FILE SHARING · ORGANIZED & SAFE
Cloud File Sharing & Access Setup
Shared drives your team can actually navigate — permissions by group, version history for every “I overwrote it” moment, and rollback if ransomware ever hits.
We set up cloud file sharing that works the way your business does: shared drives organized by team, permissions granted to groups instead of person-by-person, and version history that rescues any file someone overwrites. If ransomware ever encrypts your files, we roll everything back to the hour before it hit.
It’s for businesses with 1–50 employees still emailing attachments back and forth or nursing an aging office file server. Set up remotely at a flat rate, no contract — including moving everything off the old server without losing a folder.
What we set up
Group-Based Permissions
Access follows teams, not individuals — new hires get the right folders on day one, and one change updates everyone. No more permission-by-permission cleanup.
Version History & Rollback
Every save is kept, so an overwritten proposal or a mass-encryption attack rolls back to a clean version in minutes — not rebuilt from memory.
External Sharing Controls
Share files with clients and vendors through expiring, permission-limited links — instead of attachments that float around inboxes forever, unrevokable.
Migration From File Servers
We move everything off the old office server — structure and permissions intact — and retire the box that’s been humming in the closet since 2016.
Choosing a file platform: SharePoint, Google Shared Drives, or Dropbox Business
For a business with 5–40 staff, the file platform decision usually follows the email decision. If you run Microsoft 365, SharePoint and OneDrive are already included in Business Basic ($6/user/month) and up, so paying separately for Dropbox rarely makes sense. If you run Google Workspace, Shared Drives are included from the Business Standard tier ($14/user/month). Dropbox Business earns its keep mostly in creative and media firms that move large video files and collaborate with outside contractors who already live in Dropbox.
| Platform | Storage per user | Version history | External sharing controls | Price band |
|---|---|---|---|---|
| SharePoint / OneDrive (M365) | 1 TB OneDrive + 1 TB org SharePoint pool (+10 GB/license) | 500 versions by default, configurable | Tenant-wide policy, per-site overrides, link expiration, domain allowlists | Included in M365 ($6–$22/user/mo) |
| Google Shared Drives | 2 TB pooled (Business Standard), 5 TB (Plus) | 100 versions or 30 days (keep-forever per file) | Org-unit level policy, trusted domains, link expiration on paid tiers | Included in Workspace ($7–$22/user/mo) |
| Dropbox Business | 9 TB pooled (Standard) to unlimited-style (Advanced) | 180 days (Standard) / 365 days (Advanced) | Link passwords, expiration, download disable on all business tiers | $15–$24/user/mo, separate from email suite |
One structural difference matters more than any feature checkbox: SharePoint and Google Shared Drives store files owned by the organization, while OneDrive and My Drive store files owned by the person. Company files belong in the org-owned space. When they live in personal drives, they leave with the employee.
The permission model that survives growth
Most 15-person firms we assess have the same permission structure: everyone has access to everything, because that was the easiest setting when there were four people. That works until it doesn’t — the day a departing salesperson downloads the entire client folder, or a new hire opens the payroll spreadsheet on day two. The fix is boring and reliable:
- Grant access to groups, never individuals. Create security groups like Sales, Operations, Finance, and Leadership, and assign folder permissions to those. When someone joins or changes roles, you change one group membership instead of hunting through forty folders.
- Least privilege by department. Sales sees Sales and Shared. Finance sees Finance and Shared. Only Leadership sees payroll, HR files, and contracts. Read-only where edit isn’t needed.
- Set external sharing defaults tenant-wide. In SharePoint admin, set the default link type to “specific people” instead of “anyone with the link.” In Google, restrict sharing to trusted domains. Users can still share externally — they just have to do it deliberately.
- Break inheritance sparingly. Every folder with unique permissions is one more thing to audit. A flat structure of 6–10 top-level libraries with group-based access beats a deep tree of one-off exceptions.
Sync versus stream: why Files On-Demand matters
The old sync model downloaded a full local copy of everything to every machine. That is how a 2 TB SharePoint library ends up trying to fit on a laptop with a 256 GB SSD, and how sync clients grind for hours after a big folder move. Modern clients stream instead: OneDrive Files On-Demand and Google Drive for desktop show every file in Explorer or Finder as a placeholder that downloads only when opened. A green check means it’s cached locally; a cloud icon means it lives online until you need it.
Our default setup: Files On-Demand enabled everywhere, with “always keep on this device” reserved for the handful of folders someone genuinely works on offline — a field tech’s job packets, a bookkeeper’s working files. We also cap which libraries sync at all. Nobody needs the 400 GB archive library synced to a laptop; that’s what the browser is for.
Version history and ransomware rollback
Versioning quietly solves two problems. The everyday one: someone overwrites the master pricing sheet, and you restore yesterday’s version in thirty seconds from the file’s history menu. The serious one: ransomware encrypts a synced folder, the sync client dutifully uploads the encrypted copies, and the previous versions become your recovery path. OneDrive keeps 500 versions per file by default and offers a one-click “Restore your OneDrive” that rolls the whole drive back to any point in the last 30 days. SharePoint offers the same per-library restore. Google keeps 100 versions or 30 days unless a version is pinned.
Two caveats worth knowing. First, versioning is not backup — a deleted file eventually leaves the recycle bin (93 days across SharePoint’s two-stage bin), and a compromised admin account can purge versions. A third-party backup of M365 or Workspace closes that gap. Second, rollback quality depends on catching the infection inside the retention window, which is one reason we monitor for mass-change events rather than waiting for someone to notice.
External links, migration, and departures
External links. An “anyone with the link” URL is a password-free door to your data that gets forwarded, pasted into tickets, and indexed in inboxes forever. Use “specific people” links for anything sensitive, set expiration (30–90 days is a sane default for client shares), and run a quarterly sharing report — both SharePoint and Google admin consoles list every externally shared item, and the first run is always eye-opening.
Migrating in. Coming from an aging file server or a tangle of personal Dropbox and Gmail accounts, the working order is: inventory what exists, archive what nobody has touched in two years, design the new library and group structure first, then move data with the proper tooling (SharePoint Migration Tool, Google’s migration service, or Movebot for cross-platform jobs) so timestamps survive. Watch path lengths — SharePoint rejects URLs past roughly 400 characters, and deep nested folders from old file servers hit that limit constantly.
When someone leaves. Files in Shared Drives or SharePoint need nothing — they were never the person’s property. Their OneDrive or My Drive is the risk. Standard offboarding: disable sign-in, transfer drive ownership to their manager (M365 grants the manager access automatically if configured; Google has an explicit transfer step), revoke their externally shared links, and only then remove the license after the 30-day retention window. Skipping that sequence is how firms lose the only copy of a client contract.
Frequently asked questions
Should we use OneDrive or SharePoint for company files?
SharePoint for anything more than one person needs; OneDrive only for an individual’s working files. SharePoint libraries are owned by the organization, carry group permissions, and survive employee departures. A common failure pattern is the office manager’s OneDrive quietly becoming the de facto file server — it works until she leaves.
Can version history really recover us from ransomware?
Usually, yes — if the encryption happened within the retention window and your admin account wasn’t compromised. OneDrive and SharePoint can roll a whole library back to a point in time within 30 days. We still recommend independent cloud-to-cloud backup, because versioning and recycle bins can both be defeated by an attacker with admin rights.
How long does moving off an old file server take?
For 200–800 GB and a 10–30 person firm, plan on two to three weeks end to end: a few days of inventory and structure design, a pilot group for a week, then a weekend cutover for the bulk transfer. Users typically lose no working time — the old server stays read-only during a short overlap.
Do we need Dropbox if we already pay for Microsoft 365?
Rarely. M365 already includes 1 TB per user plus a pooled SharePoint quota, with versioning and external sharing controls. The exceptions are media-heavy workflows with very large files or clients who mandate Dropbox. Otherwise a second platform mostly adds cost, a second permission model to audit, and one more place files go missing.
Talk to a real technician today
Free IT assessment for US small businesses. Flat monthly rate, no contracts, same-day remote response.
