Microsoft 365 Hero Links: What They Are and How They Change SharePoint and OneDrive Sharing
Microsoft 365 Hero Links are Microsoft’s next-generation sharing model for files and folders in SharePoint and OneDrive. Instead of creating and redistributing a new URL every time the audience changes, a file or folder can have one primary, stable link whose access settings can be adjusted over time.
Last updated: 27 August 2026. Rollout dates and technical behavior may change; always verify Microsoft 365 Message Center post MC1454378 for your tenant.
Hero Links in one minute
- A Hero Link is intended to become the primary sharing link for a file or folder.
- The same URL can remain in use while an authorized person changes its audience or role.
- The default audience is designed to be Only people added to the file, so the URL alone does not broaden access.
- Organization-wide or Anyone access can be selected only where Microsoft 365 sharing policy allows it.
- Earlier sharing links are expected to remain available under Other links.
- Effective access can still come from direct, inherited, group-based, guest, and link-based permissions—not from the Hero Link alone.
Why Microsoft is changing the sharing model
Today, users can create several links to the same item for different audiences and roles. A link may then be copied into email, Teams, a ticket, or documentation. When requirements change, people often create another link and redistribute it. The result is a growing set of URLs that can be hard to explain and review.
Microsoft describes Hero Links as a simpler model: one prominent link that works consistently when it is copied from the sharing dialog, an email flow, or the browser address bar. The main benefit is continuity. A project owner can keep the URL already used by colleagues while changing who it grants access to, subject to policy and permissions.
How a Hero Link differs from earlier sharing links
One primary link instead of a new URL for each change
The important change is not merely visual. Microsoft says the audience and permissions of an already shared Hero Link can be adjusted without sending a different URL. That makes the link easier for people to reuse, but it also means the meaning of a stored URL may change over time.
Only people added is the conservative default
With Only people added to the file, the link is an access path for people who already have permission; possessing the URL does not by itself add a new recipient. This is conceptually close to the existing-access scope documented by Microsoft Graph, but administrators should avoid assuming that current Graph representations map one-to-one to every Hero Link state until Microsoft publishes complete API guidance.
Audience can be broadened where policy permits
Microsoft documentation for the SharePoint Online DefaultMainLinkScope site property currently lists OnlyPeopleAdded, Organization, and Anyone. Anyone remains conditional: if anonymous sharing is disabled at tenant or site level, it cannot become the effective default. A site may always be more restrictive than the organization.
Legacy links do not disappear
Microsoft’s Message Center guidance says existing links continue to work and appear under Other links. This avoids abruptly breaking old workflows, but it also creates a transition period in which a single item can have both a Hero Link and older audience-specific links.
Audience and role are separate decisions
The audience answers who can use the link; the role answers what they can do. Depending on file type, policy, and permissions, Microsoft describes options such as view, edit, and view without download. Administrators should record both dimensions. “Organization link” is not enough information if one version permits editing and another is read-only.
A stable URL does not equal stable access
Consider a project handbook whose Hero Link is placed in a team workspace. On Monday its audience is Only people added. On Friday the owner changes it to the organization. The URL in the workspace has not changed, but many more users may now be able to open it. That can be legitimate and useful. From a governance perspective, however, the authorization state has changed and should be observable.
The reverse is also valuable: an owner can narrow the audience without asking everyone to replace bookmarks. The stable-link model can reduce link sprawl while making change history more important.
Effective access remains broader than link inventory
A file can be reachable because of membership in a Microsoft 365 group, direct permission, inherited SharePoint access, a guest invitation, a Hero Link, or an older link. Microsoft notes that effective access reflects the applicable combination of permissions. Therefore, finding the Hero Link is not the same as proving who can open the file.
A defensible review should separate at least:
- the item and its site or OneDrive context;
- direct and inherited access;
- group and guest membership;
- Hero Link audience and role;
- legacy links under Other links;
- expiration or other conditions where they are explicitly exposed;
- when the evidence was observed and whether coverage was complete.
Rollout timing
Microsoft 365 Roadmap ID 492622, last modified on 26 August 2026, lists general availability rollout beginning in September 2026 across supported commercial and US government clouds. Microsoft 365 Message Center post MC1454378 described staged completion through late October 2026. Roadmap dates are estimates, and tenants may not receive the experience simultaneously.
What administrators should do now
- Read MC1454378 in the Microsoft 365 admin center and record the expected rollout for each tenant.
- Review tenant and site external-sharing policies, including whether Anyone links are permitted.
- Baseline important sites, current sharing links, guests, and high-impact folders before rollout.
- Select a pilot site and test the new sharing dialog with non-sensitive content.
- Document how audience and role changes appear in Manage Access, audit records, PowerShell, and Microsoft Graph.
- Keep legacy-link review in scope; Hero Links do not automatically remove older links.
What is still under technical validation
Microsoft Graph’s public permission model documents sharing-link scopes and roles, and the beta createLink action documents addressBar and adminDefault link types. As of this update, Microsoft’s public v1.0 documentation does not provide a complete, Hero-Link-specific contract for tenant-wide discovery, change history, expiration behavior, or every remediation action. Those gaps should be treated as unknown until verified in a rolled-out tenant and supported documentation.
How SharedLinks365 is approaching Hero Links
SharedLinks365 is designed around Microsoft 365 sharing governance: visibility, explainable risk, and practical prioritization across SharePoint and OneDrive. Hero Links are being evaluated as part of its technical roadmap. This article does not claim that SharedLinks365 already detects, changes, or revokes Hero Links.
For related background, see how to find SharePoint sharing links, compare Anyone and Specific People links, and review links without expiration.
Continue with focused Hero Links guides
- Hero Links security and governance risks
- How to prepare for and audit Hero Links
- Hero Links governance for MSPs
Frequently asked questions
What is a Microsoft 365 Hero Link?
It is Microsoft’s planned primary sharing link for a SharePoint or OneDrive file or folder. The URL is designed to stay stable while authorized users adjust its audience or role.
Does a Hero Link automatically give access to everyone who has the URL?
No. The default Only people added scope is intended not to grant new access by possession of the URL alone. Organization or Anyone access depends on the selected audience and administrative policy.
Will existing sharing links stop working?
Microsoft’s rollout guidance says existing links remain available under Other links. Administrators should continue to review them during and after rollout.
Can Microsoft Graph already identify every Hero Link?
Complete Hero-Link-specific discovery is not yet documented in the public Microsoft Graph v1.0 contract. Validate behavior in your tenant before relying on automation.
Simple, Smart, and Secure: The next step in sharing files in Microsoft 365
Microsoft 365 Roadmap ID 492622
Microsoft 365 Message Center MC1454378 (tenant-specific)
Set-SPOSite and DefaultMainLinkScope
Microsoft Graph permission resource
Reviewed by the SharedLinks365 Technical Team — AGORA TECH S.r.l. SharedLinks365 is an independent product and is not developed or endorsed by Microsoft.
Follow Hero Links governance development
Join Early Access for product updates as technical validation progresses.
Join Company Early Access