Most organisations have realised that email is not always the best place for external collaboration. It’s familiar, quick, and easy to use, but when you’re exchanging sensitive or confidential information while working with lawyers, advisers or investors, the question is whether that data can be controlled.
Tools like Outlook can be secure when managed well, but email habits are ingrained and can be harder to control outside of the business. Attachments get forwarded, versions multiply and confidential documents sit in shared inboxes. For legal matters, funding rounds, acquisitions, due diligence, board discussions or investor conversations, this results in some pretty significant risk.
This is exactly why more and more businesses are moving this type of work into tools like Microsoft Teams and SharePoint. Used properly, they can give you a cleaner, more structured way to work with external parties. The good news is they’re built for collaboration. The less-good news is that collaboration needs rules around files, external participants, governance and data retention.
The risks of external collaboration
Teams has become the go-to place for meetings, project conversations and file sharing. That makes sense for businesses trying to move away from sensitive information being passed around by email.
But as more and more external work begins to shift into Teams, the amount of business data within it grows quickly. And it’s not just text we need to be thinking about, either. As Rachael Heade, Director of Records Compliance for Microsoft Corporate, External, and Legal Affairs, says: “We tend to think of the recordings we make during meetings as an individual’s data, but they actually represent the company’s data.”
Meeting content, deal discussions, transcripts and shared files all become part of the organisation’s record. Every chat, file, and shared link adds yet another level of risk.
One of the most pressing questions is what happens after the meeting ends. External participants may still have access to the meeting chat, shared content and participant information. Sometimes that access is useful because the work is still active. At other times, it quickly becomes unnecessary.
Microsoft Teams chats and channel messages remain available by default. People forget to handle it after the fact; projects move on, and staff change. And so what starts as a neat collaboration space can very easily become a messy archive of information some users really shouldn’t have access to.
Of course, this escalates into a compliance issue. The simple answer is to set up policies that automatically delete data after the meeting ends. Yet some information cannot be deleted too quickly because it may need to be retained for legal, regulatory, contractual, or internal policy reasons.
At the same time, keeping everything forever is not the answer. Under regulations like GDPR, for example, organisations are expected to keep personal data for no longer than is strictly necessary, so organisations need to have an understanding of what they are holding onto and why.
This means Teams and SharePoint need to be managed as business systems, not simply as communication software. If a business is using these tools to collaborate with lawyers, consultants, investors and other external parties, there needs to be a clear plan. Who can access what? How is access approved? How long should information be retained? What should be removed altogether?
Optimising your environment
The aim is to build a Microsoft environment where people can work efficiently without adding risk.
Retention policies are a key part of that, with Microsoft offering options for retaining and/or deleting Teams chats and channel messages, including shared channels. They can also preserve important content for a required period, even if a user tries to delete it. In practice, this gives businesses much more control over what happens to information once it has been created, and after a meeting ends.
There are three main options:
- A retain-only policy keeps content forever or for a defined period
- A delete-only policy removes content after a specified period
- A retain-and-delete policy keeps content for a set time, then removes it when that period ends
The right approach depends on the work and its level of risk. For example, an informal project chat with an external consultant may not need to be kept for years. A deal room containing due diligence documents, legal advice, investor discussions, signed agreements and board-level decisions, however, is very different. That information could be needed for eDiscovery, dispute handling, audit evidence or regulatory review. You may find yourself using a mix of all three options.
External users also need to be invited properly. Best practice is to add external collaborators to Microsoft Entra ID as guest users. This gives the organisation a clear identity record, rather than treating them as an anonymous contact with a link. It allows internal policies to extend to external participants, as Microsoft 365 retention and compliance controls rely on identity attributes to apply governance rules. Once added as guests, external users can be managed under the same framework as internal staff, with consistent control over access, retention and data handling.
Finding the right balance
Microsoft Teams and SharePoint are designed to make collaboration easier. They help people meet, share, review, decide, and move work forward, without relying on endless email chains and the risks associated with them. However, these tools being easier doesn’t automatically mean they’re safer.
There are a number of concerns here. External users can keep access for longer than they should. Sensitive documents can be shared too widely. Meeting chats can become unmanaged records. Retention can rely on individual habits rather than established business policy.
Of course, none of this means that Teams and SharePoint are the wrong choice. It just means that these tools need to be set up, configured, and optimised around the business’s regulatory needs and ways of working.
Here at Reliable, we help businesses get that balance right. We work with organisations to optimise their Microsoft environments so that Teams, SharePoint, OneDrive, Entra ID, and retention policies are all there to fully support secure collaboration rather than creating extra uncertainty and risk.Â

