Fix SharePoint Oversharing Before You Buy Copilot: A 30-Day Cleanup Plan
Fix SharePoint oversharing before Copilot in 30 days: find exposure with SharePoint Advanced Management, contain it, hand fixes to site owners, then lock defaults.
Techrupt Team7 min read

Microsoft 365 Copilot answers from anything a user can already open. It doesn’t create new access, but it removes the obscurity that kept overshared content safe. A salary file in a site shared with “Everyone except external users” was always open to the whole company. Copilot makes it one prompt away. That is why oversharing, not licence cost, is what stops most Copilot rollouts.
For most organizations of 100 to 1,000 users, the fix fits in 30 days: a week to find the exposure, a week to contain the worst of it, a week to hand the cleanup to site owners, and a week to change the defaults so it doesn’t come back. The tools are SharePoint Advanced Management (SAM) and Microsoft Purview, and SAM comes with your first Copilot licence.
What you need before day one
Microsoft’s SAM prerequisites say SharePoint administrators get the Copilot-related SAM features once at least one user in the tenant is assigned a Microsoft 365 Copilot licence. The only other route is the SharePoint Advanced Management Plan 1 add-on.
So “before you buy Copilot” really means before you buy all of it. Assign a handful of pilot licences, use the SAM tools that come with them to clean up, then size the full purchase from pilot evidence. That order also avoids paying for seats you can’t use yet, which we cover in what a Copilot rollout actually costs in Canada.
You also need a SharePoint Administrator, and a named person in HR, finance and legal who can say which sites hold sensitive data. The technical work is the easy part. Knowing which sites matter is where the time goes.
The 30-day plan at a glance
| Week | Goal | Main tools | Done when |
|---|---|---|---|
| 1 | Find the exposure | Data access governance reports | You have a ranked list of high-risk sites |
| 2 | Contain the worst of it | Restricted Content Discovery, public team fixes | High-risk sites no longer appear in pilot users’ Copilot answers |
| 3 | Hand the fix to site owners | Site access reviews, site ownership policy | Most reviews are complete and sensitive sites have two owners |
| 4 | Change the defaults | Sharing settings, inactive site policy, sensitivity labels | New sharing is narrower by default and policies are running |
This is the “Permissions and oversharing” area of our free Microsoft 365 Copilot Readiness Assessment, and the one we treat as must-pass. A zero on any of its three questions means Copilot is likely to surface content it shouldn’t, whatever the rest of the score says.
Week 1: Find the exposure
In the SharePoint admin center, open Reports > Data access governance and run three reports.
Site permissions across your organization. This snapshot shows the sites with the broadest access, including sites with thousands of users, guests or “Everyone except external users” (EEEU) permissions. Microsoft recommends starting here.
Shared with ‘Everyone except external users’. This activity report covers the last 28 days. Content reaches EEEU through a public site or team, where EEEU becomes part of the membership, or through a file or folder shared with EEEU directly.
Sharing links. Also 28 days. It shows where people created the most “Anyone”, “People in your organization” and “Specific people” links.
Then sit down with HR, finance and legal and mark which broadly shared sites hold sensitive data. The most common finding in our assessments is not a bad tenant setting. It’s a public team created years ago for one project that now holds HR or client files nobody meant to publish.
What to measure: sites with EEEU or Everyone access, organization-wide and Anyone links created in 28 days, sites with fewer than two owners, and a ranked list of high-risk sites. These are your baseline for week 4.
Week 2: Contain the highest-risk sites
Some sites won’t be fixed before the pilot starts. For those, apply Restricted Content Discovery (RCD). In Active sites, open the site’s Settings tab and turn on Restrict content from Microsoft Copilot, or use PowerShell:
Set-SPOSite -Identity <site-url> -RestrictContentOrgWideSearch $true
RCD keeps a site out of organization-wide search and Copilot answers without changing permissions. Users can still open what they have access to and find content they own or recently worked on. Microsoft calls it a temporary control and warns that overuse makes Copilot answers less complete. Apply it early: the setting propagates through the search index, and a site with more than 500,000 items can take over a week.
Don’t plan around Restricted SharePoint Search. The older stopgap, an allow list of up to 100 sites, was never a security boundary, and it is retiring. New enablement has been blocked since July 31, 2026, so if it isn’t on already, you can’t turn it on. Use RCD.
Where a public team clearly shouldn’t be public, fix it rather than hide it. Switching a public Microsoft 365 group to private removes EEEU from the site’s Members group. For business-critical sites that should only open to one group, SAM’s restricted access control does that directly.
What to measure: every RCD site listed with an owner and a planned removal date. Test with a pilot account that Copilot no longer returns content from those sites, and confirm it in Microsoft Purview audit.
Week 3: Hand the fix to site owners
IT can’t judge whether the whole company should see a folder of contracts. The site owner can, and site access reviews put that question in front of them.
From the site permissions, EEEU or sharing links report, select sites and choose Initiate site access review. The web view takes up to 100 sites at a time, PowerShell handles more, and the site permissions report allows up to 1,000 reviews a month. Each owner gets an email about the specific issue found. From the review page they can remove EEEU, delete sharing links, fix group membership and complete the review with comments.
Customize that email and tell owners it’s coming. An unexpected “review your site permissions” email looks like phishing.
In the same week, create a site ownership policy under Site lifecycle management. Set a minimum of two owners and run it in simulation first. It can notify current owners, the managers of owners who have left, and active members who could take over.
What to measure: completion rate on the My review requests tab, EEEU and sharing link counts against your week 1 baseline, and sensitive sites still below two owners.
Week 4: Change the defaults so it doesn’t come back
Default sharing link. In the SharePoint admin center sharing settings, set File and folder links to Specific people, or at least Only people in your organization, with view as the default permission. Users can still pick a broader link, but most never change the default.
Organization-wide sharing. Turn off Anyone links, or make them expire and view-only. Microsoft’s Copilot setup guidance also recommends disabling EEEU at the tenant level.
Inactive site policy. Old sites are a quality problem as well as a risk, because Copilot can quote a 2019 policy as if it were current. After three monthly notifications without a response, the policy can do nothing, make the site read-only, or make it read-only and then archive it to Microsoft 365 Archive, which keeps the content out of Copilot.
Sensitivity labels. Permissions decide who can reach a file. Labels travel with it, and Purview DLP can stop Copilot from processing content with your most sensitive labels. Manual labelling comes with Microsoft 365 E3. Default labels for document libraries and auto-labelling need E5 or an E5 information protection add-on, as our Microsoft 365 licensing guide explains.
What to measure: new organization-wide and Anyone links per week against week 1, policies in active mode, and label coverage on your sensitive libraries. Then retake the readiness assessment. If the permissions area passes, widen the pilot.
Keeping it clean after launch
Oversharing creeps back as teams create new sites. Microsoft’s secure and governed data foundation blueprint follows the same order as this plan: find the risk, apply interim protection, fix access, set guardrails. The last step is a schedule, not a project.
| Check | How often | Where |
|---|---|---|
| Site permissions snapshot | Quarterly | Data access governance |
| EEEU and sharing links activity | Monthly | Data access governance |
| Site access reviews on sensitive sites | Twice a year | Data access governance |
| Sites still under RCD | Monthly, removing each once fixed | Start-SPORestrictedContentDiscoverabilityReport |
| Ownership and inactive site policies | Monthly, in active mode | Site lifecycle management |
| Copilot interactions with sensitive data | Ongoing | Microsoft Purview |
The report cadence is Microsoft’s own recommendation. A site still under RCD six months after launch is a site nobody fixed. The wider controls, from DLP to usage policy, are covered in how to roll out Copilot with AI guardrails.
Before you sign for the full seat count
Run the three data access governance reports this week. They tell you whether you’re facing a 30-day cleanup or a longer one, and that is worth knowing before the purchase order, not after.
Techrupt’s Microsoft Copilot consulting team runs this cleanup alongside your pilot, so the seat count you buy reflects what the pilot shows. Book a consultation and we’ll go through your reports with you.



