---
name: SharePoint Oversharing Audit
description: Site-level audit of SharePoint Online sharing links by type, flagging Anyone links and unapproved external recipients in a risk-ranked action table.
lastReviewed: 2026-10-01
---

# SharePoint Oversharing Audit

> **TL;DR:** This skill audits sharing links by type across SharePoint Online sites, flags Anyone links and unapproved external recipients that breach your policy, and ranks sites by risk. For Everyone or Everyone Except External Users grants, use the EEEU sweep.

## What does the SharePoint oversharing audit do?

The SharePoint oversharing audit is a read-only skill that reviews sharing links and site permissions across the SharePoint Online sites in scope. It flags Anyone links and external access that breach your organisation's policy, then ranks sites by risk so administrators know where to remediate first.

It reads sharing permissions through Microsoft Graph (the driveItem permissions API). Microsoft states that Microsoft 365 Copilot respects existing permissions, so tightening broad and anonymous access is core Copilot-readiness work. Pair the findings with Microsoft Purview sensitivity labels: the Data access governance sensitivity labels for files report shows which sites hold labelled files.

## When should you run this skill?

Run the audit before a Microsoft 365 Copilot rollout and then on a regular schedule. Microsoft recommends running site permissions snapshot reports quarterly and sharing-link and Everyone except external users activity reports monthly, because Copilot respects existing permissions and overshared sites raise the risk of unintended exposure.

Invoke this skill when asked to:

- "Run an oversharing audit"
- "Review sharing links"
- "Check external access across our sites"
- "Prepare sharing governance report"

## Policy defaults (adjust to your organisation)

These are starting thresholds for this skill, not Microsoft defaults.

| Setting | Default |
| --- | --- |
| Anyone links | Not permitted |
| External sharing | Allowed only to named approved domains |
| Internal broad sharing | Flagged if site has more than 50 unique users (a coarse count; claim-level detail is in the EEEU sweep) |
| Review period | Previous 30 days |

## How this skill works, step by step

The skill works in seven read-only steps: it lists the sites in scope, retrieves each site's active sharing links by type, flags Anyone links and unapproved external recipients, calculates a High, Medium or Low risk score using your thresholds, and compiles the results into a single remediation table for review.

1. List all SharePoint Online sites in scope (or the selected site).
2. For each site, retrieve active sharing links by type: Anyone, People in your organisation, Specific people.
3. Flag any sites with Anyone links (policy breach).
4. Flag sites sharing with external addresses not on the approved domain list.
5. Note each site's last review date if recorded.
6. Calculate a risk score: High (Anyone link or more than 5 external), Medium (1 to 5 external), Low (internal broad only).
7. Compile into the output table below.

## Output format

Produce a Markdown table with these columns:

| Site Name | URL | Sharing Type | External Recipients | Anyone Links | Risk | Recommended Action |
| --- | --- | --- | --- | --- | --- | --- |

Follow the table with a summary:

- Total sites reviewed: N
- High risk: N (requires immediate review)
- Medium risk: N (schedule review within 30 days)
- Low risk: N (monitor at next governance cycle)

## Scope and safety

This skill is read-only by default and takes no destructive actions. It does NOT:

- Remove or modify sharing links (read-only, no destructive actions)
- Access email or calendar data
- Assess permissions at the file level (site level only)

## Licensing and permissions

### Licences and add-ons

| Capability used | Requirement |
| --- | --- |
| SharePoint Advanced Management capabilities, including Data access governance reports | A base subscription: Office 365 E3, E5 or A5; Microsoft 365 E1, E3, E5 or A5; or Microsoft 365 GCC, GCC-High or DoD. Plus at least one Microsoft Copilot licence assigned to a user, or (where the subscription includes SharePoint K, P1 or P2) the SharePoint Advanced Management Plan 1 add-on. Microsoft 365 E7 also qualifies |
| Data access governance reporting with Microsoft 365 E5 only | Activity reports only, returning up to 10,000 sites, with no snapshot reports or remedial actions |

### Least-privilege roles

- SharePoint Administrator to open the SharePoint admin center and run Data access governance reports
- SharePoint Advanced Management Administrator where you also need advanced governance capabilities, such as removing permissions at scale (outside this skill's read-only scope)

### Microsoft Graph permissions (read-only)

For the list-permissions call on a driveItem, Microsoft lists these permissions:

- Application: `Files.Read.All` (least privileged); `Sites.Read.All` is a higher-privileged alternative
- Delegated (work or school account): `Files.Read` (least privileged); `Files.Read.All` and `Sites.Read.All` are higher-privileged alternatives

Grant the least-privileged option that works. The permissions needed to enumerate sites are not covered by that page, so confirm them in the Microsoft Graph permissions reference before granting consent.

## Frequently asked questions

### Does the oversharing audit change or remove sharing links?

No. The skill is read-only and takes no destructive actions. It reports findings only. To stop sharing, Microsoft says to delete the Anyone link on the file or folder, turn off Anyone links for the site, or remove guest permissions from the item; an administrator does that separately.

### Which licences do I need for SharePoint Advanced Management reports?

The SharePoint Advanced Management features need a supported base subscription such as Microsoft 365 E3 or E5 plus either at least one Microsoft Copilot licence assigned to a user or the SharePoint Advanced Management Plan 1 add-on. Microsoft 365 E5 alone gives Data access governance reporting only, without snapshot reports or remedial actions.

### Which SharePoint reports help find oversharing?

Data access governance reports in the SharePoint admin center include snapshot reports, such as site permissions across your organisation, and activity reports covering sharing links (Anyone, People in the organisation and Specific people) and sharing with Everyone except external users over the last 28 days. The site permissions report includes Anyone link, guest permission, external participant and Everyone permission counts for each site.

### How current is the site permissions report?

The first report can take up to 5 days and later reports complete within 24 hours. Data can be up to 48 hours old, and you can run the report again every 30 days. Sites with a NoAccess lock status and archived sites are excluded, so note them as a coverage gap.

### Can Microsoft 365 Copilot expose overshared content?

Microsoft states that Copilot respects existing permissions, so a site with many permissioned users, Anyone links or Everyone except external users access carries higher risk of unintended exposure through Copilot interactions. The site permissions report highlights the top 100 sites by permissioned users to focus remediation where it matters most.

## When should I run this instead of the EEEU sweep?

Run this audit when the question is who outside the organisation, or anonymously, can reach content: it covers link types, Anyone links and external recipients at site level. The [EEEU sweep](/sharepoint/everyone-except-external-users-sweep) covers a narrower question: which sites, libraries and items grant access to the Everyone or Everyone Except External Users claims, scored by reach and label sensitivity. If you need both, run this audit first to close Anyone and external exposure, then run the sweep on the sites in scope.

## Related skills

- [Everyone Except External Users (EEEU) Sweep](/sharepoint/everyone-except-external-users-sweep): run after for the narrower claim-level view of Everyone and Everyone Except External Users grants, down to item level.
- [External Sharing Deep Audit](/sharepoint/external-sharing-deep-audit): run after to inventory externally shared items by recipient domain and risk.
- [Sharing Links Activity Audit](/sharepoint/sharing-links-activity-audit): run after to analyse link creation, use and stale links.
- [Broken Permission Inheritance Audit](/sharepoint/broken-permission-inheritance-audit): run after to review unique permissions on flagged sites.
- [SharePoint Copilot Readiness Guide](/sharepoint/copilot-readiness-guide): the pillar guide that maps each oversharing step to a read-only skill.

## Sources

Licensing, roles, report names, link types, cadence and Graph permissions were checked against the Microsoft Learn pages below (re-verified 2026-09-30). The thresholds, risk bands and step order are this skill's own design, not Microsoft guidance.

- [Overview of external sharing in SharePoint and OneDrive in Microsoft 365](https://learn.microsoft.com/en-us/sharepoint/external-sharing-overview)
- [Data access governance reports for SharePoint and OneDrive sites](https://learn.microsoft.com/en-us/sharepoint/data-access-governance-reports)
- [Site permissions for your organization report](https://learn.microsoft.com/en-us/sharepoint/data-access-governance-site-permissions-report)
- [Prerequisites for SharePoint Advanced Management](https://learn.microsoft.com/en-us/sharepoint/sharepoint-advanced-management-prerequisites)
- [Microsoft Graph permissions reference](https://learn.microsoft.com/en-us/graph/permissions-reference)
- [List sharing permissions on a driveItem](https://learn.microsoft.com/en-us/graph/api/driveitem-list-permissions)
