技术问询:如何通过Office 365 API获取共享链接相关外部用户列表
Hey there, let's tackle your two Office 365 API questions head-on— I’ve worked with these SharePoint and Graph APIs extensively, so here’s the practical breakdown:
1. 获取AnyoneWithLink类型共享链接的外部用户列表
First off, a key caveat: AnyoneWithLink (anonymous access) links don’t track fully anonymous users, since they don’t require login. That means you can’t get a complete list of every person who accessed via this link if they didn’t sign in. But you can capture external users who did authenticate when accessing:
- Use Microsoft Graph’s
getActivitiesByIntervalendpoint: This pulls access/activity logs for a specific file/folder. Look at theactorfield in the response— if theuserPrincipalNameisn’t from your tenant, that’s an external user. Example request:GET /sites/{site-id}/drive/items/{item-id}/getActivitiesByInterval(startDateTime='2024-01-01T00:00:00Z', endDateTime='2024-06-01T00:00:00Z', interval='day') - Leverage Audit Logs: If your tenant has audit logging enabled (admin-controlled), use the Graph API’s audit logs endpoint to filter access events for the document. This will capture authenticated external users:
Note: Audit logs have a default retention period of 90 days, so you’ll only get data within that window.GET /auditLogs/directoryAudits?$filter=resourceDisplayName eq 'YourDocumentName' and activityDisplayName eq 'Access file'
2. 是否存在获取通过共享链接分享文档的所有外部用户的API
Yes, but it depends on the scope (single document vs. tenant-wide) and the type of sharing link:
For a specific document:
- Get all direct sharing permissions first: Use this Graph API call to pull all shared links and their granted users/groups. For non-anonymous links, the
grantedToIdentitiesfield will list external users directly:GET /sites/{site-id}/drive/items/{item-id}/permissions - Combine with activity logs: As mentioned above, add data from
getActivitiesByIntervalor audit logs to capture authenticated users who accessed via AnyoneWithLink links.
For tenant-wide bulk retrieval:
- Graph API with filtering: To find all external users granted access via sharing links across your sites, use a filtered permissions request:
GET /sites/{site-id}/drive/root/permissions?$filter=grantedToIdentities/any(u: u/user/tenantId ne 'YourTenantID') - PowerShell alternative: If you prefer scripting, use the SharePoint Online Management Shell to bulk scan sites and files:
Get-SPOSite -Limit All | ForEach-Object { Get-SPOFile -Site $_.Url -Recursive | Get-SPOSharingLink }
Critical Notes:
- Anonymous users (no login) via AnyoneWithLink can’t be tracked— there’s no way to get their info via API, since they don’t authenticate.
- All these requests require appropriate permissions (e.g.,
Files.Read.All,Sites.Read.All,AuditLog.Read.All) granted to your Azure AD app or user account.
内容的提问来源于stack exchange,提问作者Vivek Baranwal
相关产品推荐
相关产品推荐

