The standard advice on Copilot and SharePoint permissions is clean up first, roll out second. It is correct, and it has a failure mode: on a tenant with a decade of sprawl, the cleanup is a six-month project, the Copilot licences are already purchased, and the rollout stalls while the business pays for seats nobody is allowed to use. Frontrow's pre-flight checklist at /insights/sharepoint-onedrive-permissions-checklist-before-copilot covers what to fix; this runbook covers how to sequence the fixing so the rollout doesn't have to wait for it.
The sequence rests on a licensing fact plenty of tenants haven't noticed: assign at least one Microsoft 365 Copilot licence and SharePoint administrators get access to SharePoint Advanced Management (SAM) features, no separate add-on purchase required. SAM contains exactly the tooling the problem needs. The reports find the risky sites, Restricted Content Discovery shields those sites from Copilot while they get fixed, and site access reviews push the fixing out to the people who actually know what the content is. Shield while you clean, then unshield deliberately.
The sequence at a glance
- 1Run the Data Access Governance reports to get an oversharing baseline across the tenant.
- 2Pull the Everyone except external users report and treat every hit above a size threshold as unsafe until reviewed.
- 3Apply Restricted Content Discovery to the risky sites, which removes them from Copilot and tenant-wide search without touching a single permission.
- 4Kick off site access reviews so site owners recertify who should have access and fix the sharing that shouldn't exist.
- 5Unshield site by site, against exit criteria, with a date logged for each.
Copilot licences can go live after step three. That is the entire point of the pattern: the shield converts a rollout blocker into background remediation.
Step 1: baseline with the Data Access Governance reports
The Data Access Governance (DAG) reports live in the SharePoint admin centre and answer the question every Copilot readiness conversation starts with: which sites are shared more broadly than anyone intended. The sharing links reports surface sites with active Anyone links and organisation-wide links; the sensitivity label report shows which sites hold labelled content and which hold nothing but unlabelled files. Run them all, export, and rank sites by a simple product of breadth of access and likely sensitivity of content.
The patterns that surface are predictable. Frontrow documents the five most common at /insights/five-oversharing-patterns-australian-tenants, and the mechanism behind why Copilot turns them from embarrassing into urgent at /insights/copilot-permissions-trap. The short version: Copilot removes the difference between technically accessible and actually findable, so every stale broad share in the baseline is now one well-phrased question away from a screenshot.
Step 2: the Everyone except external users report
One report deserves its own step. Everyone except external users (EEEU) is the claim that includes every internal account in the tenant, and for fifteen years it has been the path of least resistance for anyone who wanted sharing to just work. It shows up on intranets that grew document libraries, on migrated file-server content where a lazy mapping granted it wholesale, and on sites where an owner clicked the biggest button available in 2019 and moved on.
The DAG report listing content shared with EEEU is the closest thing the tenant has to a map of Copilot blast radius, because everything on it is retrievable by every licensed user's Copilot session. Triage is blunt: for each site, either the content is genuinely meant for the whole organisation, or the EEEU grant comes off. The only decision the report can't make is which of those two it is, and that belongs to the site owner in step four.
Step 3: shield with Restricted Content Discovery
Restricted Content Discovery (RCD) is the SAM control that makes the parallel timeline honest. Applied to a site, it keeps that site's content out of tenant-wide search and out of Copilot and agent retrieval, while changing no permissions at all. People who work in the site keep their access, keep opening their files, and keep searching within the site itself. What changes is that the site's content stops being reachable through organisation-wide discovery, which is precisely the channel an ungoverned Copilot rollout exposes.
Apply RCD to the sites the baseline flagged: the EEEU report hits pending review, the sites carrying old Anyone links into sensitive libraries, the migrated file-server dump nobody has audited. This is not subtle work and it should not be. A site wrongly shielded costs a few search results for a few weeks; a site wrongly unshielded is the salary-spreadsheet demonstration that ends rollouts.
RCD is a different control from Restricted SharePoint Search, and the two get conflated constantly. Restricted SharePoint Search is a tenant-level allow-list: search and Copilot see only the sites explicitly approved, and everything else is dark by default. RCD is a per-site deny-list: the tenant stays open and specific sites go dark. For a tenant that is mostly fine with a risky minority, RCD preserves normal search for everyone while the minority gets fixed, which is why it is the better fit for the shield-while-you-clean pattern. For a tenant where nobody can even say which sites are fine, the allow-list model covered at /insights/restricted-sharepoint-search-copilot is the more defensible starting posture. The honest selector: deny-list when you can enumerate the problem, allow-list when you can only enumerate what's safe.
Step 4: site access reviews, run by owners
IT cannot decide whether the 2021 restructure folder should be visible to all staff. The site owner can, in about ninety seconds. SAM's site access reviews operationalise that: from a DAG report, an administrator initiates a review on a flagged site, and the site owner gets a task to walk through who has access and confirm or remove it. The work of judging content lands with the people who know the content, and IT's job collapses to chasing the laggards and processing the outcomes.
Two habits make reviews actually finish. Batch them, ten to twenty sites a fortnight, because two hundred simultaneous review requests get two hundred simultaneous ignores. And pair each review with the specific finding that triggered it: an owner told your site is shared with every person in the company through a grant added in March 2019 acts; an owner told please review your permissions files the email.
Step 5: unshield deliberately
The failure mode of any temporary control is becoming permanent by neglect, and a site left under RCD forever is content the organisation quietly lost from search. Unshielding needs exit criteria, checked per site: the EEEU grant is gone or affirmed as intentional, sharing links flagged in the baseline are pruned, the access review is complete and actioned, and sensitivity labels are applied where the site's content warrants them. When a site passes, remove RCD, log the date and the approver, and move on. A one-line register of shielded sites, trigger findings and unshield dates turns the whole exercise into something that can be shown to an auditor, a board, or a cyber insurer.
Try it
Score your tenant's oversharing risk first
Ten minutes across twelve dimensions, including the EEEU and sharing-link patterns this runbook shields against. The output is a sensible site list for step three.
Score each dimension · 4 options
Is your tenant ready for Microsoft 365 Copilot?
Copilot is as smart as your tenant is tidy. Twelve quick questions — each mapped to a Microsoft-native capability that closes the gap. Takes about ten minutes.
- 01
Anonymous "anyone with the link" shares
External access
How does your tenant handle anonymous sharing links?
- 02
Tenant-wide / "Everyone except external" site sharing
Permissions hygiene
Do you have sites shared with "Everyone" or "Everyone except external users"?
- 03
External guest access hygiene
External access
How do you manage external guest users in Entra ID?
- 04
Site collection admin sprawl
Identity & privileged access
How tightly is SharePoint site collection admin access controlled?
- 05
Broken permission inheritance
Permissions hygiene
How much unique (non-inherited) permissioning exists across your sites?
- 06
Orphaned sites with no active owner
Permissions hygiene
How do you handle sites whose owner has left or gone inactive?
- 07
OneDrive personal sharing patterns
External access
Do staff share sensitive documents (HR, finance, contracts) from OneDrive?
- 08
Sensitivity label coverage
Content classification
How much of your content is classified with Microsoft Purview sensitivity labels?
- 09
Restricted SharePoint Search / content discovery controls
Content classification
Have you enabled Restricted SharePoint Search or equivalent discovery controls for sensitive sites?
- 10
Microsoft Teams / Groups public vs private hygiene
Permissions hygiene
How strict is the hygiene on Team / Microsoft 365 Group privacy settings?
- 11
Legacy classic SharePoint sites
Permissions hygiene
Do you still have classic (pre-modern) SharePoint sites in the tenant?
- 12
Access review cadence for sensitive sites + external access
Identity & privileged access
How often do you review access to sensitive sites and external user lists?