What to take away
Start a SharePoint external-sharing review with three questions: who can access the content, which permission or link gives them access, and who can confirm the business need? Microsoft 365 Copilot also makes broad internal access worth reviewing. Use this workflow to document decisions, make targeted corrections, and verify the result.
1. Separate outside collaboration from broad internal access
An anonymous sharing link, an authenticated supplier, and a large internal group represent different audiences. Name the audience and its business purpose before deciding whether access is excessive. A shared project folder may be appropriate during a contract and unnecessary after handover. Its owner can explain that change in context.
Microsoft applies the stricter organization or site sharing setting; OneDrive cannot be less restrictive than the SharePoint organization setting. Check both levels when investigating an unexpected option. Copilot references content the user is authorized to access. Our practical conclusion: review broad internal permissions alongside external sharing, because restricting outside collaboration alone does not address an internal audience that is too wide.
References: Microsoft — External sharing overview · Microsoft — Copilot data-protection architecture
2. Record the scope and evidence before making changes
Choose the business process, sites or OneDrive locations, owners, and review date. Start with content whose audience you can validate. Record unknowns explicitly and assign an investigator; a missing owner is a follow-up task, not permission to delete a share.
Where available, Microsoft’s Data Access Governance site-permission snapshot helps prioritize exposure. It is a dated report, excludes archived and NoAccess sites, and can lag changes. Check SharePoint Advanced Management licensing and administrative prerequisites before relying on it. Preserve the report date and verify current permissions in the source.
| Review field | What to retain | What it helps decide |
|---|---|---|
| Location and owner | Site or item reference; responsible business owner | Who can validate the purpose? |
| Audience and access path | Link, direct permission, group, or inherited access | Which specific route needs investigation? |
| Evidence and date | Report or source check; collection date; known gaps | Is the finding current enough to act on? |
| Business decision | Keep, remove, narrow, or investigate; reason and assignee | What change is justified? |
| Completion and exception | Source verification; remaining paths; next review date | Is the decision implemented and still appropriate? |
References: Microsoft — Site-permission snapshot report · Microsoft — SharePoint Advanced Management prerequisites
3. Work through one folder with its owner
Consider a fictional procurement folder for a completed supplier project. A former supplier still appears in its permissions, a finance colleague needs the records, and a broad internal group also has access. Ask the owner to assess these three audiences independently. “The project ended” does not answer whether the finance colleague still needs access.
Record the supplier removal, retained finance access, and internal-group investigation as separate decisions. Give each an implementer and reason. If the supplier works on another project, removing their tenant-wide identity could disrupt that work; investigate the relevant resource first. For an uncertain group, identify its membership and purpose before proposing a change. Keep the item reference in the review record without copying unnecessary document contents.
4. Distinguish permission changes from discovery restrictions
Match the action to the outcome the owner approved. These controls answer different questions; record which one you applied and why.
- Restricted Content Discovery requires applicable SharePoint Advanced Management access and a Microsoft Copilot license. Check current feature prerequisites in your tenant.
- For restricted site access control, shared and private channel sites need separate configuration. External shared-channel participants from another tenant remain governed by channel and site permissions.
- Document a temporary restriction’s owner and exit condition so the underlying permission review continues.
| Action or control | Purpose | Boundary to preserve |
|---|---|---|
| Remove a permission or link | Close an unnecessary access path | Verify whether other direct, inherited, or group paths still exist. |
| Restricted Content Discovery | Temporarily limit organization-wide discovery during a site review | SharePoint only, not OneDrive. Permissions and direct access remain; summarizing an open document is a separate experience. |
| Restricted site access control | Add a control-group condition to access | Users need both an existing permission and allowed-group membership. External participants in shared channels are a documented exception. |
| Record an owner decision | Approve the intended audience and next action | Approval is not evidence that the access change was completed. |
References: Microsoft — Restricted Content Discovery · Microsoft — Restricted site access control · Microsoft — SharePoint Advanced Management prerequisites
5. Verify access and discovery as separate outcomes
After an administrator applies a supported correction, inspect current permissions. Use authorized test identities and synthetic files where needed to check that the intended recipient lost access while required collaborators still have it. Record the tested identity, resource, access path, date, and result. A screenshot of a completed task does not establish effective access.
For a Copilot check, record discovery behavior separately. A missing answer does not prove permission removal. Microsoft notes that discovery updates need propagation; allow for that before interpreting a test. If someone still reaches the file directly, investigate the remaining permission paths instead of repeatedly testing the same prompt. Leave the review open when evidence is incomplete.
References: Microsoft — Restricted Content Discovery
6. Close decisions with evidence and revisit exceptions
Track decision pending, change pending, and verified complete separately. A retained exception needs a business owner, justification, limited scope, and next review date. If the owner leaves or the collaboration changes, reopen the relevant decision. Choose review frequency from your organization’s risks and requirements rather than treating one cadence as a universal compliance rule.
Report verified corrections and unresolved work together. Link account or group-membership questions to your user-access review process. Keep the file-level record specific enough that a colleague can understand what changed without repeating the entire investigation.
How Elba supports a Microsoft sharing review
Elba can bring supported SharePoint and OneDrive item and permission findings into a data-protection workflow. With the separate Data Protection connection enabled, an eligible issue can expose a supported permission-removal action. Confirm the available action and verify its result in Microsoft.
The Microsoft 365 directory connection is separate. Importing users does not enable document inspection or every Microsoft security capability. Use the integration details below to establish which findings and actions your workspace supports before building a review around them.
SharePoint and OneDrive sharing review checklist
Your checks stay on this page and reset when you reload it.
Common questions
Does Microsoft 365 Copilot bypass SharePoint permissions?
Microsoft states that Copilot references authorized content. Investigate permissions broader than the business need; do not describe ordinary retrieval of accessible content as a permission bypass.
Does blocking external sharing address all Copilot exposure?
No. Outside collaboration and broad internal access are separate review questions. An internal audience may still exceed the business need even when outside sharing is restricted.
Does Restricted Content Discovery remove access?
No. Existing permissions remain. Keep direct-access verification separate from discovery checks, and continue the underlying permission review.
Does connecting Microsoft 365 to Elba automatically cover documents?
No. The base connection synchronizes directory information. SharePoint and OneDrive Data Protection use a separate connection, and available findings and actions depend on that connection and the eligible item.
Sources & further reading
Primary documentation used to review this guide. Product settings and edition requirements can change; check the linked documentation before making changes.