Copilot reaches whatever the person asking can reach. If a decade of casual sharing has left content accessible more broadly than intended, deployment surfaces that on day one. This guide covers the assessment and the remediation, and it will probably add six weeks to your AI timeline.
If you have to build it
SharePoint Advanced Management reporting, broad-access link identification, permission inheritance review, site ownership reconciliation, and the restricted access controls that limit exposure while remediation proceeds.
Why it matters
The problem this solves
The permission debt was always there. What changes is that finding an overshared document used to require knowing it existed, and now it requires asking a reasonable question.
In healthcare this matters more than most sectors, because the content that tends to be overshared — clinical correspondence, incident reports, staffing records — is exactly what a clinician might reasonably query.
Before you start
Prerequisites
Check these before beginning. Most stalled implementations stall on one of them.
Licensing
SharePoint Advanced Management for the governance reporting. Microsoft 365 Copilot licences for the deployment itself, which should come after this work rather than during it.
Roles
SharePoint Administrator. Note that file-level reporting now requires the SharePoint Advanced Management Administrator role specifically, which is a superset and must be assigned explicitly — global admins do not hold it by default.
Sponsorship
Executive backing to delay deployment if the findings warrant it. Without that, the assessment becomes a formality.
Scope
A prioritised site list. Attempting the whole estate at once produces a report nobody acts on.
How it works
The concepts worth understanding first
Configuration is straightforward once these are clear. Skipping them is why most first attempts produce something that works and cannot be maintained.
Everyone Except External Users is the pattern to hunt
This sharing option grants access to every internal account. It is used because it works immediately and a permissions request does not. SharePoint Advanced Management now reports on it specifically, as a downloadable export rather than a dashboard, because the row counts are typically enormous.
Broken inheritance is where exposure hides
A library that broke permission inheritance in 2017 has been drifting ever since. Nobody reviews it because nobody knows it happened. These are usually a small number of sites carrying a disproportionate share of the risk.
Restricted access control buys you time
Site-level restricted access limits content to a defined group regardless of individual permissions. It is a blunt instrument and it is genuinely useful as a holding measure on high-risk sites while proper remediation proceeds.
Configuration
Step by step
Settings shown are the ones that matter, not every field on the form. Values are starting points to validate against your own environment.
01
Assign the reporting role and run the baseline
The SharePoint Advanced Management Administrator role has to be assigned explicitly, even to a global administrator. Assign it to yourself first, then run the governance reports.
Start with the sharing links report and the permissions report. Export both — the volume defeats on-screen review.
Sharing links, EEEU exposure, permission state, site ownership
Output
Export to Excel or Power BI; file-level data is too large for a dashboard
02
Prioritise by content sensitivity, not by exposure count
A site with ten thousand overshared documents that are all published policies is lower risk than a site with forty overshared documents containing patient data.
Cross-reference the exposure report against your Purview classification results if you have them. If you do not, prioritise by site purpose and owner knowledge.
Priority 1
Sites containing PHI or staffing records with broad-access links
Priority 2
Sites with broken inheritance and no active owner
Priority 3
High-volume exposure of non-sensitive content
Defer
Template, training and published-policy libraries
03
Reconcile site ownership before changing anything
Every site needs an owner who can approve a permission change. Orphaned sites are common and they block remediation entirely, because nobody is willing to remove access without someone accountable saying it is fine.
This step is administrative rather than technical and it is usually the longest part of the project.
04
Apply restricted access to the highest-risk sites
Restricted Access Control limits a site's content to members of a specified group. Apply it to Priority 1 sites as an immediate containment measure while the detailed permission work proceeds.
Communicate this before you apply it. Users who lose access without warning raise tickets, and a wave of tickets is how remediation programmes get paused.
Control
Restricted Access Control at site level
Group
The site's legitimate membership group, verified with the owner
Communication
Notify site members before enabling, with a route to request access
05
Remediate links and inheritance, then re-baseline
Remove or replace broad-access links with scoped ones. Re-establish inheritance where it was broken without reason. Then run the reports again and compare.
Bulk disabling of overshared links is available and should be used deliberately rather than broadly — a bulk action across the estate will break something a clinician relies on.
Verify it worked
Re-run the sharing and permission reports and confirm Priority 1 exposure has fallen to the agreed threshold.
Confirm every site in scope has a named, responsive owner recorded.
Pick five remediated documents and confirm the intended users still have access and others do not.
Run a Copilot query as a test user against a remediated site and confirm nothing unexpected surfaces.
Confirm the support queue has returned to baseline after any restricted access changes.
Best practice
What we do on every engagement of this type
Assign the SharePoint Advanced Management Administrator role explicitly before you start
Prioritise by content sensitivity, not by the size of the exposure number
Fix site ownership first — it blocks everything else
Use restricted access as containment while detailed remediation proceeds
Communicate before removing access, always
Re-baseline after remediation and schedule a recurring review
Pitfalls
What catches most first attempts
Every one of these is avoidable, and every one of them is common enough that we check for it by default.
!Running a bulk link removal across the estate
It is available and it is tempting. It will also break a workflow that a ward relies on, and the resulting escalation will pause the programme. Remediate by site, with the owner involved.
!Deploying Copilot to a pilot group during remediation
The pilot group will find the unremediated content, and the finding will reach leadership as an incident rather than as a planned discovery. Finish the priority sites first.
!Treating the report as the deliverable
An exposure report nobody acts on is an audit finding waiting to be discovered. Agree the remediation commitment before you run the assessment.
!Ignoring OneDrive
Personal OneDrive accounts hold a surprising amount of shared clinical content. They are in scope, and they are usually forgotten until someone queries something they should not see.
Completion checklist
Advanced Management Administrator role assigned and reports exported
Sites prioritised by content sensitivity with a documented rationale
Every in-scope site has a named, responsive owner
Restricted access applied to Priority 1 sites with user communication sent
Broad-access links remediated site by site with owner sign-off
Post-remediation baseline captured and recurring review scheduled
Want a second pair of eyes?
We run this assessment as a scoped, fixed-price engagement with the findings report delivered to you regardless of whether you take the remediation work further with us.