What actually works
Configuration that fails closed, plus a review that catches drift.
Default deny at the tenant level
Link sharing disabled by default, enabled per workspace with justification. This inverts the path of least resistance: creating an external link becomes a deliberate act.
The cost is friction, and it is worth being honest that it is real. Teams will complain. The alternative is a control that depends on everyone remembering.
Guests instead of links
For anything recurring, a named guest is strictly better: attributable, scoped, expirable, reviewable. Make guest access the documented route for external collaboration, and treat link sharing as the exception for one-off, low-sensitivity material.
Expiry by default
Any external access should have an end date unless someone deliberately extends it. A guest without an end date becomes permanent by inattention.
Revocation that actually revokes
Worth testing rather than assuming. Some platforms cache permissions, and a revoked link may continue to work for a period. Verify with a real link against a real document, then revoke and re-test.
Evidence
You need to be able to answer: which documents are currently shared externally, with whom, and since when. A platform that cannot produce that list makes the review manual, and manual reviews do not happen on schedule.