Skip to Content
SharePointSharePoint Oversharing Audit (all broad access)

SharePoint Oversharing Audit

TL;DR: This skill audits sharing links by type across SharePoint Online sites, flags Anyone links and unapproved external recipients that breach your policy, and ranks sites by risk. For Everyone or Everyone Except External Users grants, use the EEEU sweep.

What does the SharePoint oversharing audit do?

The SharePoint oversharing audit is a read-only skill that reviews sharing links and site permissions across the SharePoint Online sites in scope. It flags Anyone links and external access that breach your organisation’s policy, then ranks sites by risk so administrators know where to remediate first.

It reads sharing permissions through Microsoft Graph (the driveItem permissions API). Microsoft states that Microsoft 365 Copilot respects existing permissions, so tightening broad and anonymous access is core Copilot-readiness work. Pair the findings with Microsoft Purview sensitivity labels: the Data access governance sensitivity labels for files report shows which sites hold labelled files.

When should you run this skill?

Run the audit before a Microsoft 365 Copilot rollout and then on a regular schedule. Microsoft recommends running site permissions snapshot reports quarterly and sharing-link and Everyone except external users activity reports monthly, because Copilot respects existing permissions and overshared sites raise the risk of unintended exposure.

Invoke this skill when asked to:

  • “Run an oversharing audit”
  • “Review sharing links”
  • “Check external access across our sites”
  • “Prepare sharing governance report”

Policy defaults (adjust to your organisation)

These are starting thresholds for this skill, not Microsoft defaults.

SettingDefault
Anyone linksNot permitted
External sharingAllowed only to named approved domains
Internal broad sharingFlagged if site has more than 50 unique users (a coarse count; claim-level detail is in the EEEU sweep)
Review periodPrevious 30 days

How this skill works, step by step

The skill works in seven read-only steps: it lists the sites in scope, retrieves each site’s active sharing links by type, flags Anyone links and unapproved external recipients, calculates a High, Medium or Low risk score using your thresholds, and compiles the results into a single remediation table for review.

  1. List all SharePoint Online sites in scope (or the selected site).
  2. For each site, retrieve active sharing links by type: Anyone, People in your organisation, Specific people.
  3. Flag any sites with Anyone links (policy breach).
  4. Flag sites sharing with external addresses not on the approved domain list.
  5. Note each site’s last review date if recorded.
  6. Calculate a risk score: High (Anyone link or more than 5 external), Medium (1 to 5 external), Low (internal broad only).
  7. Compile into the output table below.

Output format

Produce a Markdown table with these columns:

Site NameURLSharing TypeExternal RecipientsAnyone LinksRiskRecommended Action

Follow the table with a summary:

  • Total sites reviewed: N
  • High risk: N (requires immediate review)
  • Medium risk: N (schedule review within 30 days)
  • Low risk: N (monitor at next governance cycle)

Scope and safety

This skill is read-only by default and takes no destructive actions. It does NOT:

  • Remove or modify sharing links (read-only, no destructive actions)
  • Access email or calendar data
  • Assess permissions at the file level (site level only)

Licensing and permissions

Licences and add-ons

Capability usedRequirement
SharePoint Advanced Management capabilities, including Data access governance reportsA base subscription: Office 365 E3, E5 or A5; Microsoft 365 E1, E3, E5 or A5; or Microsoft 365 GCC, GCC-High or DoD. Plus at least one Microsoft Copilot licence assigned to a user, or (where the subscription includes SharePoint K, P1 or P2) the SharePoint Advanced Management Plan 1 add-on. Microsoft 365 E7 also qualifies
Data access governance reporting with Microsoft 365 E5 onlyActivity reports only, returning up to 10,000 sites, with no snapshot reports or remedial actions

Least-privilege roles

  • SharePoint Administrator to open the SharePoint admin center and run Data access governance reports
  • SharePoint Advanced Management Administrator where you also need advanced governance capabilities, such as removing permissions at scale (outside this skill’s read-only scope)

Microsoft Graph permissions (read-only)

For the list-permissions call on a driveItem, Microsoft lists these permissions:

  • Application: Files.Read.All (least privileged); Sites.Read.All is a higher-privileged alternative
  • Delegated (work or school account): Files.Read (least privileged); Files.Read.All and Sites.Read.All are higher-privileged alternatives

Grant the least-privileged option that works. The permissions needed to enumerate sites are not covered by that page, so confirm them in the Microsoft Graph permissions reference before granting consent.

Frequently asked questions

No. The skill is read-only and takes no destructive actions. It reports findings only. To stop sharing, Microsoft says to delete the Anyone link on the file or folder, turn off Anyone links for the site, or remove guest permissions from the item; an administrator does that separately.

Which licences do I need for SharePoint Advanced Management reports?

The SharePoint Advanced Management features need a supported base subscription such as Microsoft 365 E3 or E5 plus either at least one Microsoft Copilot licence assigned to a user or the SharePoint Advanced Management Plan 1 add-on. Microsoft 365 E5 alone gives Data access governance reporting only, without snapshot reports or remedial actions.

Which SharePoint reports help find oversharing?

Data access governance reports in the SharePoint admin center include snapshot reports, such as site permissions across your organisation, and activity reports covering sharing links (Anyone, People in the organisation and Specific people) and sharing with Everyone except external users over the last 28 days. The site permissions report includes Anyone link, guest permission, external participant and Everyone permission counts for each site.

How current is the site permissions report?

The first report can take up to 5 days and later reports complete within 24 hours. Data can be up to 48 hours old, and you can run the report again every 30 days. Sites with a NoAccess lock status and archived sites are excluded, so note them as a coverage gap.

Can Microsoft 365 Copilot expose overshared content?

Microsoft states that Copilot respects existing permissions, so a site with many permissioned users, Anyone links or Everyone except external users access carries higher risk of unintended exposure through Copilot interactions. The site permissions report highlights the top 100 sites by permissioned users to focus remediation where it matters most.

When should I run this instead of the EEEU sweep?

Run this audit when the question is who outside the organisation, or anonymously, can reach content: it covers link types, Anyone links and external recipients at site level. The EEEU sweep covers a narrower question: which sites, libraries and items grant access to the Everyone or Everyone Except External Users claims, scored by reach and label sensitivity. If you need both, run this audit first to close Anyone and external exposure, then run the sweep on the sites in scope.

Sources

Licensing, roles, report names, link types, cadence and Graph permissions were checked against the Microsoft Learn pages below (re-verified 2026-09-30). The thresholds, risk bands and step order are this skill’s own design, not Microsoft guidance.


Licensed under CC BY 4.0  by EDUC4TE .

SKILL.md— paste into Microsoft 365 Copilot or ClaudeDownload
▸ View skill file
How to use this skill
  1. Get the file. Download or copy the SKILL.md from the SKILL.md panel on this page.
  2. Load it into your host:
    • Microsoft 365 Copilot / Copilot Studio — add it as the instructions of a declarative agent or Copilot Studio agent.
    • Claude (Cowork / Claude Code) — drop the file into your skills folder; it loads as an Agent Skill automatically.
    • Any chat host — paste the file contents as your prompt.
  3. Grant read-only access. Assign the least-privilege roles and Microsoft Graph scopes listed in Licensing and permissions section of this article.
  4. Provide your tenant scope and run it (a site, a collection, or the whole tenant).
  5. Review the report and action the risk-ranked recommendations.

This skill is read-only by default — it inspects and reports, and never changes your tenant.

Get SKILL.md

Last reviewed 2026-10-01 · Published 2026-06-02

Last updated on