Links anyone can open
Files and folders that anyone with the link can open, without signing in. The check also finds a single file buried deep in a folder tree.
Microsoft 365 Copilot only shows what a user is already allowed to see, so before you switch it on it is worth finding out which SharePoint and OneDrive files are shared too widely: our check shows you, using read permissions only.
Access report · illustrative example
| Location | Open to | Status |
|---|---|---|
| Management / Contracts | The whole organisation | Review |
| Projects / Clients | The project team | OK |
| People / Files | Open sharing link | Review |
Before Copilot is switched on
Report → your decision → changes as a separate step
01
Microsoft's documentation says Copilot only shows organisational data that the user has at least view permission for. Copilot opens no new access, but it can surface whatever is already open.
Over a few years, organisations collect links anyone can open, files shared with everyone in the company and access left behind by people who have left. While a file has to be found by hand, few people trip over it. Once anyone can ask Copilot, such a file can turn up in an answer to someone it was never meant for.
Files shared in Microsoft Teams are stored in SharePoint sites too, so the same permissions apply.
02
We planted each of these in our test environment, and the check found all 12.
Files and folders that anyone with the link can open, without signing in. The check also finds a single file buried deep in a folder tree.
Files that anyone in your organisation can open with the link.
Links for specific people and direct permissions, so you can see exactly who has access to a folder.
Permissions left with disabled or deleted users, and OneDrives whose owner's account is disabled or deleted.
Shared company documents kept in an employee's personal OneDrive rather than in a shared library.
The check marks only the files and folders whose sharing differs from the folder they sit in, so the report is not buried in thousands of inherited permissions.
03
The app is registered in your Microsoft 365 tenant and uses read permissions only, approved by your administrator. It does not read file contents: names, paths, dates and sharing permissions are enough. There are two permission options.
| Permission | Why it is needed | Access | Option |
|---|---|---|---|
Files.Read.All | Read the list of files and folders and their sharing permissions in libraries and OneDrives | Read | A |
Sites.Read.All | Find SharePoint sites and their document libraries | Read | A |
User.Read.All | Tell active, disabled and deleted accounts apart | Read | A and B |
Sites.Selected | Read only the one site you name; your administrator grants read on that site alone | Read | B |
Option A sees every library and personal OneDrive. Option B sees only the named site; personal OneDrives stay invisible. Sites.FullControl.All is not needed: in our test it produced exactly the same results as the read permissions.
04
Measured on 2026-10-08 in our own Microsoft 365 test environment with invented data and read permissions only. We planted the risky access on purpose. The results do not show how the check will perform in your tenant.
05
06
The check only reads and changes nothing. Once you have reviewed the results, we agree which links to close and which permissions to remove.
Changes are a separate step, made only from the list you approved: by your IT team, or by us together with your IT team under separately granted rights. Then we run the check again so you can see the result.
07
08
In our test environment we checked direct permissions and links. Guest accounts, access through groups and Teams-connected sites were not part of that test. New Microsoft 365 tenants do not allow guest invitations, so we have not yet checked guest access on live data.
That is why, at the start of a pilot, we check these cases on your tenant's data and tell you the result before going further. In a large tenant Microsoft may throttle requests; the app then pauses and waits, which is why the first run happens outside working hours.
Something else on your mind?
Start by finding out who can see what: look for links anyone can open, files shared with the whole organisation and access left behind by people who have left. Then decide what to close, and only then switch Copilot on for a first group of users. Our check does the first step with read permissions only.
Microsoft's documentation says Copilot only shows organisational data that the individual user has at least view permission for. So Copilot sees as much as the user does: if a file is shared with the whole organisation, it can turn up in any employee's Copilot answer.
It is Microsoft's AI assistant inside the Microsoft 365 apps. It answers questions and drafts text using organisational data the user has access to, such as documents, emails and chats. We do not sell licences: you buy them from Microsoft or a reseller.
No. We ask for read permissions only, so the app cannot change, delete or move files. Your administrator sees the list of permissions before approving them.
Yes, if your administrator grants read access across the organisation (option A). If read access is granted to one site only (option B), personal OneDrives stay invisible. We discuss which option suits you on the call.
Microsoft has its own tools for getting data ready for Copilot, some of them with a SharePoint Advanced Management licence. On the call we look at what your licences already include. Our check is a separate app in your tenant that gives you one list of findings and the changes we propose.
In our test environment, checking 940 files and folders took about 31 seconds. In your tenant the time depends on the number of files, which is why the first run happens outside working hours.