Microsoft 365 provides various tools such as the Copilot Dashboard, Copilot Activity Reports, and SharePoint Oversharing Reports to analyze and manage content sharing and user activities. These tools help assess readiness, adoption, and impact of Copilot rollout and usage in addition to auditing sensitive data.
- Copilot Dashboard: The Insights dashboard in Teams (or the Copilot Dashboard in Teams Admin site) allows you to analyze readiness, adoption, and impact tabs to assess Copilot rollout and usage.
- Copilot Activity Reports: These reports are available in the M365 Admin Center and provide insights into how Copilot is being used across your organization.
- SharePoint Oversharing Reports (requires E5): These reports in the SharePoint Admin Center help identify instances where content is shared beyond the intended audience. These reports are only for SharePoint sites and do not include OneDrive data.
- Sharing Links report includes up to 100 sites with the highest number of sharing links created in the last 30 days.
- You can also get the primary administrator for each site.
- See a report on the types of policies applied to the sites (sensitivity, unmanaged device policy, and external sharing).
- And finally, a report showing files that have sensitivity label applied.
- SharePoint Oversharing Script: This script crawls through each site and document library to check for organization-wide sharing links. It can be customized to prioritize sensitive locations like Finance, HR, and Research.
- M365 Sharing Toolkit: This toolkit includes scripts that extract API calls as JSON and process them in Power BI or CSV.
- Purview Audit Reports (Requires E5 or E3 with Compliance add-on): These reports provide basic auditing capabilities to track user activities and configuration changes within the Microsoft M365 tenant. Use “Copilot interactions” as a condition in eDiscovery.
- Compliance Manager: Offers tools and dashboards to manage compliance with regulatory standards, simplifying compliance management.
- AI Hub: Currently in preview, the AI Hub is accessed through the Purview portal. Here, you can get recommendations to protect sensitive data and track AI interactions and visits in preconfigured reports.
1. Guest Access Reviews: Automate the periodic review of user access to teams and groups to ensure guests don’t retain access to sensitive information for longer than necessary.
Reports Requiring Additional Microsoft Subscription:
- Advanced Insights: These reports provide deeper insights into user behavior and collaboration patterns. They are available through Viva Insights.
- SAM (Security and Access Management): Accessed through the SharePoint Admin Center, these reports focus on link creation and sensitive data discovery, providing detailed insights into data access and sharing.
- Anyone links (Everyone except extern users)
- Links shared externally
- Links that don't expire
- Change history reports
Auditing for oversharing is an essential practice that helps organizations identify instances where content is shared beyond the intended audience. This can help prevent data breaches, protect intellectual property, and maintain compliance with regulatory standards. Use any of these tools available to you or create your own reports using Power BI.
Senior Project Manager at Lockwood, Andrews & Newnam, Inc.
5moThanks for sharing