Free tool · 10 minutes
SHAREPOINT OVERSHARING
RISK CHECK.
Copilot is as smart as your tenant is tidy. Twelve questions across identity, permissions, classification and external access — scored against Microsoft’s own Copilot-readiness guidance. PDF + Excel report at the end.
Score each dimension · 4 options
Is your tenant ready for Microsoft 365 Copilot?
Copilot is as smart as your tenant is tidy. Twelve quick questions — each mapped to a Microsoft-native capability that closes the gap. Takes about ten minutes.
- 01
Anonymous "anyone with the link" shares
External access
How does your tenant handle anonymous sharing links?
- 02
Tenant-wide / "Everyone except external" site sharing
Permissions hygiene
Do you have sites shared with "Everyone" or "Everyone except external users"?
- 03
External guest access hygiene
External access
How do you manage external guest users in Entra ID?
- 04
Site collection admin sprawl
Identity & privileged access
How tightly is SharePoint site collection admin access controlled?
- 05
Broken permission inheritance
Permissions hygiene
How much unique (non-inherited) permissioning exists across your sites?
- 06
Orphaned sites with no active owner
Permissions hygiene
How do you handle sites whose owner has left or gone inactive?
- 07
OneDrive personal sharing patterns
External access
Do staff share sensitive documents (HR, finance, contracts) from OneDrive?
- 08
Sensitivity label coverage
Content classification
How much of your content is classified with Microsoft Purview sensitivity labels?
- 09
Restricted SharePoint Search / content discovery controls
Content classification
Have you enabled Restricted SharePoint Search or equivalent discovery controls for sensitive sites?
- 10
Microsoft Teams / Groups public vs private hygiene
Permissions hygiene
How strict is the hygiene on Team / Microsoft 365 Group privacy settings?
- 11
Legacy classic SharePoint sites
Permissions hygiene
Do you still have classic (pre-modern) SharePoint sites in the tenant?
- 12
Access review cadence for sensitive sites + external access
Identity & privileged access
How often do you review access to sensitive sites and external user lists?
FAQ
Common questions on Copilot readiness and oversharing
- What does Copilot oversharing risk actually mean?
- Microsoft 365 Copilot can surface any content that a given user already has permission to access. If your SharePoint tenant has content shared broadly — to Everyone, to anonymous links, to stale guest accounts — Copilot will naturally retrieve it when asked. Oversharing risk is the gap between intended access and effective access. Microsoft's Copilot blueprint documentation covers this in detail.
- Is this tool running against my tenant?
- No. The assessment runs entirely in your browser. Nothing is sent anywhere, no Microsoft consent flow is triggered, and no tenant data is read. It is a self-assessment based on your answers to the 12 questions — useful as a first-pass before any paid audit or Microsoft consultation.
- Do I need SharePoint Advanced Management to act on the recommendations?
- Some of the recommendations reference SharePoint Advanced Management (SAM), which is an add-on to the SharePoint plan. Where a SAM capability is recommended, the equivalent non-SAM path is usually possible with more manual effort. The recommendations also cover Microsoft Entra ID Access Reviews, Microsoft Purview, and Microsoft 365 Defender capabilities — most included in Microsoft 365 E3 / E5 / Business Premium.
- How do Microsoft Purview sensitivity labels reduce oversharing risk?
- Sensitivity labels carry permission policies and encryption with them, and Copilot honours both. A document labelled 'Confidential' can be scoped so that Copilot will not surface its contents to users outside a defined group, even if they technically have SharePoint read access. Pairing oversharing remediation with a Purview label rollout reinforces both controls.
- What should I do with the report?
- Share the PDF with your IT or security team as a starting baseline. Each priority fix points to a specific Microsoft capability you likely already have. If you want a second opinion on the sequence — or the full tenant audit that sits behind it — book a 30-minute review with our Microsoft MVP–led Applied AI team.