Collaboration with external partners is everyday business for Swiss companies. But how do you securely share documents, project information, and knowledge with externals? SharePoint offers native extranet capabilities that combine security with user-friendliness.
What Is a SharePoint Extranet?
An extranet is a protected area of your SharePoint environment that gives external users – clients, partners, suppliers, or consultants – controlled access. Unlike a public website, the content is protected and only visible to authenticated users.
Typical Extranet Scenarios
- Client projects: Shared project documentation with clients
- Supplier portal: Orders, delivery notes, quality documents
- Partner portal: Marketing materials, co-selling documents, deal registration
- Consultant portal: Collaboration with external consultants and freelancers
- Board portal: Secure document repository for board members
Architecture of a SharePoint Extranet
Option 1: Dedicated Extranet Site
A separate SharePoint site for external users:
- Advantages: Clear separation of internal and external content
- Disadvantages: Duplicate maintenance of shared documents
- Ideal for: Supplier portals, partner hubs
Option 2: Shared Channels in Teams
Microsoft Teams Shared Channels for direct collaboration:
- Advantages: Seamless communication, no separate login needed
- Disadvantages: Limited structuring options
- Ideal for: Project work with individual external partners
Option 3: Hybrid Approach
Combination of dedicated site and shared channels:
- Extranet Site: Structured documents, knowledge base, FAQs
- Shared Channels: Daily communication and collaboration
- Ideal for: Long-term partnerships with many touchpoints
Security: The Key to Success
Guest Policies
Configure who can grant external access:
- Who can invite guests?: Only admins, site owners, or all members
- Which domains are allowed?: Allowlist for trusted domains
- Which domains are blocked?: Blocklist for competing companies
- Guest expiration policy: Automatic removal after X days of inactivity
Conditional Access
Azure AD Conditional Access for external access control:
- MFA required: Multi-factor authentication for all external access
- Device compliance: Only from managed or compliant devices
- Location-based: Access only from specific countries/regions
- App restriction: Access only via browser, not desktop sync
Sensitivity Labels for Extranet Content
Automatic protection rules for externally shared documents:
- Encryption: Documents remain encrypted, even after download
- Watermarks: Automatic watermarks on confidential documents
- Expiry date: Automatically revoke access after X days
- Print restriction: Prevent download or printing
Best Practices
- 1Least Privilege: Give externals only the minimum necessary access
- 2Regular Reviews: Review all external access quarterly
- 3Audit Trail: Enable audit logging for all external activities
- 4Naming Convention: Clearly label extranet sites (e.g., "EXT-ClientName")
- 5Onboarding Process: Standardized process for setting up new external access
- 6Offboarding Process: Automated cleanup at project end
Swiss Compliance
Especially important for Swiss companies:
- nFADP: Data transfer abroad only with adequate protection
- Data residency: Microsoft 365 data in Swiss data centers (Switzerland region)
- Contractual protection: DPA (Data Processing Agreement) with external partners
- Industry regulation: FINMA, Swissmedic and industry-specific requirements
Conclusion
A SharePoint extranet is the natural extension of your internal collaboration to external partners. With proper configuration of guest policies, Conditional Access, and Sensitivity Labels, collaboration is secure and compliant.

