AI & Copilot7 September 202610 min read

How to Find Out Who Has Access to What in SharePoint Before Deploying Copilot

Microsoft Copilot queries your SharePoint data using the permissions of the user asking the question. If a user has access to a file — even a file they have never opened and did not know existed — Copilot can surface it in response to a relevant query. Before deploying Copilot, you need to understand what your current SharePoint permissions actually look like. This article explains how to do that.

Why SharePoint permissions drift

SharePoint permissions accumulate over time without anyone actively reviewing them. A project team is given access to a site and the project ends — the access is never revoked. A staff member is promoted and gets added to a leadership SharePoint group — they later leave but the guest account remains. A document is shared via link and the link never expires.

This is normal. It is not negligence — it is what happens when people are focused on their work rather than their permissions. But after three to five years of an active SharePoint environment, the actual permission state often bears little resemblance to who should have access to what.

Copilot makes this visible in a way it has never been before. Search could technically surface accessible files, but users did not know to search for them. Copilot, when asked a relevant question, will actively retrieve and present content from across everything the user can access — including things they would never have thought to look for.

Where to start: the SharePoint admin centre

The SharePoint admin centre (accessible to SharePoint administrators via admin.microsoft.com) is your primary tool for understanding your permission landscape at scale.

Key reports and views to check

  • Sites overview: lists all SharePoint sites in your tenant, including those with external sharing enabled. Filter for sites with 'Anyone' or 'Specific people' sharing to identify your highest-exposure sites.
  • Sharing reports: Microsoft 365 admin centre provides a sharing activity report showing recent external sharing events. This gives you a view of what has been shared outside your organisation recently.
  • Access requests: sites that have accumulated many access requests without review are a signal that permissions are not being actively managed.
  • Inactive sites: SharePoint admin centre can identify sites with no recent activity. Inactive sites are often the ones with the worst permissions hygiene, because nobody has looked at them recently.
  • External users report: lists all guest accounts in your Entra ID, when they were invited, and what they last accessed. This is often the most surprising report — organisations frequently discover guest accounts for people who left a client organisation years ago.

Checking permissions on a specific site

For any site you want to review in detail: go to the site settings, then Site permissions. This shows you the groups and individuals with access and their permission level. Look for:

  • 'Everyone' or 'Everyone except external users' in any permission group. This means any authenticated user in your tenant can access the site.
  • Named users who are no longer employees. Former staff accounts that have not been deprovisioned still appear in SharePoint permission groups.
  • Guest users from external organisations who are no longer active. Their access persists until explicitly revoked.
  • Broken permission inheritance. Sites or libraries where permissions are set independently from the parent site can be difficult to review systematically.

Finding files shared via link

Link-based sharing is often the hardest to track. When a user shares a document via 'Share', they create a link that grants access to that file. These links do not appear in the site permissions view — they are attached to the individual file or folder.

To find shared links: go to the file or folder in SharePoint, select Manage access, and view Shared with. For site-wide link visibility, the Microsoft 365 Compliance portal provides reports on sharing activity. For anonymous links specifically, the SharePoint admin centre 'Sharing' settings show what link types are currently permitted.

What to look for: the four highest-risk patterns

  1. 01

    'Everyone' group membership in any sensitive site

    Any SharePoint site containing financial, HR, legal or client data that has 'Everyone' or 'Everyone except external users' in its permission groups means every user in your tenant can access that content via Copilot.

  2. 02

    Anonymous sharing links that have not expired

    An anonymous sharing link gives access to a document without any authentication. If these exist for sensitive documents and have no expiry date, anyone with the link — including external parties who received it years ago — can still access the content.

  3. 03

    Ownerless sites containing sensitive content

    Sites with no active owner have no one accountable for their content or permissions. They are commonly the sites where the most problematic content lives, because no one has been reviewing them.

  4. 04

    Former employee guest accounts still active

    Guest accounts created for external contractors, former staff, or clients who have moved on continue to exist in Entra ID until explicitly removed. Copilot respects their access — if they still have permissions, they can still access content.

The most common outcome of a SharePoint permissions review is that the organisation discovers content is far more broadly accessible than anyone assumed. This is almost always a slow accumulation rather than a single oversight. The fix is systematic, not dramatic.

What to do with what you find

Prioritise based on sensitivity. Start with sites containing financial data, HR records, client information, and board-level communications. Remove 'Everyone' group access from those sites. Expire or revoke anonymous sharing links. Remove inactive guest accounts. Assign ownership to ownerless sites.

Then set policies that prevent the same accumulation recurring: link expiry policies, guest access review cycles, and site ownership requirements for any new site creation.

This work is worth doing regardless of Copilot. Copilot just makes the stakes of not doing it much more visible.

Next step

Copilot Readiness Assessment

The Copilot Readiness Assessment conducts a systematic review of your SharePoint permissions, identifies the highest-risk patterns, and gives you a prioritised remediation plan before Copilot deployment.

Learn more