Skip to content

Control 1.2: SharePoint Oversharing Detection and Remediation (DSPM for AI)

Control ID: 1.2 Pillar: Readiness & Assessment Regulatory Reference: GLBA §501(b), SEC Regulation S-P (Rule 248.30), FFIEC IT Handbook (Information Security Booklet) Last Verified: 2026-07-26 Governance Levels: Baseline / Recommended / Regulated


Objective

Detect, assess, and remediate SharePoint oversharing risks before and during Microsoft 365 Copilot deployment using Microsoft Purview Data Security Posture Management (DSPM). This control addresses the "discovery amplification" risk -- where Copilot's ability to search and synthesize content across a user's entire permission scope transforms latent oversharing issues into active data exposure incidents.

The unified DSPM experience reached general availability in May 2026 (Microsoft 365 roadmap ID 532728). It converges the previous DSPM and DSPM for AI surfaces into a single solution, adding data security objectives, AI observability, item-level scanning and remediation, and the Data Security Posture Agent across M365 and Copilot workloads. The previous surfaces remain available and are now named DSPM (classic) and DSPM for AI (classic). The current experience is reached from the Microsoft Purview portal > Solutions > DSPM; the classic surfaces appear in the same portal under their "(classic)" names. Where Microsoft 365 admin-center shortcuts are available, treat them as convenience entry points and verify the current path against the Purview experience before documenting operational procedures.


Why This Matters for FSI

  • GLBA §501(b): Requires financial institutions to protect against unauthorized access to customer financial information. SharePoint sites shared with "Everyone" or "Everyone Except External Users" create access paths that Copilot can exploit to surface non-public personal information (NPI) to users who should not have access.
  • SEC Regulation S-P (Rule 248.30): Requires broker-dealers, investment companies, and investment advisers to adopt written policies and procedures addressing administrative, technical, and physical safeguards for customer records and information. Oversharing detection directly supports these technical safeguards.
  • FFIEC IT Handbook (Information Security Booklet): Expects institutions to implement the principle of least privilege. Broad SharePoint sharing directly contradicts this principle and can result in examination findings.
  • Sarbanes-Oxley §§302/404 (where applicable to ICFR): Where oversharing affects access controls over financial reporting data, workpapers, or internal control evidence, Sarbanes-Oxley §§302 and 404 assessments may need to evaluate the risk that Copilot could surface pre-release financial information or audit findings to unauthorized personnel.
  • FINRA Rule 3110 (supervisory systems and WSPs): Requires firms to maintain supervisory systems and written supervisory procedures (WSPs) reasonably designed to achieve compliance. Oversharing controls support supervision of access risks, particularly where Copilot could surface information across supervisory boundaries.

Control Description

Understanding Discovery Amplification

Microsoft 365 Copilot inherits the calling user's permissions and searches across all content that user can access via Microsoft Graph. Before Copilot, a user with overly broad SharePoint permissions might never navigate to or discover sensitive content. With Copilot, a simple natural language query can surface that content instantly.

Discovery amplification refers to this phenomenon: existing permission gaps that were low-risk due to practical obscurity become high-risk when AI-powered search makes all accessible content equally discoverable.

Pre-Copilot State Post-Copilot Reality
User has access to 500 SharePoint sites but regularly visits 10 Copilot searches all 500 sites on every query
"Everyone" sharing links exist but are rarely clicked Copilot treats these as valid access paths for grounding
Stale project sites with broad permissions sit unused Copilot can retrieve and cite content from these sites
Sensitive files buried in nested folders Copilot surfaces them based on relevance, not folder depth

DSPM Capabilities

Microsoft Purview DSPM provides purpose-built tools for detecting and remediating oversharing risks. The unified experience organizes them under data security objectives such as Prevent oversharing of sensitive data and Prevent data exposure in Microsoft 365 Copilot and Microsoft Copilot interactions, and adds AI-specific capabilities across the M365 and Copilot surface:

Capability Description Frequency
Data risk assessments The current name for what earlier releases called the oversharing assessment. Scans SharePoint and OneDrive (and, separately, Fabric workspaces) for content accessible to broad audiences and cross-references sensitivity labels and sensitive information types. A default assessment runs weekly across the top 100 SharePoint sites by usage; the first default assessment has a four-day delay before results appear, and results take about 48 hours to populate. See Prevent oversharing with data risk assessments. Weekly default + on-demand custom
Item-level scanning and remediation Identifies and remediates potentially overshared individual items rather than whole sites. Available on custom data risk assessments only, currently limited to SharePoint sites (OneDrive is not supported for item-level scanning), a maximum of 10 sites per scan, and dependent on a registered Entra application. Remediation actions are Resolve, Apply sensitivity label, Notify site owner, and Remove sharing link. On-demand (custom assessment)
AI observability Inventory of AI apps and agents with activity in the last 30 days, showing how many are high risk and how many had sensitive interactions, with a per-agent breakdown and the policies that govern them. Continuous (30-day activity window)
Activity explorer (AI activities tab) Shows AI interaction events — AI interaction, AI website visit, DLP rule match, and sensitive info types detected — including prompts and responses where auditing or a collection policy captures them. Data is sourced from the unified audit log, so this is not a real-time view: allow 60–90 minutes for core services such as SharePoint, and note it reports on up to 30 days of data. Near-continuous (60–90 minute audit-log lag)
Asset explorer Unified view of unlabeled and classified data by workload across Microsoft and non-Microsoft locations; Microsoft locations currently cover Microsoft 365 only. The Standard tab holds the estate-wide inventory and the Agent tab hosts the Data Security Posture Agent. Continuous
Data Security Posture Agent Natural language prompts to discover sensitive information across the estate without pre-defining sensitive information types, with scheduled recurring prompts and direct sensitivity labeling of discovered files. Microsoft Learn documents this agent as in preview; Microsoft 365 roadmap ID 542790 lists general availability from June 2026 with a status of rolling out. Requires Microsoft 365 E5 with security compute units (SCUs) provisioned. On-demand or scheduled (daily / weekly / monthly)
AI app and agent discovery DSPM > Discover > Apps and agents surfaces AI apps and their agents in use across the organization, including apps not sanctioned through the Copilot Control System or IT governance processes. A separate, dedicated Shadow AI page for unmanaged standalone AI agents is in Frontier preview in the Microsoft 365 admin center under Agents > Shadow AI; it is not part of DSPM and has its own prerequisites (Microsoft 365 E5 and Intune enrollment for managed Windows devices). Continuous
Posture dashboard Key posture metrics, the top objectives to address based on risk, a snapshot of data use across the data estate, and a 30-day trend graph for the organization's data security posture. Continuous
Objectives and remediation actions DSPM > Objectives groups prioritized actions under data security objectives such as Prevent oversharing of sensitive data and Prevent data exposure in Microsoft 365 Copilot and Microsoft Copilot interactions. DSPM > Actions > Remediation actions exposes the same one-click policies independently of the objective workflows. Continuous
Non-Microsoft data source coverage Extends posture coverage to third-party SaaS and IaaS platforms such as Google Cloud Platform, Snowflake, and Databricks, and integrates partner risk insights from solutions such as Varonis, Cyera, BigID, and OneTrust. Configured through DSPM setup tasks, which include Microsoft Sentinel data lake integration (in preview). On-demand setup, then continuous

Oversharing Risk Categories

Risk Category Description Example Remediation Approach
Everyone / EEEU Access Content shared with all internal users via "Everyone" or "Everyone Except External Users" groups SharePoint site with "Everyone" as a member Remove broad groups, replace with specific security groups
Company-Wide Sharing Links Content shared via "People in your organization" sharing links Documents with company-wide links in sensitive libraries Revoke links, apply sensitivity labels, restrict link creation
Anonymous Sharing Links Content shared via "Anyone with the link" links Files accessible without authentication Revoke immediately, audit for data exposure
Large Group Membership Content accessible to groups with >500 members that effectively grant org-wide access "All Employees" group membership on sensitive sites Review group necessity, scope to relevant populations
Inherited Permissions Subsites or libraries inheriting permissions from broadly shared parent sites Sensitive library inheriting site-level "Everyone" permission Break inheritance, apply targeted permissions

Remediation Workflow

Detect ──> Triage ──> Remediate ──> Verify ──> Monitor

  1. DETECT: Run a DSPM data risk assessment
  2. TRIAGE: Prioritize findings by sensitivity x access breadth
  3. REMEDIATE: Apply appropriate fix per risk category
  4. VERIFY: Run a new assessment to confirm remediation effectiveness
  5. MONITOR: Set weekly cadence for ongoing detection

Remediation Actions by Type

Action When to Use Impact
Restrict access Remove broad groups (Everyone, EEEU) from site/library permissions Users lose access -- coordinate with site owners
Apply sensitivity labels Label content to enable DLP policies that prevent Copilot from processing Copilot respects label-based DLP restrictions
Remove sharing links Revoke company-wide or anonymous sharing links Existing links stop working -- communicate to affected users
Enable Restricted Content Discovery Use SharePoint Advanced Management to stop a site's content appearing in organization-wide search and Microsoft 365 Copilot discovery experiences Permissions are unchanged and content stays in the search index. Users can still open content directly, and can still discover content they own or recently interacted with. Also removes SharePoint AI entry points such as the Copilot button on the site.
Relocate content Move sensitive content to properly governed sites with appropriate permissions Content available in correct governance context
Archive content Move stale content to archive with restricted access Removes from active Copilot grounding scope

Copilot Surface Coverage

Copilot Surface Oversharing Risk Level Why
Microsoft 365 Copilot Chat Critical Cross-workload search surfaces all overshared content
SharePoint Copilot Critical Directly queries SharePoint content and respects site-level permissions
Teams Copilot High Accesses files shared in channels, which may link to overshared SharePoint sites
Word / Excel / PowerPoint High "Draft from" and "Reference" features pull from accessible SharePoint content
Outlook Copilot Medium May reference SharePoint content linked in email threads
OneDrive Copilot Medium OneDrive-specific, but shared folders create similar risks
Copilot Pages High AI-generated pages may incorporate overshared content into new collaborative artifacts
Copilot Notebooks High AI-generated notebooks may incorporate overshared content into analytical artifacts
Loop Copilot Medium Loop components can reference SharePoint content
Viva Engage Copilot Low Limited SharePoint content retrieval in social context

Governance Levels

Level Requirement Rationale
Baseline Enable the unified DSPM experience. Review the default data risk assessment. Review and triage top 20 highest-risk sites. Remediate sites with "Everyone" or anonymous access containing sensitive information types. Establish monthly custom assessment cadence. Review the AI app and agent discovery dashboards to identify unsanctioned AI tools. Addresses the most critical oversharing risks that could result in immediate regulatory exposure when Copilot is enabled. Visibility into unsanctioned AI apps is minimum viable governance for Copilot rollouts.
Recommended All Baseline requirements plus: remediate top 50 oversharing sites. Establish weekly review of DSPM data risk assessment results. Configure AI observability for continuous monitoring across Copilot and third-party AI apps and agents. Deploy the Data Security Posture Agent for exploratory data risk investigation. Implement automated alerts for new oversharing detections. Document remediation actions and outcomes. Provides ongoing oversharing governance with AI-specific visibility. The Data Security Posture Agent lets compliance teams investigate data risks without requiring pre-defined SITs.
Regulated All Recommended requirements plus: remediate all flagged oversharing sites before Copilot enablement. Use item-level scanning in custom data risk assessments for high-priority oversharing findings without disrupting site access, within the documented 10-site limit. Implement continuous DSPM monitoring with SOC/compliance team integration. Enable full AI observability alerting for Copilot interaction anomalies. Establish formal oversharing incident response procedures. Maintain remediation evidence for regulatory examination. Conduct quarterly independent review of DSPM findings. Comprehensive oversharing governance that supports compliance with GLBA, SEC Reg S-P, and FFIEC expectations for access control and data protection. Item-level remediation enables surgical remediation without business disruption, supporting faster compliance timelines.

Setup & Configuration

Step 1: Access DSPM

The unified DSPM experience is accessible from two paths:

  • Full DSPM: Microsoft Purview portal (https://purview.microsoft.com) > Solutions > DSPM
  • Copilot security quick access: Microsoft 365 admin center > Copilot > Overview > Security. This Copilot security dashboard covers the default DLP policy for Microsoft 365 Copilot, oversharing management, and data compliance insights. Viewing it requires the Global Reader role; making changes requires the AI Administrator role.

On first use, DSPM prompts you to accept initial setup tasks if they are not already turned on for the tenant. Allow roughly a day before tenant data is available to act on.

Prerequisites: - Microsoft 365 E5, or the Microsoft Purview Suite (formerly Microsoft 365 E5 Compliance) - Entra Compliance Admin, Entra Global Admin, or the Purview Compliance Admin role group. Some DSPM activities need additional roles — for example, the Data Security Viewer role for Security Copilot features. - SharePoint Advanced Management for full data access governance integration. Most SAM features, including Restricted Content Discovery, the data access governance reports, and site access reviews, become available once at least one Microsoft 365 Copilot license is assigned in the organization. Restricted site creation by apps is excluded and requires the SAM Plan 1 add-on.

Step 2: Run the Data Risk Assessment

Navigate to DSPM > Discover > Data risk assessments:

  1. Review the Default assessment, which runs weekly across the top 100 SharePoint sites by usage. Select View details, then select a site to open the flyout with Overview, Identify, Protect, and Monitor tabs.
  2. Use the Identify tab to see how much data has been scanned for sensitive information types, and start an on-demand classification scan where coverage is incomplete.
  3. Use the Protect tab to apply the built-in remediation options: restrict access by sensitivity label through a Microsoft 365 Copilot DLP policy, restrict all items through SharePoint Restricted Content Discovery, create an auto-labeling policy, or create a retention policy for content not accessed for at least three years.
  4. Use the Monitor tab to see how many items are shared with anyone, with everyone in the organization, with specific people, and externally, and to start a SharePoint site access review.
  5. Select Create custom assessment to scope an assessment to specific users or sites. Custom assessments are the only path to item-level scanning and remediation; select Item-level on the Scan level page and authenticate with the registered Entra application.

Both default and custom assessments provide an Export option (Excel, CSV, JSON, TSV). Custom assessment results expire after 30 days; duplicate the assessment to re-run it with the same selections. Microsoft documents a limit of 200,000 items per location, a maximum of 10 SharePoint sites for item-level scanning, and no OneDrive support for item-level scanning.

Step 3: Review AI App and Agent Discovery

  1. Open DSPM > AI observability for the inventory of AI apps and agents with activity in the last 30 days, how many are high risk, and how many had sensitive interactions.
  2. Open DSPM > Discover > Apps and agents for the dashboard of AI apps and their agents used across the organization, with details of the sensitive data accessed by the 20 most recently used agents and the Purview policies protecting them.
  3. Use these views to identify AI tools that are not sanctioned through the Copilot Control System or IT governance processes, and route findings to the governance team. Organizations that also want the dedicated unmanaged-agent view can evaluate the Shadow AI page in the Microsoft 365 admin center under Agents > Shadow AI, which is in Frontier preview and separate from DSPM.

Deploy the agent from the Microsoft Purview portal > Agents > Explore agents, then select the Data Security Posture Agent and complete Setup. Microsoft recommends deploying it with an agent identity rather than an organizational user account. Once deployed, it is surfaced inside DSPM from Asset explorer > Agent tab. Use natural language prompts to investigate data exposure, and schedule prompts to re-run daily, weekly, or monthly. Example prompts: - "Show me files accessed by Copilot in the last 30 days that may contain financial data" - "Which SharePoint sites have sensitive content accessible to users who don't have Copilot licenses"

The agent requires Microsoft 365 E5 with security compute units (SCUs) provisioned, and consumes SCUs on each run. Microsoft Learn documents the agent as in preview.

Step 5: Configure Assessment Schedule

The default data risk assessment runs weekly. Layer custom assessments on top of it to match the governance level: - Baseline: Monthly custom assessment covering in-scope sites - Recommended: Weekly review of default assessment results, plus custom assessments as scope changes - Regulated: Weekly review of default assessment results with continuous monitoring and formal sign-off

Custom assessment results do not refresh in place; duplicate an assessment to produce updated results.

Step 6: Set Up Activity Explorer Monitoring

Navigate to DSPM > Discover > Activity explorer and select the AI activities tab to monitor: - AI interaction — a user interacted with a generative AI site, including prompts and responses where auditing or a collection policy captures them - AI website visit — a user browsed to a generative AI site - DLP rule match — a data loss prevention rule matched during an AI interaction, including DLP for Microsoft 365 Copilot - Sensitive info types — sensitive information types found during an AI interaction

Activity explorer draws on the unified audit log rather than a live feed. Allow 60–90 minutes for activities in SharePoint, OneDrive, Exchange, and Teams to appear, and note that it reports on up to 30 days of data. Turning auditing on is required for Microsoft 365 Copilot and Microsoft 365 Copilot Chat interaction events.

Step 7: Configure Remediation Workflows

For each oversharing finding, determine the appropriate remediation action and track execution: - Assign site owner for remediation - Set remediation deadline based on risk severity - For critical items, use item-level scanning in a custom data risk assessment to address specific files immediately - Verify remediation through a new assessment run - Document action taken and outcome


Financial Sector Considerations

  • Non-Public Personal Information (NPI): Under GLBA, financial institutions must protect NPI. Run DSPM assessments with particular attention to sites containing customer account information, loan documents, credit reports, and financial statements. Oversharing of NPI-containing sites is a high-severity finding.
  • Chinese Wall / Information Barrier Risk: Investment banking, research, and trading operations that maintain information barriers must assess whether SharePoint oversharing could allow Copilot to bridge these barriers. Cross-reference DSPM findings with information barrier policies (see Control 2.4 Information Barriers).
  • Merger & Acquisition Data Rooms: Deal-related SharePoint sites often have broad internal sharing for project teams. Assess whether these sites could expose material non-public information (MNPI) through Copilot queries by non-deal-team members.
  • Regulatory Examination Files: Maintain DSPM assessment reports, remediation logs, and verification records in your regulatory examination file. Demonstrating systematic oversharing detection and remediation supports favorable examination outcomes.
  • Third-Party / Vendor Content: Financial institutions often share SharePoint sites with external partners (auditors, consultants, regulators). Review external sharing configurations alongside internal oversharing to ensure Copilot does not surface content from externally shared sites inappropriately.
  • Dual-Registration Considerations: Entities registered with both FINRA and SEC (or state regulators) should map oversharing findings to each applicable regulatory requirement to ensure comprehensive coverage.

Verification Criteria

  1. The unified DSPM experience is activated and accessible from the Microsoft Purview portal > Solutions > DSPM
  2. Data risk assessment results have been reviewed across all in-scope SharePoint site collections, using custom assessments where the weekly default assessment scope (top 100 sites by usage) does not cover them
  3. Oversharing findings have been triaged and prioritized by risk severity (sensitivity x access breadth)
  4. Remediation actions have been completed for the appropriate number of sites per governance level (top 20 / top 50 / all flagged)
  5. Item-level scanning in a custom data risk assessment has been used for critical oversharing findings at the Regulated tier
  6. No sites containing sensitive information types have "Everyone," "Everyone Except External Users," or anonymous sharing links (Regulated level)
  7. AI observability is configured and providing unified visibility across Copilot and any third-party AI apps and agents
  8. AI app and agent discovery findings are reviewed by the governance team to identify unsanctioned AI tools
  9. The Data Security Posture Agent has been deployed and used to conduct at least one exploratory data risk investigation (Recommended and Regulated levels)
  10. Activity explorer is reviewed on the AI activities tab at the specified cadence, with unified auditing turned on
  11. Assessment cadence is configured per governance level (monthly / weekly / continuous), on top of the weekly default assessment
  12. Automated alerts are configured for new oversharing detections and unsanctioned AI app findings (Recommended and Regulated levels)
  13. Remediation actions are documented with timestamps, responsible parties, and verification dates
  14. Assessment reports and remediation logs are retained per the organization's document retention policy and accessible for regulatory examination

Item-Level Oversharing Remediation (Solution 16)

DSPM data risk assessments and Data Access Governance are primarily site-scoped, and native item-level scanning is bounded — it is available only in custom assessments, only for SharePoint sites, and only for up to 10 sites per scan. Microsoft 365 Copilot surfaces content at the individual file level, meaning a properly locked-down site can still contain individual files with unique permissions that expose sensitive content through Copilot queries. Solution 16 from FSI-CopilotGov-Solutions extends the oversharing detection in this control to the item level across a broader estate.

How Solution 16 Extends This Control

Capability DSPM (This Control) Solution 16 Extension
Scope Site collection level, plus item-level scanning in custom assessments limited to SharePoint sites and a maximum of 10 sites per scan Individual file and folder level, without the per-scan site cap
Detection Sites shared with Everyone/EEEU/large groups; items carrying external or anonymous sharing links Files with unique permissions differing from parent (broken inheritance)
Risk scoring Site-level risk score Item-level risk score (sensitivity × access breadth × permission delta)
Remediation Site-level permission changes; item-level Resolve, Apply sensitivity label, Notify owner, and Remove sharing link Item-level permission restoration, inheritance repair
Cadence Weekly default site assessment; custom assessments on demand Monthly item scan (HIGH-risk sites weekly at Regulated tier)

When to Deploy Solution 16

Deploy Solution 16 after completing initial DSPM oversharing remediation through this control (1.2). The recommended sequence:

  1. Complete the DSPM data risk assessment review (this control)
  2. Remediate top site-level oversharing findings
  3. Deploy Solution 16 for item-level scanning on remediated sites
  4. Identify uniquely permissioned items that site-level remediation missed
  5. Remediate item-level findings through approval workflow

For full implementation details, see Control 1.14: Item-Level Permission Scanning.


Automating Access Reviews for High-Risk Sites (Solution 18)

DSPM identifies high-risk SharePoint sites through data risk assessments and risk scoring. Its assessment results include manual launch points — Start a SharePoint site access review on the Microsoft 365 Monitor tab, and an Entra access review option on the Fabric Monitor tab — but it does not automatically create access reviews on a recurring, risk-threshold-driven basis. Solution 18 from FSI-CopilotGov-Solutions bridges this gap by reading DSPM risk scores and automatically creating Entra ID Access Reviews for high-risk sites.

The Gap Solution 18 Addresses

Process Step Native DSPM With Solution 18
Risk identification ✅ Identifies oversharing risk ✅ Reads DSPM risk scores
Access review creation ⚠️ Manual launch per site from the assessment Monitor tab ✅ Auto-creates Entra ID Access Reviews
Review scope N/A Scoped to users with access to HIGH/CRITICAL risk sites
Review cadence N/A Configurable (quarterly for HIGH, monthly for CRITICAL)
Remediation Manual remediation Access Reviews revoke access upon reviewer denial
Audit trail DSPM assessment logs DSPM logs + Entra ID Access Review completion records

How Solution 18 Works

  1. Reads DSPM risk scores for all assessed SharePoint sites
  2. Filters sites at or above the configured risk threshold (HIGH or CRITICAL)
  3. Creates Entra ID Access Reviews scoped to users with access to each flagged site
  4. Configures review parameters: reviewer assignment (site owner + compliance delegate), review cadence, auto-apply of denied access
  5. Tracks completion and generates compliance evidence

Regulatory Value

For financial institutions subject to GLBA and FFIEC access control expectations, the combination of DSPM risk identification (this control) with automated access reviews (Solution 18) supports the continuous monitoring of access controls that regulators expect. Organizations should verify that review configurations meet their specific regulatory obligations.

Note: Solution 18 uses representative sample data for DSPM risk score integration. Organizations should validate risk score thresholds against their DSPM deployment before production use.


Additional Resources


FSI Copilot Governance Framework v1.8.0 - July 2026