Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
The Agent Access Insights report provides SharePoint administrators with rich information on how the agents are accessing content across all SharePoint and OneDrive sites in your organization. The report includes all agents registered and activated agent, such as SharePoint agents, Declarative agents, Custom agents, and more. With this report, you can see how agents interact with your content, spot access patterns, and view agent distribution across sites. Use these insights to strengthen your security and apply governance controls like Restricted access control and Restricted content discovery.
Agent Access Insights use Microsoft 365 unified audit logs to track how agents access your SharePoint sites and OneDrive accounts. These logs capture signals like reading, searching, and interacting with content, giving you a clear view of agent activity.
You can generate and manage the Agent Access Insights report in the SharePoint Admin Center or using SharePoint Online Management Shell.
What do you need to get insights on agent access to SharePoint and OneDrive?
What are the license requirements?
Your organization needs to have the right license and meet certain administrative permissions or roles to use the feature described in this article.
First, your organization must have one of the following base licenses:
- Office 365 E3, E5, or A5
- Microsoft 365 E1, E3, E5, or A5
Additionally, you need to have Microsoft 365 Copilot license.
Note
At least one user in your organization must be assigned a Copilot license (this user doesn't need to be a SharePoint administrator). If your organization has a Copilot license and at least one person in your organization is assigned a Copilot license, SharePoint administrators automatically gain access to the SharePoint Advanced Management features needed for Copilot deployment.
Administrator requirements
You must be a SharePoint administrator or have equivalent permissions.
Important
If you don't have a Microsoft SharePoint Advanced Management license, you'll be asked to enable data collection, so that the product starts to collect the relevant audit data to build this report. Once enabled, the reports can be generated 24 hours later and contain data from the point of collection. Data is stored for 28 days. If no reports are generated at least once in three months, data collection is paused and should be enabled again. To enable data collection for these reports, refer to the Data collection for Agent Access Insights report section in this article.
How to access the Agent Access Insights report in SharePoint Admin Center?
- Sign in to the SharePoint admin center with the SharePoint administrator credentials for your organization.
- In the left navigation pane, expand Reports, and select Agent Insights.
- Select Agent Access.
- Review the report details, including agent activity, access patterns, and site distribution.

How to create agent access reports in SharePoint Admin Center
- On the Agent Insights page, select Create a report.
- Provide a Report name and specify the report duration (1, 7, 14, or 28 days).
- Select Create and run.

Note
You can create reports for the past 1, 7, 14, or 28 days. Data older than 28 days is automatically rolled off.
View the agent access report status in SharePoint Admin Center
To check if a report is ready or when it was last updated, see the Status column.

View the agent access report details in SharePoint Admin Center
When a report is ready, select it to view the data. You can view the top 100 sites hosting the highest number of agents. You can search for sites or filter by site template, and governance policies.

View top 20 agents for a specific site
When you select a site, you can view the top 20 agents accessing the content across the selected site.

View agent distribution across sites
On the Agent Access report page, choose Unique Agents found in SharePoint Sites or Unique Agents in OneDrive Account. This view displays how agents are distributed across your organization's sites. You can quickly see the number of sites in each site template category and how many unique agents are accessing them.

Apply content governance policies from the access report
You can apply content governance policies on the sites from the access insights report. The policies available are Restrict site access policy and Restrict Content Discovery policy.
Important
After a policy is applied to the site from the insights report, the policy status on the existing report won't be updated. To view the updated status of the policy on the site, select the policy to view the latest status or access the Active site panel and review the site settings.
How to access the Agent Access Insights report using SharePoint Online Management Shell?
You can generate, check, and manage Agent Access Insights reports using SharePoint Online Management Shell.
Prerequisites
If you haven't, download and install the latest version of SharePoint Online Management Shell.
Connect to SharePoint Online as at least a SharePoint administrator in Microsoft 365. For more information, see Getting started with SharePoint Online Management Shell.
To generate and view these reports, ensure the organization has the SharePoint Advanced Management add-on license or Microsoft 365 Copilot license.
Create and view an Agent Access Insights report with SharePoint Online Management Shell
With permissions of at least a SharePoint administrator, you can generate and view the insights report using the following commands:
- To generate report for a one-day default report duration, run the command:
Start-SPOM365AgentAccessInsightsReport

This command generates an Agent Access Insights report for the past one day by default.
- You can specify a different duration (7, 14, or 28 days) using the
-ReportPeriodInDaysparameter. For example, to create a report for the past 28 days, run:
Start-SPOM365AgentAccessInsightsReport -ReportPeriodInDays <28>
- To check the status of all active and available reports, run the command:
Get-SPOM365AgentAccessInsightsReport
- To view the details of a specific report, run the command:
Get-SPOM365AgentAccessInsightsReport -ReportId <ReportId>
Replace <ReportId> with the actual Report ID obtained from the previous command.
- To download and view the report, run the command:
Export-SPOM365AgentAccessInsightsReport -ReportId <ReportId> -Action Download
Note
PowerShell displays up to 100 sites but downloaded reports can contain up to 1 million sites.
Export-SPOM365AgentAccessInsightsReport -ReportId <ReportId> -View Download
Replace <ReportId> with the actual Report ID.
- You can also view summarized insights of agents across all site types by running the command:
Get-SPOM365AgentAccessInsightsReport –ReportId -Content SiteDistribution
SiteDistribution: Provides the summarized view of agents across all types of sites like Communication sites, Microsoft 365 group connected sites, OneDrive accounts, and more.
Data collection for Agent Access Insights report
If you don't have a Microsoft SharePoint Advanced Management license, you'll be asked to enable data collection. This section explains how to enable and check status for data collection for the Agent Access Insights report.
Enable data collection
This PowerShell command starts collecting audit data for reports on activities from the previous day:
Start-SPOAuditDataCollectionForActivityInsights –ReportEntity M365AgentInsights
Check data collection status
Once data collection is enabled, the reports can be generated after 24 hours. To check whether reports can be generated, use the PowerShell command:
Get-SPOAuditDataCollectionStatusForActivityInsights -ReportEntity M365AgentInsights
The command returns the current data collection status, which can be "NotInitiated,"InProgress," or "Paused." Reports can be generated when the status is "InProgress."
Known experiences with Microsoft 365 Agent Access Insights
Here are some important known experiences to keep in mind when working with Agent Access Insights reports in SharePoint Admin Center or SharePoint Online Management Shell:
You can rerun a report only after 24 hours have passed since the last report was generated.
For large tenants, data may take up to 48 hours to become available.
Only one report can exist for each report range value (1, 7, 14, or 28 days). This means you can see a maximum of four reports at any given point.
When you generate a new report for the same date range, it replaces the previous report. To keep the old report, download it before creating a new one.
Reports use Microsoft 365 unified audit data, which may not include every audit event.