---
name: Everyone Except External Users (EEEU) Sweep
description: Item-level sweep for SharePoint content granted to Everyone or Everyone Except External Users, scored by reach and label sensitivity, then risk-ranked.
lastReviewed: 2026-06-02
---

# Everyone Except External Users (EEEU) Sweep

> **TL;DR:** This skill finds SharePoint sites, libraries and items granted to the "Everyone" or "Everyone Except External Users" claims, scores each by reach and sensitivity, and ranks them. It does not audit Anyone links or external sharing; use the oversharing audit for that.

## What does the EEEU sweep check in SharePoint Online?

This skill scans SharePoint Online and Microsoft Graph for permissions granted to the "Everyone Except External Users" (EEEU) and "Everyone" claims, which silently give every internal account access to content. Because Microsoft 365 Copilot honours existing permissions, content granted to these claims can be surfaced to any internal user during a Copilot rollout. The sweep maps each grant back to its site, library and item so you can apply least-privilege remediation. It reads from Data Access Governance signals and Graph permission data without changing anything.

## When should you run this skill?

- "Find Everyone Except External Users links across our tenant"
- "Show me where EEEU gives broad access before we enable Copilot"
- "Which sites grant access to Everyone or all internal users?"
- "Audit our oversharing risk for Microsoft 365 Copilot readiness"
- "List files anyone in the organisation can open"
- "Where are the worst least-privilege violations in SharePoint?"

## How this skill works, step by step

1. Connect read-only to Microsoft Graph and SharePoint Online with delegated assessment scopes.
2. Enumerate sites in scope, prioritising those flagged in Data Access Governance reports.
3. Inspect site, library and item permissions for the EEEU and "Everyone" claims.
4. Resolve each claim to the principals it actually grants (all internal users, or all users).
5. Detect sensitivity labels and content type signals on affected items to gauge impact.
6. Score each finding by reach (number of users), content sensitivity and exposure breadth.
7. Aggregate findings per site and rank from highest to lowest residual risk.
8. Recommend a least-privilege remediation action for each finding.
9. Compile the risk-ranked output without writing any change to the tenant.

## Output format

The skill returns a ranked table of EEEU and Everyone exposures, one row per affected site or item.

| Site | Claim | Sensitivity | Risk | Recommended action |
| --- | --- | --- | --- | --- |
| Finance Hub | EEEU | Confidential | High | Replace EEEU with named owners group |
| Project Atlas | Everyone | General | Medium | Scope to project members only |
| Team Wiki | EEEU | General | Low | Confirm intent; document exception |

Summary:

- Total sites reviewed: 142
- Sites with EEEU or Everyone grants: 37
- High risk: 9
- Medium risk: 14
- Low risk: 14

## Scope and safety

This skill is read-only by default and makes no changes to permissions, sharing settings or content.

This skill does NOT:

- Remove, modify or replace any EEEU, Everyone or other permission grant.
- Alter sharing policies, sensitivity labels or site configuration.
- Notify users or site owners of the findings.
- Audit Anyone links or external recipients (the [SharePoint Oversharing Audit](/sharepoint/sharepoint-oversharing-audit) covers those).
- Access file content beyond the metadata needed to score risk.

## Licensing and permissions

### Licences and add-ons

| Capability used | Minimum licence |
| --- | --- |
| Read SharePoint and Graph permissions, sensitivity labels | Microsoft 365 E3 (E5 for richer sensitivity label signals) |
| Data Access Governance reports (EEEU and Everyone oversharing) | SharePoint Advanced Management (SAM), included with Microsoft 365 E5 or sold as an add-on |

### Least-privilege roles

- Global Reader (read-only tenant-wide visibility)
- SharePoint Administrator (read-only use; required to open Data Access Governance reports)

### Microsoft Graph permissions (read-only)

- `Sites.Read.All` — enumerate sites and read their permission grants
- `Files.Read.All` — read library and item permissions and metadata
- `Group.Read.All` — resolve group-based principals behind EEEU and Everyone claims
- `InformationProtectionPolicy.Read.All` — read sensitivity label definitions to gauge content impact

The Data Access Governance reports themselves are viewed in the SharePoint admin centre and are not exposed through Microsoft Graph; open them with a SharePoint Administrator or Global Reader role.

## When should I run this instead of the oversharing audit?

Run this sweep when the question is which content every internal account can reach: it resolves the Everyone and Everyone Except External Users claims down to site, library and item, scored by reach and label sensitivity. The [SharePoint Oversharing Audit](/sharepoint/sharepoint-oversharing-audit) covers the wider question of Anyone links, link types and external recipients at site level. If you need both, run the audit first, then this sweep on the sites in scope.

## Related skills

- [SharePoint Oversharing Audit](/sharepoint/sharepoint-oversharing-audit): run first to close Anyone and external exposure, then use this sweep for the broad internal claims.
- [Site Permissions Baseline](/sharepoint/site-permissions-baseline): run alongside to snapshot owners, broad access and broken-inheritance scopes on the flagged sites.
- [Broken Permission Inheritance Audit](/sharepoint/broken-permission-inheritance-audit): run after to review unique permissions on the sites this sweep flags.
- [SharePoint Copilot Readiness Guide](/sharepoint/copilot-readiness-guide): the pillar guide that places this sweep in the full oversharing-fix sequence.
- [Microsoft Purview Copilot Governance Guide](/purview/copilot-governance-guide): run after remediation to check the Purview controls documented for Microsoft 365 Copilot.

## Sources and compliance

- [Data access governance reports](https://learn.microsoft.com/en-us/sharepoint/data-access-governance-reports)
- [Build a secure and governed data foundation for Microsoft 365 Copilot](https://learn.microsoft.com/en-us/microsoft-365/copilot/microsoft-365-copilot-secure-governed-data)
- Maps to Essential Eight: Restrict administrative privileges (least privilege over broad access grants).
- Aligns with ISM controls for access control and need-to-know data handling.
- Reference: [ASD Essential Eight Maturity Model](https://www.cyber.gov.au/resources-business-and-government/essential-cyber-security/essential-eight/essential-eight-maturity-model)
