
In a recent YouTube video, Nick Ross [MVP] (T‑Minus365) urges organizations to audit SharePoint access before enabling Microsoft 365 Copilot. He explains that while Copilot does not create new permissions, it can quickly surface files and sites that were already accessible but hard to find, turning old governance gaps into immediate exposure. Consequently, Ross demonstrates practical steps to discover and prioritize those risks across a tenant.
First, Ross walks viewers through built-in Microsoft reports and then shows a custom PowerShell script he developed for a tenant-wide view of site-level permissions. He highlights why a single site permissions report is useful yet often insufficient at scale, and he stresses that broader discovery tools are necessary for large or aged environments. Therefore, his video mixes native admin tools with automation to improve coverage and repeatability.
Ross outlines common ways SharePoint permission sprawl grows undetected. Project sites get created, groups evolve, users change roles, and inherited or broadly shared links can remain active for years without review, creating a quiet accumulation of access that no one routinely inspects.
Moreover, he explains that common sharing patterns — such as links set to Anyone with the link or permissions granted to groups like Everyone except external users — expand the searchable surface for any tool that follows standard permission checks. Over time, stale owners and orphaned sites amplify the problem because there is no clear owner to remediate or remove unnecessary access.
In the demonstration, Ross first uses Microsoft’s Site permissions for users report to show what a site-level view can reveal, including direct permissions and inherited access. He then runs through his tenant-wide PowerShell script to map where permissions were granted and to flag patterns that indicate broad exposure or public sites, thus giving administrators an ordered list to review.
He also recommends combining these outputs with Microsoft features like SharePoint Advanced Management and Microsoft Purview so discovery aligns with governance. By doing so, teams can categorize sites by risk, identify inactive or ownerless sites for cleanup, and prioritize remediation where the business impact and ease of fix converge.
Ross emphasizes several tradeoffs administrators must weigh when preparing for Copilot. Tightening sharing and revoking broad links improves security, but it can also disrupt legitimate collaboration and slow users who rely on wide access. Thus, administrators face a balance between protecting sensitive data and preserving productivity.
He also points out operational challenges: manual audits are accurate but resource intensive, while automated scans scale well but can produce false positives that require human judgment. In addition, legacy permission inheritance, large numbers of sites, and unclear ownership complicate any clean-up effort, and change management is necessary to avoid surprising users with sudden access restrictions.
To address these challenges, Ross advocates a staged approach: audit first, prioritize second, and remediate third. He suggests using the site permissions report and tenant-wide scripts to identify the highest-risk findings, then focusing on sites with broad links, public exposure, or no owner before tackling lower-risk items.
Furthermore, Ross recommends combining automated detection with governance controls such as periodic site access reviews, clearer ownership requirements, and targeted user education about safe sharing practices. Finally, he encourages teams to consider automation to maintain hygiene over time rather than relying on one-off audits, while remaining mindful that automation requires tuning to reduce noise.
The key message from Nick Ross is straightforward: prepare your SharePoint estate before you give AI tools broader access. Although Copilot does not alter permissions, it will make existing permissions more actionable and visible, which raises the urgency of cleaning up overshared content now rather than after exposure occurs.
In closing, Ross offers practical artifacts — including a free PowerShell audit script available through his community — and demonstrates how combining native reports with tenant-scale tooling can reveal and rank issues. As organizations plan Copilot deployments, administrators will need to balance security, user productivity, and operational cost while investing in processes that sustain permission hygiene over time.
Copilot overshared files, Audit SharePoint, Copilot data exposure, SharePoint access review, Microsoft 365 Copilot security, Protect overshared files, SharePoint auditing best practices, Copilot privacy risks