External user can't open a shared file: permissions and link fixes
For anyone who shared a file with someone at another company and got back "I can't open it." This runbook walks you through the fastest checks first: wrong account, expired or restricted link, blocked file type, and company security settings that stop external access.
TL;DR — If someone at another company cannot open a file you shared, the most common cause is that the share is restricted to specific people or to people inside your organization, and the recipient is signed into the wrong account. Start by opening the file's sharing settings, switch the link to allow the intended external recipient, and resend it to the exact email address they will use. Reading time: ~6 min
The scenario
It is a normal Tuesday afternoon: you send a file to a client contact, vendor, or partner, and five minutes later they reply with a screenshot that says they do not have access. You can open the file yourself, your teammates can open it, and the link looked fine when you copied it. The other person says they clicked the same link on both desktop and phone and still hit a wall. Now you need to work out whether the problem is the link, the recipient's account, the file itself, or your company's external-sharing policy.
Symptoms
- The recipient sees one of these messages:
- "You need access"
- "Access denied"
- "You don't have permission to view this file"
- "This link has expired"
- "This item might not exist or is no longer available"
- "Sign in with a different account"
- "Your organization blocks access to this content"
- The link opens for you, but not for the external person.
- Internal coworkers can open the file; people outside your company cannot.
- The recipient can open other shared files from you, but not this one.
- The recipient says the link opens a login page, then returns them to an access error.
- The file downloads for some people but is blocked on a company-managed laptop with a browser or security warning.
Likely causes
| Cause | How common | Quick check |
|---|---|---|
| Share is limited to internal users or specific people only | Very common | Open the file and click Share or Manage access; if it says "Only people in your organization" or lists different recipients, this is likely it |
| Recipient is signed into the wrong email/account | Very common | Ask them to open the link in a private/incognito window and sign in with the exact email address you shared to |
| Link expired, was revoked, or the file was moved/deleted | Common | Open the original file and copy a fresh link from Share; if the old link no longer appears in sharing settings, it was changed or revoked |
| External sharing is blocked by your company's admin policy | Common | In the file's sharing dialog, try adding the external email; if the UI refuses it or shows a policy warning, this is the cause |
| File type or download is blocked by the recipient's company security tools | Sometimes | Ask the recipient to try from a personal device/network or check whether the browser shows a download/security block message |
| Password-protected or encrypted file was shared without the password or required app | Less common | Try opening the exact file from a different browser/device yourself; if it prompts for a password or a desktop app, send those details separately |
Step-by-step diagnosis
-
Confirm the exact recipient email address you intended to share with.
- Menu path: open your email or chat where you sent the file, then compare that address with the address shown in the file's Share or Manage access panel.
- This is your problem if the file is shared to
alex@partnerco.combut the person is trying withalex@subsidiary.partnerco.com, a personal address, or a different alias. - Jump to Fixes → Share is limited to internal users or specific people only.
-
Check the file's current sharing scope.
- Menu path: open the file → Share or Manage access.
- Look for wording like
Restricted,Only people in your organization,Specific people, orAnyone with the link. - This is your problem if external access is not allowed by the current setting, or the listed people do not include the recipient.
- Jump to Fixes → Share is limited to internal users or specific people only.
-
Rule out the wrong signed-in account.
- Ask the recipient to do this exact test: open a private/incognito browser window, paste the link, and sign in with the exact email address you shared to.
- This is your problem if the link works in private/incognito or after switching accounts.
- Jump to Fixes → Recipient is signed into the wrong email/account.
-
Generate a fresh link and test it.
- Menu path: open the file → Share → Copy link or Create link.
- Send the fresh link to the recipient instead of forwarding an old email thread.
- This is your problem if the new link works but the old one does not, or if the old link no longer appears in the file's access list.
- Jump to Fixes → Link expired, was revoked, or the file was moved/deleted.
-
Try adding the external recipient again from the sharing dialog.
- Menu path: open the file → Share → enter the external email address.
- This is your problem if the UI shows a warning such as
External sharing is disabled,Your organization does not allow sharing with this domain, or it refuses to save the recipient. - Jump to Fixes → External sharing is blocked by your company's admin policy.
-
Check whether the issue is the file type or the recipient's device security.
- Ask the recipient what they see exactly: browser warning, download blocked, antivirus alert, or "file type not allowed." Ask them to try another browser or a non-managed device if their company policy allows it.
- This is your problem if the link opens but the download or file open action is blocked only on their company device.
- Jump to Fixes → File type or download is blocked by the recipient's company security tools.
-
Check whether the file itself needs a password or a desktop app.
- Try opening the same file yourself from a different browser or device.
- This is your problem if you are prompted for a password, certificate, or a specific desktop application to open the file.
- Jump to Fixes → Password-protected or encrypted file was shared without the password or required app.
Fixes
Share is limited to internal users or specific people only
Open the file and update the share settings.
- Menu path: Open file → Share / Manage access.
- Change the access level from
RestrictedorOnly people in your organizationto the least-open option that still fits your need:Specific peopleand add the recipient's exact email address, orAnyone with the linkif your company allows it and the file is not sensitive.
- If there is a permission choice, select
Viewerunless they truly need edit access. - Click Send or Copy link, then resend the new link.
If your tool supports domain-restricted sharing, add the partner's domain exactly as provided by your admin or contract contact.
Verify it worked: ask the recipient to open the newly sent link in a private/incognito window and confirm they can see the file without requesting access.
Recipient is signed into the wrong email/account
Ask the recipient to switch accounts before opening the link.
Send them these steps:
1. Open a private/incognito window.
2. Paste the file link.
3. When prompted, sign in with this exact email address: you@their-company.com
4. If it still opens the wrong account, sign out of all accounts in that browser and try again.
If they use a browser profile for work and another for personal use, ask them to try the work profile only.
Verify it worked: they can open the file after signing in with the exact address you shared to, without seeing "Sign in with a different account."
Link expired, was revoked, or the file was moved/deleted
Create a fresh share link from the current file location.
- Menu path: Open the file from its current folder/location → Share → Copy link / Create link.
- Do not reuse a forwarded link from an old email or chat.
- If the file was moved, rename-confirm it by opening it first, then sharing from there.
- If the file was deleted or is in trash/recycle bin, restore it first in your storage provider's dashboard, then share again.
⚠️ If you restore or move a file in a shared team folder, other people may briefly lose access or see duplicate versions. If the file is actively being used, warn the team first.
Verify it worked: the fresh link opens the correct file for the recipient, and the old error This link has expired or item might not exist is gone.
External sharing is blocked by your company's admin policy
If the sharing dialog blocks external addresses, this is not something you can usually fix from the file itself.
Do this first:
- Capture the exact warning text from the sharing dialog.
- Check your provider's admin or security dashboard if you have access. Common places are:
- your provider's dashboard (for example: Admin/Organization settings → Sharing)
- your identity provider (sign-in system) under Applications → File storage app → Sharing / External collaboration
- If you are not an admin, send your IT/admin team a short request like this:
Please allow external sharing for this file or for recipient domain partnerco.com.
File: [paste file name or URL]
Recipient: alex@partnerco.com
Business need: client review by [date]
Current error: [paste exact warning text]
Preferred access: view-only, specific people only
If policy cannot be changed, use an approved alternative such as a customer portal, secure file transfer tool, or password-protected ZIP shared through your company's approved channel.
Verify it worked: the admin policy allows the external email or domain, and you can add the recipient in the file's sharing dialog without an error.
File type or download is blocked by the recipient's company security tools
This usually happens with executables, scripts, macro-enabled documents, archives, or uncommon file extensions.
Try one of these safer alternatives:
- Export the file to a standard format such as PDF or CSV from the app's File → Export / Download as menu.
- Put the file into a password-protected ZIP if your company policy allows it, and send the password in a separate channel.
- Share a view-only online version instead of a download.
If you need to send a ZIP from your computer, use your normal desktop tool. If you have command-line access, this is the generic format:
zip -e deliverable.zip original-file.ext
Then send the password by phone or separate chat, not in the same email.
Verify it worked: the recipient can download or view the converted file without their browser or endpoint security (device protection software) blocking it.
Password-protected or encrypted file was shared without the password or required app
If the file itself needs extra steps, send those steps explicitly.
Send a note like this with the link:
Open the file in Microsoft Excel desktop app, not browser preview.
Password: [send separately]
If prompted to choose an app, select Adobe Acrobat / Excel / Word as appropriate.
If the file was encrypted by mistake, create a non-encrypted copy from the original app and share that version instead, if your data-handling policy allows it.
Verify it worked: the recipient can open the file after using the correct app or password, with no further access prompt.
Prevention
- Use "specific people" shares with the exact external email, not broad old links. This avoids the wrong-person and wrong-account problem. Before sending, re-open Share / Manage access and confirm the recipient list matches the email thread.
- Add a pre-send check to your team process: open the link in a private/incognito window before sending it externally. Use this copy-paste checklist in your ticket or handoff:
External file share checklist:
[ ] Opened link in private/incognito window
[ ] Confirmed recipient email in Share settings
[ ] Set permission to Viewer unless edit is required
[ ] Confirmed link is not expired
[ ] Sent any password in a separate channel
- Prefer standard export formats for external recipients. For client review, export to PDF or CSV instead of sending native project files, macro-enabled spreadsheets, or uncommon formats.
- Ask your admin to allow domain-based external sharing for frequent partners. If you regularly work with one client domain, request a policy entry for that domain instead of one-off exceptions. Keep the request template handy:
Request: allow view-only external sharing to domain partnerco.com
Reason: recurring client reviews
Scope: specific people only, no public links
Owner: your-team@your-company.com
- Keep a backup delivery path for urgent deadlines. Document one approved fallback such as a customer portal, secure transfer service, or password-protected ZIP so you are not inventing a workaround under pressure.
- Log exact error text in the ticket. Ask the recipient for a screenshot or the full message, not "it doesn't work." Messages like
Sign in with a different account,link expired, andorganization blocks accesspoint to different fixes immediately.
This article was written by an AI system and published pending human review. Verify anything you intend to act on.
Have a project in mind?
Get an instant AI price estimate for it, or talk directly to our team.
One email a month on what we learn building with AI