SharePoint vs. OneDrive vs. Teams: Differences, Connections, and Why Everything Ultimately Runs Through SharePoint
SharePoint, Teams, and OneDrive have long been part of everyday work life in many companies. We save our own drafts in OneDrive, collaborate with our department on a SharePoint project, and coordinate with each other in a Teams chat on the side. Three applications that seem to do the same thing but differ in important details. Surprisingly often, it remains unclear where an uploaded file actually ends up, who can access it, and what happens when a colleague leaves the company.
This uncertainty is not a sign of ignorance, but stems from the architecture of Microsoft 365 itself. The three services are not separate tools, but closely integrated building blocks that are built on the same foundation behind the scenes. Once you understand how they work together, you’ll share files more securely, assign permissions more thoughtfully, and navigate the entire Microsoft 365 ecosystem much more easily.

Three Services, One Common Foundation
The most important point to start with is this: In the end, almost every path leads through SharePoint. Microsoft 365 combines three services—SharePoint, OneDrive, and Teams—for document storage, personal storage, and communication. Because they are constantly used together in everyday work, it’s easy to get the impression that they perform similar tasks. In fact, however, each service plays its own distinct role, and two of them are technically built on top of the third.
SharePoint is the platform for collaborating on documents and projects. At its core, OneDrive is nothing more than a private SharePoint site and serves as personal storage. And Teams uses SharePoint and OneDrive in the background for long-term file storage instead of maintaining its own repositories. At first glance, this relationship may sound like technical nitpicking, but it has very practical implications for who can access which content and for how long.
Where does each file go? The simple rule of thumb
If you summarize how these elements work together, the result is a surprisingly simple rule: Files in a Teams channel are stored in SharePoint. Files from a Teams chat are shared via OneDrive. And OneDrive itself is essentially a private SharePoint site. So, in the end, SharePoint is almost always behind all these processes, either directly or indirectly via OneDrive.
This clarity is more than just a technical footnote. It explains why a presentation shared in a channel remains accessible to the entire team even after the original creator has long since left the company, while the same file can disappear from a private chat linked to that person’s OneDrive. And it’s essential for answering what is perhaps the most important question: Who is actually allowed to view and edit all this content?
How Permissions Work in Microsoft 365
Just as important as the question of where files are stored is the question of access rights. Microsoft 365 follows a clear, hierarchical structure that can be represented as a chain: from Microsoft Entra ID through Microsoft 365 groups and the Teams and SharePoint services, all the way down to individual document libraries, folders, and files.
The starting point is Microsoft Entra ID, formerly known as the Azure AD directory service. This service stores information about which users exist in the organization and which groups they belong to. Based on this information, Microsoft 365 groups are created, which serve as central permission containers and bundle memberships across various services. When a team is created, Microsoft automatically creates such a group. This group controls not only access to the team itself but also to the associated SharePoint site.
Permissions are inherited from the group through Teams and SharePoint down to libraries, folders, and individual files. The major advantage of this model is that access rights can be managed centrally through groups and team memberships without having to share each individual file separately. Anyone who is a member of the correct group automatically gains access to the relevant content and automatically loses that access when their membership ends.

Why Individual Approvals Can Quickly Become a Problem
In practice, it’s very tempting to quickly share a single document or folder directly with a specific person. It’s convenient and useful in the moment. In the long run, however, this undermines the very clean inheritance logic that makes Microsoft 365 so easy to manage.
The reason lies in a unique feature of SharePoint: As soon as a different, explicit permission is assigned to a subobject, this automatically interrupts permission inheritance at that point. Unlike with a traditional file server and its NTFS permissions, this break in SharePoint occurs, so to speak, automatically. With each individual permission granted, a coherent, group-based structure gradually turns into a patchwork quilt. The more such exceptions accumulate, the harder it ultimately becomes to understand who actually has access to what.
That is precisely why experienced administrators recommend managing permissions through groups and team memberships whenever possible, and using direct sharing only where it is truly necessary. The most robust approach is to assign permissions at the site level rather than for each individual document. This keeps the structure manageable and auditable.
The Real Challenge: Keeping Track of Everything
As elegant as the permissions model is in theory, it becomes increasingly challenging in day-to-day operations. This is because Microsoft 365’s built-in tools make it difficult to maintain a centralized overview of which files have been shared overall, which external shares exist, and what actual permissions an individual ultimately possesses. In an organization with hundreds of users, dozens of teams, and just as many automatically generated SharePoint sites, this quickly adds up to a nearly unmanageable volume of access permissions.
Almost every IT department is familiar with the typical consequences: Employees retain access to an old project after switching departments; guest users aren’t removed in a timely manner once a project ends; and a confusing landscape of access rights quietly grows out of individual direct approvals. What began as a convenient shortcut becomes an issue at the latest during the next audit or when considering standards such as ISO 27001, NIS2, or the GDPR. This is because these standards require proof that access rights are granted on an as-needed basis and reviewed regularly.
What This Means for Your Access Management
The key takeaway from all of this is good news: Because virtually all access routes go through SharePoint and the chain consisting of Entra ID and Microsoft 365 groups, this access can also be managed from a central location. You don’t have to tackle the complexity of SharePoint, OneDrive, and Teams file by file; you just need to address it at the right level. Many organizations are surprised by just how much can be managed using the existing SharePoint structures alone.
This is exactly where BAYOOSOFT Access Manager comes in. The solution consolidates permission management across Active Directory, Microsoft Entra ID, file servers, SharePoint, Exchange mailboxes, and other line-of-business applications into a single, centralized interface, thereby providing transparency into who has access to what and on what basis. Through an NTFS Permission Analyzer and reporting that spans teams and SharePoint sites, effective permissions and external shares become visible, rather than remaining scattered across countless individual views.
The real difference, however, lies in what happens between individual actions. A continuous target-actual comparison constantly checks the permissions actually granted against the defined target state, and a proactive auto-correction feature resets deviations based on rules before they turn into permanent permission clutter. Supplemented by self-service requests, automated Joiner-Mover-Leaver processes, recurring recertifications, and a complete audit trail, documented compliance becomes a permanently effective operational state. This ensures that Microsoft 365’s well-designed permission logic remains not only clean at the time of setup but also stable and auditable over time—without the need to review each file individually.
Conclusion
SharePoint, OneDrive, and Teams are not competing standalone solutions, but rather closely integrated components of a unified system. SharePoint serves as the foundation for working on documents and projects, OneDrive provides personal storage, and Teams brings communication and collaboration together in a single interface. Ultimately, almost every path leads through SharePoint, either directly or via OneDrive.
Those who understand this interplay and the underlying access control logic can share files more securely and maintain a clearer overview. And those who manage the inevitably growing complexity not on a file-by-file basis, but at the central level using Entra ID, groups, and SharePoint, can transform a potential mess into a controlled, auditable state. That’s exactly what the BAYOOSOFT Access Manager is designed to do.
