Nobody decided to share the payroll folder with the whole company. It happened one reasonable decision at a time.
Oversharing is never a single mistake. It is a site opened up for a project in 2022, a link sent to a contractor that never expired, a file share migrated with its permissions carried across as they were, and a site whose owner left. None of it was visible while finding a document required knowing it existed. All of it becomes visible the moment anything searches on a user behalf, which is why Copilot is usually the trigger for this work rather than the cause of the problem.
- Pre-existingCopilot exposes, it does not create
- EveryoneThe sharing scope to hunt first
- Orphaned sitesThe commonest finding
- RecurringOversharing regenerates
Eight sources, and none of them were a bad decision at the time.
Sharing with Everyone, or Everyone except external users
The highest-impact finding and the fastest to hunt for. A site or library granted to the organisation-wide group, usually so one person could get to it without anybody having to work out the right group. It stays that way indefinitely because nothing surfaces it, and it means any content added to that location afterwards is company-wide by default.
Sharing links that never expired
Anyone links created for a supplier, a candidate or a client, still live years later, frequently still forwarded around outside your tenant. Most organisations have thousands and have never inventoried them. Setting a default expiry going forward is straightforward; the accumulated back catalogue is the work.
Permissions inherited from a file server migration
The most consistent finding in Indian estates over the last few years, because so many organisations moved from on-premises file shares to SharePoint quickly. Migrating permissions as-is preserves twenty years of accumulated NTFS drift, including groups nobody can explain and access granted to people who left long ago.
Broken inheritance at item level
A library where inheritance was broken so one folder could be shared differently, repeated dozens of times over several years until the effective permissions on any given item can only be determined by checking. These are invisible from the site level and are why a site-by-site review understates the problem.
Orphaned and ownerless sites
The owner left, the project ended, and the site persists with its content and its sharing intact and nobody accountable for either. SharePoint Advanced Management identifies inactive, ownerless and uncertified sites specifically, and this is usually the largest single category by count in the estates we assess.
Access that survived a role change
Someone moved from finance to operations and kept both sets of access, because removing the old one required somebody to notice. Repeated across a few years of internal moves, this produces a small number of individuals who can reach almost everything, and they are rarely the people anybody would choose.
Copies, exports and personal OneDrive sprawl
A report exported to OneDrive to work on at home, a spreadsheet copied out of a restricted site into a shared one, an archive of departmental files somebody kept just in case. The copy carries none of the original access restrictions, so a control applied carefully to the source is defeated by a duplicate nobody knows about.
Sensitive content in the wrong place entirely
Compensation spreadsheets in a general HR site, board material in a leadership site shared more widely than intended, redundancy planning in a folder inherited from a previous restructure. These are the findings that pause a Copilot pilot, and they are usually about location rather than about permissions being technically wrong.
Twelve things we look for, in priority order.
Broad exposure
- Sites or libraries granted to Everyone except external usersThe single highest-impact finding
- Sites granted to the tenant-wide group by any other routeNested groups hide this from a casual review
- Anyone links with no expiry, especially on sensitive librariesFrequently thousands, rarely inventoried
- External guests with access they no longer needContractors and former partners persist for years
Ownership and lifecycle
- Ownerless sites, and sites whose owner has leftUsually the largest category by count
- Inactive sites with no access in a long periodCandidates for archive rather than remediation
- Sites created for projects that have endedContent is live, accountability is not
- Duplicate sites from migrations or reorganisationsThe old one is rarely locked down
Content in the wrong place
- Compensation, payroll and appraisal data outside restricted sitesThe classic pilot-pausing find
- Board, legal and corporate development materialCheck the leadership site sharing scope specifically
- Identity documents and scanned personal dataAlso a DPDP finding, not only a Copilot one
- Exports and copies sitting in personal OneDriveThe copy carries none of the original restrictions
Remediation ranked by exposure, not alphabetically.
We use the tooling your licence already activates
SharePoint Advanced Management supplies the content management assessment and site lifecycle tooling this work needs, and a single Microsoft 365 Copilot licence in the tenant activates it. We check entitlements before proposing any third-party governance product, and in the large majority of engagements none is needed.
We fix by impact, not by inventory order
A complete permissions inventory is a multi-month project and is not what makes an estate safe. We rank by what a search would surface first: broad-audience grants, sensitive content in open locations, then unexpired links, then lifecycle. That ordering makes a pilot safe in weeks rather than quarters.
We involve the owners rather than acting unilaterally
Removing access without asking breaks work and produces a backlash that stalls the whole programme. We identify who actually needs each location, confirm with the business owner, and communicate before changes land. Slower on paper, considerably faster in practice because nothing gets reverted.
We change the defaults so it does not rebuild
Cleaning up without tightening default sharing behaviour, link expiry and site provisioning means doing it again. We set the defaults as part of the engagement so the backlog cannot regenerate at the same rate, which is the difference between a project and a fix.
The dominant finding, by sector.
GCCs and technology
Deliberate openness as a cultural choice, which works well until something searches on your behalf. Engineering documentation, roadmaps and design material reachable far more widely than leadership assumes.
BFSI and fintech
Generally the tightest production systems and the loosest collaboration estate. Information barriers configured in one place and undermined by a shared site nobody mapped against them.
Manufacturing and engineering
Recent file server migrations with permissions carried across as-is, so decades of NTFS drift now lives in SharePoint. Drawings, specifications and supplier agreements are the sensitive categories.
Healthcare and diagnostics
Patient and staff data in departmental libraries created for a purpose that ended. Overlaps directly with DPDP data mapping, so the two are worth running as one exercise rather than two.
Professional services
Matter and client separation maintained by convention rather than by permission, which holds right up until somebody asks a question that crosses two clients.
Education
High turnover producing orphaned sites at scale, plus years of collaborative project sites nobody closed. Volume rather than sensitivity is usually the problem here.
Six actions, what each one costs you, and what it buys.
Removing organisation-wide grants
The highest value action available and usually the fastest, because the findings are few and concentrated. The work is not technical, it is establishing who genuinely needs each location so the replacement grant is right first time.
- Typically a small number of sites, found quickly by report
- Confirm the real audience with the business owner before changing anything
- Replace with a scoped group rather than removing access outright
Relocating sensitive content
Sometimes the permissions are technically correct and the content is simply in the wrong place, which is the case for most pilot-pausing findings. Moving it is faster and safer than restructuring the permissions around it.
- Compensation, board and legal material are the recurring categories
- Moving beats re-permissioning when the location was the mistake
- Check for copies before assuming the move resolved it
Clearing the sharing link backlog
Slower, because there are usually thousands and most are harmless. Prioritise links on sensitive libraries and links shared externally, and set a default expiry so the backlog stops growing while you work through it.
- Set default expiry first, since that stops the problem compounding
- Prioritise external and anonymous links over internal ones
- Expect some breakage, so communicate before bulk revocation
Resolving orphaned and inactive sites
The largest category by count and the least urgent by risk, which makes it ideal to run alongside a pilot rather than in front of it. Site lifecycle management identifies these directly, so the finding is cheap and the decision is the work.
- Assign an owner, archive, or delete, and each needs a human decision
- Attestation to a plausible owner is usually faster than investigating
- Archive rather than delete where retention obligations are unclear
Untangling migrated file share permissions
The slowest item and frequently the largest. Decades of accumulated drift carried into SharePoint cannot be reasoned about item by item at any sensible cost, so the practical approach is to rebuild the intended model at library level and migrate into it.
- Do not try to audit inherited permissions item by item
- Define the intended access model with the business, then apply it
- Run old and new in parallel briefly so nothing breaks silently
Reviewing external guests
Contractors, former partners, auditors and candidates who were given access for a defined purpose that ended. Usually straightforward to remediate and frequently the finding that most alarms a leadership team, because the names are recognisable and the dates are old.
- Review by last activity date, which sorts the list quickly
- Guest access expiry policies stop the list rebuilding indefinitely
- Check what they can reach, not only that they still have an account
Dealing with duplicates and copies
The finding that undermines everything else, because a carefully permissioned document is defeated by a copy somebody made into an open location. Harder than it sounds, since detection needs content inspection rather than a permissions report.
- Search for the sensitive content itself, not for the original location
- Personal OneDrive is where most problem copies live
- Sensitivity labels travel with the copy, which is why labelling helps here
Repairing broken inheritance
Libraries where inheritance was broken repeatedly over years, so effective permissions on any item can only be determined by checking it. Invisible from a site-level report, which is why a site-by-site review consistently understates the problem.
- Report on items with unique permissions rather than reviewing sites
- Restoring inheritance is safer than auditing each exception
- Expect a small number of legitimate exceptions, and document those
Applying labels so protection survives the copy
Permissions belong to a location and labels belong to the document, which is why labelling is the only control that still applies after somebody makes a copy. Worth doing alongside the permission work rather than as a separate later project.
- A label travels with the file into OneDrive, mail and downloads
- Automatic application beats asking users to classify
- This is also what makes Copilot honour your confidentiality markings
Changing the defaults so it does not rebuild
The item that determines whether this is a project or a fix. Default sharing scope, link expiry and type, external sharing posture, and how new sites are provisioned. Cheap to change, and the difference between holding the improvement and repeating the exercise in two years.
- Default link type set to specific people rather than anyone
- Default expiry applied to new links from the outset
- New sites provisioned with an owner and a review date attached
A one-off cleanup against a posture you maintain.
| Feature | Dimension | One-off cleanup | Maintained posture |
|---|---|---|---|
Trigger | A Copilot rollout or an incident | Scheduled, with the rollout as the starting point | |
Scope | Whatever the assessment surfaced that month | Reassessed as the estate changes | |
Default sharing settings | Left as they are | Tightened, so new sharing starts safer | |
Link expiry | Existing links cleaned, new ones unrestricted | Default expiry set, so the backlog cannot rebuild | |
Site ownership | Orphans fixed once | Ownership attested on a cycle | |
New sites | Created however people create them | Provisioned with a sensible default posture | |
State after eighteen months | Substantially back where it started | Broadly held, with known exceptions | |
Copilot expansion | Blocked again at the next cohort | Proceeds without a fresh cleanup |
Restricted SharePoint Search is scoping, not security.
It is a tenant-wide setting that limits Microsoft Search and Copilot grounding to an allow-list of up to one hundred SharePoint sites, and it is frequently misunderstood as a fix. It changes no permissions whatsoever. Everyone who could reach the excluded content before can still reach it, by navigating to it the way they always did. What it buys you is time: a pilot can run against verified sites while remediation continues elsewhere. Treated as the permanent answer, it hides an unresolved problem behind a setting somebody will eventually turn off.
- Useful for unblocking a pilot without waiting for a complete tenant cleanup
- Changes nothing about who can open what by direct navigation
- The allow-list is capped, so it does not scale as a governance model
- Have a dated plan to lift it, or the cleanup will not happen
Four stages to a searchable estate.
- 1
Assess, and rank by what search would surface
Content and permission risk across SharePoint and OneDrive, sharing link inventory, external guest review, and site lifecycle covering inactive, ownerless and uncertified sites. Output is a ranked remediation list rather than a full inventory, ordered by exposure rather than by site name.
- 2
Close the broad exposure first
Organisation-wide grants removed or scoped, sensitive content relocated where the problem is location rather than permission, unexpired links on sensitive libraries cleaned, and external guests reviewed. This is the work that makes a pilot safe, and it is typically a small fraction of the total inventory.
- 3
Deal with ownership and lifecycle
Orphaned sites given an owner or archived, inactive sites reviewed for archival, duplicates from migrations resolved. This is the largest category by count and the least urgent by risk, so it runs in parallel with a pilot rather than blocking it.
- 4
Set the defaults and the review cycle
Default sharing scope tightened, link expiry set, site provisioning given a sensible starting posture, and ownership attestation put on a recurring cycle. Without this the estate returns to where it started, which is the outcome we most want to avoid for you.
What to check on a cycle, and how often.
Monthly
- New sites created, and whether each has a named ownerThe cheapest moment to attach accountability
- Any new organisation-wide grantsShould be rare, and each one deliberate
- External guests added during the periodConfirm the purpose and set an end date
- Anonymous links created on sensitive librariesA short list once defaults are set correctly
Quarterly
- Site ownership attestationOwners confirm they still own it and the audience is right
- Sites with no activity in the periodArchive candidates before they become orphans
- Permission changes on sites holding sensitive contentA focused review rather than a tenant-wide one
- Guest accounts with no recent activityRemove rather than leaving indefinitely
Annually
- Full content and permission risk assessmentThe same report that started the cleanup
- Review of default sharing and link expiry settingsThey drift as people request exceptions
- Sensitivity label coverage against content growthAutomatic application needs its classifiers checked
- A search-time spot check performed as a real userThe most honest test of whether the estate is safe
Oversharing, answered plainly.
What this sits inside.
Copilot readiness
The wider readiness programme this usually forms part of: labels, identity hygiene, data residency, enablement and measurement.
Learn moreCopilot data governance
Sensitivity labels, what Copilot does with your content, data residency, and where the DPDP obligations intersect.
Learn moreMicrosoft SharePoint
SharePoint as a platform: intranet, document management, migration and the governance model underneath all of it.
Learn moreFind out what is shared with everybody.
The assessment runs mostly on tooling your Microsoft licensing already activates, and the serious findings are usually a short list in predictable places. Tell us roughly how large your estate is and whether you migrated from file shares, and we will tell you what to expect. Remote-first from Hyderabad, serving all of India.
Related Services
Explore more solutions that work great with this service
Copilot Readiness
Assess what Copilot would surface before it surfaces it
Learn moreSharePoint
SharePoint intranet and document management
Learn moreCopilot Data Governance
Residency, labels, retention and the DPDP intersection
Learn moreDPDP Data Mapping
Find the personal data you actually hold
Learn more