---
name: SharePoint Advanced Management Governance Audit
description: "Audit SharePoint Advanced Management: data access governance reports, restricted access control, site ownership policies and AI readiness signals."
lastReviewed: 2026-06-22
---

# SharePoint Advanced Management Site Governance Audit

> **TL;DR:** This skill audits the Microsoft SharePoint Advanced Management capability set — data access governance, restricted access control, site ownership policies, and Copilot readiness — to surface governance gaps in the SharePoint estate and produce a prioritised remediation table.

## What does the SharePoint Advanced Management site governance audit cover?

Microsoft SharePoint Advanced Management (SAM), included in Microsoft 365 E5 and available as an add-on, provides a set of governance capabilities that extend beyond the base SharePoint Online feature set. It includes data access governance (DAG) reports surfacing over-shared sites, restricted access control for site-level data perimeters, site ownership policies that enforce minimum active-owner requirements, and change history for governance events. As organisations roll out Microsoft 365 Copilot, SAM's restricted access control becomes a critical data perimeter control: it limits which users' prompts can return content from high-sensitivity sites. This skill audits the SAM configuration and reports, identifies sites without active owners, surfaces sites flagged in DAG reports as over-shared, confirms whether restricted access control is deployed for Highly Confidential sites, and checks whether the site lifecycle policy is configured.

## When should you run this skill?

- "Audit SharePoint Advanced Management configuration"
- "Which sites are flagged in data access governance reports?"
- "Find SharePoint sites with no active owner"
- "Check if restricted access control is enabled for sensitive sites"
- "Review SAM governance configuration before Copilot rollout"
- "Audit SharePoint site ownership policies"

## How this skill works, step by step

1. Open the SharePoint admin centre → Reports → Data access governance
2. Export the "Sites shared externally" and "Sites with sensitivity labels" DAG reports
3. In the SharePoint admin centre → Policies → Sharing, confirm the site-level sharing override is set to require admin approval for new guest invitations on sensitive sites
4. Navigate to SharePoint admin centre → Sites → Active sites → filter for sites with no owners or only inactive owners (last activity > 90 days) using the site ownership policy report
5. Run `Get-SPOSite -Filter {RestrictedAccessControl -eq $true}` via SharePoint Online Management Shell to list sites with restricted access control (RAC) enabled
6. Identify Highly Confidential or PROTECTED-labelled sites that do NOT have RAC enabled — these are Copilot grounding risks
7. Review the site lifecycle policy: SharePoint admin centre → Policies → Site lifecycle management — confirm active-owner attestation is enabled and the expiry period is set
8. Export the change history report for governance events in the review period
9. Score each finding: High (Highly Confidential site without RAC or no active owner), Medium (over-shared site in DAG report, no lifecycle policy), Low (minor configuration gap)

## Output format

| Site | Sensitivity Label | Restricted Access Control | Active Owner | DAG Flag | Risk | Recommendation |
| --- | --- | --- | --- | --- | --- | --- |
| /sites/ExecComms | Highly Confidential | No | Yes | No | High | Enable restricted access control |
| /sites/ProjectAlpha | Confidential | Yes | No | Yes | High | Assign active owner, trigger attestation |
| /sites/HRPolicies | Confidential | Yes | Yes | No | Low | Compliant |

Summary:

- Sites with restricted access control: N of N sensitive-labelled sites
- Sites with no active owner: N
- Sites flagged in DAG over-sharing reports: N
- Site lifecycle policy active: Yes/No
- High-risk sites: N

## Scope and safety

Read-only by default — this skill does NOT:

- Modify site permissions or sharing settings
- Enable restricted access control on any site
- Assign or remove site owners

## Licensing and permissions

### Licences and add-ons

| Capability used | Minimum licence |
| --- | --- |
| SharePoint Advanced Management (DAG reports, site ownership policy, restricted access control) | Microsoft 365 E5, or SharePoint Advanced Management add-on |
| Restricted access control (RAC) for Copilot data perimeter | SharePoint Advanced Management add-on |

### Least-privilege roles

- SharePoint Administrator (read DAG reports, site ownership policy, restricted access control status)
- Global Reader (read-only tenant-wide SharePoint admin centre access)

### Microsoft Graph permissions (read-only)

- `Sites.Read.All` — enumerate SharePoint sites and their configuration properties
- `Sites.FullControl.All` is NOT required — read-only review only
- DAG reports and site ownership policy data are accessed through SharePoint admin centre and SharePoint Online Management Shell (`Get-SPOSite`, `Get-SPOSiteGroup`)

## Related skills

- [Data Access Governance Report Review](/sharepoint/data-access-governance-report-review): run after to interpret the Data Access Governance reports and plan remediation.
- [SharePoint Oversharing Audit](/sharepoint/sharepoint-oversharing-audit): run alongside to review sharing links and site permissions directly.
- [Site Lifecycle Review](/sharepoint/site-lifecycle-review): run after to review inactive and ownerless sites.
- [SharePoint Copilot Readiness Guide](/sharepoint/copilot-readiness-guide): the pillar guide that places this audit in the Copilot-readiness sequence.
- [Microsoft Purview Copilot Governance Guide](/purview/copilot-governance-guide): run after to review the Purview controls documented for Microsoft 365 Copilot.

## Sources and compliance

- [SharePoint Advanced Management overview (Microsoft Learn)](https://learn.microsoft.com/en-us/sharepoint/advanced-management)
- [Restricted access control for SharePoint sites (Microsoft Learn)](https://learn.microsoft.com/en-us/sharepoint/restricted-access-control)
- [Data access governance reports for SharePoint (Microsoft Learn)](https://learn.microsoft.com/en-us/sharepoint/data-access-governance-reports)
- Aligns with PSPF protective marking requirements: restricted access control limits Copilot grounding for PROTECTED content
- Pair with SharePoint Oversharing Audit and External Sharing Deep Audit for complete SharePoint governance coverage
