How to Prepare for and Audit Hero Links in SharePoint and OneDrive
To prepare for Microsoft 365 Hero Links, start with a baseline, use a non-sensitive pilot site, and validate what your tenant actually exposes through the user interface, audit records, PowerShell, and Microsoft Graph. Do not treat one setting or one screenshot as proof of complete rollout.
Last updated: 27 August 2026. Check Microsoft 365 Message Center post MC1454378 for tenant-specific timing.
1. Confirm the rollout signal
Microsoft 365 Roadmap ID 492622 currently lists general availability rollout beginning in September 2026. Message Center post MC1454378 provides the operational notice for administrators and described staged deployment through late October. Because rollout is service-controlled, two tenants—or even two users—may not see the experience at the same time.
Record the Message Center status, target release preferences, affected clouds, and date checked. Use that as context, not as proof that every workload surface is active.
2. Recognize the new experience in a pilot
Use a dedicated SharePoint site with non-sensitive test files and folders. In the sharing dialog, look for one prominent primary link, the Only people added audience, controls to adjust audience and role, and an Other links area for earlier links. Test both SharePoint and OneDrive because service behavior and timing can differ.
The appearance of the new dialog is strong evidence for that user and item. It is not evidence of tenant-wide completion.
3. Build a pre-rollout baseline
Before the interface changes, export or document the current state for a manageable set of important sites. Include:
- tenant and site external-sharing policy;
- site owners and sharing capability;
- existing Anyone, organization, and specific-people links where observable;
- direct, inherited, group, and guest access;
- role, expiration, and download restrictions where available;
- high-impact folders and files;
- observation time, coverage, errors, and permission limitations.
For an established process, use the SharePoint external-sharing audit guide.
4. Understand DefaultMainLinkScope
The SharePoint Online Set-SPOSite documentation defines DefaultMainLinkScope as a site or OneDrive-level property that controls the default audience of the primary link for items at the root of a document library. The documented values currently include OnlyPeopleAdded, Organization, and Anyone, with Anyone effective only when anonymous sharing is permitted.
Important: this is a configuration default, not an activation detector. Its presence in the cmdlet does not prove that the Hero Links user experience has reached a tenant, and the default does not prevent an authorized user from selecting another audience allowed by policy. Microsoft’s Message Center guidance did not identify a separate tenant-wide equivalent for this same property.
Read before write
For discovery, prefer read-only inspection of site properties and policy. Do not run bulk Set-SPOSite changes as a preparation shortcut. A write operation changes user defaults across a site and deserves change control, pilot evidence, and rollback planning.
5. Use an essential test matrix
| Test | Expected evidence | Why it matters |
|---|---|---|
| New item, Only people added | URL does not grant a new person access | Validates conservative default |
| Change to Organization | Same URL; broader authenticated audience | Validates stable-link behavior |
| Change back to Only people added | Same URL; broader access removed | Validates narrowing |
| Anyone, where allowed | Anonymous use matches site policy | Validates policy boundary |
| View, edit, no-download | Role and download behavior match selection | Separates audience from capability |
| Legacy link | Visible under Other links and still behaves as configured | Checks coexistence |
| Folder link | Behavior remains correct as folder contents change | Tests changing resource scope |
| Guest and offboarded owner | Effective access and ownership remain explainable | Tests lifecycle governance |
6. Validate Graph without overclaiming
Microsoft Graph v1.0 represents a drive item’s permissions, including sharing-link scope, role, URL, recipients where available, and expiration. The public model supports listing permissions item by item. It does not provide a universal tenant-wide “all links” endpoint.
The beta createLink documentation includes addressBar and adminDefault link types, which are relevant signals, but beta APIs can change and are not supported for production use. Until Microsoft publishes a complete Hero-Link-specific contract, test whether the same item and URL can be identified consistently before and after audience changes. Record raw evidence, API version, permissions, and failures.
7. Validate audit evidence
Microsoft Purview documents events for anonymous-link creation and removal, secure links, invitations, and sharing changes. During the pilot, change one variable at a time and search for the resulting events. Determine whether you can reliably answer:
- who changed the Hero Link;
- when the audience or role changed;
- the before and after values;
- whether the item and stable URL can be correlated;
- how long the evidence remains available under your licensing and audit-retention settings.
If a field is missing, classify it as unavailable or unverified—not as a safe state.
8. Review expiration separately
Do not assume that policies created for legacy Anyone or guest links automatically provide the same lifecycle for Hero Links. Microsoft’s public documentation does not yet describe every Hero Link expiration scenario. Test each allowed audience in the pilot and keep legacy links in the review.
Pre-rollout checklist
- Identify tenant owners and read MC1454378.
- Select pilot sites and test identities.
- Document sharing policy and DefaultMainLinkScope.
- Capture a baseline of links, guests, permissions, and high-impact items.
- Define evidence fields and incomplete-coverage handling.
- Inform service desk and site owners about the interface change.
Post-rollout checklist
- Confirm the new dialog on SharePoint and OneDrive.
- Run the audience and role test matrix.
- Compare Manage Access, audit, PowerShell, and Graph evidence.
- Review Other links and effective access.
- Repeat on more than one site and user.
- Monitor policy exceptions and unexpected scope widening.
- Update procedures only after observed behavior is repeatable.
For the underlying sharing model and terminology, read the complete Microsoft 365 Hero Links guide.
Continuous monitoring after the pilot
Rollout validation is a starting point. A stable URL can change audience later, and new legacy or direct permissions may appear. Define review frequency based on data sensitivity and business exposure. Prioritize changes rather than generating a flat list of every shared item.
SharedLinks365 is evaluating Hero Links as part of its technical roadmap. Its current positioning is Microsoft 365 sharing governance; this guide does not claim completed Hero Link discovery or remediation. Learn about the planned visibility workflow and security approach.
Frequently asked questions
Does DefaultMainLinkScope prove Hero Links are enabled?
No. It defines a site or OneDrive default audience. Validate the user experience and evidence in the tenant.
Should I change every site to OnlyPeopleAdded now?
Not as an automatic rollout step. Review the current policy and business need, test in a pilot, and apply normal change control before modifying production defaults.
Can I audit Hero Links only with Microsoft Graph?
Graph is part of the evidence, but current public documentation does not establish a complete Hero-Link-specific tenant-wide inventory and history workflow. Combine it with policy, Manage Access, and audit evidence.
Simple, Smart, and Secure: The next step in sharing files in Microsoft 365
Microsoft 365 Roadmap ID 492622
Microsoft 365 Message Center MC1454378 (tenant-specific)
Set-SPOSite documentation
Microsoft Graph permission resource
Microsoft Purview audit activities
Reviewed by the SharedLinks365 Technical Team — AGORA TECH S.r.l.
Follow technical validation
Join Early Access to follow SharedLinks365 development for Microsoft 365 sharing governance.
Join Company Early Access