Sharing-link, permission and Everyone except external users reports for finding oversharing.
From Ultra Transcenders AB-900 by Tony Rough (coming November 2026)
Before fixing oversharing, an administrator has to find it. Data access governance (DAG) reports identify sites that contain potentially overshared or sensitive content. They are in the SharePoint admin center at Reports > Data access governance, and can also be generated with SharePoint Online PowerShell.
| Report | Type | What it shows |
|---|---|---|
| Site permissions across your organization (recommended first) | Snapshot | Permission structure of every SharePoint and OneDrive site, by number of unique users with access; finds sites with thousands of users, guests or EEEU |
| Site permissions for users | Snapshot | All sites that given users can access (up to 100 users per request), directly or through groups |
| Sites and files shared via special SharePoint groups | Snapshot | Exactly which sites, folders and files are public through EEEU or Everyone |
| Sensitivity label applied to files | Snapshot | Sites holding files with a chosen sensitivity label (requires E5 or G5) |
| Sharing links | Activity, last 28 days | Sites where users created the most Anyone, People in your organization or Specific people (guest) links |
| Shared with ‘Everyone except external users’ | Activity, last 28 days | Sites and items shared with EEEU recently |
Snapshot reports show the state on the date generated; activity reports catch recent oversharing as it happens. Microsoft suggests running the permissions snapshot quarterly and the activity reports monthly.
Common trap: Expecting the sharing links report to list every link that exists - it is an activity report covering links created in the last 28 days; the baseline of current access comes from the site permissions snapshot report.
This note is one section of Ultra Transcenders AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals, an independent study guide that explains every topic the exam covers by technology, with comparison tables, diagrams and the common traps, plus a glossary linked to Microsoft Learn.
Due on Amazon in November 2026, in Kindle and paperback editions.
About the book · AB-900 terms in the glossary · All AB-900 study notes
Verify explicitly, use least privilege access and assume breach, and the pillars they apply to.
How Conditional Access turns sign-in signals into block or grant decisions, and what licence it needs.
What the score measures, how often it is recalculated and which recommendations raise it.
What each Exchange Online mailbox permission allows and which recipients and groups can hold it.
How restricted site access limits a site to members of chosen groups, even for users with permission.
What the two built-in reasoning agents are for, how they are deployed and when a custom agent fits.
How billing policies connect metered Copilot Chat and SharePoint agent use to an Azure subscription, and what budgets do.