AI engineering

Prepare a Tenant for Microsoft 365 Copilot by Fixing Oversharing First

Find overshared SharePoint and OneDrive content with Data access governance reports and DSPM, contain it with RCD and RAC, then hand cleanup to site owners before Copilot rollout.

14 min read
On this page

To prepare a tenant for Microsoft 365 Copilot, fix oversharing before you assign licences: run the Data access governance site permissions report to find the SharePoint and OneDrive sites with the broadest access, use the activity and special-group reports to find "Everyone", "Everyone except external users" and "Anyone" exposure, and temporarily hide the riskiest sites with Restricted Content Discovery. Then send site access reviews to owners so they remove the excess access themselves, and set secure defaults so the problem doesn't come back. Copilot respects existing permissions, so every overshared file it can reach is a file the user could already open.

Who this is for and what you will have at the end

This guide is for Microsoft 365 and SharePoint administrators who have been asked to "get the tenant ready" for a Copilot pilot or a wider rollout, and who need a repeatable process rather than a one-off cleanup.

At the end you will have:

  • A baseline of which sites expose content to the most users, for SharePoint and OneDrive.
  • A list of sites and items shared with the special "Everyone" and "Everyone except external users" (EEEU) groups, and sites where people are creating "Anyone" and organization-wide links.
  • Interim protection on the highest-risk sites, so Copilot and organization-wide search don't surface them while cleanup is in progress.
  • Site access reviews in progress, tracked centrally.
  • Guardrails that stop new oversharing at the source.

Why oversharing is the real readiness problem

Copilot retrieves content through Microsoft Graph in the security context of the signed-in user. It doesn't grant new access, but it removes the "security through obscurity" that many tenants have relied on for years. A budget workbook in a forgotten site that grants access to EEEU was technically readable by everyone before; with Copilot, a question about budgets can surface it.

Microsoft's site permissions report distinguishes two kinds of exposure that are worth understanding before you start:

  • Current exposure: users added directly or through Microsoft Entra groups. The "Total permissioned users" count rises as soon as you add them.
  • Potential exposure: sharing links and grants to EEEU. These don't raise the user count until someone actually uses the link or opens the content, but they make content reachable by a very large audience.

A good readiness plan addresses both: large audiences on sites, and broad grants hidden at item level.

Prerequisites

  • Base licence: Office 365 E3, E5 or A5; Microsoft 365 E1, E3, E5 or A5; or Microsoft 365 GCC, GCC-High or DoD.
  • SharePoint Advanced Management (SAM): available when at least one user has a Microsoft Copilot licence assigned, when you buy the SharePoint Advanced Management Plan 1 add-on, or with Microsoft 365 E7. Organizations with Microsoft 365 E5 but without SAM can use Data access governance reports with reduced functionality: no snapshot reports, no remedial actions, and activity reports limited to 10,000 sites.
  • Roles: SharePoint Administrator for most tasks. The SharePoint Advanced Management Administrator role adds the ability to view metadata across content and remove permissions at scale, and is required for the item-level special-groups report.
  • PowerShell: the latest SharePoint Online Management Shell. Data access governance cmdlets need module Microsoft.Online.SharePoint.PowerShell version 16.0.25409 or later, and the special-groups report needs 16.0.27215.12000 or later. Connect with Connect-SPOService without the -Credential parameter, which isn't supported for these cmdlets.
  • Purview: access to the Microsoft Purview portal if you also want Data Security Posture Management (DSPM) data risk assessments.
Connect-SPOService -Url https://contoso-admin.sharepoint.com

Step 1: Get a permissions baseline

Start with the Site permissions across your organization snapshot report. It counts the unique users who can reach each site at any scope (site groups, Entra groups and item-level grants), plus Entra group grants, broken inheritance, guest and external participant permissions, EEEU and Everyone grants, and the number of "Anyone" and "People in your organization" links.

In the portal:

  1. In the SharePoint admin center, expand Reports and select Data access governance.
  2. Under Site permissions across your organization, select View reports, then Create report.
  3. When the report is ready, select View report under SharePoint or OneDrive. The view lists the top 100 sites with the most permissioned users; download the CSV to analyse up to 1 million sites.

With PowerShell, create one report per workload:

Start-SPODataAccessGovernanceInsight -ReportEntity PermissionedUsers -ReportType Snapshot -Workload SharePoint -CountOfUsersMoreThan 0 -Name "OrgWidePermissionedUsersReportSharePoint"
 
Start-SPODataAccessGovernanceInsight -ReportEntity PermissionedUsers -ReportType Snapshot -Workload OneDriveForBusiness -CountOfUsersMoreThan 0 -Name "OrgWidePermissionedUsersReportODB"
 
# Check status and get the ReportId
Get-SPODataAccessGovernanceInsight -ReportEntity PermissionedUsers
 
# Download the CSV
Export-SPODataAccessGovernanceInsight -ReportID <ReportId> -DownloadPath "C:\DAGReports"

Timing to plan around:

  • The first report takes up to five days, whatever the size of the tenant. Later runs finish within 24 hours.
  • Data is captured up to 48 hours before generation.
  • You can rerun the report every 30 days.
  • Sites with a NoAccess lock state and archived sites are excluded.

In the CSV, sort by Number of users having access, then look at EEEU permission count, Everyone permission count, Anyone link count, Items with unique permissions count and Site Sensitivity. A site with thousands of users, no sensitivity label and a high EEEU count is a typical first-wave candidate.

Step 2: Watch what is changing now

Snapshot reports show the current state; activity reports show where oversharing is happening right now, over the last 28 days. Use both: Microsoft suggests snapshot reports quarterly and activity reports monthly.

# Sites creating the most links of each type in the last 28 days
Start-SPODataAccessGovernanceInsight -ReportEntity SharingLinks_Anyone -Workload SharePoint -ReportType RecentActivity
Start-SPODataAccessGovernanceInsight -ReportEntity SharingLinks_PeopleInYourOrg -Workload SharePoint -ReportType RecentActivity
Start-SPODataAccessGovernanceInsight -ReportEntity SharingLinks_Guests -Workload SharePoint -ReportType RecentActivity
 
# Sites and items shared with Everyone except external users in the last 28 days
Start-SPODataAccessGovernanceInsight -ReportEntity EveryoneExceptExternalUsersAtSite -Workload SharePoint -ReportType RecentActivity -Name "PublicSiteViaEEEU"
Start-SPODataAccessGovernanceInsight -ReportEntity EveryoneExceptExternalUsersForItems -Workload SharePoint -ReportType RecentActivity -Name "PublicItemsViaEEEU"

Replace SharePoint with OneDriveForBusiness to run the link reports for OneDrive. For OneDrive, the EEEU report is supported only at item level.

If your organization doesn't have SAM, you must turn on data collection first. Reports become available 24 hours later, only contain data from that point, data is kept for 28 days, and collection pauses if no report is generated for three months:

Start-SPOAuditDataCollectionForActivityInsights -ReportEntity SharingLinks_Anyone
Get-SPOAuditDataCollectionStatusForActivityInsights -ReportEntity SharingLinks_Anyone

Reports can be generated when the status is InProgress; the other values are NotInitiated and Paused.

Step 3: Find the exact items shared with Everyone and EEEU

The site report tells you which sites are overshared. The sites and files shared via special SharePoint groups report tells you exactly which sites, folders and files are effectively public through "Everyone" or EEEU, and how access was granted. That makes scripted cleanup possible without waiting on every owner.

Start-SPODataAccessGovernanceInsight -ReportEntity EveryoneExceptExternalUsers -ReportType Snapshot
Start-SPODataAccessGovernanceInsight -ReportEntity Everyone -ReportType Snapshot

This report has no -Workload parameter and covers both SharePoint and OneDrive. The output file is limited to 1 million rows, and grants on hidden system files and system groups are excluded because they exist by design (for example, the Everyone group inside the Style Resources Reader group on classic publishing sites). Running it requires the newer module version and the SharePoint Advanced Management Administrator role.

Step 4: Add sensitivity to the picture with DSPM

Permission counts tell you how wide a site is open, not whether it holds anything sensitive. Microsoft Purview Data Security Posture Management fills that gap with data risk assessments, found under DSPM > Discover > Data risk assessments in the Purview portal.

  • A default assessment runs weekly against the top 100 SharePoint sites by usage. The first results appear after a four-day delay.
  • Custom assessments let you choose users and sites. Results take at least 48 hours and don't refresh; duplicate the assessment to rerun it.
  • Each site's flyout has Overview, Identify, Protect and Monitor tabs. Protect offers to create a DLP policy that stops Copilot processing labelled content (Restrict access by label), apply Restricted Content Discovery (Restrict all items), create an auto-labeling policy for unlabeled sensitive files, or create a retention policy for content not accessed for at least three years. Monitor links to a SharePoint site access review.
  • Optional item-level scanning in custom assessments currently covers up to 10 SharePoint sites and lets you remove sharing links, apply labels or notify owners per item.

The combination you are looking for is high audience plus sensitive content: those sites go first.

Step 5: Contain the highest-risk sites while you clean up

Two SAM controls help while permissions are being fixed. They do different things:

ControlWhat it changesCopilot and searchScope
Restricted Content Discovery (RCD)Discoverability only; permissions are unchangedContent from the site, including files users recently interacted with, doesn't appear in organization-wide search or Copilot responses, and AI entry points such as the Copilot button are hidden on the siteSharePoint sites only, not OneDrive
Restricted access control (RAC)Access: only members of up to 10 specified groups can open the site, even if they had permissions or a linkUsers outside the groups can't see the content in search or CopilotSharePoint sites and OneDrive

Turn on RCD for a site in Sites > Active sites > select the site > Settings > Restrict content from Microsoft Copilot, or with PowerShell:

Set-SPOSite -Identity https://contoso.sharepoint.com/sites/finance -RestrictContentOrgWideSearch $true
Get-SPOSite -Identity https://contoso.sharepoint.com/sites/finance | Select RestrictContentOrgWideSearch

RCD is designed as a temporary control. Users who already have access can still open the content directly, and RCD doesn't affect searches that start from within the site or Copilot working on a document the user already has open. It doesn't remove content from the index, so eDiscovery and auto-labeling keep working, and sites with more than 500,000 items can take more than a week to update. For a full walkthrough, including reporting and moving off the retiring Restricted SharePoint Search, see Restricted SharePoint Search retirement: moving to Restricted Content Discovery.

When a site must be limited to a defined audience, use RAC. Enable it for the tenant (it can take up to an hour), then apply it per site:

Set-SPOTenant -EnableRestrictedAccessControl $true
 
Set-SPOSite -Identity https://contoso.sharepoint.com/sites/finance -RestrictedAccessControl $true
Set-SPOSite -Identity https://contoso.sharepoint.com/sites/finance -AddRestrictedAccessControlGroups <group GUID>
Get-SPOSite -Identity https://contoso.sharepoint.com/sites/finance | Select RestrictedAccessControl, RestrictedAccessControlGroups

Membership of the control group doesn't grant access on its own; users need both the site permission and group membership. Shared and private channel sites are separate site collections, so configure them individually.

Step 6: Hand remediation to site owners

Administrators often can't, and shouldn't, review file-level content. Site access reviews delegate that work to the people who understand the site.

  1. In Reports > Data access governance, open a supported report: sharing links, EEEU, or the site permissions baseline.
  2. Select the sites (up to 100 at a time in the web view), then Initiate site access review.
  3. Select Customize and preview email to set the title, message, comments and a link to your internal guidance. Saved customizations apply to later reviews from that report type.
  4. Select Send.

Owners receive an email that opens a review page specific to the issue: the EEEU grants and who added them, the links created, or a per-item breakdown of permissioned users, groups and links, with Manage access buttons. When finished they select Complete review and add comments, which come back to you.

Track everything in the My review requests tab. Status stays pending until the owner completes the review, and a review is marked failed if, for example, the owner's email is invalid. For larger waves, script it:

Start-SPOSiteReview -ReportID <ReportId> -SiteID <SiteId> -Comment "Remove org-wide access before Copilot rollout"
Get-SPOSiteReview -ReportEntity PermissionedUsers

You can start up to 1,000 reviews per calendar month from the site permissions report. Site access reviews support SharePoint sites only, not OneDrive accounts. When a site's review is complete and you have rerun the reports, remove the interim RCD setting so the content becomes useful to Copilot again.

Step 7: Set guardrails so oversharing doesn't return

Cleanup without guardrails is temporary. Microsoft's secure-foundation guidance for Copilot recommends:

  • Sharing defaults: in Policies > Sharing, set the default link to something narrower than "Anyone" and restrict "Anyone" links and company-wide sharing groups. Per site, use Active sites > select the site > Sharing > Default sharing link type.
  • Site sensitivity labels at provisioning, so privacy and sharing settings are set correctly by default, plus default and auto-labeling for files and email.
  • RAC by default for business-critical sites when they are created.
  • Site lifecycle management: inactive site policies, site ownership policies and site attestation policies, under Site lifecycle management in the SharePoint admin center.
  • Microsoft 365 Archive for inactive sites. Content, permissions and metadata are preserved, users can't access the site until it is reactivated, and Microsoft states that Copilot isn't trained on archived content.
  • Content Management Assessment (Advanced Management > Start assessment), rerun every 30 days to track progress.

Verify

  1. Rerun the site permissions report after 30 days and compare user counts and EEEU counts for the sites you remediated.
  2. Rerun the EEEU and sharing-link activity reports monthly; the same sites shouldn't keep reappearing.
  3. Check My review requests for pending and failed reviews.
  4. With a pilot account that is not a member of a restricted site, ask Copilot about a topic that only that site covers, and confirm it doesn't answer from that content once RCD or RAC has propagated.
  5. Check the DSPM default assessment each week for new high-risk sites.

Troubleshooting

SymptomCause and fix
Data access governance reports don't generateReports might not work when nonpseudonymized report data is selected for the organization. A Global Administrator can clear Display concealed user, group, and site names in all reports in the Reports setting of the Microsoft 365 admin center.
Activity reports are empty or unavailableWithout SAM, data collection must be enabled and becomes useful 24 hours later. Check Get-SPOAuditDataCollectionStatusForActivityInsights; if it shows Paused, no report was generated for three months. Re-enable it.
First site permissions report still running after two daysExpected. The first report takes up to five days.
Snapshot reports and remedial actions are missingThe tenant has E5 but not SAM. Assign at least one Copilot licence or buy the SAM Plan 1 add-on.
Special-groups report cmdlet failsUpdate the SharePoint Online Management Shell to 16.0.27215.12000 or later and make sure you hold the SharePoint Advanced Management Administrator role.
Site access review marked as failedThe site owner's email couldn't be used. Fix site ownership, then start a new review.
A site with RCD still appears in Copilot answersPropagation depends on site size and the number of sites being updated; sites with more than 500,000 items can take more than a week. Check whether the user is working inside the site or on a document they already have open, which RCD doesn't affect.
A user lost access after RAC was appliedThey aren't in any of the site's control groups. Add them to the group; they also need existing site permissions.

Closing checklist

  • SAM availability confirmed and SharePoint Online Management Shell updated.
  • Site permissions baseline created for SharePoint and OneDrive, CSVs exported.
  • Monthly sharing-link and EEEU activity reports scheduled.
  • Special-groups report run and EEEU or Everyone grants on sensitive items removed.
  • DSPM default assessment reviewed; high-audience sensitive sites listed.
  • RCD or RAC applied to the first-wave sites, with an owner and an end date for each.
  • Site access reviews sent and tracked; RCD removed after review.
  • Sharing defaults, site labels, lifecycle policies and archiving in place.

If you plan to build your own AI search over SharePoint as well as using Copilot, the same permission hygiene applies; see RAG over SharePoint documents with permission trimming kept intact.

References

Questions people ask

Does Microsoft 365 Copilot ignore SharePoint permissions?

No. Copilot only uses content the signed-in user can already open, so it respects existing permissions. The risk is that many sites grant access far more broadly than intended, through "Everyone except external users", large groups or organization-wide links, and Copilot makes that content much easier to find.

Do I need a separate licence for SharePoint Advanced Management to prepare for Copilot?

Usually not. If at least one user in the organization has a Microsoft Copilot licence assigned, SharePoint administrators get the SharePoint Advanced Management capabilities that support a Copilot deployment. Some features, such as restricted site creation, still need the SharePoint Advanced Management Plan 1 add-on.

How long does the first site permissions report take?

The first site permissions for your organization report takes up to five days, regardless of tenant size. Later reports complete within 24 hours, capture data from up to 48 hours before generation, and can be run again every 30 days.

Should I block Copilot entirely until every site is cleaned up?

Microsoft's guidance is to identify high-risk sites, apply interim controls such as Restricted Content Discovery or DLP for Copilot to those sites, and remediate access in parallel. Blocking everything reduces the value of Copilot and isn't required if the riskiest content is contained.

Microsoft 365 CopilotSharePoint Advanced ManagementSharePoint OnlineMicrosoft Purview
  1. Replace Restricted SharePoint Search with Restricted Content Discovery

    Restricted SharePoint Search is retiring. Inventory the allow list, apply Restricted Content Discovery to the sites that need it, verify propagation, then turn RSS off.

    AI engineering10 min read
  2. Audit, Retain and Search Microsoft 365 Copilot Prompts with Purview

    Find Copilot interactions in the Purview audit log, keep or delete prompts and responses with a retention policy, and search or purge them with eDiscovery when something goes wrong.

    AI engineering11 min read
  3. Control Web Search in Microsoft 365 Copilot and Copilot Chat: Admin Guide

    Allow, restrict or disable Bing web grounding for Copilot and Copilot Chat with the Cloud Policy setting, and understand exactly what leaves the tenant.

    AI engineering11 min read