GTools.pro — Zero-Knowledge M365
ToolsPricingDesktopIndustriesCompareBlogSecurityTrustAbout
  1. Home
  2. Blog
  3. The SharePoint oversharing review to run before enabling Copilot

SharePoint Oversharing Review Before Copilot

Check SharePoint for anonymous links, "Everyone" permissions, and broken inheritance before turning on Microsoft 365 Copilot — a five-step review for one admin.

By George Curta

How do I check SharePoint for oversharing before turning on Microsoft 365 Copilot?

Oversharing Report and Sharing Report surface every anonymous link, Everyone-permission grant, and external share across SharePoint before Copilot can reach them. Unique Permissions Audit finds broken inheritance that quietly widens access beyond a site’s intended scope, and Copilot Readiness turns those findings into a single readiness score. Fixing what these tools surface is a manual step in the SharePoint admin center or Entra ID, not an automatic one.

Leadership wants Microsoft 365 Copilot live next quarter, and the SharePoint sharing structure it will search across was built one ad-hoc share-with-anyone click at a time. Copilot itself grants nothing new — a prompt only surfaces content the person asking could already open through their own Microsoft Graph permissions — but that means every anonymous link, every broken permission boundary, and every stale guest account left over from a project three years ago becomes far easier to stumble into the moment a natural-language search sits on top of it. The review below runs before the rollout, not during the rollout demo. What oversharing looks like before anyone turns Copilot on Oversharing rarely looks like a single dramatic mistake. It accumulates from years of individually reasonable decisions — a folder shared for one project that outlived the project, a permission inherited down five levels of subsites, a guest account added for a vendor engagement that ended a year ago. None of it shows up on a dashboard by default; it shows up when someone actually goes looking. Anonymous "anyone with the link" shares still active on files nobody remembers sharing "Everyone" or "Everyone except external users" permissions applied to a library that was meant for one team Broken inheritance where a folder-level grant quietly widened access past the site’s intended scope External guest accounts and B2B sharing left active long after the engagement that created them ended Step 1 — Pull the oversharing report before anything else Start with Oversharing Report rather than a manual click-through of every site. It scans the tenant for anonymous links, Everyone permissions, and excessive external sharing in one pass, then prioritizes the results by risk level with a direct link to each shared item, so remediation does not require re-finding what was already flagged. This is the report every later step in this review builds on. Step 2 — Check anonymous and Everyone links specifically Anonymous links are the highest-severity finding in almost every tenant, because they require no sign-in at all — anyone with the URL can open the content, whether or not they belong to the organization. Everyone and Everyone-except-external-users permissions are the next tier: they were often applied years ago to make an early SharePoint rollout simpler, and nobody has revisited them since. Sharing Report inventories every link by type — anonymous, organization, specific people — and identifies pending invitations alongside them, so triage starts with a full list rather than a partial one. Critical: anonymous links open to sensitive or regulated content High: "Everyone" or "Everyone except external users" permissions on a library not meant for the whole organization Medium and Low: organization-wide links and specific-people shares still active well past the project that created them Step 3 — Review unique permissions and broken inheritance A site can look properly locked down at the top level and still have individual folders that broke away from that structure years ago. Unique Permissions Audit scans up to five levels deep in document libraries to find exactly those items — content where permissions differ from the parent, the pattern that most often indicates oversharing or access creep rather than a deliberate decision. This is the step that turns up the findings a top-level site review would never see. A subfolder shared directly with a vendor, bypassing the site’s own permission structure A document library where an earlier administrator widened access to solve a one-time problem and never reverted it A subsite that inherited nothing from its parent because inheritance broke during an earlier migration Step 4 — Run the Copilot Readiness assessment Once the individual sharing and permission findings are in hand, Copilot Readiness Assessment turns them into a single readiness score by analyzing sharing permissions, anonymous links, and external access together — the same signals the earlier steps surfaced individually, now read as one pre-rollout picture instead of three separate reports. Treat the score as a summary of Steps 1 through 3, not a replacement for running them. Step 5 — Decide what gets fixed before rollout, and what gets tracked after Not every finding needs to block the rollout date, and treating all of them as equally urgent is how a review stalls before it finishes. Anonymous links on sensitive content and Everyone permissions on anything not meant for the whole organization are worth fixing first. Stale external access and long-broken inheritance on genuinely low-sensitivity sites can move to a tracked backlog instead — the review’s job is to make that distinction explicit before Copilot goes live, not to fix every finding in one pass. Fix first: anonymous links on sensitive content, and "Everyone" permissions on anything not meant for the whole organization Track after rollout: stale external access and long-broken inheritance on low-sensitivity sites Re-run Oversharing Report, Sharing Report, Unique Permissions Audit, and Copilot Readiness on a schedule afterward, since new sharing links and new permission breaks accumulate the same way the original ones did What this review cannot tell you This is a detective control, not a fix and not a SIEM: Oversharing Report, Sharing Report, Unique Permissions Audit, and Copilot Readiness all produce ranked findings, and remediation happens afterward in the SharePoint admin center or Entra ID. How severity gets ranked here comes from an internal heuristic documented separately from — and not always matching — Microsoft’s own Secure Score, and what the audit can see tops out at whatever Graph permission scope this app was actually granted. A handful of signals also need a specific Microsoft license before they’ll show up at all, so treat these findings as a starting point rather than a complete picture — none of this substitutes for Microsoft’s own Copilot rollout guidance.

Frequently asked questions

Does the oversharing review replace the Copilot Readiness Assessment?

No — treat them as sequential. Oversharing Report and Sharing Report surface individual sharing risks, such as anonymous links and Everyone permissions, that an admin fixes one at a time. Copilot Readiness Assessment turns those same signals into one readiness score for deciding whether the tenant is ready for rollout, so it runs after the individual reports, not instead of them.

What does Copilot actually change about SharePoint sharing risk?

Copilot itself does not create new access — it answers a prompt using whatever the asking user can already reach through Microsoft Graph. What changes is discoverability: a broken permission boundary that sat quietly for years becomes reachable the moment anyone in the company can ask a natural-language question and get an answer pulled from wherever it lives.

Does gtools.pro fix the oversharing it finds automatically?

No. This is a detective control — Oversharing Report, Sharing Report, Unique Permissions Audit and Copilot Readiness all produce ranked, exportable findings, and remediation happens afterward in the SharePoint admin center or Entra ID. Severity rankings use a documented internal heuristic that may diverge from Microsoft Secure Score.

Related topics

  • sharepoint oversharing
  • copilot readiness
  • anonymous links sharepoint
  • sharepoint permissions audit
  • microsoft 365 copilot security

About the platform

This is a zero-knowledge toolkit. It helps IT admins, MSPs, security teams run their cloud safer. Use it inside a browser. Or install our Mac or Windows app.

Tenant secrets stay on your disk. We never store, log, or read them. Our server only sees billing metadata.

How it works

  1. You unlock a local vault with a passphrase. Argon2id stretches it.
  2. Tokens get sealed with XChaCha20-Poly1305 before any sync.
  3. X25519 protects shared keys. Ed25519 signs every action.
  4. Each operation runs against Graph from your device, not ours.

What you can do

  • Back up mail. Files. Chat threads.
  • Export Intune settings. One click.
  • Audit SharePoint shares. Spot risk.
  • Find idle sites. Reclaim quota.
  • Score Copilot. Plan rollout.
  • Move tenants. No staging.
  • Client-side keys. Always on.
  • Your data. Your disk.
  • One app. Many tenants.

Editions

  • Solo. Free. Three tools. No card.
  • Backup. Durable backups for your tenant.
  • Watchtower. Audits and alerts on risk.
  • Move. Tenant migration suite.
  • Blueprint. Config export for enterprise.
  • Everything. Full platform plus desktop and support.

Trust signals

  • Open source crypto primitives via libsodium.
  • Public threat model at /trust.
  • Public pricing. Direct purchase. No sales call.
  • Cancel any time inside settings.
  • EU-based billing. PayPal checkout today; card payments planned.

Built in Germany by Voltage Brothers Infrastruktur UG. Suits cloud workspaces of every size.

Standards, regions, retention

Regions: Frankfurt. Dublin. North America. Retention scales from 7 days. Up to unlimited. Schedules run hourly. Daily. Weekly. Monthly. Reports export as JSON. CSV. PDF. Evidence packs bundle hashes. Chain-of-custody metadata sits beside them.

Standards covered: ISO 27001 controls. SOC 2 readiness. NIS2 mapping. GDPR Article 28 terms. Audit logs cover entitlement events. Billing actions. License rotations. Workload payloads never reach a remote log.

Who uses it

  • Tenant admins running a single estate.
  • MSPs managing dozens of customer cloud workspaces.
  • Security teams investigating sharing risk.
  • Compliance officers preparing audit evidence.
  • Acquisition teams during M&A integration.
  • Procurement teams reviewing vendor risk.
  • Solo consultants billing by workspace hour.

Supported regions

Frankfurt, Dublin, Amsterdam, Stockholm, Paris, plus North America. Annual revenue scales from small studios up through multinational estates. Payment today is PayPal checkout; card payments (Stripe) are planned.

Numbers worth knowing

  • 49 capabilities. 6 editions.
  • Free tier: 3 tools. 0 cards.
  • Argon2id. 256 MB memory cost.
  • XChaCha20-Poly1305. 256-bit cipher.
  • X25519. 256-bit shared keys.
  • Ed25519. 100% of writes signed.
  • Retention: 7 days. 365 days. Or unlimited.
  • Founded 2024. Built in Germany.
  • Backup edition: 14 EUR per user per year.
  • Watchtower edition: 7 EUR per user per year.
  • Move edition: 9 EUR per migrated seat. One-time. 450 EUR project minimum.
  • Blueprint edition: 449 EUR per tenant per year.
  • Everything bundle: 2490 EUR per tenant per year.
  • Audit reports: 25 dedicated checks.
  • Config export: 9 Microsoft 365 workloads.
  • Migration record set in April 2026. 153,584 files. 0 errors.
  • Compliance posture updated in 2026.
  • Pricing: 1 public page. 0 sales calls.
  • Cancellation: 1 self-service page.
  • Audit logs: 90 days. Entitlement events.
  • GDPR Article 28. 27 member states.
  • NIS2 Directive. 18 sectors. Live since 2024.
  • SOC 2 Type II evidence. JSON. CSV. Signed PDF.
  • ISO 27001. 93 Annex A controls. 2022 revision.

Product.

  • Tools.
  • Pricing.
  • Desktop.
  • Security.
  • Industries.
  • Compare.
  • Download.
  • Blog.
  • For MSPs.
  • For SMB IT.

Company.

  • About.
  • Trust & Compliance.
  • Privacy Policy.
  • Terms of Service.
  • Impressum.

Connect.

  • hello@gtools.pro.
  • GitHub.

© 2026 GTools.pro · A product of Voltage Brothers Infrastruktur UG (haftungsbeschränkt).