You’re probably oversharing on Google Drive—fix these 5 settings immediately

You’re probably oversharing on Google Drive—fix these 5 settings immediately

Published Jul 30, 2026, 8:30 AM EDT Nick Lewis is an editor at How-To Geek. He has been using computers for 20 years --- tinkering with everything from the UI to the Windows registry to device firmware. Before How-To Geek, he used Python and C++ as a freelance programmer. In college, Nick made extensive use of Fortran while pursuing a physics degree. Nick's love of tinkering with computers extends beyond work. He has been running video game servers from home for more than 10 years using Windows, Ubuntu, or Raspberry Pi OS. He also uses Proxmox to self-host a variety of services, including a Jellyfin Media Server, an Airsonic music server, a handful of game servers, NextCloud, and two Windows virtual machines. He enjoys DIY projects, especially if they involve technology. He regularly repairs and repurposes old computers and hardware for whatever new project is at hand. He has designed crossovers for homemade speakers all the way from the basic design to the PCB. Nick enjoys the outdoors. When he isn't working on a computer or DIY project, he is most likely to be found camping, backpacking, or canoeing. Oversharing on Google is almost a bit too easy. Google is designed for seamless collaboration, which means the system tends to default to settings that reduce the amount of friction you encounter when attempting to share. Unfortunately, that also means some of the default settings are overly permissive by default. You can limit the amount of potential exposure you have by tweaking five settings. One setting solves 90% of your problems The single most important setting available is the one that controls who can access a file. When a file is set to "Anyone with the link," it's open to anyone who happens to get the URL, and they don't even need to sign in to view or comment. That means one errant paste could share a sensitive file with billions of people. You should always make sure that it is set to restricted unless you specifically want it to be set some other way. When set to Restricted, access is tied directly to named accounts, and the link only works for people you have explicitly invited. Don't give away more abilities than are necessary Google sometimes defaults new shares to Editor, but in general, giving people less control over your documents is a much safer approach. You have three roles to choose from: Viewer (look only), Commenter (suggest and comment), and Editor (change and reshare). Editor access confers the ability to change sharing settings, which is an ability you don't want most recipients to have, and one that they likely don't need. If you are sending a document for review or as a reference, Viewer or Commenter will work just fine for the overwhelming majority of applications. Keep in mind that downgrading a role later will often cause an interruption if someone is in the middle of a task. You're better off deciding the right level of access before you hit send. Don't let Editors change file or folder permissions Only you make the important decisions Even if you’ve assigned the right roles, an Editor can still invite new people to the document. You can stop this by unchecking the box that allows Editors to change permissions. This restricts all sharing changes to the owner only. I always turn it off. Double-check how you have permissions configured for both files and folders. A file will typically inherit the permissions of its parent folder, which means that a locked-down file within a broadly accessible folder is going to be as insecure as that folder. It is worth keeping your folder hierarchy in mind when you're auditing your files' security. Thankfully, Google no longer lets you give someone lower permissions on a file than they have on its parent folder, but I'd still keep an eye on it. If you do need to specifically restrict permissions for a file, you should create a subfolder with whatever strict restrictions you want to impose, then move the file into it. Control where your files go You might assume that Viewers don't have any ability to reshare your documents, but in practice they do. By default, people with Viewer access can save a copy of a document to their own drive or to their local machine. If you really want to tighten things up, you can disable options to download, print, or copy documents. If a Commenter or Viewer attempts to use one of those buttons, they'll find it grayed out and inactive. As with everything in Drive, this isn't a foolproof guarantee. Someone can still take a screenshot or video (or a photo of their monitor), so it really only adds a minor barrier. Put an expiration date on access Don't let people have access forever unless it is necessary A common security problem—in more areas than just Google Drive—is stale access, where collaborators retain access long after they should have lost it. You can set an automatic expiration date, so a person's access ends on a specific day without you having to remember to manually revoke it. Once the date passes, they lose access unless you manually choose to extend it. If they retain access to the parent folder, then the expiration date doesn't remove their access. There is one noteworthy limitation: It doesn't apply to a link that has been set to "Anyone with Link" access. It only applies to invites you've sent to specific people. Unfortunately, automatic expiration is primarily aimed at professional use. It is available in Business and Enterprise plans, some Education plans, and a few paid personal plans. If you're on a free plan, you have to remember to pull access when it becomes relevant. Google Drive security isn't time-consuming There is no way to completely lock down your files and use Google's collaboration features; however, 10 minutes is enough to tangibly cut down on your chances of accidentally sharing something with the entire planet. And regardless of your default settings, you should always encrypt your sensitive files before you upload them to Google Drive, and any sensitive files you share should always have their permissions audited before you send them out.

Original Source

Read the full article at Howtogeek →

KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.