The SharePoint oversharing report is the piece of visibility every Microsoft 365 admin has been missing, and starting early August 2026, Microsoft is finally shipping it inside the SharePoint admin center. If you have ever told a security team you do not know exactly what is exposed, only which sites might be, this closes that gap. It does not change a single permission. It just tells you, file by file, what your organization has actually shared with Everyone and Everyone except external users.
This article breaks down what the new SharePoint oversharing report actually shows, who is affected, what to do with it once it lands, and why item-level visibility changes how you should think about SharePoint governance.
What and Why: The Problem the SharePoint Oversharing Report Solves
SharePoint Advanced Management already gives admins data access governance reports that flag sites containing the Everyone and Everyone except external users (EEEU) special groups. The gap has always been the next step. Knowing a site contains one of these groups tells you almost nothing about what is actually inside it. A site could have thousands of files with only three exposed through EEEU, or it could be a site where nearly everything is exposed. Without item-level detail, every one of those sites required a manual dig to find out which.
The new report closes that gap. Instead of stopping at the site, it gives administrators item-level permission detail for anything shared through Everyone or Everyone except external users, across both SharePoint and OneDrive. You get the specific files and folders exposed, not a general warning that a site deserves attention.
How the SharePoint Oversharing Report Replaces the Manual Hunt
Before this update, remediation started with a site permissions baseline report, which told you a site was risky, and ended with someone opening that site and manually hunting for what was actually shared broadly. That process does not scale past a handful of sites. The SharePoint oversharing report replaces the manual hunt with a direct list of exposed items, so remediation goes straight to the content that matters instead of the site that might contain it.
Rollout Schedule for the SharePoint Oversharing Report
| Phase | Date | What happens |
|---|---|---|
| General Availability (Worldwide) begins | Early August 2026 | Rollout starts across tenants with SharePoint Advanced Management |
| General Availability complete | Mid-August 2026 | All eligible tenants should have access to the report |
There is no separate Preview phase for this change. Microsoft is rolling the SharePoint oversharing report straight to general availability across the SharePoint admin center.
What the New SharePoint Oversharing Report Actually Shows
The report covers two special groups that most oversharing incidents trace back to:
- Everyone: content shared with every user in the tenant, including guests
- Everyone except external users (EEEU): content shared with every internal user, but not guests
For each group, the report lists the specific files and folders exposed, not just the site they live in. Reporting is accessible in two places, through the SharePoint admin center Reports pane, and through the SharePoint Online PowerShell module for admins who want to script it into an existing audit process.
Everyone vs EEEU: How the SharePoint Oversharing Report Treats Each
These two groups fail in different ways. Everyone links are often the more dangerous of the two, since guests get pulled in as well, but EEEU sharing is the one that hides in plain sight because it feels internal and therefore safe. The report treats them as separate categories precisely because the remediation path is different: an Everyone exposure might need to be locked down immediately, while an EEEU exposure might only need to move to a smaller, named group.
Impact on Your Organization
The people who will use the SharePoint oversharing report day to day are SharePoint Advanced Management administrators, along with anyone responsible for prioritizing and remediating sharing risk across SharePoint and OneDrive. No end users are affected, and nothing about their access changes. This is purely an administrative visibility feature.
Action Required: What to Do When the SharePoint Oversharing Report Lands
Microsoft’s message center post is explicit that no action is required before rollout. Here is the practical version of what to do once it is live in your tenant.
1. Tell your SharePoint admins it exists. Most oversharing conversations start because someone stumbles onto a bad example, not because the org went looking. Make sure whoever manages SharePoint Advanced Management knows the report is there before that happens again.
2. Run it and triage by exposure, not by site. Sort by files exposed through Everyone first, since guest exposure carries more risk than internal-only exposure through EEEU.
3. Fold it into your existing governance and audit process. If you already review data access governance reports on a schedule, add the SharePoint oversharing report to that cadence rather than treating it as a one-off check.
4. Update your internal documentation. Any runbook or audit checklist that references SharePoint permission reviews should point to this report as the new starting point for item-level remediation.
Admin Tips for the SharePoint Oversharing Report
- Pair it with the site permissions baseline report, use the baseline to find risky sites and this report to find the exact files inside them
- Run it monthly alongside your other data access governance activity reports rather than as a one-time cleanup
- Loop in whoever owns your sensitivity label rollout, since files exposed through Everyone or EEEU without a label are your highest priority
- Treat a clean report as a moving target, not a milestone, new files get overshared every week
License Check
The SharePoint oversharing report sits under SharePoint Advanced Management. Microsoft’s message center post specifically calls out SharePoint Advanced Management administrators as the audience for this change, and Microsoft’s own documentation notes that generating the detailed EEEU and Everyone item-level report through PowerShell requires the SharePoint Advanced Management Administrator role, assigned by a Global administrator. If your organization already has SharePoint Advanced Management, this ships to you at no extra cost. If you are not certain whether your tenant has it, that is worth confirming before you go looking for the report in the admin center.
The Paul-Take
I have sat in enough governance reviews where the answer to what is actually shared with Everyone was a shrug and a promise to check later. That is exactly the gap the SharePoint oversharing report closes, and it closes it in the most useful way possible: it does not touch a single permission, it just tells the truth about what is already exposed. Microsoft has been building toward this since the original data access governance reports shipped, and this is the missing piece that turns ‘this site looks risky’ into ‘here are the seventeen files you need to fix today’.
My advice: do not let this sit in the message center queue as a nice-to-have. The week it lands in your tenant, run it once, sort by Everyone exposure first, and get eyes on whatever comes back. Oversharing does not wait for your next quarterly review, and now neither should you.
This should be rolling out in August 2026 (General Availability) according to Microsoft.
If you want the fuller picture of how SharePoint Advanced Management handles governance beyond this one report, read SharePoint Catalog Management: Smart New Site Groups, and if Copilot access is as much a part of your oversharing concerns as SharePoint sharing is, Restricted Content Discovery: Copilot and Search Get Sharper covers the search and Copilot side of the same problem.
MVP Reference List
- Message Center ID: MC1450131
- Microsoft 365 Roadmap ID 561038
- Get item-level permission details for ‘Everyone except external users’ and ‘Everyone’ (Microsoft Learn)
- Data access governance reports for SharePoint and OneDrive sites (Microsoft Learn)
- What is SharePoint Advanced Management? (Microsoft Learn)