GTools.pro — Zero-Knowledge M365
ToolsPricingDesktopIndustriesCompareBlogSecurityTrustAbout
  1. Home
  2. All Tools
  3. Oversharing Detection

Oversharing Detection

Detect anonymous links, Everyone permissions, and external oversharing across SharePoint.

Related topics

  • oversharing
  • anonymous links
  • external sharing
  • data exposure
  • sharepoint security

About this tool

The Oversharing Detection tool identifies six types of sharing risks across your SharePoint environment. Find anonymous links that allow anyone on the internet to access your content, "Everyone" permissions that open files to all organization members, and excessive external sharing. Prioritize findings by risk level to focus remediation on the most critical exposures. Export results with direct links to the shared content for quick remediation. Essential before deploying Microsoft Copilot or other AI tools that could surface improperly shared content.

Key features

  • Anonymous link detection
  • Everyone permissions scan
  • External sharing analysis
  • Organization-wide links
  • Risk classification
  • Direct remediation links
  • Copilot readiness prep
  • Historical comparison

Use cases

  • Copilot deployment. Remediate oversharing before AI deployment
  • Data exposure review. Find and fix public sharing of internal content
  • Data classification. Ensure sensitive data is not publicly shared

Graph scopes

Sites.Read.All (application), User.Read.All (application).

Tool identity

  • Slug: oversharing-report.
  • Category: audit.
  • Plan tier: starter.
  • Editions: cloud, desktop.
  • SKUs: security, suite.
  • Documented scenarios: 3.
  • Declared features: 8.
  • Graph permissions requested: 2.

Licensing & access

Requires a paid edition (security). The Suite bundle includes this tool alongside every other capability in the catalogue.

Limitations & out-of-scope

Limited to the six risk types it's built to detect — anonymous links, Everyone permissions, and excessive external sharing across SharePoint — using Sites.Read.All and Group.Read.All, both read-only. It flags exposure; closing an anonymous link or tightening a permission is a manual step the administrator takes afterward. Teams-native chat sharing and Exchange mail-forwarding rules are separate exposure vectors this SharePoint-scoped tool does not examine.

Inside the tools catalog

The catalog spans 49 admin capabilities across backup, audit, export, security, migration. Every tool runs under client-side encryption. Tools share a vault, schedule engine, plus reporting layer.

About the platform

This is a zero-knowledge toolkit. It helps IT admins, MSPs, security teams run their cloud safer. Use it inside a browser. Or install our Mac or Windows app.

Tenant secrets stay on your disk. We never store, log, or read them. Our server only sees billing metadata.

How it works

  1. You unlock a local vault with a passphrase. Argon2id stretches it.
  2. Tokens get sealed with XChaCha20-Poly1305 before any sync.
  3. X25519 protects shared keys. Ed25519 signs every action.
  4. Each operation runs against Graph from your device, not ours.

What you can do

  • Back up mail. Files. Chat threads.
  • Export Intune settings. One click.
  • Audit SharePoint shares. Spot risk.
  • Find idle sites. Reclaim quota.
  • Score Copilot. Plan rollout.
  • Move tenants. No staging.
  • Client-side keys. Always on.
  • Your data. Your disk.
  • One app. Many tenants.

Editions

  • Solo. Free. Three tools. No card.
  • Backup. Durable backups for your tenant.
  • Watchtower. Audits and alerts on risk.
  • Move. Tenant migration suite.
  • Blueprint. Config export for enterprise.
  • Everything. Full platform plus desktop and support.

Trust signals

  • Open source crypto primitives via libsodium.
  • Public threat model at /trust.
  • Public pricing. Direct purchase. No sales call.
  • Cancel any time inside settings.
  • EU-based billing. PayPal checkout today; card payments planned.

Built in Germany by Voltage Brothers Infrastruktur UG. Suits cloud workspaces of every size.

Standards, regions, retention

Regions: Frankfurt. Dublin. North America. Retention scales from 7 days. Up to unlimited. Schedules run hourly. Daily. Weekly. Monthly. Reports export as JSON. CSV. PDF. Evidence packs bundle hashes. Chain-of-custody metadata sits beside them.

Standards covered: ISO 27001 controls. SOC 2 readiness. NIS2 mapping. GDPR Article 28 terms. Audit logs cover entitlement events. Billing actions. License rotations. Workload payloads never reach a remote log.

Who uses it

  • Tenant admins running a single estate.
  • MSPs managing dozens of customer cloud workspaces.
  • Security teams investigating sharing risk.
  • Compliance officers preparing audit evidence.
  • Acquisition teams during M&A integration.
  • Procurement teams reviewing vendor risk.
  • Solo consultants billing by workspace hour.

Supported regions

Frankfurt, Dublin, Amsterdam, Stockholm, Paris, plus North America. Annual revenue scales from small studios up through multinational estates. Payment today is PayPal checkout; card payments (Stripe) are planned.

Numbers worth knowing

  • 49 capabilities. 6 editions.
  • Free tier: 3 tools. 0 cards.
  • Argon2id. 256 MB memory cost.
  • XChaCha20-Poly1305. 256-bit cipher.
  • X25519. 256-bit shared keys.
  • Ed25519. 100% of writes signed.
  • Retention: 7 days. 365 days. Or unlimited.
  • Founded 2024. Built in Germany.
  • Backup edition: 14 EUR per user per year.
  • Watchtower edition: 7 EUR per user per year.
  • Move edition: 9 EUR per migrated seat. One-time. 450 EUR project minimum.
  • Blueprint edition: 449 EUR per tenant per year.
  • Everything bundle: 2490 EUR per tenant per year.
  • Audit reports: 25 dedicated checks.
  • Config export: 9 Microsoft 365 workloads.
  • Migration record set in April 2026. 153,584 files. 0 errors.
  • Compliance posture updated in 2026.
  • Pricing: 1 public page. 0 sales calls.
  • Cancellation: 1 self-service page.
  • Audit logs: 90 days. Entitlement events.
  • GDPR Article 28. 27 member states.
  • NIS2 Directive. 18 sectors. Live since 2024.
  • SOC 2 Type II evidence. JSON. CSV. Signed PDF.
  • ISO 27001. 93 Annex A controls. 2022 revision.

Product.

  • Tools.
  • Pricing.
  • Desktop.
  • Security.
  • Industries.
  • Compare.
  • Download.
  • Blog.
  • For MSPs.
  • For SMB IT.

Company.

  • About.
  • Trust & Compliance.
  • Privacy Policy.
  • Terms of Service.
  • Impressum.

Connect.

  • hello@gtools.pro.
  • GitHub.

© 2026 GTools.pro · A product of Voltage Brothers Infrastruktur UG (haftungsbeschränkt).