HowTo: Embed a SharePoint or OneDrive Video in CyberHoot

28th September 2026 | HowTo, Platform, Training HowTo: Embed a SharePoint or OneDrive Video in CyberHoot

You can assign your own videos as CyberHoot training, including videos that already live in SharePoint, OneDrive, or Microsoft Stream. All CyberHoot needs is the video’s sharing link, and one sharing setting on the Microsoft side so your learners are allowed to watch it.

This is the same CustomHoots workflow you already use for YouTube and Vimeo videos, with one extra step in Microsoft 365.

Before you start:

Before uploading your video, make sure you have the following:

  • A Microsoft 365 account that can upload to SharePoint or OneDrive and share the file.
  • The video file itself. MP4 is recommended for the best compatibility, but MOV, M4V, and WebM files are also supported.
  • CyberHoot admin access with the CustomHoots power-up enabled.
  • Permission from your Microsoft 365 administrator to create “Anyone with the link” sharing links. Some organizations turn these off.
    • Please read Who Can Watch The Video below before you start.

1. Upload the Video to SharePoint or OneDrive:

Upload the video the way you normally would, then open it so it plays in the Stream player.

Note: Store training videos in a SharePoint site library rather than in one person’s OneDrive. A video kept in personal OneDrive stops playing for everyone when that employee leaves and their account is deleted, which quietly breaks the training assignment months later.

2. Share the Video with Anyone Who Has the Link:

This step is what lets your learners watch the video, so do not skip it.

  1. With the video open, select Share.
  2. Open the link settings and choose Anyone with the link.
  3. Leave the permission at can view. Learners never need edit rights.
  4. Apply the setting. You can confirm it later under Share > Manage access > Links, where it reads “Anyone with the link can view”.

Note: “People in [your company]” and “Specific people” links are not enough. Those require every learner to be signed into Microsoft 365 in the same browser, and anyone who is not gets an empty player instead of your video.

3. Copy the Sharing Link:

In the same Share menu, select Copy link. You will get an address like this:

https://contoso-my.sharepoint.com/:v:/g/personal/jsmith_contoso_com/IQAS8BzaQm7gRb9yu

That is the whole link. There is no embed code to copy and nothing to edit by hand.

4. Add the Video to CyberHoot:

  1. Sign into CyberHoot and navigate to Power-Ups > CustomHoots.
  2. Add a new training, or edit an existing one.
  3. For the content type, choose Video.
  4. Paste the sharing link into the Video Link field.
  5. Fill in the name, description, and any quiz questions you want to ask.
  6. Save the training, then assign it to a group the way you assign any other CustomHoot.

CyberHoot recognises a SharePoint or OneDrive sharing link and plays the video file directly in the training page, rather than loading Microsoft’s player. That is what lets it play for your learners without a Microsoft sign-in.

5. Simulate the Training as an Admin:

Before you assign the video to anyone, watch it yourself through CyberHoot’s simulator. A simulation runs the training exactly as an employee sees it, without recording a completion or affecting anyone’s compliance score.

  1. In Power-Ups > CustomHoots, find your new training in the list.
  2. Select the Simulate Training icon on that row. It is the small chalkboard icon in the row action buttons.
  3. Step through the training and confirm the video appears, plays, and has sound.
  4. If you added quiz questions, run through those too, then close the simulation.

Note: If you are signed into Microsoft 365 while you test, a video with the wrong sharing setting can still play for you and fail for everyone else. Make sure to test in a browser where you are not logged into Microsoft365.

Who Can Watch the Video:

An Anyone with the link share means exactly that: the link is the key. Your learners do not need a Microsoft account, and neither does anyone else who gets hold of the address. Treat these videos as unlisted rather than private, the same way you would an unlisted YouTube video.

  • Do not use this for videos containing confidential or regulated material. Keep those on a “People in [your company]” link and accept that learners must be signed into Microsoft 365.
  • Microsoft Stream view counts and analytics do not record plays that happen inside CyberHoot. CyberHoot’s own training reports still track who completed the assignment.
  • If the sharing link is deleted or expires in Microsoft 365, the video stops playing in CyberHoot. Leave the link in place for as long as the training is assigned.

Already Using a Microsoft Embed Code?

Older trainings may hold an embed address copied from Microsoft’s Embed code dialog, containing /_layouts/15/embed.aspx. Those keep working, but only for learners signed into your Microsoft 365 tenant with access to the file. Everyone else sees an empty player. To fix that, replace the embed address with the sharing link from step 3.

Troubleshooting:

What you seeWhat it meansWhat to do
Empty video area for staff, plays for youThe sharing link is not set to Anyone with the linkRedo step 2, then paste a freshly copied link into the training
Empty video area for everyoneThe link is an embed address, or the sharing link was edited by handCopy the link again with Share > Copy link and paste it unchanged
“This item might not exist or is no longer available”The video was moved, renamed, or deleted, or the sharing link was removedReshare the video and paste the new link into the training
Video plays but will not play full screen or downloadExpected. The player offers playback controls onlyNothing to do
Video plays, but the Mark Completed button never appearsUnrelated to the video. The learner has not reached the end of the assignmentAsk them to scroll down and finish the assignment steps

Other CyberHoot HowTos:

Latest Blogs

Stay sharp with the latest security insights

Discover and share the latest cybersecurity trends, tips and best practices – alongside new threats to watch out for.

Corp MDM: The Fake Work App Who Wanted to Read Your Texts

Corp MDM: The Fake Work App Who Wanted to Read Your Texts

Author: Katie Boquetti | Editorial: Craig Taylor Editorial by Craig Taylor: We've known for a while here...

Read more
OAuth Consent Phishing: Protect Your Permissions, Not Just Your Password

OAuth Consent Phishing: Protect Your Permissions, Not Just Your Password

Author: Katie Boquetti | Editorial: Craig Taylor Editorial by Craig Taylor: I'm blessed to have...

Read more
Fake Software Installers Are Turning Off Windows Update

Fake Software Installers Are Turning Off Windows Update

Author: Katie Boquetti | Editorial: Craig Taylor Editorial by Craig Taylor: I remember the early days of...

Read more