Skip to main content
SharePoint oversharing, India

Nobody decided to share the payroll folder with the whole company. It happened one reasonable decision at a time.

Oversharing is never a single mistake. It is a site opened up for a project in 2022, a link sent to a contractor that never expired, a file share migrated with its permissions carried across as they were, and a site whose owner left. None of it was visible while finding a document required knowing it existed. All of it becomes visible the moment anything searches on a user behalf, which is why Copilot is usually the trigger for this work rather than the cause of the problem.

Microsoft
Microsoft
SharePoint
Cloud Solution Partner
  • Pre-existingCopilot exposes, it does not create
  • EveryoneThe sharing scope to hunt first
  • Orphaned sitesThe commonest finding
  • RecurringOversharing regenerates
Where oversharing comes from

Eight sources, and none of them were a bad decision at the time.

Understanding how a tenant got here matters, because the remediation differs by cause and because blaming users produces resistance rather than cleanup. Every one of these was a sensible action taken under time pressure by somebody trying to get work done.

Sharing with Everyone, or Everyone except external users

The highest-impact finding and the fastest to hunt for. A site or library granted to the organisation-wide group, usually so one person could get to it without anybody having to work out the right group. It stays that way indefinitely because nothing surfaces it, and it means any content added to that location afterwards is company-wide by default.

Sharing links that never expired

Anyone links created for a supplier, a candidate or a client, still live years later, frequently still forwarded around outside your tenant. Most organisations have thousands and have never inventoried them. Setting a default expiry going forward is straightforward; the accumulated back catalogue is the work.

Permissions inherited from a file server migration

The most consistent finding in Indian estates over the last few years, because so many organisations moved from on-premises file shares to SharePoint quickly. Migrating permissions as-is preserves twenty years of accumulated NTFS drift, including groups nobody can explain and access granted to people who left long ago.

Broken inheritance at item level

A library where inheritance was broken so one folder could be shared differently, repeated dozens of times over several years until the effective permissions on any given item can only be determined by checking. These are invisible from the site level and are why a site-by-site review understates the problem.

Orphaned and ownerless sites

The owner left, the project ended, and the site persists with its content and its sharing intact and nobody accountable for either. SharePoint Advanced Management identifies inactive, ownerless and uncertified sites specifically, and this is usually the largest single category by count in the estates we assess.

Access that survived a role change

Someone moved from finance to operations and kept both sets of access, because removing the old one required somebody to notice. Repeated across a few years of internal moves, this produces a small number of individuals who can reach almost everything, and they are rarely the people anybody would choose.

Copies, exports and personal OneDrive sprawl

A report exported to OneDrive to work on at home, a spreadsheet copied out of a restricted site into a shared one, an archive of departmental files somebody kept just in case. The copy carries none of the original access restrictions, so a control applied carefully to the source is defeated by a duplicate nobody knows about.

Sensitive content in the wrong place entirely

Compensation spreadsheets in a general HR site, board material in a leadership site shared more widely than intended, redundancy planning in a folder inherited from a previous restructure. These are the findings that pause a Copilot pilot, and they are usually about location rather than about permissions being technically wrong.

The hunt

Twelve things we look for, in priority order.

Ranked by what an AI assistant or an enterprise search would surface first, which is a different order from a conventional permissions review. The point is to make the estate safe to search, not to make it perfect.

Broad exposure

  • Sites or libraries granted to Everyone except external users
    The single highest-impact finding
  • Sites granted to the tenant-wide group by any other route
    Nested groups hide this from a casual review
  • Anyone links with no expiry, especially on sensitive libraries
    Frequently thousands, rarely inventoried
  • External guests with access they no longer need
    Contractors and former partners persist for years

Ownership and lifecycle

  • Ownerless sites, and sites whose owner has left
    Usually the largest category by count
  • Inactive sites with no access in a long period
    Candidates for archive rather than remediation
  • Sites created for projects that have ended
    Content is live, accountability is not
  • Duplicate sites from migrations or reorganisations
    The old one is rarely locked down

Content in the wrong place

  • Compensation, payroll and appraisal data outside restricted sites
    The classic pilot-pausing find
  • Board, legal and corporate development material
    Check the leadership site sharing scope specifically
  • Identity documents and scanned personal data
    Also a DPDP finding, not only a Copilot one
  • Exports and copies sitting in personal OneDrive
    The copy carries none of the original restrictions
How we work

Remediation ranked by exposure, not alphabetically.

We use the tooling your licence already activates

SharePoint Advanced Management supplies the content management assessment and site lifecycle tooling this work needs, and a single Microsoft 365 Copilot licence in the tenant activates it. We check entitlements before proposing any third-party governance product, and in the large majority of engagements none is needed.

We fix by impact, not by inventory order

A complete permissions inventory is a multi-month project and is not what makes an estate safe. We rank by what a search would surface first: broad-audience grants, sensitive content in open locations, then unexpired links, then lifecycle. That ordering makes a pilot safe in weeks rather than quarters.

We involve the owners rather than acting unilaterally

Removing access without asking breaks work and produces a backlash that stalls the whole programme. We identify who actually needs each location, confirm with the business owner, and communicate before changes land. Slower on paper, considerably faster in practice because nothing gets reverted.

We change the defaults so it does not rebuild

Cleaning up without tightening default sharing behaviour, link expiry and site provisioning means doing it again. We set the defaults as part of the engagement so the backlog cannot regenerate at the same rate, which is the difference between a project and a fix.

What we find

The dominant finding, by sector.

GCCs and technology

Deliberate openness as a cultural choice, which works well until something searches on your behalf. Engineering documentation, roadmaps and design material reachable far more widely than leadership assumes.

BFSI and fintech

Generally the tightest production systems and the loosest collaboration estate. Information barriers configured in one place and undermined by a shared site nobody mapped against them.

Manufacturing and engineering

Recent file server migrations with permissions carried across as-is, so decades of NTFS drift now lives in SharePoint. Drawings, specifications and supplier agreements are the sensitive categories.

Healthcare and diagnostics

Patient and staff data in departmental libraries created for a purpose that ended. Overlaps directly with DPDP data mapping, so the two are worth running as one exercise rather than two.

Professional services

Matter and client separation maintained by convention rather than by permission, which holds right up until somebody asks a question that crosses two clients.

Education

High turnover producing orphaned sites at scale, plus years of collaborative project sites nobody closed. Volume rather than sensitivity is usually the problem here.

The remediation

Six actions, what each one costs you, and what it buys.

Remediation is not uniformly difficult. Two of these are quick and high value, two are slow and unavoidable, and two are about preventing the problem returning. Knowing which is which is what lets you make an estate safe in weeks rather than quarters.

Removing organisation-wide grants

The highest value action available and usually the fastest, because the findings are few and concentrated. The work is not technical, it is establishing who genuinely needs each location so the replacement grant is right first time.

  • Typically a small number of sites, found quickly by report
  • Confirm the real audience with the business owner before changing anything
  • Replace with a scoped group rather than removing access outright

Relocating sensitive content

Sometimes the permissions are technically correct and the content is simply in the wrong place, which is the case for most pilot-pausing findings. Moving it is faster and safer than restructuring the permissions around it.

  • Compensation, board and legal material are the recurring categories
  • Moving beats re-permissioning when the location was the mistake
  • Check for copies before assuming the move resolved it

Clearing the sharing link backlog

Slower, because there are usually thousands and most are harmless. Prioritise links on sensitive libraries and links shared externally, and set a default expiry so the backlog stops growing while you work through it.

  • Set default expiry first, since that stops the problem compounding
  • Prioritise external and anonymous links over internal ones
  • Expect some breakage, so communicate before bulk revocation

Resolving orphaned and inactive sites

The largest category by count and the least urgent by risk, which makes it ideal to run alongside a pilot rather than in front of it. Site lifecycle management identifies these directly, so the finding is cheap and the decision is the work.

  • Assign an owner, archive, or delete, and each needs a human decision
  • Attestation to a plausible owner is usually faster than investigating
  • Archive rather than delete where retention obligations are unclear

Untangling migrated file share permissions

The slowest item and frequently the largest. Decades of accumulated drift carried into SharePoint cannot be reasoned about item by item at any sensible cost, so the practical approach is to rebuild the intended model at library level and migrate into it.

  • Do not try to audit inherited permissions item by item
  • Define the intended access model with the business, then apply it
  • Run old and new in parallel briefly so nothing breaks silently

Reviewing external guests

Contractors, former partners, auditors and candidates who were given access for a defined purpose that ended. Usually straightforward to remediate and frequently the finding that most alarms a leadership team, because the names are recognisable and the dates are old.

  • Review by last activity date, which sorts the list quickly
  • Guest access expiry policies stop the list rebuilding indefinitely
  • Check what they can reach, not only that they still have an account

Dealing with duplicates and copies

The finding that undermines everything else, because a carefully permissioned document is defeated by a copy somebody made into an open location. Harder than it sounds, since detection needs content inspection rather than a permissions report.

  • Search for the sensitive content itself, not for the original location
  • Personal OneDrive is where most problem copies live
  • Sensitivity labels travel with the copy, which is why labelling helps here

Repairing broken inheritance

Libraries where inheritance was broken repeatedly over years, so effective permissions on any item can only be determined by checking it. Invisible from a site-level report, which is why a site-by-site review consistently understates the problem.

  • Report on items with unique permissions rather than reviewing sites
  • Restoring inheritance is safer than auditing each exception
  • Expect a small number of legitimate exceptions, and document those

Applying labels so protection survives the copy

Permissions belong to a location and labels belong to the document, which is why labelling is the only control that still applies after somebody makes a copy. Worth doing alongside the permission work rather than as a separate later project.

  • A label travels with the file into OneDrive, mail and downloads
  • Automatic application beats asking users to classify
  • This is also what makes Copilot honour your confidentiality markings

Changing the defaults so it does not rebuild

The item that determines whether this is a project or a fix. Default sharing scope, link expiry and type, external sharing posture, and how new sites are provisioned. Cheap to change, and the difference between holding the improvement and repeating the exercise in two years.

  • Default link type set to specific people rather than anyone
  • Default expiry applied to new links from the outset
  • New sites provisioned with an owner and a review date attached
Two approaches

A one-off cleanup against a posture you maintain.

Oversharing regenerates, because the behaviours that caused it are the behaviours that make collaboration work. A cleanup with no maintenance is measurably back to where it started within a year or two.
Feature
Dimension
One-off cleanup
Maintained posture
Trigger
A Copilot rollout or an incidentScheduled, with the rollout as the starting point
Scope
Whatever the assessment surfaced that monthReassessed as the estate changes
Default sharing settings
Left as they areTightened, so new sharing starts safer
Link expiry
Existing links cleaned, new ones unrestrictedDefault expiry set, so the backlog cannot rebuild
Site ownership
Orphans fixed onceOwnership attested on a cycle
New sites
Created however people create themProvisioned with a sensible default posture
State after eighteen months
Substantially back where it startedBroadly held, with known exceptions
Copilot expansion
Blocked again at the next cohortProceeds without a fresh cleanup

Restricted SharePoint Search is scoping, not security.

It is a tenant-wide setting that limits Microsoft Search and Copilot grounding to an allow-list of up to one hundred SharePoint sites, and it is frequently misunderstood as a fix. It changes no permissions whatsoever. Everyone who could reach the excluded content before can still reach it, by navigating to it the way they always did. What it buys you is time: a pilot can run against verified sites while remediation continues elsewhere. Treated as the permanent answer, it hides an unresolved problem behind a setting somebody will eventually turn off.

  • Useful for unblocking a pilot without waiting for a complete tenant cleanup
  • Changes nothing about who can open what by direct navigation
  • The allow-list is capped, so it does not scale as a governance model
  • Have a dated plan to lift it, or the cleanup will not happen
The engagement

Four stages to a searchable estate.

  1. 1

    Assess, and rank by what search would surface

    Content and permission risk across SharePoint and OneDrive, sharing link inventory, external guest review, and site lifecycle covering inactive, ownerless and uncertified sites. Output is a ranked remediation list rather than a full inventory, ordered by exposure rather than by site name.

  2. 2

    Close the broad exposure first

    Organisation-wide grants removed or scoped, sensitive content relocated where the problem is location rather than permission, unexpired links on sensitive libraries cleaned, and external guests reviewed. This is the work that makes a pilot safe, and it is typically a small fraction of the total inventory.

  3. 3

    Deal with ownership and lifecycle

    Orphaned sites given an owner or archived, inactive sites reviewed for archival, duplicates from migrations resolved. This is the largest category by count and the least urgent by risk, so it runs in parallel with a pilot rather than blocking it.

  4. 4

    Set the defaults and the review cycle

    Default sharing scope tightened, link expiry set, site provisioning given a sensible starting posture, and ownership attestation put on a recurring cycle. Without this the estate returns to where it started, which is the outcome we most want to avoid for you.

Keeping it clean

What to check on a cycle, and how often.

Oversharing regenerates, because the behaviours that cause it are the behaviours that make collaboration work. These are the recurring checks that keep the regeneration rate manageable, with the cadence we recommend for a mid-sized estate.

Monthly

  • New sites created, and whether each has a named owner
    The cheapest moment to attach accountability
  • Any new organisation-wide grants
    Should be rare, and each one deliberate
  • External guests added during the period
    Confirm the purpose and set an end date
  • Anonymous links created on sensitive libraries
    A short list once defaults are set correctly

Quarterly

  • Site ownership attestation
    Owners confirm they still own it and the audience is right
  • Sites with no activity in the period
    Archive candidates before they become orphans
  • Permission changes on sites holding sensitive content
    A focused review rather than a tenant-wide one
  • Guest accounts with no recent activity
    Remove rather than leaving indefinitely

Annually

  • Full content and permission risk assessment
    The same report that started the cleanup
  • Review of default sharing and link expiry settings
    They drift as people request exceptions
  • Sensitivity label coverage against content growth
    Automatic application needs its classifiers checked
  • A search-time spot check performed as a real user
    The most honest test of whether the estate is safe
Questions we get asked

Oversharing, answered plainly.

Next step

Find out what is shared with everybody.

The assessment runs mostly on tooling your Microsoft licensing already activates, and the serious findings are usually a short list in predictable places. Tell us roughly how large your estate is and whether you migrated from file shares, and we will tell you what to expect. Remote-first from Hyderabad, serving all of India.