Frontrow Technology
← All insights & guides
Guide

Modern Workplace

Copilot oversharing: the shield-while-you-clean runbook

SharePoint Advanced Management comes with a Copilot licence, and its reports, Restricted Content Discovery and site access reviews sequence into a runbook that unblocks the rollout.

Simon Aspinall · 28 August 2026 · 10 min read

The standard advice on Copilot and SharePoint permissions is clean up first, roll out second. It is correct, and it has a failure mode: on a tenant with a decade of sprawl, the cleanup is a six-month project, the Copilot licences are already purchased, and the rollout stalls while the business pays for seats nobody is allowed to use. Frontrow's pre-flight checklist at /insights/sharepoint-onedrive-permissions-checklist-before-copilot covers what to fix; this runbook covers how to sequence the fixing so the rollout doesn't have to wait for it.

The sequence rests on a licensing fact plenty of tenants haven't noticed: assign at least one Microsoft 365 Copilot licence and SharePoint administrators get access to SharePoint Advanced Management (SAM) features, no separate add-on purchase required. SAM contains exactly the tooling the problem needs. The reports find the risky sites, Restricted Content Discovery shields those sites from Copilot while they get fixed, and site access reviews push the fixing out to the people who actually know what the content is. Shield while you clean, then unshield deliberately.

The sequence at a glance

  1. 1Run the Data Access Governance reports to get an oversharing baseline across the tenant.
  2. 2Pull the Everyone except external users report and treat every hit above a size threshold as unsafe until reviewed.
  3. 3Apply Restricted Content Discovery to the risky sites, which removes them from Copilot and tenant-wide search without touching a single permission.
  4. 4Kick off site access reviews so site owners recertify who should have access and fix the sharing that shouldn't exist.
  5. 5Unshield site by site, against exit criteria, with a date logged for each.

Copilot licences can go live after step three. That is the entire point of the pattern: the shield converts a rollout blocker into background remediation.

Step 1: baseline with the Data Access Governance reports

The Data Access Governance (DAG) reports live in the SharePoint admin centre and answer the question every Copilot readiness conversation starts with: which sites are shared more broadly than anyone intended. The sharing links reports surface sites with active Anyone links and organisation-wide links; the sensitivity label report shows which sites hold labelled content and which hold nothing but unlabelled files. Run them all, export, and rank sites by a simple product of breadth of access and likely sensitivity of content.

The patterns that surface are predictable. Frontrow documents the five most common at /insights/five-oversharing-patterns-australian-tenants, and the mechanism behind why Copilot turns them from embarrassing into urgent at /insights/copilot-permissions-trap. The short version: Copilot removes the difference between technically accessible and actually findable, so every stale broad share in the baseline is now one well-phrased question away from a screenshot.

Step 2: the Everyone except external users report

One report deserves its own step. Everyone except external users (EEEU) is the claim that includes every internal account in the tenant, and for fifteen years it has been the path of least resistance for anyone who wanted sharing to just work. It shows up on intranets that grew document libraries, on migrated file-server content where a lazy mapping granted it wholesale, and on sites where an owner clicked the biggest button available in 2019 and moved on.

The DAG report listing content shared with EEEU is the closest thing the tenant has to a map of Copilot blast radius, because everything on it is retrievable by every licensed user's Copilot session. Triage is blunt: for each site, either the content is genuinely meant for the whole organisation, or the EEEU grant comes off. The only decision the report can't make is which of those two it is, and that belongs to the site owner in step four.

Step 3: shield with Restricted Content Discovery

Restricted Content Discovery (RCD) is the SAM control that makes the parallel timeline honest. Applied to a site, it keeps that site's content out of tenant-wide search and out of Copilot and agent retrieval, while changing no permissions at all. People who work in the site keep their access, keep opening their files, and keep searching within the site itself. What changes is that the site's content stops being reachable through organisation-wide discovery, which is precisely the channel an ungoverned Copilot rollout exposes.

Apply RCD to the sites the baseline flagged: the EEEU report hits pending review, the sites carrying old Anyone links into sensitive libraries, the migrated file-server dump nobody has audited. This is not subtle work and it should not be. A site wrongly shielded costs a few search results for a few weeks; a site wrongly unshielded is the salary-spreadsheet demonstration that ends rollouts.

RCD is a different control from Restricted SharePoint Search, and the two get conflated constantly. Restricted SharePoint Search is a tenant-level allow-list: search and Copilot see only the sites explicitly approved, and everything else is dark by default. RCD is a per-site deny-list: the tenant stays open and specific sites go dark. For a tenant that is mostly fine with a risky minority, RCD preserves normal search for everyone while the minority gets fixed, which is why it is the better fit for the shield-while-you-clean pattern. For a tenant where nobody can even say which sites are fine, the allow-list model covered at /insights/restricted-sharepoint-search-copilot is the more defensible starting posture. The honest selector: deny-list when you can enumerate the problem, allow-list when you can only enumerate what's safe.

Step 4: site access reviews, run by owners

IT cannot decide whether the 2021 restructure folder should be visible to all staff. The site owner can, in about ninety seconds. SAM's site access reviews operationalise that: from a DAG report, an administrator initiates a review on a flagged site, and the site owner gets a task to walk through who has access and confirm or remove it. The work of judging content lands with the people who know the content, and IT's job collapses to chasing the laggards and processing the outcomes.

Two habits make reviews actually finish. Batch them, ten to twenty sites a fortnight, because two hundred simultaneous review requests get two hundred simultaneous ignores. And pair each review with the specific finding that triggered it: an owner told your site is shared with every person in the company through a grant added in March 2019 acts; an owner told please review your permissions files the email.

Step 5: unshield deliberately

The failure mode of any temporary control is becoming permanent by neglect, and a site left under RCD forever is content the organisation quietly lost from search. Unshielding needs exit criteria, checked per site: the EEEU grant is gone or affirmed as intentional, sharing links flagged in the baseline are pruned, the access review is complete and actioned, and sensitivity labels are applied where the site's content warrants them. When a site passes, remove RCD, log the date and the approver, and move on. A one-line register of shielded sites, trigger findings and unshield dates turns the whole exercise into something that can be shown to an auditor, a board, or a cyber insurer.

Try it

Score your tenant's oversharing risk first

Ten minutes across twelve dimensions, including the EEEU and sharing-link patterns this runbook shields against. The output is a sensible site list for step three.

Score each dimension · 4 options

Is your tenant ready for Microsoft 365 Copilot?

Copilot is as smart as your tenant is tidy. Twelve quick questions — each mapped to a Microsoft-native capability that closes the gap. Takes about ten minutes.

  • 01

    Anonymous "anyone with the link" shares

    External access

    How does your tenant handle anonymous sharing links?

  • 02

    Tenant-wide / "Everyone except external" site sharing

    Permissions hygiene

    Do you have sites shared with "Everyone" or "Everyone except external users"?

  • 03

    External guest access hygiene

    External access

    How do you manage external guest users in Entra ID?

  • 04

    Site collection admin sprawl

    Identity & privileged access

    How tightly is SharePoint site collection admin access controlled?

  • 05

    Broken permission inheritance

    Permissions hygiene

    How much unique (non-inherited) permissioning exists across your sites?

  • 06

    Orphaned sites with no active owner

    Permissions hygiene

    How do you handle sites whose owner has left or gone inactive?

  • 07

    OneDrive personal sharing patterns

    External access

    Do staff share sensitive documents (HR, finance, contracts) from OneDrive?

  • 08

    Sensitivity label coverage

    Content classification

    How much of your content is classified with Microsoft Purview sensitivity labels?

  • 09

    Restricted SharePoint Search / content discovery controls

    Content classification

    Have you enabled Restricted SharePoint Search or equivalent discovery controls for sensitive sites?

  • 10

    Microsoft Teams / Groups public vs private hygiene

    Permissions hygiene

    How strict is the hygiene on Team / Microsoft 365 Group privacy settings?

  • 11

    Legacy classic SharePoint sites

    Permissions hygiene

    Do you still have classic (pre-modern) SharePoint sites in the tenant?

  • 12

    Access review cadence for sensitive sites + external access

    Identity & privileged access

    How often do you review access to sensitive sites and external user lists?

Common questions

Frequently asked

Is SharePoint Advanced Management really included with a Copilot licence?
Yes. When an organisation assigns at least one Microsoft 365 Copilot licence, SharePoint administrators get access to SharePoint Advanced Management features without buying the standalone SAM add-on. Tenants that priced SAM separately a year or two ago and passed on it often don't realise the tooling is now sitting in their admin centre unused.
Does Restricted Content Discovery change who can access a site?
No. RCD changes discoverability, not permissions. Everyone who could open the site's files can still open them, and search within the site keeps working. What stops is the site's content appearing in tenant-wide search results and being retrieved by Copilot and agents. That is why it works as a shield: it takes the risk surface out of Copilot without breaking anyone's day job.
What's the difference between Restricted Content Discovery and Restricted SharePoint Search?
Direction. Restricted SharePoint Search is a tenant-level allow-list: only approved sites are visible to organisation-wide search and Copilot, everything else is dark. RCD is per-site: the tenant stays open and specific risky sites go dark. Use RCD when you can list the problem sites; use the allow-list when the governed sites are the only list you trust.
How long should sites stay shielded?
As short as the cleanup honestly takes, tracked per site rather than as one blanket window. In practice Frontrow sees most flagged sites clear their exit criteria inside one to three months of owner-driven review. The discipline that matters is the register: every shielded site has a trigger finding, a review status and an unshield date, so nothing stays dark by neglect.
Will users notice when RCD is applied?
Mostly no. People working inside a shielded site see no change. The people who notice are those who relied on tenant-wide search or Copilot to find that site's content from outside it, and for a site under review that is the behaviour being deliberately paused. A short note to affected site owners covers it.
Can Copilot licences go live before the permissions cleanup is finished?
That is the purpose of the sequence. Once the baseline is run and the risky sites are under RCD, Copilot's retrieval surface is limited to the sites that passed triage, and the rollout can proceed while reviews run in the background. The alternative, waiting for a full-tenant cleanup, generally means months of paid licences delivering nothing.

Want Frontrow to run this with your team?

A 30-minute call with a senior consultant. No deck. Frontrow walks through your tenant, your priorities and the next sensible move.