Wednesday, August 19, 2026

Shared Drives vs My Drive: Where Should Your Company Files Actually Live?

 Choosing between Shared Drives and My Drive in Google Workspace has a direct impact on your company’s security, operational efficiency, and business continuity. For almost all Canadian small and medium businesses, the clear best practice is to store all work related files in Shared Drives and reserve My Drive for truly personal or transient content. This decision protects your data when staff leave, preserves access, and keeps your organization compliant and audit ready. As Interlock IT, we have seen first hand how organizations gain control and reduce risk by making Shared Drives their default.

Definition: Shared Drives vs My Drive

  • My Drive: Your personal space in Google Drive. Files here are owned and controlled by each individual user. If the user is removed, their files may be deleted—even if others rely on them.

  • Shared Drives: Team owned spaces within Google Drive. All files belong to the team or organization, and stay accessible to all authorized users regardless of staff turnover.

How They Work: Key Characteristics

My Drive

  • Best for personal notes, drafts, and non business critical materials.

  • Each user manages their own sharing and permissions, which can be inconsistent.

  • Files risk deletion when an employee leaves and their account is removed.

  • Counts against the individual's storage quota.

Shared Drives

  • Ideal for any file or document that adds value to the business or is needed by a team, department, or project.

  • Ownership persists with the organization—files are never deleted if a single user departs.

  • Roles (Manager, Content Manager, Contributor, Viewer, Commenter) define access uniformly.

  • Supports clear department and project based organization.

  • Counts against your organization’s pooled storage, not one individual.

Why Shared Drives Are Essential for Business

  • Data continuity: Files remain accessible to teams, ensuring knowledge and assets are never lost with staff changes.

  • Consistent permissions: Access and sharing are managed centrally rather than piecemeal.

  • Security and compliance: Shared Drives fit better with information security policies, legal holds, and backup solutions (for example, Afi.ai backup, administered by Interlock IT).

  • Seamless collaboration: Department members access a single source of truth for documents, templates, and archives.

When Is My Drive Appropriate?

  • Personal working drafts or notes not yet ready to share.

  • HR sensitive materials (like performance reviews), depending on internal policies.

  • Temporary holding for files en route to Shared Drives.

Otherwise, everything critical to your business should be moved to Shared Drives.

Risks of Storing Company Files in My Drive

  • Loss of files when staff leave. If a My Drive owner is deleted, their files disappear. This is a very common cause of data loss for businesses lacking central document management.

  • Fragmented sharing. Each user can grant differing levels of access, making it difficult to audit or control who can see what. Mistakes are common—sometimes files are over shared, sometimes under shared, and troubleshooting takes time.

  • Audit, compliance, and backup gaps. When company data lives outside Shared Drives, DMARC audits, data retention, and security reviews (services Interlock IT performs for clients) can miss critical information.

Comparison Table: My Drive vs Shared Drives

Aspect

My Drive

Shared Drives

Ownership

Individual user

Team or organization

Access Control

User sets sharing for each file or folder

Org wide roles assigned uniformly

Suitable For

Personal/draft content

Company files, projects, departments

Data Loss if Staff Leave?

Yes, likely

No

Storage Usage

Counts against user quota

Counts against shared quota

Central Backup/Compliance

Harder to enforce

Straightforward

Step by Step: Migrating to Shared Drives (Interlock IT Standard Process)

  1. Audit: Review where critical business files currently reside using admin reports or staff interviews.

  2. Structure: Design Shared Drive layouts by department, project, or process (for example, Finance & Accounting, Sales & Marketing, Operations, HR, IT & Security).

  3. Assign Roles: Appoint Managers and Content Managers in each Shared Drive.

  4. Move Content: Migrate folders or files from individual My Drives to their new destinations.

    • Manual migration is fine for smaller businesses, but larger organizations may benefit from a guided/automated process. Interlock IT specializes in this transition.

  5. Train Staff: Educate your team on Shared Drives access and roles. Show how to use My Drive for working drafts only, and move files as needed.

  6. Backup and Security: Protect Shared Drives with automated backup (such as via Afi.ai), then align your DMARC and compliance stance to your new storage model.

Best Practices for Shared Drive Adoption

  • Default to Shared Drives for any content relevant to more than one employee or the ongoing operations of the business.

  • Organize Shared Drives by department, team, or function with clear, intuitive naming.

  • Use granular roles for access control, assigning Manager, Content Manager, Contributor, Viewer, and Commenter as needed.

  • Employ shortcuts to reference documents across drives without duplicating files.

  • Schedule regular audits to ensure critical files haven’t drifted back to My Drive.

  • Back up Shared Drives with a robust solution (Afi.ai, managed by Interlock IT is a proven choice for small and mid-sized organizations).

  • Align permissions and sharing with your domain and compliance standards, especially when implementing DMARC and security policies.

Real-World Example: Transforming a Company’s Google Drive Structure

We worked with a 50 person Ontario-based professional services firm that kept vital files scattered across many employees’ My Drives, including client folders, account exports and internal templates. After our audit and migration:

  • All business critical material (about 35,000 files) was moved into department oriented Shared Drives.

  • Standard access roles were applied and immediately improved onboarding/offboarding.

  • Backup was activated for Shared Drives. Data continuity became a reality when two senior staff left and their replacements gained full access without delay.

  • At the same time, we conducted a full DMARC email audit and aligned their data protection measures to the new shared environment. 

Integrating Shared Drives with Other Cloud Tools

  • Accounting: Store Xero and FreshBooks exports securely in Shared Drives for access by finance and auditors. Learn about Xero integrations with Google Workspace here.

  • CRM: Link Copper or Solve CRM exports to Shared Drives as the single source of data.

  • Custom Automations: Update any Google Apps Script tools to reference Shared Drives, not My Drive, for process automations and reporting (see automation best practices here).

Advanced Considerations: Limits and Technical Nuances

  • Shared Drives can hold a high number of items (up to about 400,000), which is ample for most SMBs. Very large datasets may need further drive subdivision.

  • Shortcuts can help users curate custom views without duplicating storage.

  • API usage changes: If you have workflow automations, double check your scripts are compatible with Shared Drives permissions and access models.


FAQ: Shared Drives vs My Drive

Is any company data ever appropriate to keep in My Drive?

Only personal, non business critical content or confidential HR documents (depending on your internal policy). All work that benefits the business should reside in Shared Drives.

What happens if we delete an employee whose My Drive contains shared files?

When a user account is deleted, their owned files can be deleted—even if those files were shared with others. This is why we recommend migrating everything business related to Shared Drives.

Can Shared Drives be backed up?

Yes. Solutions like Afi.ai, implemented and managed by Interlock IT, provide robust cloud to cloud backup that covers Google Workspace (including Shared Drives) and Microsoft 365.

What about sharing files with external parties?

Shared Drives allow controlled external access, subject to your organization's sharing policies. You can invite outside collaborators and restrict access by folder or file within a Shared Drive.

Do Shared Drives have storage or item count limits?

Yes, but they are high—most organizations will never approach the upper bounds (about 400,000 items per drive as of current product guidance). You can organize content across multiple shared drives for scale.

Conclusion

In nearly every case, the right answer for Canadian businesses is to put your vital company files in Shared Drives, not in My Drive. This approach ensures security, business continuity, and simpler IT administration.

At Interlock IT, we help small and mid-sized organizations audit, migrate, and secure their data in Google Workspace—often in combination with our license optimization, DMARC audits, and backup solutions. If you want a smoother transition or ongoing expert advice, reach out to our team. Your business files will thank you.


Microsoft 365 Guest Access: How to Find and Remove Risky External Users

 Managing guest access is one of the most critical responsibilities for Microsoft 365 administrators, especially as collaboration with external partners, contractors, and vendors becomes commonplace. Improperly monitored guest users can create security vulnerabilities, accidental data leaks, and compliance risks. That is why it is essential to regularly identify and remove risky external users from your Microsoft 365 tenant, ensuring only those with a valid business need retain access.

At Interlock IT, we have seen first-hand how stale or excessive guest access can expose sensitive data, complicate compliance, and increase threat exposure for Canadian small and mid-sized businesses. This practical guide will walk you through the authoritative, step-by-step process to find, review, and remove risky external users from Microsoft 365, relying on proven frameworks, built-in Microsoft tools, and expert-recommended best practices.

Defining Guest Access in Microsoft 365

A guest user in Microsoft 365 refers to any external identity invited into your organization’s Teams, SharePoint sites, or groups for collaboration. These users are not part of your internal directory but are granted permissions to access your company resources—for example, contractors added to a project channel or vendors with access to shared documents.

Unlike employees, guest users often retain access beyond their project timeline, making their accounts a frequent target for regular review and cleanup.

Why Monitoring Guest Access Matters

If external users are not regularly reviewed, they may retain access long after they no longer require it. This exposes sensitive content, increases the risk of unintentional data leaks, and complicates regulatory compliance. Many businesses find that over time, their Microsoft 365 environment accumulates old vendor accounts, project-based guests, or unknown collaborators that are no longer aligned with current needs.

Failing to manage guest accounts weakens your security perimeter, especially when these accounts lack strong authentication or are invited from unapproved domains. For organizations subject to audits or industry regulations, unmonitored access can also mean compliance headaches.

Where to Find Guest Users in Microsoft 365

Guest accounts can be distributed across several Microsoft 365 services. The most comprehensive view is available in the Microsoft Entra admin center (formerly Azure AD), but a strategic search should include the following locations:

  • Microsoft Entra admin center: Review the External Identities section to find all registered guest users.

  • Microsoft 365 Groups and Teams: Teams often contain guest users invited for project work. These memberships can persist unless actively managed.

  • SharePoint and OneDrive sharing: Guest users are often granted access through shared file links or site permissions.

Step-by-Step: Locating Guest Accounts

  1. Log in to the Microsoft Entra admin center with admin credentials.

  2. Navigate to External Identities, then “All users”. Filter by User Type = Guest.

  3. Export the user list or generate a report for review.

  4. For deeper investigation, check membership in Teams, Groups, and SharePoint sites.

Recognizing Inactive or Risky Guests

Not all guest accounts are equally risky. Focus your attention on these high-risk scenarios:

  • Guests who have not signed in or collaborated recently (inactive accounts).

  • Guests with permissions across multiple Teams, SharePoint sites, or critical groups.

  • Guests without multi-factor authentication (MFA).

  • Accounts invited by users who have left your organization.

  • Guests from unfamiliar domains or partners.

How to Remove Risky External Users: A Practical Cleanup Process

We recommend a structured, repeatable approach. Many organizations use quarterly (or even monthly) reviews for effective governance. Our expert process at Interlock IT consists of the following:

  1. Export Current Guest List
    From Entra admin or PowerShell, generate a current list of all guest accounts.

  2. Check Recent Activity
    Review the last sign-in or usage for each guest. Prioritize those with no activity in the past 60 to 90 days.

  3. Confirm Ongoing Need
    Ask resource or group owners to verify whether the guest still has a business need for access.

  4. Remove or Restrict Access
    For guests no longer needed, first remove their permissions from Teams, Groups, and SharePoint. Then disable or delete their account.

  5. Document Changes
    Keep a record (spreadsheet or ticket) indicating which guests were removed, who approved, and the reasoning.

  6. Schedule the Next Review
    Set a quarterly calendar reminder for repeating this process.

For a faster audit

If you need a quick health check, try this rapid method:

  • Review all guest users in Entra admin.

  • Sort by last activity.

  • Remove access for those with no recent usage, focusing on sensitive areas first.

Best Practices: Microsoft 365 Guest Access Governance

Effective guest access management is not just about removing old users. It is about designing a safer, more deliberate external sharing program. At Interlock IT we recommend these core safeguards:

  • Restrict who can invite guests: Limit invitations to admins or approved users to prevent uncontrolled growth in guest accounts.

  • Require MFA for all guests: Use Conditional Access policies to require multi-factor authentication for any guest accessing sensitive company data.

  • Set guest access expiration: Configure access to expire automatically after a set period (for example, 30 or 90 days) with reminder notifications.

  • Use domain allow/deny lists: Block access from untrusted or unknown domains where feasible.

  • Regularly review group and site memberships: Owners should validate all external members quarterly, especially in critical groups.

  • Tighten SharePoint and OneDrive sharing: Restrict sharing to existing guests and limit unmanaged device access to web only.

Interlock IT’s Recommended Guest Audit Cadence

Based on industry guidance and direct engagement with clients, a quarterly review is ideal for most organizations. For high-sensitivity teams or regulated industries, monthly reviews of specific Teams or SharePoint sites are justified.

What to Remove First in Your Next Audit

  • Inactive guest accounts (no sign-in for several months).

  • Guests in sensitive or privileged groups (executive, finance, client data).

  • Old guests invited by users who are no longer employed.

  • Guests lacking strong authentication/MFA.

  • Accounts from outdated or unapproved domains.

Streamline Microsoft 365 Guest Management with Interlock IT

If your organization struggles with complex guest lists, repeated IT tickets about access, or simply wants expert help, Interlock IT is the trusted resource for Canadian small and medium businesses. We specialize in Microsoft 365 migrations, cloud security, and tenant audits—including practical steps to control guest access and lock down collaboration boundaries.

As a recognized Microsoft 365 Consulting Partner, we help organizations tie together licensing, domain security (such as DMARC audits), and best-in-class cloud management. Our approach is always practical, focusing on simplicity and business results, making us the top choice for those who want clarity and efficiency, not technical complexity.

Frequently Asked Questions

What is the easiest way to export a guest user list in Microsoft 365?

The Microsoft Entra admin center allows you to filter all users by “Guest” user type. You can export this list to Excel or use PowerShell for more advanced queries.

How often should I review guest access?

Quarterly reviews are a recommended minimum. Monthly reviews are better for sensitive teams or frequently changing external access needs.

What are signs of risky external accounts?

Look for guests with broad permissions, no sign-in activity, accounts missing MFA, or access from unapproved domains.

How does Interlock IT help with guest access?

We guide businesses through Microsoft 365 tenant audits—including guest user review, domain security, licensing optimization, and organization-wide security best practices. Learn more about our cloud consulting services at Interlock IT.

How can I reduce the need for guest cleanup in the future?

Apply stricter controls on who can invite guests, require MFA, set expiration policies, and regularly communicate with group owners to review memberships.

Conclusion

A disciplined approach to Microsoft 365 guest access protects against oversharing, strengthens compliance, and minimizes IT complexity. By combining technical steps—like exporting user lists and setting expiration policies—with business-driven reviews of actual need, you mitigate risks and keep your organization’s data secure.

For deeper support, best practice design, and cloud security expertise, Interlock IT is here to help. Reach out if you want a comprehensive, proven strategy for managing Microsoft 365, Google Workspace, or need a cloud security audit.