Prevent Copilot Oversharing with SharePoint Premium f/ Microsoft’s Sanjoyan Mustafi

Microsoft’s Sanjoyan Mustafi is back again! This time, he’s here to help you prevent the Copilot oversharing problem with SharePoint Premium Permission State Report! If you’re looking for a way to inform yourself on how to FINALLY prevent oversharing with Copilot, this one is for you!

Watch my 80+ courses on Pluralsight

Video Summary

  • New Permission State Report: Microsoft is introducing a new report called the Permission State Report, which provides a snapshot of the current permissions on files, folders, libraries, or sites, helping to identify oversharing issues.
  • Detailed Reporting Options: The report allows filtering by SharePoint sites or OneDrive, template types, sensitivity labels, and the number of users. It helps track oversharing by showing the number of files, sensitive data, broken inheritance, and sharing links.
  • Workflow for Site Owners: A new workflow enables admins to send access review requests to site owners, who can then review and clean up permissions. This process is fully auditable, ensuring transparency and accountability.
  • Automated and Scheduled Reports: An upcoming feature called Auto Run will allow admins to schedule permission checking reports at regular intervals, making it easier to maintain a secure environment over time.
  • Integration with M365 Copilot: All features under SharePoint Advanced Management (SAM) will be included with the M365 Copilot license, making it more accessible and cost-effective for organizations to secure their SharePoint environments.

For more information, read the transcript blog below, or watch the video above!

Video Transcript

Hello, everyone. We are live from ESPC 2024 in Stockholm, and it’s the last day of the conference. Copilot is, of course, a big topic, as with every Microsoft conference, but what we hear a lot is that oversharing is a major blocker to not only buying Copilot but also deploying it across the organization. In the past year, Microsoft has done tremendous work by adding a ton of features to help with data access governance reports, such as the “Everyone except external users” report, among others. However, as much as we love them, there are still a few things missing. Today, I’m joined by Sanjoyan Mustafi. How are you doing, Sanjoyan?

Thank you, Vlad. I’m doing great. This is an awesome conference, and you know, it’s the last day we are recording this, and I’m very privileged and honored to join your show.

Well, thank you so much for being here. The reason I wanted to get you on video today is that you have been working on something cool to bridge the gap between data access governance and a few of the gaps that were missing. I love data access governance reports, but one of the big problems people had was that they only looked at the last 28 days.

That is true. You get some amazing insights from the report, but you have no idea how bad your situation is overall; you only know how bad people were in the last 28 days. So, while it helps you keep your environment Copilot ready, it doesn’t necessarily get it there.

True. But you told me you’ve been working on something cool to help solve that. Can you talk a bit about it?

Yes, thanks for setting that up. It is true that we started our journey with audit-based data where we tracked what is happening to your data, who is sharing, and who is oversharing over the last 28 days. As Vlad mentioned, several of our customers also told us that they first need to understand what oversharing is happening at this point in time and then track it on a month-by-month basis. So, the big news, Vlad, is that we are introducing a new report called the “Permission State Report.” What does “state” mean? State refers to the permissions situation on a file, folder, library, or site at this point in time. It tells you how many users have access right now. That is the power of this new report.

So, it takes a snapshot of my environment?

You used the right word, “snapshot.” Yes. As you create a snapshot, you know everything. If we look at it, and you gave me access to a quick early demo, in data access governance, we are going to have a new option called “Content accessible to permissioned users.” From here, we create a new report. Can you talk a bit about the options we have?

Absolutely. You see, like any other report, you give a name to the report, and then you choose whether you want to run the report against SharePoint sites or OneDrive. Yes, we now have the power to run your reports against all your OneDrives and SharePoint sites seamlessly. You make the choice. You can further filter down based on template types, for example, communication sites, team sites, or any other template you are using. You can also filter on sensitivity labels if you are using them. Finally, the main choice you are going to make is whether you want to run an audit-based report or, as Vlad mentioned earlier, a snapshot report. That’s what we are going to choose today. The very last option in this report is about the number of users you think you are going to track against the people who have access to a SharePoint site. For example, we can say that if I have to run this report, more than a thousand users are defined as oversharing according to my company. So, you can say, “Find all the sites which have contents that are shared with more than 1,000 people.”

Okay, and that’s where you start. Is there a minimum today, and what is the minimum amount of users? Can I put it to one?

That’s a good question. Vlad always analyzes our product deeply, so you asked the right question. Today, we have a limit of 100. You cannot mention less than 100 in the report. However, the good news, Vlad, is that we are going to change that next year, where you can have one. You can’t have zero, of course, because if it’s zero, you have other problems.

Yeah, you have the owner report a problem for that. Nobody’s using your site.

Okay, so right now it’s 100. However, it will go down to one in the future, next year—next calendar year.

Next calendar year, definitely. We’ll try to do it early.

I always ask when it’s Microsoft, and what year—calendar or fiscal—they are not the same. Okay, awesome. So, we do the report; it takes a bit to run, I guess. I don’t think it’s instant. Do you want to explain that part?

Yes, you are absolutely right. It takes some time, depending on the size of the tenant. I’ll explain why, Vlad. We have to go to each and every site, each and every library, folder, subfolder—any nesting that you have—all the files, every file, to find out whether you have broken inheritance on the file, and then extract the data, deduplicate the data, because you might have the same user having access to document A and document B. We do not want to count them twice. So, we do all the cleanup and then roll up the data at a site level. Yes, it takes some time, but you can trust the data. We provide clean data, again, depending on the number of sites.

Maybe a technical question on the backend. Do you use Microsoft Graph Data Connect to build this? Because I know that’s another way right now to take a snapshot. Or did you build something specifically for this?

I would answer it this way. Internally, we built this data lake where we pump in all the data on a regular basis and then extract the content. If you are trying to use Microsoft Data Connect, which you can do on your own, however, this report will save you some effort because you need to create the data connect, connect it with Synapse, build a report, pull the data, and maintain this solution.

If you are just looking for an oversharing-based solution, I would recommend running this report at least once. It’s easy, just a couple of clicks, and then you get that level of clarity around sites, files, and folders that are overshared. This will be much cheaper than Graph Data Connect because Graph Data Connect charges you based on size, whereas this is included in the SAM license.

True, true. Okay, so we wait a bit. The report runs. We see all our reports here, and after that, we open up the report, and we have a ton of information.

Yes, let’s talk about some of the columns that we see here on the screen. The first one that I see is “Files containing sensitive data.”

I would like to start with the first column, which is “Count of files.”

“Count of files.” Yes, perfect.

So, this is the first piece of information we provide in the report. We say the site that has more than 100 users because we started the report with that. Then we say how many files you have. Why is that important? Because we would like to stop oversharing of a site with more files versus fewer files. So, probably that is a measure or a metric for you to consider—that this site is highly exposed and has a lot of content in it. Then you are right. We are bringing in a new feature, which we don’t have right now, but we will bring this information.

We connect with the sensitive information type that you define in Purview Portal. We have plans next year to marry these two so that you know not only does this site have, let’s say, 1,000 files, but 100 files contain passport numbers, SSN numbers, credit card numbers, and other sensitive information types you’ve defined. We’ll show you how these files indicate the importance of the site’s content. It really helps you prioritize your data.

As you mentioned, identifying your most sensitive data and securing it right away is crucial. If a site has many files, none of which are sensitive, it can be a lower priority. Next, we see broken permission inheritance. SharePoint is very flexible, but with great flexibility comes complexity. In the screenshot, we’re lucky not to have many broken permissions, but in real life, this can be more common.

Broken inheritance means that the site’s content has been shared multiple times. For example, Vlad, you might have a site with 100 users at the site level, but a few folders within it are shared with the entire company. This means the site itself might not be heavily shared, but individual contents are. Broken inheritance is a sign of oversharing. After that, we have “Everyone except external users,” which should hopefully always be at zero.

I agree unless there’s a specific reason for sharing with everyone, such as a keynote session by Satya Nadella intended for all employees. However, sensitive content like mergers or acquisitions should not be shared with everyone. We show the count of files, folders, or libraries shared with everyone in a given site—higher counts indicate higher chances of oversharing. Ideally, this count should be zero. Instead, I recommend creating groups such as “all company,” “all full-time employees,” and “all contractors” and sharing with those groups instead.

Next, we see “People in your organization” links and “Anyone” links, which can cause oversharing. A company shareable link is a link generated once that can be passed around. Anyone who clicks the link gains access to the file, but unless they click it, they won’t get permission. This link is an indicator of oversharing, as more people can potentially access the file. I liken it to leaving a key under a carpet—it’s not entirely hidden and poses a risk.

“Anyone” links can lead to oversharing, especially if the default option is set to grant anyone with the link edit permissions. Users tend to choose the path of least resistance and create broad access links. I advise changing the default to “people with existing permissions” to prevent breaking inheritance. Finally, we have site privacy settings (public or private), site sensitivity, and whether external sharing is enabled or not. Currently, external sharing is shown as simply on or off, but we’ll gather customer feedback for potential improvements.

After running a report and identifying high-risk sites, you can take action. If a sensitive site, such as finance or legal, has excessive access, you can immediately apply a Restricted Access Control Policy. This can be done right from the report.

However, in several cases, we have spoken to many admins across the industry, and because of business continuity and productivity, they don’t want to apply a restrictive policy on day one itself. They would like to talk to the owner of the data—the real business owners—to find out what is going on with the data. So, what we have done, Vlad, in this case, is provide a workflow for the admin so that they can start a conversation with the site owner in a way that can be maintained across the system. The site owners can now look at exactly the problem areas in their site, clean them up, and then respond back. This entire workflow is now inside the system as part of your reporting and action.

I love that we have empowered the business users because, as an admin, I know everything about the admin center, but I don’t know who works on your project or who should be there or not. By putting that responsibility on the business owner, we ask them to look at everything and tell us if there is anybody they can remove or if everything looks right. This not only empowers them but also reduces the admin workload as we delegate the responsibility to the business owner to take care of their own stuff.

So, we say, “Okay, Sanjoyan, you are the owner of this site. We think it might be overshared, but we want you to check it out and validate it for us.” You receive an email saying, “Your

SharePoint admin asked you to do a review.” You click on a link, and then you get to a site.

Correct. You will get the email in the context of the site that you own or administer, specifying a link that will take you to a specific new page we have created inside the site called the “Site Access Review Page.”

In this review page, we provide more details. If the site has 1,000 files, it would be overwhelming to check each file individually. We have identified which files and folders are contributing to oversharing within a site and present that information. So, in this example, the site had many files, but we only present the primary contributors to oversharing.

I see here I have “krosa Finance,” which is my SharePoint site level, and then I have a file and a folder. These are my broken inheritance items.

Exactly. If you look at the next slide, we provide details such as the number of users uniquely permitted to each file. For example, if a file says 9,000 users, it’s improbable for you, as the site owner, to individually share the file with all 9,000 users. You don’t have that many friends, right? So, we need to help you understand why this happened.

The next column shows the number of groups with access. When you hover over the group count, a popup shows each individual group permitted to that document and the count of members in those groups. For instance, if the “contoso marketing” group has 7,000 users, this is the major contributor to oversharing. By removing that one group, you can dramatically reduce oversharing.

Is there a way to have just one button to revert to the original file permissions when I know it’s a broken inheritance?

We are thinking about designing a feature like that. Imagine a big red button that says, “Hey, I am non-compliant, click this button and make me compliant.” This concept is similar to the Staples “that was easy” button.

After handling the exceptions, you can find better ways to add people to the full site rather than breaking permissions. Historically, people have created folders and used them to give permissions, but we recommend using the site as your boundary. This keeps all permissions at the site level and avoids complicated folder structures.

True, but I think users did this because, in the on-premise days, it wasn’t easy to create a new site. Now, it’s much easier to create sites in SharePoint Online without needing IT intervention.

Lastly, the “status” column allows you to provide context for legitimate cases of broad sharing. For example, if a file is intended for marketing or social sharing, you can justify its broader sharing. This justification is auditable, and the admin can review it later to ensure compliance.

And so again, as you said, Vlad, we put the responsibility back to the real people who understand the file and know what it is.

Exactly, exactly.

Awesome. Is there a way right now to just say, “Do an access review every three months?” Like, with Entra ID and access reviews, I can say every three months to email the site owners and ask for a full site review. Can we have that kind of proactive scheduling, or are we more in a reactive mode where we do a snapshot or identify ten problematic sites and review those ten?

What you ask is absolutely legitimate. We are coming up with a feature called Auto-Run. It’s coming early next year. With this feature, you can schedule permission checking reports to run every month, every two months, or every three months. Let’s say you run this report against 10,000 sites you have. I’m already scared. You do it once and send the reviews to your site owners. Assume the site owners do good work and clean it up. From that point onward, you can run much cheaper audit-based reports.

I recommend running the permission report first and then the audit-based report. Once you reach an acceptable state—everything won’t be perfectly clean, but it will be acceptable—by running the audit report, you can monitor who is contributing to oversharing by tracking the activity. For example, Vlad is a good user, but last month, he shared ten files with thousands of people. You can then narrow down and find patterns to address the root cause of the problem. Yes, in practice, you can do this because we are giving the auto-run feature. You can plan your next steps accordingly.

When you talk about the audit-based report, you mean more of the data access governance reports we have today, showing all the “anyone” links or “people in my organization” links for the past 28 days. These are the options we have now. They’re not called audit-based in the UI, but we know how they run in the background.

Correct. This is an important point. We showed you that a report will tell if a site has, let’s say, 100 company-sharable links. If the site owner cleaned it up and the count became zero, you can track it. If the count increases, you can ask why this is happening.

Awesome. If I want to run this today, is it available?

That’s a good question. The UX we showed in this demo will be released early next year. However, today, you can run all the stages we spoke about using PowerShell commands, which are already released.

You are a geek.

I know it’s coming to the UI eventually, but I love PowerShell. We started with PowerShell because if you have a large number of sites with a lot of content, it can be overwhelming to scroll through. So, we found it natural for people to download the report in CSV format, which you can do today. The PowerShell generates the CSV out of the box, allowing you to do your own filtering.

More questions for you: I’m intrigued by this, and I’m thinking about access reviews in Entra ID. Is there a way to handle lazy users who ignore me?

We don’t have a big red button from a SharePoint side right now. But, if you are talking about entitlement management…

In Entra ID access reviews, I can set it to take automatic actions if the owner doesn’t respond, such as denying access or taking the recommended action. Is there a way to automatically fix it and make the site compliant?

Yes, you can definitely do that right now. If the owner doesn’t respond, you can auto-fix it to make the site compliant.

Awesome. If the owner is on vacation and comes back angry, is there an undo button?

That’s an excellent question. Admins are usually afraid to change site permissions without talking to the business owner. If the business owner is on leave and comes back to find that permissions were changed, users might be upset. We recommend using restricted access control for this. You define a security group, put ten people in it, and apply that security group using restricted access control on the site. When the site owner returns, they can clean up and then remove the security group from the site. This way, whoever legitimately should have access will continue to have access.

Restricted access control is like a checkbox to secure the site temporarily. It doesn’t change any permissions on the files; it just applies a policy. Once everything is cleaned up, you can remove the protection and have a clean site.

Exactly. It’s like a protection umbrella across the site without changing permissions inside the site, unless you change them manually. After cleanup, remove the protection because the site is now in the desired state.

I love it. I don’t know why I didn’t think of that, but it makes so much sense.

I think you answered a lot of my questions. For once, I’m out of questions.

I feel good, Vlad. If you want, I can look at more, but I can’t wait to play with it. The documentation to run it via PowerShell is already live, and I’ll make sure to put a link in the description below. If you have SAM, definitely try it out. If you don’t have SAM yet, get a trial and try it out. The best time to secure your SharePoint environment is yesterday, so start doing it today. Worst case, you get a free trial for 30 days, extend it to 60 days, and by then, the new licensing changes will come into effect. You’ll be able to get SAM at a very interesting price because it’s now included with M365 Copilot.

You are right. Thanks for bringing this topic up. We announced this at Ignite, and you covered it in your prior video post. All the features under SharePoint Advanced Management will be available if you have a Copilot license. Please talk to your Microsoft team to find out more and get the Copilot license. We all need to try Copilot, and before that, run these reports, check your data, and clean up your data, so you have peace of mind when you deploy Copilot.

Awesome. Thank you so much for your time. This is amazing. I already started the PowerShell on my tenant, so I can’t wait to see the results and start playing with it. Thank you so much for your time and for helping us learn how to make our SharePoint environment more secure. Thank you for being here.

Thank you.

Blogs and Videos