Understand data protection and governance tasks for Microsoft 365 and Copilot
SharePoint Oversharing and Advanced Management
ImportantInvestigate effective access from evidence to permission path, remediate the source, and apply SharePoint Advanced Management controls correctly.
Aligned to the current AB-900 guide, verified July 22, 2026.
Why this matters
AB-900 expects you to trace how SharePoint access was granted, use governance reports as evidence, and distinguish discovery controls from permission remediation.
Must Know
- Copilot respects effective SharePoint permission; it may reveal oversharing more quickly, but it does not create the source access.
- Access can be direct, inherited, group-derived, Teams-connected, or link-based. Find the actual permission path before removing access.
- Data Access Governance reports identify exposure and support review; reports do not change permissions automatically.
- Fix oversharing at the source by correcting owners, memberships, links, inheritance, or unique item permissions.
- Restricted access control adds an allowed-group gate on top of normal SharePoint permission; membership in that group alone does not grant access.
- Restricted content discovery reduces organization-wide search and Copilot discovery while permissions are reviewed; it does not block direct access for users who already have permission.
- SharePoint Advanced Management groups governance capabilities; choose the narrow control that matches the observed risk.
Compare and Distinguish
- Copilot permission trimming vs source remediation: honor effective access vs correct who should have access.
- Direct vs inherited vs group-derived vs link-based access: four distinct permission paths that can produce the same ability to open a file.
- Data Access Governance report vs access control: evidence and review support vs enforcement.
- Restricted access control vs normal permission: additional allow-group gate vs the underlying SharePoint grant.
- Restricted content discovery vs restricted access control: reduce organization-wide discovery vs block access unless both gates are satisfied.
Scenario examples
- Scenario: Copilot cites a finance file and the employee can open it manually. Think: Trace SharePoint access and remediate broad membership/link/permission before changing Copilot settings.
- Scenario: A user has site permission but is outside the restricted-access group. Think: Access is denied because both normal permission and control-group membership are required.
- Scenario: A user is added to the restricted-access group but has no site permission. Think: Access is still denied because the restriction never grants permission.
- Scenario: A site is hidden from organization-wide discovery but a user opens a saved link. Think: Restricted content discovery changed discovery, not the user’s permission.
Exam traps
- Copilot does not grant SharePoint access and cannot be expected to repair an overshared source.
- Restricted access control restricts existing access and never grants access by itself.
- Restricted content discovery leaves permissions unchanged and is not permanent remediation.
- A report identifies evidence; an administrator or owner must still change the permission or governance object.
Key takeaways
- Can the user open it? How did access arrive? Fix that source path.
- Report → review → right-size permission → apply targeted controls → retest.
- RAC = normal permission AND allowed group; RCD = discovery suppression, not access denial.
How it works
- SharePoint evaluates the user’s identity, direct and group membership, sharing links, inheritance/unique permissions, and any site-level access restriction. A user must satisfy every required gate.
- Data Access Governance aggregates permission states and sharing patterns. Administrators use the evidence to start owner reviews, remove broad links or memberships, restore inheritance where appropriate, and monitor change.
- Restricted access control adds a permitted-group gate on top of normal permission. Restricted content discovery changes organization-wide discovery behavior while leaving access intact.
Objects and administrative surfaces
- Active sites, sharing settings, Data Access Governance, site access reviews, restricted access control, restricted content discovery, and lifecycle controls — SharePoint admin center.
- Site Owners/Members/Visitors, Microsoft 365 groups, Entra security groups, sharing links, unique permissions, libraries, folders, and files — SharePoint/Entra resource experiences.
- Copilot readiness and data-risk evidence can also appear in Microsoft Purview DSPM; source permission remains managed in SharePoint/identity surfaces.
When to use it
- Use Data Access Governance reports to identify broadly exposed sites, understand how a user receives access, and prioritize review.
- Use restricted access control for a high-risk site that must be usable only by designated groups in addition to normal permission.
- Use restricted content discovery selectively and temporarily while high-risk sites are reviewed; remove it after access is right-sized.
Security and governance implications
- Assign accountable site owners, review anonymous/company-wide links and broad groups, and use expiration/access reviews where appropriate.
- Prefer group-managed site roles and inheritance over scattered direct item grants; document justified exceptions.
- Use discovery suppression as a temporary risk-reduction measure and track the permission-remediation work to completion.
Troubleshooting signals
- Step 1: test whether the user can open the exact content directly. Step 2: inspect Check Permissions or equivalent evidence and identify direct, inherited, group, link, or Teams-derived access.
- Step 3: use site-permissions-for-user and permission-state/sharing reports to determine whether the issue is isolated or systemic. Step 4: correct source ownership, group membership, links, inheritance, or unique permissions.
- Step 5: verify restricted access/discovery configuration, control-group membership, propagation, licensing, and expected behavior. Step 6: retest direct and Copilot access.
- If access remains after one grant is removed, look for another path such as nested group membership, a second link, site admin status, or unique permission.
More detail
- Copilot respects SharePoint permission. If a user can open a cited file manually, Copilot did not create the access; it made already-authorized content easier to discover. Remediation begins with the source permission model.
- Effective access can come from a direct user grant, site/library/folder inheritance, Microsoft 365 or Entra group membership (including nesting), a sharing link, Teams-connected membership, or unique item permissions. The investigator must find the actual path before removing access.
- A sound troubleshooting sequence is: confirm direct access; identify how permission was received; inspect owner/membership/link/inheritance evidence; use Data Access Governance reports to measure broader exposure; correct source access; then add targeted controls if residual risk requires them.
- Data Access Governance reports include permission-state and sharing views and a site-permissions-for-user report that helps show which sites a person can access and how access is granted. Reports identify risk and support access reviews; they do not silently repair permissions.
- SharePoint Advanced Management includes capabilities for data access governance, site lifecycle and ownership, access reviews, restricted access control, restricted content discovery, and other content-governance scenarios. Use the narrow control that matches the risk.
- Restricted access control requires a user to have normal site/content permission and membership in an allowed control group. It restricts existing access; adding a user to the control group does not grant normal site access.
- Restricted content discovery suppresses selected site content from organization-wide search and Copilot discovery while permissions are reviewed. Users with permission can still access content directly, so it is a temporary discovery control—not a substitute for right-sizing permission.
Ready for the quiz?
- Why is Copilot permission trimming not a fix for oversharing?
- Which access paths should you investigate before changing a permission?
- What does a Data Access Governance report do—and not do?
- How do restricted access control and restricted content discovery differ?
Related objectives
- D2.4.a — Identify the tools to troubleshoot oversharing in an organization
- D2.4.b — Run a data access governance report in SharePoint
- D2.4.c — Understand features and capabilities of SharePoint Advanced Management, including restricted access control