

    What is the most secure way to share files with external users?

    A named guest account with a login for anyone who needs ongoing access, and a short-lived expiring link for anyone who does not. On Microsoft 365, enforce expiry on Anyone links at the tenant level rather than trusting people to remember.

    How do I know if an external user actually read the file?

    Storage tools will not tell you. That needs a tracking tool reporting opens and page-level engagement, whether DocSend, LiveDocument or something similar. Sharing and tracking are different jobs and most stacks only cover the first.

    I got tired of sending things out and waiting to find out what happened, which is why LiveDocument exists at all. If that is a familiar feeling, the pricing page is the place to start.

    About the Author

    Cameron James

    Cameron is the founder of LiveDocument. He writes about sharing documents, PDFs, decks and contracts, and why pairing a video walkthrough with a document beats sending it cold.