Exercise - Remediate an oversharing risk before rollout

Completed

A data access governance report flags a Finance site with broad "Everyone except external users" sharing. Before Relecloud expands Copilot, you need to close that exposure using the remediation sequence you just learned.

Important

Prerequisites for this exercise:

  • A Microsoft 365 E5 (or E7/Frontier Suite) tenant with SharePoint Administrator access.
  • A lab site pre-seeded with broad "Everyone except external users" (EEEU) sharing exposure—seed one yourself if your lab doesn't provide it.
  • SharePoint Advanced Management availability for the Restricted Access Control step.

If your tenant doesn't include SharePoint Advanced Management, complete Tasks 1-3 and read through Task 4 to see where RAC fits in the sequence.

Task 1: Identify the overshared site

  1. Sign in to the SharePoint admin center at admin.microsoft.com/sharepoint, then select Reports > Data access governance > Site permissions, and run the report.
  2. Sort by sharing links or exposure breadth and locate the Finance site with broad EEEU sharing.
  3. Note the site's current permission state before you change anything—you'll compare against this after remediation.

Task 2: Disable "Everyone except external users" sharing tenant-wide

  1. Go to Policies > Sharing, and under the SharePoint sharing settings, locate the option controlling Everyone except external users availability.
  2. Turn this option off tenant-wide, and select Save.
  3. Reflect: this is a tenant-wide change, not a per-site one—it prevents new EEEU shares from being created anywhere in the tenant going forward, closing the automatic-scale problem the Introduction's puzzle described.

Task 3: Turn on Purview Audit

  1. Sign in to the Microsoft Purview portal at purview.microsoft.com, go to Audit, and confirm (or turn on) Microsoft Purview Audit (Standard) for the tenant.
  2. Confirm audit logging now captures Copilot interaction activity alongside standard user and admin actions.

Task 4: Apply restricted access control to the business-critical finance site

  1. Back in the SharePoint admin center, open the flagged Finance site and select its Policies tab.
  2. Under Restricted access control, select Edit, scope access to a security group representing the Finance team, and save.
  3. Confirm: unlike Restricted Content Discovery, RAC actually restricts who can access the site—the correct, stronger control for a business-critical site that's already been flagged as overshared, not just an interim discovery fix.
  4. Reflect on the full sequence you just ran: identify (the governance report) → cross-reference (would be DSPM, if you have it available) → audit/protect (disabling EEEU, turning on Purview Audit) → access control (RAC on the business-critical site). This is the repeatable remediation Relecloud runs before every expansion phase, not a one-time fix for this single site.

You've now identified, closed, and locked down Relecloud's Finance site oversharing exposure using the full remediation sequence—the data-readiness gate this module's Copilot rollout can't skip.