The Future of File Sharing in Microsoft 365: Hero Link Deep Dive

Microsoft just unveiled the biggest update to file sharing in OneDrive and SharePoint in over a decade — and we’ve got the inside scoop from Principal Product Manager Stephen Rice

Recorded live at the Microsoft 365 Community Conference, this video breaks down the new Hero Link sharing model: a simpler, smarter, and more secure way to share files in Microsoft 365.

Whether you’re an IT admin or an end user, this is your essential guide to what’s coming later this year.

🔗 Connect with Stephen Rice LinkedIn and check out the SyncUp Podcast

🗣 Got questions? Join the OneDrive Office Hours

Watch my 100+ courses on Pluralsight

Video Summary

  • New Sharing Experience: Microsoft announced a major update to the sharing experience in OneDrive and SharePoint, aiming to make sharing simpler, smarter, and more secure.
  • Hero Link: The introduction of the “Hero Link” allows users to manage file permissions with a single link, which can be updated without needing to resend it. This link can be customized for different access levels and is designed to streamline sharing.
  • Bulk Permissions: Users can now update permissions for multiple people at once, making it easier to manage access for large groups without repetitive steps.
  • Feedback Integration: Microsoft emphasized that this update is a result of extensive user feedback. They actively listen to customer suggestions and incorporate them into product improvements.
  • Training and Support: Ahead of the rollout, Microsoft plans to provide comprehensive training materials and documentation to ensure a smooth transition for users. They also host monthly OneDrive office hours for direct interaction with the product team.

For more information, read the transcript blog below, or watch the video above!

Transcript

We’re live from the Microsoft 365 Community Conference, where Microsoft just made an amazing announcement. They are improving, or completely, I wouldn’t say changing, but improving the way that sharing is done to make it easier and better. Microsoft did a blog post about it, but instead of reading the blog post, let’s deep dive into it together because this is so new. I’m joined by Principal PM at Microsoft, Stephen Rice. Thank you for being here.

“Yeah, thanks for having me, Vlad. I’m so excited to be here. This is really fun. I cannot wait for us to show this. I was lucky enough to see a preview at the MVP Summit, so now I cannot wait for everybody else to see it as well.”

“It’s actually better because at MVP, we showed you screenshots. I have live code that runs all of it, and it’s… Yeah, this is exciting. This will be… But I’m going to ask you questions. I’m going to ask you to interrupt me and like…”

“Perfect.”

“The only caution is, you know, this is… we’re still in development. There are still things not done. We’re… we’re in the railroad, you know, where if I go off track, things will go crazy.”

“I think everybody would rather see a live demo that breaks a bit than Figma.”

“It makes it… There’s nothing wrong with Figma.”

“There’s nothing wrong with Figma, but I think… but still…”

“So what can you tell us about the new sharing?”

“So to start with, we wanted to kind of address a lot of the feedback we’ve been hearing from customers for years about sharing in OneDrive and SharePoint, files and folders, things like that. Sharing… like I… so I’ve worked on this for… oh no, see now I’m going to feel old… like since 2015 or so.”

“Wow.”

“Yeah, so I was… my favorite stat, just as an aside, when I joined OneDrive and SharePoint, we had four admin settings for sharing.”

“That’s not a lot.”

“That’s not a lot. We have like 50 plus now, so the product has matured quite a bit since then. And this was an opportunity to address some of the core feedback. Like we’re making some changes here to sharing that like we’ve not touched some of this in like 15 plus years.”

“Wow.”

“So the goal is what you know, you saw at the MVP Summit. I like the rabbit-duck picture, you know, there’s the blue-gold dress kind of thing. Depending on your perspective, different people will approach it in different ways, but the goal is to make sharing simpler, smarter, and more secure.”

“Right. I… I’ve seen that before. Isn’t that how they talked about Teams in the keynote on the first day of the conference?”

“It is. I have… I see… I have to be… I have to be calm. Jeff said it. I can’t… I can’t go against Jeff.”

“You cannot go against Jeff.”

“But like…”

“No, Jeff doesn’t watch this, right?”

“Maybe he does.”

“Maybe he does.”

“We’ll find out.”

“We’ll find out if he yells at me. But so internally, this is what we call simple, smart, and secure sharing. So when Teams was up there, I was like, I sent a message in our team chat like, ‘Hey, I think they stole our name.’ But the… You also may see this referred to as the hero link sharing model.”

“Which I like the hero link a lot better.”

“I do as well. It’s… but I… I know why it’s called the hero link, but now you’re going to have to tell everybody why it’s the hero link.”

“Yes, so let’s… let’s dive into it. So I’ve got two users set up on my experience here. On the left is myself, Stephen. On the right is a co-worker, Cassie. So I’m going to run you through kind of the demo we did for the keynote session that Jason did on Wednesday, if I remember correctly. So let’s go through. So I’ve got this file. Step one, I need to share it with my co-worker, Nester. So as expected, click on share, click on share, and this is the brand new sharing experience that we are delivering as part of this update. There are a couple of different pieces to it. You’ve got the add people section there at the top. We’ve got an integrated managed access experience, which is the thing I’m really excited about. No longer do we have this separate share and manage access. It’s all in one place. So now you already see who has access. You can make informed decisions.”

“Awesome.”

“And then we have this file access setting. This is where the hero link lives. We’ll come back to that in just a moment. So I need to show Nester. So I’m going to come in here, select Nester. First change, as soon as you go into the add people flow, we go into this kind of focused experience. You’re writing an email, you want to get that message sent. You don’t need to worry about the rest of it now. So we bring you into that experience. First exciting feature that we brought in, you may remember there’s that checkbox in the old grant access experience when you want to, like choose whether to send an email notification or not. Now you can do that in the share experience.”

“I like it.”

“Super helpful. You know, if you have a new person join the team, you need to share a bunch of files with them. You don’t want to spam them with 20 emails.”

“No.”

“You just want them to have access and later email with everything in. Let them use Copilot, you know, to find everything.”

“Talking about Copilot, I see I had a file summary with Copilot. I think that’s already here today, right?”

“That exists today. Let’s see, let’s test myself. I believe, like two weeks ago,o we extended it to additional file types as well. We added support for encrypted documents, if you have a label on them, things like that. But yeah, we’re bringing it into this experience as well. This is one of those things, like you’ve got your dedicated Copilot chat experiences, and then we want to bring that kind of Copilot magic in line when it makes sense. In this case, you know, you can see it generates a nice summary of my documents.”

“I love it because nobody ever writes stuff in there. Now we can actually…”

“I always get an email, ‘Somebody shared a file with you.’ I don’t know why, nothing. I don’t know what a file is. Now I know, and it’s one click, you get the summary. So let’s just complete the flow. I add Nester. First thing I have to call out, Nester shows up in Manage Access in the integrated experience immediately. So, immediate confidence I shared with the right person.”

“No need to refresh.”

“No need to refresh. It’s just there. Second thing, we’ve added this kind of external tag here for your external users.”

“Nice.”

“Again, external users are where we see the most risk when it comes to sharing because you overshare content with an external user, that’s a much bigger issue. So we wanted to bring that front and center.”

“Awesome.”

“And then the next thing I want to show you is bulk updating permissions within this experience. So today, if I wanted to update Michaela and Ascend here to edit, I would click Michaela, edit, confirm, click Ascend, edit, confirm. Now select them both, can edit, confirm, and they’re done.”

“That’s cool.”

“Yeah, I love it.”

“So you can have that for remove permission, for whatever, bulk edit. Is there a limit, like 10 people or…”

“That’s a good question. There is probably a limit of about 10, something like that. But still, it’s way better than one at a time.”

“I love it.”

“And the type of thing where as we add it and people use it, like that’s, ‘Hey, is this used a lot? Great, more signal, let’s up that limit and keep going.'”

“Awesome.”

“Okay, so let’s get into the hero link.”

“Yes.”

“So this is what exists here at the bottom in this kind of file access settings. Each file, one hero link, one link for you to worry about.”

“No more 10 links for the same file.”

“Well, we’ll get there. But for your average use case, one link to worry about. Defaults to only people added to the file, so just this set of people that you can see here. Keeps your file nice and secure.”

“Kind of works like an admin.”

“Thank you. That’s something I think we’ve been asking you for since 2015, of having the default one be people that already have access at the tenant level.”

“You see, the story I actually like telling here is the reason… so let’s back up a little. There are three generations of sharing, this being the third.”

“Wow, okay.”

“I’m sketching.”

“Yeah, but generation one, direct permissions, advent of the cloud. I add Vlad to my file, you have access, you’re good to go. Number one problem people encountered is Vlad says, ‘I don’t know why I’m talking in third person for you, but that’s fine. I need Nester to have access.’ Forward the email to Nester, Nester gets access denied because of course.”

“Of course.”

“Generation two, we introduce sharing links, people in my organization links, anyone links, things like that. Now I send you a person in my org link, you need Nester to have it, forward it, and all works. The thing that has changed between generation two and now, and the reason we are excited about kind of going to this more locked-down default, is that Teams and Outlook both have integration with sharing. So if you now click forward, type in Nester, Outlook says, “Hey, Nester doesn’t have access to this file. Do you want to fix it?” None of that existed in 2015.

“No.”

“Okay, the ecosystem has matured around us, which lets us kind of get to this more advanced world. Now I’m going to share with Cassie. Now I’m going to quiz you. Does Cassie have access to this file, Vlad?”

“No.”

“Yeah, well, I’m a dumb end user. I shouldn’t say dumb. I am a miseducated end user. I’m working too quickly. I’m going to copy that link anyway and paste it here for Cassie, as you would expect. Quick aside, this page is also getting updated. It’s just not…”

“Are we going to get a sad ice cream cone or…”

“No, it’s a little bit better. We’re going to show it in the session. I don’t have the screenshot here. I’ll send it to you after this. But there’s… how should I put this? It does not look like it was built in 2004. It looks beautiful, modern, what is it, fluent design, whatever design language is. But Cassie no longer has access.”

“Yeah, sad.”

“The power of the hero link, I can update this file to people in my organization. It confirms, lets me know that I’m extending access. Now you will testify, the camera shows my hands, I’m not copying the link again. All I’m doing is refreshing Cassie’s session. And because I’ve updated the hero link, it just works right away. You don’t have to send a new link. It’s one link that you can update the permissions on.”

“That’s cool.”

“So now everybody who has the link can view, but the people above there can also edit.”

“Yep.”

“And it’s all the same link.”

“And it’s all the same link. You know what else is the same link? Say Cassie needs to send this to Zoe. Copying the address bar, which historically has not been a path to success in the ecosystem, sends it to Zoe, who has never accessed the file.”

“And so now you can copy the URL at the top.”

“Yep, that is… It’s all the hero link. One link. It’s flexible. Wherever you get the link, that’s what you get.”

“That’s something that everybody has asked for since forever, all the users.”

“So this… I love it. I’m so excited about it. All right, let’s dive back in here. Next thing you’ll see now that I’ve refreshed the experience… oh, you can see it’s open by two.”

“Yeah, this is new. You didn’t see this at the MVP Summit, did you, Vlad?”

“No, this is new.”

“So I can see the people who have access to the link. So I can still stay in control of my content. I know who’s using the link. If I see 20 people show up here, someone linked my link. Not great.”

“I’m going to ask you questions. Is it open forever, or is it open in the last x days or…”

“It’ll just show you if it was opened at some point. It doesn’t have that time.”

“Okay.”

“And then, of course, hero links giveth access and hero links taketh away access. So if I come back here, I lock the file back down. It lets me know, ‘Hey, this is going to restrict access for some people.’ And we’ll just refresh Cassie’s session over here, and we’re back to access denied. I’ve kept my document secure all in a single place.”

“The fact that it’s so instant.”

“I know, that’s one of my favorite parts.”

“This is amazing.”

“Okay, all right, let’s go to your… there’s one more thing for you today.”

“Nice.”

“You asked about additional links.”

“Yes.”

“So let’s say I’ve got this file. I want it fairly locked down. Maybe I want it for people in my organization, what it might be. But I do need to share it with people outside the company, say a marketing vendor. That is where the power of additional links comes in. And this is also our backwards compatibility story if you’re an existing customer. So this is really important before we do it. Nothing we have today breaks. It all works. So all the links we have today, everything still 100% works.”

“All 100% works.”

“Your hero links will all start from scratch, so you don’t have to worry about a file being opened up in a way you didn’t expect. All your existing links continue to work the way they do today.”

“That’s amazing.”

“Yeah, it just… everything we can do to try and make this change as manageable for you all as possible.”

“Is it something that’s going to remain forever, or is it more for backward… I mean, forever is always a big word to say, especially with…”

“Yeah, this is the mantra we’ve had, is simple by default, powerful on demand. The thing we saw for most people is that they create one link for a file. And then they get confused when multiple links get created if they manage these types of things. So that’s where the hero link comes in, which I call lowering the floor. One link per file. If you’re not thinking, don’t worry about it. There’s one link to manage. But there are cases where you need the full power of SharePoint.”

“Yes.”

“And that is where the kind of additional link functionality comes in. And so the first thing we did to really help highlight that is you can now name your links. So I need a link for my marketing partners. So maybe they’re an external vendor. I’ll make it an anyone link. I’ll give them, let’s say, view access. I’ll have it expire. I can set a password. This creates a separate URL, a separate link named that I can now manage and share individually. So if I send this link around to people, they will get the link. They get that kind of anonymous login experience. If I send the hero link around, it’s based on whoever else has access.”

“And then when I’m ready to revoke this link, I can just come in and revoke it. And that link’s lifetime is done. And so it really positions additional links, the kind of existing sharing links we have today, as a power user feature that they are. It gives you that granularity you want when you need it and not when you don’t.”

“I love that you also spend time improving the old experience with the name of the link. It’s a small feature, but it helps so much.”

“It’s one of those things where… I was trying to think of a good analogy, but like, you know, as soon as you name something, like you name a pet, like, oh, now you’re done. The pet is yours. Now you can name your link. It just… it gives it a purpose. It gives it a sense of like, this is why this exists. And also for you, six months later, when you’re like, ‘Why did I make this?’ Oh, it was for marketing people. Okay, you know what? I don’t work with them anymore. I know I made it. I can delete it.”

“Yep.”

“Whereas if you see it six months later, you’re like, ‘I don’t know why we had it. I’m not going to delete it just in case.”

“Yep, exactly.”

“And then, you know, goes without saying, but like all the existing eDiscovery compliance features that people have come to know and expect, all continue to work here. It’s all part of the ecosystem and good to go.”

“If we share with a group, are there any cool things about that? If I share with a security group or do I have a sec… let’s go to a SharePoint site.”

“I see my test site that I really need to update. You know, Relic Cloud, the like-new Contoso.”

“There cannot be a new Contoso.”

“I mean, there… sorry, the poor replacement for Contoso. I just hadn’t seen it, so I was like, ‘Oh, Relic.’ I assumed it was like Relic, and it’s like, ‘Oh, this is not right.’ But so I’ll show you in the context of like a SharePoint site, the visitors, members, and owners groups show up as well.”

“Nice.”

“Security groups would also show up. I don’t know if I have a security group.”

“Probably all companies.”

“Well, let’s see. This is a dev environment. We do have an all-company.”

“There you go. Sometimes, demo tenants are predictable.”

“Sometimes they are. So you’ll see those show up as well. We’ve got some other things we’re working around, like label improvements, experiences, and things like that. There are also some shared changes that we don’t have in the environment here. Let’s go back here. So, one of the things we’ll be adding is per file reshare controls. So are you familiar with members can share?”

“So members can share effects across an entire site.”

“Members can share but for a single file.”

“Nice.”

“So I can be secure by default, but if ever there are five files in my site that I need to, they can own it.”

“Yep.”

“They can have it.”

“Exactly.”

“Yes. So yeah, there’s a lot. This is the stop sharing command, which we continue to have if you need to, like, you know, turn a file back to private or whatever it might be. But yeah, this is the new experience coming. I guess I assume you want to know dates.”

“Because every…”

“Dates.”

“So right now we’re looking at kind of end of this calendar year, so Q4-ish. Blog, message center post, roadmap ID, all that good stuff. We’ll have more details as we get closer.”

“Awesome. Are we looking at public preview or GA?”

“We’re probably looking at GA is what it’s looking at right now.”

“So we might get a public preview towards Ignite then?”

“I would… I’m hoping so. Hoping so. We’ll see. We’ll see.”

“If you wanted… I mean, is this YouTube? I guess I should have asked ahead of time.”

“So yeah, let us know in the comments below, right? Like that’s engagement, right?”

“Exactly. Comments below. Tell us if you want a public preview.”

“Well, I think everybody wants a public preview. As an IT pro, I think I can say for… we like to test things before we roll it to the users and create training and things like that because it’s a lot easier.”

“But you still need to create training for it. Let’s talk about training. That’s one of the things we are committed to. So we’re recording this type of video. Our goal is to record more videos like this, not necessarily through you, but just in general.”

“Oh, you’re always welcome, by the way.”

“I might take you up on that. But we want to put as much IT training together and end-user training together, documentation ahead of release.”

“Cool.”

“So that all you can start to expect in Q3 is where we’re kind of roughly targeting. So ahead of the rollout, you’re not going to go at it blind. You’ll have as much information as we can give you, so you can make this transition successful because it’s a big change. We know it’s a big change, so we want to make sure you can land the train.”

“That is amazing. And having those will save companies so much time because they just have to fill in the blanks or the things that are more specific for them, instead of doing everything from scratch. So that is amazing.”

“From an IT pro perspective, are there any new tools, any new settings that we can use? So I see the default here already that only people added to the file can access it. That will be the default across SharePoint and OneDrive?”

“So that will be the default default.”

“Okay. I guess I’m so used to it being different.”

“So yeah, the default default setting is only people added, and then you’ll be able to choose on a per site collection basis if you want it to be people in your organization. So if you have, like your HR site or something like that, where it makes sense to have something a little bit more open, you’ll have the ability to set that up.”

“You said per site collection. Can I still change it at a tenant, or will it be per site?”

“Currently, the plan is for per site.”

“Okay.”

“Definitely listen for feedback if folks are interested in it for per tenant as well. From an oversharing point of view, I love it.”

“Yep.”

“Because too many people just open it up by default, and I’d rather it have locked down by default and then make it more permissive where it makes sense.”

“That’s how we talk about it internally. It is, you know, anytime you change a tenant-level setting, especially, you know, an organization of 20,000, 100,000 people, there’s always risk there. And so it’s finding the right balance there. If folks are interested in that tenant-level default, comments below.”

“Yeah, let me know. And any questions you have, by the way, write them down and I’ll email you all the questions that hopefully I’ll be able to answer some of them. But if not, I’ll email all of them to you, so I might spam you with…”

“Yeah, please do. I guess this will be interesting timing-wise. The next OneDrive office hours, which is the third Wednesday of every month, is also going to be a kind of M365 recap, and we’re going to talk about this as well. So, folks have questions and want to join that call, I’ll send them the link so they can come in and get ready with the questions.”

“Dude, I would love to have all kinds of questions for that.”

“Awesome.”

“One of my favorite meetings.”

“So, another question for you. When you had it open, you saw that two people opened the link and things like that. From an API point of view or a PowerShell point of view, are we going to have access to those statistics?”

“That’s a good question that I’m not sure on. I’ll actually have to get back to you on it.”

“That’s also a bit of a biased question because I work at Cesuit, so we have a lot of reports and things like that. And I’m sure, like, I’m joking around, but also admins have reports, things like that. They might want to get this information.”

“All the existing reporting will get updated for this as well. I know we’re working on updating like the Vroom and graph APIs, so if those are the ones you’re looking at, those should also be covered. I’ll have to double-check exactly which information is included for each.”

“Awesome.”

“But this is another place where if there’s information you’re looking for and it’s not there, just tell us.”

“Awesome.”

“And yeah, that’s the cool thing that we know is coming in December. There might still be a little bit of time to add some features in.”

“Might.”

“Active development, as you know, is evidenced by this page. I mean, this page has existed for a long time, but I just love that it already works. So like to see it live, it’s really cool.”

“I mean, and like for… so you were at the MVP Summit in March, right? End of March?”

“Yeah.”

“So this came together, like the work started obviously before then, but in March, we did not have a working end-to-end demo. And we had this function by the end of April. That’s when Jeff saw it for the first time and was super excited.”

“I bet.”

“And yeah, we’re looking forward to it. Like, it’s not an understatement, like the biggest change I think we made in sharing, like direct permissions.”

“You did mention that you had… You found some old code.”

“Yeah, yeah. I mean, this is… so to make this work, we had to touch code that was, you know, some of the core sharing permission model type stuff to enable the hero link, to enable that kind of like instant refresh, like you saw. But what I can say is that I love it.”

“Good.”

“I know that everybody who has seen it has loved it. So those are the kind of changes we need sometimes in M365. Sometimes the simple core stuff, I think Jeff calls it the core stuff, has such a bigger impact than the Copilot stuff we’re going to get in six months because that’s the stuff we do every day.”

“So you know, you mentioned Jeff talking about core changes versus kind of like Copilot fundamentals. This is a case where, like, you know, sometimes people will ask like, ‘Hey, does Microsoft listen to people’s feedback?’ Hopefully. I mean, I know people ask it, but about a year and a half ago-ish, we shipped our last iteration of the sharing experience, trying to simplify and address the feedback we were hearing. But it was a UX experience change. The model didn’t change like we’re doing here. It’s because people kept giving us that feedback that helped us justify, like, ‘Hey, we’re going to go touch really old code to make the experience better because we need that underlying change.’ So we do listen to feedback. Please send us the feedback through all the avenues, you know, whether it’s MVPs or showing up at a conference like this one, where 200 Microsoft people, 200 engineers and PMS, are at this conference. So this is a perfect one to come give them ideas.”

“Exactly.”

“And like we can’t always say like, ‘Hey, we’re going to work on it. You’ll see it tomorrow.’ But we look at all of the feedback, we aggregate it together to understand what the trends are, and then go and make the changes. And sometimes it takes maybe longer than you might like, but when you… There’s usually a good reason for that.”

“Like now you had to touch code.”

“Exactly.”

“And then you keep asking us, and it’s like, ‘No, this is important. Vlad bugged me like five times last week. We’re just going to go do it so Vlad stops talking to us.”

“So this is the way. So let me know. I’ll set up a flow. Whatever you bug me, I’ll forward it to him, and everything will get fixed in M365.”

“Just going to put a block on your account.”

“That’s the cool thing with MVP licenses. I can get a lot of domains now.”

“But I think this covers it. Thank you so much for the time. For everybody listening, again, if you have any questions, please put them in the comments below, and I’ll also put a link to the OneDrive office hours.”

“You guys do them monthly?”

“Monthly, third Wednesday. And it’s… yeah, I mean aka.ms/driveofficehours.”

“Well, that makes it easy. So this way, if you have any questions, whenever you see the video, whether it’s this month or two months away from now, you know you have a time where you can go and ask questions directly to the product team.”

“And you were the first product team that did that in the M365 space, I think.”

“I think Stream technically did it first, although…”

“Rest in peace, Stream.”

“But they’re not there anymore, so it’s okay. But yeah, it’s one of my favorite meetings every month, honestly, I love talking to people.”

“Thank you so much for taking the time.”

“Yeah, thanks for having me. And for everybody, please go follow Stephen. I’ll have all his details in the description below. And don’t forget to subscribe to the channel to get more awesome videos such as this one. See you next time.”

Blogs and Videos