4.3 · OneDrive, SharePoint & Teams (admin side)

Level 4 · Expert: cloud & Microsoft 365 administration

4.3OneDrive, SharePoint & Teams (admin side)

Objective: understand how OneDrive, SharePoint and Teams fit together, and administer their sharing and access with care.
Estimated time: 12 min

Three Microsoft 365 services handle collaboration and storage, and they are deeply connected. OneDrive is personal cloud storage — a user's own files, private until shared. SharePoint is shared, organization-level storage and an intranet — team document libraries, sites, news. Teams is the collaboration hub — chat, calls, meetings — and, importantly, it is not a separate store: Teams keeps its channel files in SharePoint and links personal files to OneDrive. So the three are really one connected system: chat and meet in Teams, on files that live in SharePoint or OneDrive.

For an administrator, the job is to configure and, above all, secure sharing and access. Because these tools make sharing effortless — internal links, external guests, whole-team libraries — the risk is over-sharing sensitive data. Apply the familiar discipline: least privilege, group-based access, and thoughtful external-sharing settings. A new Team automatically creates a linked SharePoint site and a group, so understanding that plumbing helps you reason about where files actually live and who can reach them. Set sensible defaults, review access periodically, and remember that convenience and confidentiality must be balanced. Handle sharing carelessly and a private folder becomes company-wide, or worse, public; handle it with care and these tools become a safe, powerful collaboration platform.

Section vocabulary

OneDrive
Personal cloud storage for a user's own files, private until shared.
SharePoint
Shared organization-level storage, document libraries and intranet sites.
Teams
The collaboration hub (chat, calls, meetings) that stores files in SharePoint and OneDrive.
Linked site/group
Creating a Team automatically creates a SharePoint site and a group behind it.
External sharing
Settings that control whether and how files can be shared with guests outside the organization.
Check your understanding

What is the logic of OneDrive, SharePoint and Teams?

Tutorial 4.3
Tutorials: « 4.3 » OneDrive SharePoint Teams explained work together (search)
Click to see up-to-date results ↗

In practice — Reason about where files live

  1. For a personal draft, a team library and a chat attachment, say whether it lives in OneDrive or SharePoint.
  2. Explain what is created behind the scenes when a new Team is made.
  3. Describe how you would apply least privilege to a SharePoint document library.
  4. Decide a sensible default for external (guest) sharing and justify it.
You can explain how OneDrive, SharePoint and Teams interconnect and administer their access with least privilege in mind.

Key takeaways

  • OneDrive = personal storage; SharePoint = shared storage/intranet; Teams = collaboration on top of both.
  • Teams isn't a separate store — its files live in SharePoint and OneDrive.
  • A new Team auto-creates a linked SharePoint site and group.
  • Secure sharing with least privilege and careful external-sharing settings — convenience must not override confidentiality.

Frequently asked questions

If Teams stores files in SharePoint, why do people find it so confusing?

Because the storage is hidden behind the chat experience. Users drop a file into a Teams channel and think of it as « in Teams », when it actually lives in the SharePoint site that was created with that Team; a file shared in a private chat lives in the sender's OneDrive instead. The collaboration layer and the storage layer are the same data seen through different windows. For an administrator this is clarifying rather than confusing: once you know channel files are SharePoint and chat files are OneDrive, you know exactly where to set permissions, apply retention, or investigate access. Explaining this plumbing to users also helps them share more deliberately.

What is the main risk with these tools, and how do I manage it?

Over-sharing. Sharing is a click away — internal links, guest access, whole-team libraries — so sensitive files can quietly spread far wider than intended, sometimes to external guests or broad internal audiences. Manage it with the same principles as file shares: least privilege (grant only needed access), group-based permissions, and deliberate external-sharing settings rather than wide-open defaults. Review who has access to important libraries periodically, and set organization defaults that lean toward caution. Data-handling obligations can also differ by jurisdiction, so align external sharing with the rules that apply to you. The goal is to keep collaboration frictionless while ensuring confidential material stays with the people who should see it.

More resources