Introduction
An accounting manager asks Copilot to prepare a budget summary. Result: the AI assistant unwittingly integrates the salaries of the entire company, extracted from an HR site shared "with everyone" for years. No one activated a security flaw that day. Copilot simply used the access that already existed, exactly as any user could have.
This is the starting point of this article: Copilot invents nothing, it exposes what was already accessible but invisible. The real problem is that SharePoint permissions are decentralized, sharing links accumulate without ever being cleaned up, and inactive sites remain fully accessible. Most organizations have no unified view of who has access to what, spread across SharePoint, OneDrive, and Teams.
This tutorial shows you how to use ShareGate Protect, the editor's governance tool (not to be confused with ShareGate Migrate, dedicated to migrations), to gain this visibility, clean up what exists, then automate compliance maintenance over time.
Why act before enabling Copilot
If you deploy Copilot without having conducted a recent permissions audit, you risk it surfacing data that no one should have been able to access. The incident is not a Copilot bug: it's a governance debt that becomes visible very quickly.
Prerequisites before you begin
Before launching the audit, make sure you have the following:
- A global administrator role or SharePoint administrator role on the Microsoft 365 tenant to audit.
- A ShareGate Protect account (trial version or active subscription).
- The necessary rights to grant admin consent to the ShareGate application when connecting to the tenant, as the tool relies on Microsoft Graph APIs to collect data.
- A modern web browser: ShareGate Protect is a SaaS solution, no agent to install on servers.
- Ideally, read access to the Microsoft 365 admin center and SharePoint admin center to compare results during verification.
Good to know
Unlike some SharePoint Advanced Management features that only surface sharing links created in the last 28 days, ShareGate Protect indexes the complete history of links, regardless of age.
| Feature | SharePoint Advanced Management | ShareGate Protect |
|---|---|---|
| Sharing link history | Limited to last 28 days | Complete history, no date limit |
| Centralized view SharePoint/OneDrive/Teams | Partial, multi-console | Unified in a single platform |
| License optimization | Premium feature from other vendors | Included in base Protect offering |
Step-by-step procedure in ShareGate Protect
Connect your tenant to ShareGate Protect
Log in to the ShareGate Protect platform, then add your Microsoft 365 tenant. You will need to grant admin consent requested by the application so it can query your data via Microsoft Graph.
You will know the operation succeeded if the tenant appears in your environment list with a synchronization status in progress.
Wait for the first crawler run
The core of the tool is a crawler that runs every 24 hours and traverses the entire tenant (SharePoint sites, OneDrive, Teams) to centralize information in a single interface. The first run can take up to 24 hours.
Once complete, open the Tenant info tab: you should see a dashboard populated with real statistics about your environment, not empty data.
Explore the Oversharing & Security view
Go to the section dedicated to excessive sharing and security. You will find a complete breakdown of all sharing links: "Anyone" links, links shared with people in the organization, and links shared with specific people (including external).
At this stage, you should see concrete numbers, for example a count of "Anyone" links, a count of internal links, and a count of external links to specific people.
Analyze a suspicious link in detail
Click on a link to display the file name, its type, the permission level granted (read, edit), recipients, and the document URL. Use available filters (link type, site, creator, age) to target risky cases, such as external links created several years ago.
Delete non-compliant sharing links
Select a problematic link and delete it, or select multiple links for bulk deletion.
What actually gets deleted
Only the sharing link is removed. The file or document remains intact at its original location. You are removing access, not the data.
Create an automatic cleanup policy
Manual cleanup is not enough: a user can recreate an identical link the next day. Open the Policies module and choose either a ready-made policy (for example, automatic archiving of SharePoint sites inactive for more than six months), or create a custom policy.
For a custom policy, set a daily trigger, then add granular conditions: link type equals "external", creation date in the last 14 days, or restriction to a specific SharePoint site (for example the Finance site). The interface displays in real time the number of links matching your criteria before activation.
You know the policy works if, after its first execution cycle, the number of matching links decreases compared to the previous day.
Verify license optimization
Open the dedicated licenses tab. ShareGate Protect cross-references assigned licenses (E3, E5, etc.) with last login dates and actual service usage. Use Review users to identify accounts that have not logged in for several months: these are licenses paid for nothing, and potentially accounts of former employees still active, which also poses a security risk according to frameworks like Cyber Essentials.
Use the ROI calculator to build your case
On the ShareGate Protect website, an ROI calculator is available without registration or email. Simply enter the number of Microsoft 365 licensed users in your tenant: the tool estimates the real cost of excessive sharing and workspace sprawl, an excellent starting point for a quarterly review with a customer or finance leadership.
Verify that the audit has been successful
Once the procedure is complete, check the following points to confirm that governance has been effectively restored:
- The total number of external sharing links has decreased measurably in the Oversharing & Security dashboard.
- The policy execution history shows a run every 24 hours, with no errors.
- No new non-compliant links created after cleanup remain active for more than one policy cycle.
- The license report shows a realistic potential savings estimate (monthly, in local currency) and an actionable list of accounts to disable.
Recommended frequency
Repeat this verification at least once a month, and systematically before any broad Copilot deployment to a new user population.
If you encounter problems
- The crawler returns no data after 24 hours: verify that admin consent was properly granted when connecting the tenant and that the user account still has the required roles. Revoked consent on the Microsoft Entra ID side completely blocks data collection.
- A created policy shows no results: check that conditions are not too restrictive (for example a combination of filters that mutually exclude each other) and remember that the first effective run can take up to 24 hours after policy creation.
- A deleted link still appears active in SharePoint: there is a slight propagation delay between the action in ShareGate Protect and the next crawler cycle. Wait for the next run before considering it a malfunction.
Going further: MCP support
ShareGate is currently deploying MCP (Model Context Protocol) support for Protect. Concretely, this will allow you to query tenant data in natural language through tools like Claude, Copilot, or ChatGPT. The first version remains read-only, but remediation actions directly controllable via this protocol are planned for later. For MSPs managing multiple tenants, this promises a global view across the entire customer base and advanced automation of report generation.
Conclusion
SharePoint governance is one of those topics you postpone until the day an incident, often revealed by Copilot, forces you to act urgently. By following this procedure with ShareGate Protect, you first gain visibility into the actual state of your permissions, then get the cleanup tools, then the automation that prevents the problem from returning. Do this audit before expanding Copilot, not after.



