Skip to content
All services

SharePoint Permissions and Oversharing Assessment: Guests, Sharing Links, and Cleanup

Understand who can access what before an audit, a migration, or a Copilot rollout exposes the problem.

I help organizations find and fix permission sprawl in SharePoint and Microsoft 365 — broken inheritance, oversharing, stale guest and external access, and ownership gaps — and turn the findings into a cleanup plan in priority order.

16+ Years SharePoint Experience Government & Enterprise Microsoft Certified

When This Assessment Makes Sense

  • An audit or security review is coming and you need to show who can access sensitive content.
  • Microsoft 365 Copilot is being rolled out or expanded, and nobody is sure what it will be able to surface.
  • A migration is planned, and the old file share or SharePoint Server permissions should not move as they are.
  • Years of guest invitations and sharing links have never been reviewed.
  • Nobody can answer “who has access to this, and why?” with confidence.

Why Permissions Cleanup Matters

Messy permissions rarely announce themselves. They accumulate quietly — a folder shared "temporarily," a group nobody remembers creating, an external user from a project that ended two years ago — until an audit, a security incident, a migration, or a Copilot rollout suddenly makes every old decision visible.

The cost shows up as support tickets IT cannot answer confidently ("who has access to this and why?"), failed compliance reviews, oversharing of sensitive content, migration rework, and a general loss of trust in the platform.

A structured cleanup replaces exception-driven access with a group-based model that business owners understand and IT can audit — which is also the foundation for Microsoft 365 Copilot readiness.

Common Permission Risk Patterns

Broken inheritance everywhere
Nested or outdated security groups
Users with access from old roles or projects
Sensitive folders with unclear owners
External users that were never reviewed
Guests with no business owner who still needs them
Sites and files shared with Everyone except external users
Anyone and organization-wide links on sensitive files
Direct user permissions instead of group-based access
SharePoint sites with no accountable business owner
File share permissions copied without validation

What Gets Reviewed

Site, library, folder, and item-level unique permissions
Broken inheritance and where it actually matters
Sharing links (anyone, organization, specific people) and their age
External users and guest access across sites and Teams
Broad groups such as Everyone except external users
Microsoft 365 group membership vs. SharePoint group membership
Direct user assignments and admin-added exceptions
Site collection administrators and ownership accountability
High-risk and sensitive content locations

What You Receive

Prioritized permission-risk backlog
Broken inheritance summary
External sharing and guest access inventory
High-risk content and access findings
Ownerless and inactive site list
Recommended group model
Remediation order and roadmap
A repeatable access-review process for site owners
Copilot readiness observations
Optional scripts and tooling recommendations

Tooling and Technical Proof

I use PnP PowerShell, Microsoft Graph, SharePoint admin center reporting, and SharePoint Advanced Management (where licensed) to build the permission inventory. I also build open-source tools for the same problems, so you can see how the analysis works before you hire anyone:

Tooling accelerates the inventory, but the decisions — who should own what, which exceptions are legitimate, what gets simplified — are made with your site owners and security team, not by a script.

The Migration and Copilot Readiness Connection

Before a migration, a permissions review prevents old file share access models from being copied into SharePoint unvalidated — a common source of post-migration governance debt. If you are planning a move, pair this service with SharePoint migration consulting.

Before a Copilot rollout, the same review determines what AI search will be able to surface for each user. Cleaning up access first lowers the chance that Copilot surfaces content it should not. See Copilot readiness and SharePoint governance consulting for the broader picture.

Business Impact

IT spends less time answering “who has access and why” questions
Compliance and audit reviews get evidence of who has access and why
Sensitive content stops being reachable through forgotten links and stale accounts
Migration scope can shrink when dead access and ROT content are identified early
Copilot and AI search can be enabled with known, managed exposure
Site owners know what they own and what they are accountable for

Related Reading

Frequently Asked Questions

What does a SharePoint permissions and oversharing assessment look at?

Who can reach each site, library, and sensitive folder, and how: SharePoint and Microsoft 365 group membership, direct user permissions, broken inheritance, sharing links (Anyone, organization-wide, specific people), guest accounts, and broad groups such as Everyone except external users. The output is a ranked list of risky access paths, not a raw export.

What does Everyone except external users mean for oversharing?

It is a built-in group that contains every member account in your Microsoft Entra tenant, meaning everyone except guests. Anything shared with it is open to the whole organization, and Microsoft 365 Copilot can use that content when answering any of those people. Finding where it is used is one of the first checks in the assessment.

Doesn't SharePoint Advanced Management or Microsoft Purview already find oversharing?

They find a lot of it, and I use them where you have them: SharePoint Advanced Management's data access governance reports point to sites with heavy sharing-link use or content shared with Everyone except external users, and Microsoft Purview DSPM for AI can run data risk assessments on SharePoint sites. They show where to look; they do not decide which access is legitimate. The assessment combines those reports with PnP PowerShell and Microsoft Graph data, ranks the risky access paths, takes them to the business owners who can say keep or remove, and plans the changes in waves.

How do you review old guest accounts?

I list each guest with the sites and teams they can reach and when they were last active, then ask a business owner to keep or remove each one. To stop them piling up again, Microsoft Entra access reviews can make that a recurring owner review for guests in Microsoft 365 groups and Teams where your licensing includes them, and SharePoint's guest access expiration setting removes access for guests invited directly to sites and files after a set number of days.

Can the assessment be done without changing any permissions?

Yes. The assessment only reads permissions and reports. Changes come afterwards, in waves you approve, starting with the highest-risk access.

What is a SharePoint permissions cleanup?

A permissions cleanup is a structured review and remediation of who can access what in SharePoint and Microsoft 365. It covers broken inheritance, direct user permissions, stale or nested groups, sharing links, external users, and ownership gaps — and replaces ad hoc exceptions with a group-based access model that can be explained and audited.

Should permissions be cleaned up before or after a SharePoint migration?

Before, whenever possible. Reviewing permissions before migration prevents old file share problems — outdated groups, temporary exceptions, direct user access — from being copied into Microsoft 365. If the migration already happened, a post-migration cleanup is still worthwhile: the risks do not age out on their own.

Why do SharePoint permissions matter for Microsoft 365 Copilot?

Copilot answers from whatever content a user can technically access. Oversharing that was invisible in day-to-day work becomes discoverable the moment AI search summarizes it. A permissions review is one of the most effective Copilot readiness steps an organization can take.

What tools do you use to review SharePoint permissions?

A combination of PnP PowerShell, Microsoft Graph, SharePoint admin center reports, SharePoint Advanced Management where licensed, and my own open-source SPFx Permission Visualizer. The tooling matters less than the method: inventory, risk-tier, review with business owners, then remediate in priority order.

Can you fix permissions without breaking anyone's access?

That is the goal of a staged remediation. Changes are planned in waves, validated with site and business owners, and high-risk areas are corrected first with a rollback path. The point is to reduce risk without creating a support-ticket storm.

How long does a permissions cleanup engagement take?

It depends on the number of sites and the level of permission sprawl. A focused assessment of a mid-size tenant typically takes a few weeks; remediation is then scoped in waves based on the findings. You get a clear risk picture early, not at the end.

Free SharePoint planning resource

Before expanding Microsoft 365 usage, review your SharePoint risks.

Use the readiness checklist to review permissions, ownership, external sharing, retention, and lifecycle gaps before they become production issues.

Get the Checklist

Not sure how bad your SharePoint permissions actually are?

Send me a short note about your environment. A focused permissions assessment will tell you where the real risk is — before an audit, a migration, or Copilot tells you first.

Book a permissions assessment