Why this pattern exists (and what it’s not)
Email attachments are convenient, but they’re also easy to forward, mis-address, auto-sync to personal devices, and sit unencrypted in mailboxes for years. For professional service SMBs, that’s a predictable way for IDs, tax documents, contracts, and banking forms to end up in the wrong place.
This article is not “just use a portal.” It’s a constrained, Microsoft 365-native intake pattern designed for teams that need repeatable security guardrails without adding a new vendor this quarter or forcing every client into a full portal experience.
The operating constraints this solves
Constraint: Clients hate logins and change
If the upload experience looks like “create yet another account,” you’ll get pushback—or worse, clients will revert to emailing attachments because it’s faster.
Constraint: Staff need a repeatable process, not a one-off workaround
A secure intake flow has to be teachable and consistent. If each staff member invents their own “secure share” approach, you’ll end up with inconsistent permissions, missing expirations, and unclear cleanup.
Constraint: You need evidence-grade visibility
When a sensitive file goes missing, you need to answer basic questions: who created the link, who uploaded, when it happened, what happened next, and whether the link was still active.
Threat model: what we’re trying to prevent
Risk: Misdelivery and uncontrolled forwarding
Email attachments can be forwarded outside your control, and a typo in an address can become a reportable incident.
Risk: “Anyone with the link” sprawl
A sharing link that never expires becomes a long-term back door. Even if it was “safe at the time,” it may not be safe months later.
Risk: Intake becoming a permanent data lake
Even if you receive documents securely, leaving them in a broad “uploads” area increases the blast radius of any future account compromise or permission mistake.
The Microsoft 365-native intake pattern (upload-only + expiry + audit + retention)
This pattern uses Microsoft 365 capabilities you may already have: OneDrive/SharePoint, Microsoft Purview (audit + retention), and optional Power Automate for handoff.
What “upload-only” should mean in practice
Upload-only means the client can submit files into a specific destination without being able to browse other files, other clients, or your broader SharePoint content.
It also means the upload path is time-bound, traceable, and has a defined end-of-life (move + revoke + delete/retain).
Step-by-step implementation
Step 1: Create a dedicated Intake location with tight internal permissions
Create a single-purpose SharePoint site or document library (many firms name it something like “Client Intake – Incoming”). Keep membership small: only the staff who truly handle intake.
Create a separate folder per client/matter (e.g., “2026-ClientName-Tax-Intake”) so you can later apply client-specific cleanup, holds, or retention labels.
Step 2: Generate the client submission method (choose your security/friction level)
You have two practical options in Microsoft 365 depending on how strongly you need identity binding (“named recipients”) versus minimal client friction.
Option A (best for true upload-only): OneDrive/SharePoint File Request
Microsoft 365’s file request capability is designed for intake: recipients can upload into your folder without seeing what’s inside.
Use it when you want the cleanest “upload-only” behavior and the least client confusion (typically no portal navigation).
Option B (best for named recipients): “Specific people” folder link + expiration
If you must restrict the submission link to specific email addresses, use a folder sharing link configured for Specific people, Can edit, with an expiration date.
This can require sign-in or one-time passcode verification depending on your tenant settings. The tradeoff is that recipients may be able to see the folder contents (usually only what they upload if the folder starts empty), so you must keep the folder dedicated per client.
Step 3: Handoff, permission collapse, and cleanup (so intake doesn’t linger)
Once the client uploads, treat the intake area as a temporary landing zone, not the long-term home for those documents.
Move the files into the correct internal working location (client workspace, case folder, or engagement library) where permissions are already governed by your normal “need-to-know” model.
Then:
- Disable/revoke external sharing on the intake folder/link.
- Remove any external guest access that was granted for intake.
- Apply retention/cleanup rules so the intake landing zone doesn’t quietly become a historical archive.
Standardize it so your team can do it the same way every time
Use a simple intake request template (email or message)
Your staff should not be writing custom instructions each time. Standardize:
- What the client should upload (clear list)
- What not to upload (e.g., “no passwords by document”)
- The deadline and expiration window
- A second channel to confirm identity for high-risk docs (phone call, known contact method)
Add a naming convention that supports retention and eDiscovery
A consistent folder naming scheme helps you later apply retention labels, legal holds, and matter-based access reviews.
For example, include a date and matter name so the “intake landing” can be cleaned on a predictable schedule.
- Create a dedicated Intake library (restricted internal group only)
- Create one folder per client/matter (no shared client folder)
- Choose File Request (upload-only) or Specific people link (named recipients)
- Set link expiration (short by default) and disable re-sharing where possible
- Move files to the internal working library after receipt
- Revoke external access after move
- Apply Purview retention or automation for intake cleanup
- Confirm audit logging is enabled and you know where to search it
Audit trail expectations (what you can and should be able to prove)
What to log in Microsoft 365
At a minimum, you want the ability to reconstruct:
- Who created or modified the sharing link
- When external sharing was enabled/used
- When files were uploaded, accessed, moved, or deleted
- Which internal account performed the handoff into the working area
In Microsoft 365, this typically means using the Microsoft Purview audit experience (and ensuring auditing is turned on for your tenant) so SharePoint/OneDrive events are searchable when you need them.
How to operationalize auditing (so it’s not “set and forget”)
Document a simple internal procedure: who can run an audit search, what time window you check, and where you store incident notes.
This avoids the common situation where “we should have logs” turns into “we don’t know how to retrieve them” during a client escalation.

Expiring access: make short-lived the default
Set a standard intake window
Pick a standard default like “expires in 7 days” (or shorter for highly sensitive requests). Staff can extend when needed, but extensions should be intentional.
Prefer one link per request, not a perpetual upload link
Perpetual links create a long tail of risk. Treat each request as a discrete event with an end date.
After intake, collapse permissions aggressively
Once files are moved:
- Remove the external link
- Verify the intake folder no longer has external sharing
- Keep the intake folder empty (or archive internally under retention)
Retention and cleanup: prevent “forever storage” by design
Decide what “intake” is allowed to keep
Intake is a transient staging area. Most firms are best served by one of these models:
- Delete intake contents after X days (once moved and verified)
- Retain for a short period for dispute resolution, then delete
- Retain only metadata (who requested, when received) while deleting the files
Implement retention with Microsoft Purview (and keep it simple)
If your licensing supports it, use retention policies/labels targeted to the Intake library to enforce deletion after your chosen window.
If you need a more operational workflow, consider a simple Power Automate flow that moves files from Intake → Working folder and then empties Intake on a schedule (with approvals if needed).
Don’t forget legal holds and exceptions
If your firm may need to preserve certain records, make sure your retention approach can accommodate legal holds or matter-based exceptions before you automate deletion.
Where teams usually go wrong (and how to avoid it)
Mistake: Using one shared “Client Uploads” folder for everyone
Even if it feels efficient, it increases the chance of cross-client exposure. Keep folders separate per client/matter, and keep the landing zone empty between requests.
Mistake: Leaving sharing links active “just in case”
This is how you end up with unintended ongoing access months later. Make “revoke after move” part of your definition of done.
Mistake: Forgetting the mailbox problem
Even with a perfect upload flow, staff may still ask for “just email it” during busy periods. Train the team that email is not an intake channel for sensitive documents, and provide a fast alternative they can execute in minutes.

Key Takeaways
- You can replace email attachments with a Microsoft 365-native upload-only intake flow without buying a full portal.
- Use File Request for the cleanest upload-only experience, or Specific people + expiration when you must bind access to named recipients.
- Treat Intake as a temporary landing zone: move files, revoke access, then clean up on a defined schedule.
- Configure and practice audit searches so you can prove who did what, and when.
Frequently Asked Questions
Can clients upload without creating a Microsoft account?
Often, yes. With File Request, clients typically upload through a simple web experience. With “Specific people” links, your tenant may allow one-time passcode verification for external recipients, which is still lower friction than a full portal.
Is “upload-only” possible if we must restrict to a named person?
Strictly upload-only is best achieved with File Request. If you must restrict to named recipients, you can use “Specific people” links plus an empty, dedicated folder per client so there’s nothing to browse—and you still get strong access control.
Will we have an audit trail that holds up to client scrutiny?
You should be able to show link creation/modification and file activity events in Microsoft Purview audit for SharePoint/OneDrive. The practical requirement is operational: confirm auditing is enabled, and assign responsibility for running and retaining audit searches when needed.
How do we keep intake files from lingering forever?
Set an intake retention rule (delete after a defined period) and make “move to working folder + revoke link” part of the process. If you need consistency, automate the move/cleanup with a lightweight workflow.
Should we still use encrypted email sometimes?
Encrypted email can be useful for messages, but it’s still a poor long-term home for sensitive attachments. If a document must be exchanged, prefer the upload-only intake pattern for the file and use email only for coordination.
Take the Next Step
If you want to stop sensitive documents from living in inboxes—but you’re not ready to roll out a full portal—this upload-only pattern is the practical middle ground.
Your Expert Tech can help you design the Intake library structure, set sharing/expiry defaults, confirm audit logging, and implement a retention/cleanup workflow that matches how your firm actually operates. Reach out to schedule a consultation and we’ll map your requirements (client friction, named-recipient needs, and retention obligations) into a secure Microsoft 365 intake process your team can repeat confidently.

