Skip to content

Agent Knowledge Source Scanner

Version: v1.1.0 | Status: live | Domain: Content & Data Protection | Tier: 2

Item-level permission scanning for SharePoint libraries connected to Copilot Studio agents as knowledge sources.

Mapped Controls

4.3, 1.4, 1.5

Prerequisites

Role Requirement
sharepoint-admin SharePoint Site Collection Admin or Site Member access is required to read item permissions in each target knowledge source library.
global-reader Entra ID Reader or GroupMember.Read.All is required when resolving agent user scope from -AgentUserGroupId.

Verification

Run Get-KnowledgeSourceItemPermissions.ps1 and confirm RiskScore values in ./output/item-permissions-report.csv, then cross-check any flagged items in SharePoint Manage Access.

Documentation

Document
Prerequisites
Troubleshooting

View source on GitHub { .md-button }