Updates from: 11/21/2024 02:11:00
Service Microsoft Docs article Related commit history on GitHub Change details
SharePoint Advanced Management Faq https://github.com/MicrosoftDocs/OfficeDocs-SharePoint/commits/public/SharePoint/SharePointOnline/advanced-management-faq.md
+ Last updated : 11/20/2024
+ Title: "Microsoft SharePoint Premium - SharePoint Advanced Management frequently asked questions"
++++
+audience: Admin
+f1.keywords:
+- NOCSH
++
+ms.localizationpriority: medium
+
+- Highpri
+- Tier2
+- M365-sam
+- M365-collaboration
+- ContentEnagagementFY24
+search.appverid:
+- MET150
+recommendations: false
+description: "Learn about Microsoft SharePoint Premium - SharePoint Advanced Management through this FAQ."
++
+# SharePoint Advanced Management frequently asked questions
+
+Here's a list of frequently asked questions regarding [Microsoft SharePoint Premium - SharePoint Advanced Management](advanced-management.md):
+
+## My site owners did their site access review and reduced the number of Anyone and other links. Why does my report still show the same number of shared links as before?
+
+Site access review is linked to the Data access governance report from which it's generated. If you want to see the effects of the latest status of site owner actions, run the Data access governance permission report again.
+
+## I made sure to install the latest SharePoint Online Management Shell, but the SharePoint Advanced Management commands I want arenΓÇÖt present! How do I get the latest commands?
+
+You have more than one SharePoint Online Management Shell module installed on the machine you're using to run the commands. Admins would need to run the following to clean up all the modules, and then update to the latest.
+
+Uninstall-Module Microsoft.Online.SharePoint.PowerShell -Force -AllVersionsΓÇ»
+
+Then, uninstall the SharePoint Online Management Shell via the Control Panel and reinstall the [latest version](<https://www.microsoft.com/download/details.aspx?id=35588>).
+
+## Do I need to manually assign SharePoint Advanced Management licenses to users?
+
+No.
+
+## Which specific reports in Data access governance require SharePoint Advanced Management?
+
+1. Permissions report: This report lists sites where the count of users that can access is greater than a specified number. It helps identify sites with potentially excessive access.
+2. Site access review for Permissions Report: This allows tenant admins to initiate a site access review for any site within the permissions report via PowerShell. The site owner can then view the details in the site UI and take necessary actions.
+3. Site access review for 'Sharing links' report: Data access governance provides a sharing links report for tenant admins, listing sites with the highest volume of sharing links generated in the last 28 days. Tenant admins can ask the corresponding site owner to review these links and take necessary actions.
+4. Autorun Data access governance reports: You can schedule Data access governance reports to run automatically every 28 days and receive notifications when the autorun completes.
+5. Content shared with 'Everyone except external users' (EEEU) report: This report identifies sites, files, and folders shared with the EEEU domain group in the last 28 days.
+
+Reports that don't require SharePoint Advanced Management are:
+
+- Basic Permissions Reports: These reports provide a snapshot of the current state of permissions without the advanced features like site access reviews or automated scheduling.
+- Activity Reports: These reports offer insights into activities within the past 28 days, helping to manage and review access to content that might be at risk of being overshared.
+
+## What is the difference between SharePoint Premium and SharePoint Advanced Management?
+
+SharePoint Premium is an advanced content management platform that builds on the familiar SharePoint experience. It brings AI, automation, and added security to content experiences, processing, and governance. It's designed to enhance content management and experiences in Microsoft 365 as an expansion and rebranding of Microsoft Syntex.
+
+SharePoint Advanced Management, on the other hand, focuses on security and content governance. It includes features like manually applying sensitivity labels and policies, as well as automatically applying sensitivity labels and dynamic policies with Microsoft 365 E5. SharePoint Advanced Management is available as an add-on license and is administered by SharePoint administrators in the SharePoint admin center.
+
+## Do organizations really require the entire company to be licensed to take advantage of specific features or can a subset of licenses be purchased and targeted to only users impacted by SharePoint Advanced Management solutions?
+
+To use SharePoint Advanced Management, organizations must have a license for each user in the organization who will be using or benefiting from the features.
+
+However, not all features require the entire company to be licensed. Here are some key points:
+
+- Restrict SharePoint site access: If this feature is applied to a site, all members and site owners of that site need to be licensed.
+
+- Restrict OneDrive content access: If this feature is applied, all users in the tenant need to be licensed, specifically E3/E5 users.
+
+- Data Access Governance reports for SharePoint Sites: If only the reports are used, only the admins need a license. However, if you trigger the Site access review policy, all site owners need to be licensed.
+
+- Conditional access policy for SharePoint and OneDrive sites: If this is applied to a site, all members and owners of that site need to be licensed.
+
+- Advanced sites content lifecycle management: Admins and site owners need to be licensed.
+
+- Block download policy: If applied to a site, the members and owners of that site need a license. If you enable the block download policy for Teams Recordings and Transcripts at the tenant level, all users in the tenant need to be licensed, specifically E3/E5 users.
+
+- Review recent changes: Only admins need to be licensed.
+
+## If I get the SharePoint Advanced Management trial can I run Data access governance reports for my entire organization or does that go beyond licensing requirements?
+
+Yes, you can run Data Access Governance reports for your entire organization with a SharePoint Advanced Management trial license. However, there are some important considerations to keep in mind:
+
+- Licensing requirements: While you can generate Data access governance reports during the trial period, all users who benefit from the features must be licensed once the trial ends. This means that if you decide to continue using SharePoint Advanced Management features after the trial, you'll need to purchase licenses for all relevant users.
+
+- Report generation: During the trial, you can generate Data access governance reports to discover sites with potentially overshared or sensitive content. These reports help you assess and apply appropriate security and compliance policies.
+
+- Post-trial access: Any reports or data generated during the trial will remain available to you after the trial ends. However, the features stop working, and no new data are generated if SharePoint Advanced Management isn't purchased.
+
+## Are there any impacts to SharePoint Advanced Management in a multi-geo environment?
+
+SharePoint Advanced Management in a multi-geo environment has several considerations to keep in mind:
+
+- Data residency: Multi-Geo capabilities in SharePoint and OneDrive allow organizations to control where their data is stored at rest, meeting data residency requirements. Each user, Group mailbox, and SharePoint site have a Preferred Data Location (PDL) which denotes the geo location where related data is to be stored.
+
+- Site and group creation: When a user creates a SharePoint group-connected site in a multi-geo environment, their PDL is used to determine the geo location where the site and its associated Group mailbox are created. If the user's PDL value hasn't been set or is set to a geo location that hasn't been configured as a satellite location, the site and mailbox are created in the central location.
+
+- Administrative options: Managing the multi-geo environment is available through the SharePoint admin center. Some actions, such as moving a SharePoint site or a OneDrive site, require Microsoft PowerShell.
+
+- User experience: Users get a seamless experience when using Microsoft 365 services, including Office applications, OneDrive, and Search. SharePoint Hub sites enhance the discovery and engagement with content for employees, while creating a complete and consistent representation of projects, departments, or regions. In a Multi-Geo environment, sites from satellite locations can easily be associated with a hub site regardless of the hub site's geography location.
+
+## Can I initiate a Site access review manually on a site without running a Data access governance report?
+
+Initiating a Site access review manually on a site without running a Data Access Governance report isn't supported. The Site access review feature is designed to work with Data access governance reports to identify overshared sites and delegate the review process to site owner. This ensures that the review is context-specific and addresses the concerns identified in the Data access governance reports.
+
+## How many Site access reviews can I start at once?
+
+In SharePoint Advanced Management, you can initiate Site Access Reviews for up to 100 sites at once.
+
+## What defines a site owner in a Site access review in a non-group connected site?
+
+In a Site access review for a nongroup connected site, a site owner is defined as the user who has full control of that particular SharePoint Online site. This means that the site owner is responsible for creating and managing lists, libraries, and pages within the site, as well as managing user access and permissions. Site owners are best positioned to review and address oversharing issues for their own sites, as they have the necessary permissions and understanding of the site's content and sharing settings.
+
+## If there are many site owners, which site owners are picked for a Site access review?
+
+When there are multiple site owners for a SharePoint site, the Site access review process sends review requests to all site owners. This ensures that all individuals with full control over the site are involved in the review process and can address any oversharing issues identified in the Data access governance reports.
+
+## What SharePoint objects with granted permissions are reviewed for Site access reviews?
+
+In SharePoint Advanced Management, Site access reviews focus on reviewing permissions for various SharePoint objects to ensure that access is appropriately managed. The objects reviewed include:
+
+- Sites: The overall site permissions are reviewed to ensure that only authorized users have access.
+
+- Lists and libraries: Permissions for lists and libraries within the site are reviewed to ensure that sensitive information isn't overshared.
+
+- Folders and documents: Permissions for specific folders and documents are reviewed to ensure that access is restricted to authorized users only.
+
+These reviews help identify and address any oversharing issues, ensuring that sensitive information is protected and access is appropriately managed.
+
+## What is the difference between Inactive sites policy and M365 Group Expiration policies in Microsoft Entra?
+
+The Inactive sites policy and Microsoft 365 Group Expiration policies in Microsoft Entra serve different purposes and have distinct functionalities:
+
+- Inactive sites policy: This policy is designed to manage SharePoint sites that are no longer in use. It helps administrators identify and take action on sites that have been inactive for a specified period. Actions can include notifying site owners, archiving the site, or deleting it. This policy ensures that unused sites don't clutter the environment and helps maintain an organized and efficient SharePoint infrastructure.
+
+- Microsoft 365 Group Expiration Policy: This policy focuses on the lifecycle management of Microsoft 365 groups. It automatically renews groups based on user activity, such as sending an email to the group, uploading a document to SharePoint, or visiting a Teams channel. If a group is inactive for a specified period, the group owners are notified to renew the group. If the group isn't renewed, it's deleted but can be restored within 30 days. This policy helps manage the proliferation of unused groups and ensures that only active groups remain in the environment.
+
+## What if I have Inactive sites policies and Microsoft 365 Group Expiration policies running at the same time?
+
+When both policies are active, they operate independently but can complement each other in managing site and group lifecycles. Here are some key points:
+
+Notification management: If a site falls under multiple inactive site policies, notification emails aren't repeated. If a notification was sent within the last 30 days from any inactive site policy, the site remains inactive, and no further notifications are sent. The policy execution report shows the site's status as "Notified by another policy."
+
+Policy execution: The Inactive Sites Policy helps manage SharePoint sites that are no longer in use by notifying site owners and taking actions such as archiving or deleting the site. The Microsoft 365 Group Expiration Policy, on the other hand, focuses on the lifecycle management of Microsoft 365 groups, automatically renewing or deleting groups based on user activity.
+
+Effect on associated
+
+## Related topics
+
+[Microsoft SharePoint Premium - SharePoint Advanced Management overview](advanced-management.md)
SharePoint Advanced Management https://github.com/MicrosoftDocs/OfficeDocs-SharePoint/commits/public/SharePoint/SharePointOnline/advanced-management.md
Previously updated : 08/20/2024 Last updated : 11/20/2024 Title: "Microsoft SharePoint Premium - SharePoint Advanced Management overview"
SharePoint Advanced Management helps you identify, manage, and resolve common co
**What is content sprawl?** Content sprawl occurs when digital content accumulates without proper management across various storage locations in an organization. This leads to difficulties in accessing information, higher storage expenses, security vulnerabilities, and compliance complexities. You can tackle content sprawl by implementing governance strategies and utilizing tools that centralize control, optimize storage efficiency, and uphold secure data management practices.
-### Inactive SharePoint sites policy
+### Site ownership policy
+
+The site lifecycle management feature from Microsoft SharePoint Premium - SharePoint Advanced Management lets you improve site governance by having automated policies configured in the SharePoint admin center.
+
+**[Site ownership policies](create-sharepoint-site-ownership-policy.md)** are a part of site lifecycle management and help effectively manage ownership of SharePoint sites in your organization.
+
+### AI Insights
+
+The **[AI insights](ai-insights.md)** feature for [SharePoint Advanced Management](advanced-management.md) uses a language model to identify patterns and potential issues from reporting and receive actionable recommendations to solve issues.
+
+You can find the **Get AI insights** button next to various reports in the SharePoint admin center. Once selected, the AI insights feature extracts patterns from the report and offers a list of potential actions.
++
+### Inactive sites policy
You can run automated, rule-based policies to manage and reduce inactive sites with the [**Inactive SharePoint sites policy**](site-lifecycle-management.md) feature from SharePoint Advanced Management.
You can run automated, rule-based policies to manage and reduce inactive sites w
The inactive sites policy combats content sprawl by automatically identifying and managing inactive SharePoint sites. It operates by defining inactivity criteria, such as lack of updates or user activity over a set period. Once identified, site owners receive email notifications to confirm the active/inactive state of the site.
-### AI Insights
+## Manage content lifecycle
-The AI insights feature for [SharePoint Advanced Management](advanced-management.md) uses a language model to identify patterns and potential issues from reporting and receive actionable recommendations to solve issues.
+You can manage the content lifecycle for SharePoint and OneDrive sites with SharePoint advanced management features that streamline content creation, organization, and retention through automated workflows, detailed reporting, and robust compliance settings.
-You can find the **Get AI insights** button next to various reports in the SharePoint admin center. Once selected, the AI insights feature extracts patterns from the report and offers a list of potential actions.
+Effective lifecycle management not only ensures streamlined governance and enhanced collaboration but also optimizes storage, maintains data integrity, and supports regulatory compliance, ultimately improving efficiency and security.
+### Site change history reports
+
+The **[Site change history report](change-history-report.md)** feature lets you create change history reports in the SharePoint admin center to review SharePoint site property changes made within the last 180 days. Create up to five reports for a given date range and filter by sites and users. You can download the report as a .csv file to view the site property changes.
++
+### Recent site actions
+
+ The **[Recent SharePoint admin actions](recent-actions-panel.md)** policy lets you review and monitor the last 30 changes you've made to a SharePoint site's properties within the last 30 days in the SharePoint admin center. This feature only shows changes made by you and not other administrators.
-## Manage oversharing
+
+## Manage permissions and access
Copilot leverages the data stored in SharePoint and OneDrive sites to provide insights and automate tasks across your organization. Confidential data from content in SharePoint and OneDrive sites can populate in Copilot's generated insights, posing security and privacy risks.
SharePoint Advanced Management ensures this data is securely handled and accesse
By preventing oversharing and managing access effectively, you can ensure that Copilot's collaboration features are optimized. This leads to more efficient and secure use of Copilot across your organization.
-### Data access governance insights
-
-**[Data access governance insights](data-access-governance-reports.md)** lets you view reports that identify sites that contain potentially overshared or sensitive content. You can use these reports to assess and apply appropriate security and compliance policies.
-
+Before enabling Copilot for your organization and tenant, you can proactively set policies to restrict access to sites and manage content discoverability during Copilot and tenant-wide search.
### Block download policy for SharePoint and OneDrive sites
By preventing oversharing and managing access effectively, you can ensure that C
:::image type="content" source="media/sam-overview/9-block-download-policy-sharepoint-onedrive.png" alt-text="Screenshot of block download policy for SharePoint and OneDrive sites.":::
-### Conditional access policy for SharePoint and OneDrive sites
+**[Data access governance reports](data-access-governance-reports.md)** lets you view reports that identify sites that contain potentially overshared or sensitive content. You can use these reports to assess and apply appropriate security and compliance policies.
-**[Conditional access policy for SharePoint and OneDrive sites](authentication-context-example.md)** lets you enforce stringent access conditions when users access SharePoint sites. Authentication contexts can be directly applied to sites or used with sensitivity labels to connect Microsoft Entra Conditional Access policies to labeled sites.
+### Enterprise app insight reports
-## Control Copilot access to content
+**[App insights](app-insights.md)** is a SharePoint Advanced Management feature that lets you gain insights on the various non-Microsoft applications registered to your Microsoft Entra admin center and how they access your SharePoint content. This report can help you maintain and protect the integrity of your content.
-Before enabling Copilot for your organization and tenant, you can proactively set policies to restrict access to sites and manage content discoverability during Copilot and tenant-wide search.
+### Site access reviews
-### Restricted access control for SharePoint
-
-You can prevent sites and content from being discovered at the site-level by enabling **[Restricted access control for SharePoint sites](restricted-access-control.md)**. Site access restriction allows only users in the specified security group or Microsoft 365 group to access content. This policy can be used with Microsoft 365 group-connected, Teams-connected, and non-group connected sites.
+**[Site access review](site-access-review.md)** feature in the SharePoint admin center lets you delegate the review process of [data access governance reports](data-access-governance-reports.md) to the site owners of overshared sites.
+Site access review involves site owners in the review process so they can address the concern of overshared sites identified in data access governance reports.
-### Restricted access control for OneDrive
+### Data access governance management via PowerShell
-You can limit access to shared content of a user's OneDrive to only people in a security group with the **[Restricted access control for OneDrive](onedrive-site-access-restriction.md)** policy.
+While Data access governance is available in SharePoint admin center portal, large organizations usually look for **[PowerShell support](powershell-for-data-access-governance.md)** in order to manage scale via scripting and automation.
-Once the policy is enabled, anyone who is not in the designated security group won't be able to access content in that OneDrive even if it was previously shared with them. To block users from accessing OneDrive as a service, you can enable the [Restrict OneDrive service access](limit-access.md) feature.
+This document discusses all appropriate PowerShell commands available via SharePoint Online PowerShell module to manage reports from Data access governance.
+### Conditional access policy for SharePoint and OneDrive sites
-## Manage content lifecycle
+**[Conditional access policy for SharePoint and OneDrive sites](authentication-context-example.md)** lets you enforce stringent access conditions when users access SharePoint sites. Authentication contexts can be directly applied to sites or used with sensitivity labels to connect Microsoft Entra Conditional Access policies to labeled sites.
-You can manage the content lifecycle for SharePoint and OneDrive sites with SharePoint advanced management features that streamline content creation, organization, and retention through automated workflows, detailed reporting, and robust compliance settings.
-Effective lifecycle management not only ensures streamlined governance and enhanced collaboration but also optimizes storage, maintains data integrity, and supports regulatory compliance, ultimately improving efficiency and security
+### Restricted access control for SharePoint
-### Recent SharePoint admin actions
+You can prevent sites and content from being discovered at the site-level by enabling **[Restricted access control for SharePoint sites](restricted-access-control.md)**. Site access restriction allows only users in the specified security group or Microsoft 365 group to access content. This policy can be used with Microsoft 365 group-connected, Teams-connected, and non-group connected sites.
- The **[Recent SharePoint admin actions](recent-actions-panel.md)** policy lets you review and monitor the last 30 changes you've made to a SharePoint site's properties within the last 30 days in the SharePoint admin center. This feature only shows changes made by you and not other administrators.
+### Restricted access control for OneDrive
-### Change history - Site changes
+You can limit access to shared content of a user's OneDrive to only people in a security group with the **[Restricted access control for OneDrive](onedrive-site-access-restriction.md)** policy.
-The **[Change history - Site changes](change-history-report.md)** feature lets you create change history reports in the SharePoint admin center to review SharePoint site property changes made within the last 180 days. Create up to five reports for a given date range and filter by sites and users. You can download the report as a .csv file to view the site property changes.
+Once the policy is enabled, anyone who is not in the designated security group won't be able to access content in that OneDrive even if it was previously shared with them. To block users from accessing OneDrive as a service, you can enable the [Restrict OneDrive service access](limit-access.md) feature.
## Licensing
SharePoint Change Your Sharepoint Domain Name https://github.com/MicrosoftDocs/OfficeDocs-SharePoint/commits/public/SharePoint/SharePointOnline/change-your-sharepoint-domain-name.md
If your organization is going through a rebranding, merger, or acquisition and n
> [!VIDEO https://www.microsoft.com/videoplayer/embed/RWOnwY] >[!IMPORTANT]
-> - The standard version of this feature is currently available to organizations that have no more than 10,000 total SharePoint sites and OneDrive accounts combined.
+> - The standard version of this feature is currently available to organizations that have no more than 10,000 total sites, which includes SharePoint sites, OneDrive accounts and SharePoint Embedded containers combined.
> - Advanced Tenant Rename is available to organizations that have less than 100,000 total sites, available with SharePoint Advanced Management. See [Advanced Tenant Rename](change-your-sharepoint-domain-name.md#advanced-tenant-rename). > - This change affects only SharePoint and OneDrive URLs. It doesn't impact email addresses. > - For info about changing a site address, for example, from `https://contoso.sharepoint.com/sites/sample1` to `https://contoso.sharepoint.com/sites/sample2`, see [Change a site address](change-site-address.md).
SharePoint Data Access Governance Reports https://github.com/MicrosoftDocs/OfficeDocs-SharePoint/commits/public/SharePoint/SharePointOnline/data-access-governance-reports.md
Previously updated : 11/18/2024 Last updated : 11/19/2024 Title: "Data access governance reports for SharePoint sites"-+
Each EEEU report includes data as shown in the following screenshot:
- Primary admin for each site. > [!NOTE]
-> The reports don't include OneDrive data
+> Support for OneDrive data is now [available via PowerShell](powershell-for-data-access-governance.md).
### Download Everyone except external users reports
After running the report, select the report to download the data. In the report:
- Reports work if you have nonpseudonymized report data selected for your organization. To change this setting, you must be a Global Administrator. Go to the [Reports setting in the Microsoft 365 admin center](https://admin.microsoft.com/#/Settings/Services/:/Settings/L1/Reports) and clear **Display concealed user, group, and site names in all reports**. - Report data can be delayed for up to 48 hours. In new tenants, it can take a few days for data to be generated successfully and available for viewing.
-## Setting up oversharing baseline with Permissions based report
+## Setting up oversharing baseline with permissions based report
It's vital for SharePoint admin to understand the permissions setup in their tenant, particularly in the wake of Copilot adoption, as it respects user and content permissions. Copilot's data exposure risk increases with the number of users having access. Hence, SharePoint admins need to evaluate sensitive data 'exposure' by checking permissions to items or sites. Data access governance (DAG) can help establish oversharing thresholds by identifying sites with ΓÇÿtoo manyΓÇÖ permissioned users.
It's vital for SharePoint admin to understand the permissions setup in their ten
> [!IMPORTANT] > Currently, SharePoint admins can generate the report via PowerShell only. The first report for the tenant can take up to 5 days.
+> [!NOTE]
+> This report can only be run once a month.
+ ### Run the oversharing baseline report See [PowerShell for Data access governance](powershell-for-data-access-governance.md#oversharing-baseline-report-using-permissions) for more information on running the command to generate the oversharing baseline report.
SharePoint Manage Access Agents In Sharepoint https://github.com/MicrosoftDocs/OfficeDocs-SharePoint/commits/public/SharePoint/SharePointOnline/manage-access-agents-in-sharepoint.md
ms.localizationpriority: medium search.appverid: - MET150
-description: "Learn how to manage access to agents in SharePoint with built-in SharePoint permissions models, SharePoint Advanced Management features such as restricted access control, and restricted content discovery."
+description: "Learn how to manage access to agents in SharePoint with built-in SharePoint permission models, SharePoint Advanced Management features such as restricted access control, restricted content discovery, and Microsoft Purview Data Loss Prevention (DLP)."
# Manage access to agents in SharePoint
-Agents in SharePoint, powered by AI, help employees quickly find information and insights on SharePoint sites, pages, and document libraries. Agents in SharePoint access your organization's data the same way [Copilot in other Microsoft 365 apps](/sharepoint/sharepoint-copilot-best-practices#copilot-and-sharepoint) does, responding to users based on their access permissions to the data. As a SharePoint admin, you can manage employees' access to an agent in multiple ways by managing:
-- Who can access the agents-- What information the user can access through the agent-- Whether agents are available in a specific SharePoint site
+Agents in SharePoint, powered by AI, help users quickly find information and insights on SharePoint sites, pages, and document libraries. Agents in SharePoint access your organization's data the same way [Copilot in other Microsoft 365 apps](/sharepoint/sharepoint-copilot-best-practices#copilot-and-sharepoint) does, responding to users based on their access permissions to the data. As a SharePoint admin, you can manage users' access to an agent in multiple ways by managing:
+
+- Who can access the agents
+- What information the user can access through the agent
+- Where agents are available
## Manage who can access the agents Currently, users with a [Microsoft 365 Copilot license](/copilot/microsoft-365/microsoft-365-copilot-licensing) can use the agents. You can use the [Microsoft 365 Copilot setup guide](https://admin.microsoft.com/Adminportal/Home?Q=learndocs#/modernonboarding/microsoft365copilotsetupguide) in the Microsoft 365 admin center to assign the required licenses to users. For more information, see [Assign licenses to users in the Microsoft 365 admin center](/microsoft-365/admin/manage/assign-licenses-to-users) and [Microsoft 365 Copilot requirements](/copilot/microsoft-365/microsoft-365-copilot-requirements). > [!NOTE]
-> From December 1, 2024, to June 30, 2025, enterprise tenants with 50 or more Microsoft 365 Copilot licenses will receive 10,000 free Agents in SharePoint queries for unlicensed users every month as a trial. SharePoint administrators or above can [check the trial promotion status](/powershell/module/sharepoint-online/get-spocopilotpromooptinstatus) and [set trial promotion](/powershell/module/sharepoint-online/set-spocopilotpromooptinstatus) using PowerShell cmdlets. Please see terms of trial usage [here](/legal/microsoft-365/in-app-trials-terms-of-service).
+> From December 1, 2024, to June 30, 2025, enterprise tenants with 50 or more Microsoft 365 Copilot licenses will receive 10,000 free Agents in SharePoint queries for unlicensed users every month as a trial. Users with a role SharePoint administrators or higher can [check the trial promotion status](/powershell/module/sharepoint-online/get-spocopilotpromooptinstatus) and [set trial promotion](/powershell/module/sharepoint-online/set-spocopilotpromooptinstatus) using PowerShell cmdlets. Please see terms of trial usage [here](/legal/microsoft-365/in-app-trials-terms-of-service).
## Manage what information a user can access through the agents ### With built-in SharePoint features
-Agents in SharePoint use SharePoint sites, pages and document libraries as knowledge sources to respond to the user. You can control a userΓÇÖs access to the information when they use an agent by controlling their access to the site. SharePoint provides many tools to control access to a site:
+Agents in SharePoint use SharePoint sites, pages, and document libraries as knowledge sources to respond to the user. You can control a userΓÇÖs access to the information when they use an agent by controlling their access to the site. SharePoint provides many tools to control access to a site:
-- Make a site private to ensure only the people who have explicit permission to access the site.-- If the site is associated with a Microsoft 365 group and the site is private, control group membership to control who can visit the site.-- If the site isnΓÇÖt associated with a group and is private, use site permissions to control access.-- Use access governance policies available in the SharePoint admin center and PowerShell to control access based on other criteria.
+- Control access to a site that is associated with a [Microsoft 365 group](/microsoft-365/solutions/collaboration-governance-overview) by [setting the site as private](https://support.microsoft.com/office/change-a-site-s-title-description-logo-and-site-information-settings-8376034d-d0c7-446e-9178-6ab51c58df42) (team sites only) and controlling group membership.
+- Control access to a site that isn't associated with a group using [site permissions](/sharepoint/site-permissions).
+- Control access with access governance policies available in the SharePoint admin center and PowerShell.
Learn more about using SharePoint built-in features to control access [here](/sharepoint/sharepoint-copilot-best-practices#step-2prevent-oversharing-and-control-access-with-sharepoint-and-onedrive).
-## With SharePoint Advanced Management
+### With SharePoint Advanced Management
Currently, to restrict access to a site by Microsoft 365 Copilot, the SharePoint Admin can set up a [restricted access control policy](/sharepoint/restricted-access-control). As a result, all access to the site is restricted to only the group of users specified in the policy. Accordingly, the content from this site is visible in Microsoft 365 Copilot only for this restricted group of users. You can restrict access to individual sites or OneDrive.
-Learn more about additional features to prevent oversharing, control access, and enhance your content governance with SharePoint Advanced Management [here](/sharepoint/get-ready-copilot-sharepoint-advanced-management).
+Learn more about more features to prevent oversharing, control access, and enhance your content governance with SharePoint Advanced Management [here](/sharepoint/get-ready-copilot-sharepoint-advanced-management).
+
+### With Microsoft Purview Data Loss Prevention (DLP)
+
+You can prevent selected files from being used by agents by using sensitivity labels along with [Microsoft Purview Data Loss Prevention (DLP)](/purview/dlp-learn-about-dlp). You [do this](/purview/dlp-create-deploy-policy#scenario-2-block-sharing-of-sensitive-items-via-sharepoint-and-onedrive-in-microsoft-365-with-external-users) by creating a DLP custom policy with the **Content contains** > **Sensitivity labels** condition to exclude items from being processed. Identified items are available in the citations of the response, but the content of the item isn't used in the response.
+We donΓÇÖt yet support adding a sensitivity label directly to the [.agent file](https://support.microsoft.com/office/create-and-edit-an-agent-d16c6ca1-a8e3-4096-af49-67e1cfdddd42#where-agent-file). If you want to govern your *.agent* file with DLP, instead of using the Sensitivity labels as the condition, you can use conditions based on the *.agent* extension. We'll support the ability of adding a sensitivity label directly to a *.agent* file in the future.
+
+## Manage where agents are available in SharePoint with restricted content discovery
-## Turn off agents in SharePoint with restricted content discovery
+You as a SharePoint Admin can turn off all agent-related features on individual sites with the [restricted content discovery](/sharepoint/restricted-access-control). Once a site is flagged with restricted content discovery, users can't see the Copilot icon on the upper right of the site. Therefore, they donΓÇÖt have access to use the ready-made agent, create new agents, or add content from that site to any other agents. The restricted content discovery policy leaves site access unchanged but prevents the site's content from being surfaced in Microsoft 365 Copilot or organization-wide Search for all users.
+You as a SharePoint Admin can turn off all agent-related features on individual sites with the [restricted content discovery](/sharepoint/restricted-access-control). Once a site is flagged with restricted content discovery, users can't see the Copilot icon on the upper right of the site. Therefore, they donΓÇÖt have access to use the ready-made agent, create new agents, or add content from that site to any other agents. The restricted content discovery policy leaves site access unchanged but prevents the site's content from being surfaced in Microsoft 365 Copilot or organization-wide Search for all users.
-You as a SharePoint Admin can turn off all agent-related features on individual sites with the [restricted content discovery](/sharepoint/restricted-access-control). Once a site is flagged with restricted content discovery, users can't see the Copilot icon on the upper right of the site. Therefore, they donΓÇÖt have access to use the ready-made agent, create new agents, or add content from that site to any other agents. The restricted content discovery policy leaves site access unchanged but prevents the site's content from being surfaced in Microsoft 365 Copilot or organization-wide Search for all users.
+## More resources
+- [SharePoint site roles and permissions](/sharepoint/site-permissions)
+- [Permission levels in SharePoint](/sharepoint/understanding-permission-levels)
+- [SharePoint and Microsoft 365 Groups integration](/microsoft-365/solutions/groups-sharepoint-governance)
+- [Microsoft Teams, SharePoint, and Microsoft 365 Groups integration](/microsoft-365/solutions/groups-sharepoint-teams-governance)
+- [Get ready for Microsoft 365 Copilot with SharePoint Advanced Management](/sharepoint/get-ready-copilot-sharepoint-advanced-management)
+- [Learn about data loss prevention](/purview/dlp-learn-about-dlp)
SharePoint Powershell For Data Access Governance https://github.com/MicrosoftDocs/OfficeDocs-SharePoint/commits/public/SharePoint/SharePointOnline/powershell-for-data-access-governance.md
Previously updated : 11/14/2024 Last updated : 11/19/2024 Title: "Manage Data access governance reports using SharePoint Online PowerShell"
AdminComment : Check for org wide access
SiteName : All Company ```
-This triggers emails to site owner as described [here](site-access-review.md#initiate-a-site-access-review).
+This triggers emails to site owner as described [here](site-access-review.md#how-to-initiate-a-site-access-review).
### Track Site access reviews using PowerShell
SharePoint Restricted Site Creation https://github.com/MicrosoftDocs/OfficeDocs-SharePoint/commits/public/SharePoint/SharePointOnline/restricted-site-creation.md
+ Last updated : 11/19/2024
+ Title: "Restrict OneDrive and SharePoint site creation"
++
+recommendations: true
++
+audience: Admin
+f1.keywords:
+- NOCSH
++
+ms.localizationpriority: medium
+
+- Highpri
+- Tier2
+- M365-sam
+- M365-collaboration
+- essentials-manage
+search.appverid:
+description: "Learn how to restrict users from creating OneDrive and SharePoint sites using restricted site creation."
++
+# Restrict OneDrive and SharePoint site creation
++
+The restricted site creation feature lets IT administrators use [SharePoint Online Management Shell](/powershell/sharepoint/sharepoint-online/introduction-sharepoint-online-management-shell#getting-started-with-sharepoint-online-powershell) to designate which Microsoft Entra security groups in their tenant can create OneDrive and SharePoint sites.
+
+You can choose between two ways to manage site creation within your tenant: deny mode (the specified groups are unable to create sites) and allow mode (only the specified groups are allowed to create sites). Once you enable this feature for your tenant, restricted site creation is set to deny mode by default.
+
+Restricted site creation policies only control site provisioning capabilities and not site access permissions.
+
+## Prerequisites
+
+- The latest version of [Microsoft SharePoint Online Management Shell](https://www.microsoft.com/download/details.aspx?id=35588) must be installed.
+- The restricted site creation feature requires a [Microsoft SharePoint Premium - SharePoint Advanced Management](advanced-management.md) subscription.
+
+## Site types
+
+Each restricted site creation policy includes a *site type* specifying the types of sites users in the specified groups are either allowed or denied from creating.
+
+|Site type|Applies to|
+|||
+|All|OneDrive and all SharePoint sites|
+|SharePoint|All SharePoint sites (but not OneDrive)|
+|OneDrive|Only OneDrive|
+|Team|Only SharePoint team sites (group-connected and classic)|
+|Communication|Only SharePoint communication sites|
+
+Up to 10 Microsoft Entra security groups can be specified for each site type.
+
+When restricted site creation is in allow mode, a user is only allowed to create a site if they are in a group configured with a site type which applies to the site they're attempting to create. For example, a user can create a OneDrive if they are in a security group configured with the All or OneDrive site types.
+
+When restricted site creation is in deny mode, a user is blocked from creating a site if they are in any group configured with any site type which applies to the site they're attempting to create. For example, a user is blocked from creating a SharePoint communication site if they are in any group configured with the All, SharePoint, or Communication site types.
+
+> [!NOTE]
+> The restricted site creation mode is shared across all site type policies. It is not possible to use deny mode for one site type and allow mode for a different site type.
+
+## Current limitations
+
+- Only Microsoft Entra security groups (mail-enabled or non-mail-enabled) are supported at this time.
+- You can configure up to 10 security groups per site type.
+- This feature is currently unavailable for government cloud environments such as GCCH/GCC-Moderate/DoD/Gallatin.
+
+## Manage restricted site creation
+
+The `Set-SPORestrictedSiteCreation` and `Get-SPORestrictedSiteCreation` cmdlets in the SharePoint Online Management Shell allow the admin to configure and view the restricted site creation feature and policies for the tenant.
+
+> [!IMPORTANT]
+> You must use version 16.0.25513 (published November 2024) or later of the SharePoint Online Management Shell for these commands to function properly. Earlier versions do not have the current list of site types and will not operate correctly.
+
+### Enable restricted site creation for your tenant
+
+To enable restricted site creation, run the following command in the SharePoint Online Management Shell:
+
+```powershell
+Set-SPORestrictedSiteCreation ΓÇôEnabled $true
+```
+
+Restricted site creation starts in deny mode without any policies, and doesn't affect any users by default.
+
+### Set Allow or Deny mode
+
+Once you enable the restricted site creation feature, consider whether you want to deny certain groups from creating sites or allow certain groups the ability to create sites.
+
+For example, the following command sets restricted site creation to deny mode:
+
+```powershell
+Set-SPORestrictedSiteCreation ΓÇôMode Deny
+```
+
+> [!IMPORTANT]
+> Swapping between the two modes will remove all existing site type configurations. The restricted site creation feature only supports either all deny or all allow configurations.
+
+### Configure policies for site types
+
+You can specify a comma separated list of up to 10 Microsoft Entra security groups for each site type. For example, if restricted site creation is in deny mode, the following command creates a policy blocking users in either of the following two groups from creating any SharePoint site.
+
+```powershell
+Set-SPORestrictedSiteCreation -SiteType SharePoint -RestrictedSiteCreationGroups "00aa00aa-bb11-cc22-dd33-44ee44ee44ee,11bb11bb-cc22-dd33-ee44-55ff55ff55ff"
+```
+
+> [!NOTE]
+> Microsoft Entra security groups must be specified with the Object Id shown in the [Microsoft Entra admin center](/entra/fundamentals/how-to-manage-groups).
+
+To clear the configuration for site type, specify **""** for the RestrictedSiteCreationGroups:
+
+```powershell
+Set-SPORestrictedSiteCreation -SiteType All -RestrictedSiteCreationGroups ""
+```
+
+### View configuration
+
+Use the following command to view the existing restricted site creation configurations:
+
+```powershell
+Get-SPORestrictedSiteCreation
+```
+
+## User restriction
+
+When a user is blocked from creating a site by a restricted site creation policy, they receive a message depending on the type of site they're creating and how they're creating it. See the following examples for reference:
+
+When a user creates a communication site from the web, they see the error message "Due to organizational policies, you can't create this type of site."
++
+When first signing in to their OneDrive from the web, the user sees the error message "You can't make a OneDrive. If you need one, contact your administrator or help desk."
++
+When a user creates a team site from the web, the user sees the message "We're still setting up the site for this group," but the site isn't created.
++
+When creating sites through the SharePoint Online Management Shell, the cmdlet fails with the exception "Due to organizational policies, you can't create this type of site."
++
+## Related topics
+
+[Microsoft SharePoint Premium ΓÇô SharePoint Advanced Management overview](advanced-management.md)
SharePoint Site Access Review https://github.com/MicrosoftDocs/OfficeDocs-SharePoint/commits/public/SharePoint/SharePointOnline/site-access-review.md
Previously updated : 11/18/2024 Last updated : 11/19/2024 Title: "Initiate site access reviews for Data access governance reports"
description: "Learn about how to initiate site access reviews as a remedial acti
[!INCLUDE[Advanced Management](includes/advanced-management.md)]
-Site access review in the [SharePoint admin center](https://go.microsoft.com/fwlink/?linkid=2185219) lets [IT administrators](/microsoft-365/admin/add-users/assign-admin-roles) delegate the review process of [data access governance reports](data-access-governance-reports.md) to the site owners of overshared sites.
+Site access reviews in the [SharePoint admin center](https://go.microsoft.com/fwlink/?linkid=2185219) allow [IT administrators](/microsoft-365/admin/add-users/assign-admin-roles) to delegate the process of reviewing data access governance reports to site owners of overshared sites.
-Site access review involves site owners in the review process so they can address the concern of overshared sites identified in data access governance reports. This feature is crucial because:
+This review process is crucial because:
-- IT administrators can't have access to file-level or item-level details due to compliance reasons.
+- IT administrators can't access file-level or item-level details due to compliance reasons.
- Site owners are best positioned to review and address oversharing issues for their own sites. ## Prerequisites
-To use the site access review feature, you must fulfill the following prerequisites:
+Before initiating a site access review, ensure that you meet the following requirements:
-- Have a [Microsoft SharePoint Premium - SharePoint Advanced Management](advanced-management.md) subscription-- Run a non-government cloud tenant environment. Site access review isn't supported in government cloud environments such as GCCH/GCC-Moderate/DoD/Gallatin-- Have admin credentials to access the SharePoint admin center to initiate an access review-- Have site owners respond to the review requests, take necessary actions, and complete the review
+- A [Microsoft SharePoint Premium - SharePoint Advanced Management](advanced-management.md) subscription.
+- A nongovernment cloud tenant environment. Site access reviews aren't supported in government cloud environments (GCCH, GCC-Moderate, DoD, Gallatin).
+- Admin credentials for accessing the SharePoint admin center.
+- Site owners are available to respond to review requests, take necessary actions, and complete the review.
## How site access review works -- Site access review is accessible only for the top 100 sites shown in the data access governance reports. Site access review specifically targets the oversharing scenario identified in the selected data access governance report.-- When you initiate a review, the system generates a context-specific email for the site owner.-- For example, if you initiate a site access review for a report from the "Content shared with 'Everyone except external users'" category, the review email exclusively addresses sharing issues regarding that particular report.
+- Site access reviews can be initiated for the top 100 sites listed in data access governance reports. These reviews specifically target oversharing issues identified in the selected reports.
-## Support matrix
+- When you initiate a review, the system sends a context-specific email to the site owner. For example, if the review is for the "Content shared with 'Everyone except external users'" category, the email focuses solely on sharing issues for that report.
-Currently, site access review is available for
+## Supported reports
-- All Sharing link reports (Anyone, PeopleInYourOrg, Specific people shared externally)-- "Content shared with 'Everyone except external users'" reports.
+Site access reviews are available for the following reports:
+
+- Sharing link reports (Anyone, PeopleInYourOrg, Specific People shared externally)
+- "Content shared with 'Everyone except external users'" reports
- Oversharing baseline report using permissions
-## Initiate a site access review
+## How to initiate a site access review
-1. Sign in to SharePoint admin center with your admin credentials.
+1. Sign in to the SharePoint admin center with your admin credentials.
1. Expand the **Reports** section and select **Data access governance**. 1. Under "Content shared with 'Everyone except external users", select **View reports**.
-1. Select a report and choose the sites you want to review.
+1. Choose a report and select the sites you want to review.
:::image type="content" source="./media/data-access-governance/initiate-site-access-review.png" alt-text="Screenshot that shows Initiate site access review for sites listed within DAG report" lightbox="./media/data-access-governance/initiate-site-access-review.png"::: 1. Select **Initiate site access review**.
-1. Add comments in the provided section to give context to site owners.
+1. Add comments in the provided section to give context to the site owners.
:::image type="content" source="./media/data-access-governance/comments-site-access-review.png" alt-text="Screenshot that shows provide comments for context setting for site owners"::: 1. Select **Send** to initiate the review request.
-For reports available only via PowerShell such as Oversharing baseline report using permissions, site access review can also be initiated using [PowerShell commands](powershell-for-data-access-governance.md#initiate-site-access-review-using-powershell).
+For reports that are only available via PowerShell (such as the Oversharing baseline report using permissions), site access reviews can also be initiated using [PowerShell commands](powershell-for-data-access-governance.md#initiate-site-access-review-using-powershell).
-### Track initiated site access reviews
+## Track site access reviews
-To see a list of all initiated site access reviews, select the **My review requests** tab from the data access governance landing page.
+To track all initiated site access reviews, go to the **My review requests** tab on the Data access governance landing page.
:::image type="content" source="./media/data-access-governance/my-review-requests.png" alt-text="Screenshot that shows track all reviews initiated from a central page" lightbox="./media/data-access-governance/my-review-requests.png":::
-When you initiate a site access review, it remains in a pending state until the site owner completes the review. Once the site owner completes the review, the status and comments are updated with the name of the reviewer and time and date of completion. A review can be marked as failed if site access review couldn't determine a valid email ID for the site owner to deliver the site access review.
+Once a review is initiated, its status remains "pending" until the site owner completes it. After completion, the review status and comments will be updated with the reviewer's name and the date and time of completion. If a review fails (for example, due to an invalid email for the site owner), it's marked as failed.
+
+For reports available via PowerShell, such as the Oversharing baseline report, you can track reviews using this [PowerShell command](powershell-for-data-access-governance.md#track-site-access-reviews-using-powershell).
-For reports available only via PowerShell such as Oversharing baseline report using permissions, site access review can also be tracked using this [PowerShell command](powershell-for-data-access-governance.md#track-site-access-reviews-using-powershell).
+## Site access review process for site owners
-### Site access review process (for site owners)
+When you initiate a review, site owners receive an email containing:
-When you initiate a review, site owners receive an email for each site that requires attention. The email includes:
+- A relevant title.
+- Your comments (if any).
+- A request to review site permissions.
+- A link to a detailed access review page, specific to the identified issue in the data access governance report.
-- Relevant title-- Your comments (if any)-- A request to review site permissions-- A link to a detailed access review page. This page is specific for the scenario as specified in the data access governance report.
+Here are examples of the different emails a site owner might receive:
-The following image shows the email notification regarding 'Everyone except external users' last 28 days report:
+- Content shared with 'Everyone except external users' report for the past 28 days:
+ :::image type="content" source="./media/data-access-governance/email-eeeu-files-folders-lists.png" alt-text="Screenshot that shows email received by site owners for oversharing via EEEU" lightbox="./media/data-access-governance/email-eeeu-files-folders-lists.png":::
-The following image shows a report of shared links generated in the last 28 days:
+- Sharing links report for the past 28 days:
+ :::image type="content" source="./media/site-access-review/3-email-sharing-links.png" alt-text="Screenshot that shows the detailed oversharing permissions reports email notification." lightbox="./media/site-access-review/3-email-sharing-links.png":::
-The following image shows the oversharing baseline report using permissions:
+- Oversharing baseline report using permissions:
+ :::image type="content" source="./media/site-access-review/2-email-permissions-report.png" alt-text="Screenshot that shows the sharing links within the last 28 days report email notification." lightbox="./media/site-access-review/2-email-permissions-report.png":::
-#### Review 'Everyone except external users' site access review requests (for site owners)
+### Review 'Everyone Except External Users' site access requests
Site owners can review and manage access in two main areas: - **SharePoint groups:**
- - View which groups contain 'Everyone except external users'.
+ - View which groups contain 'Everyone except external users.'
- See when and by whom the group was added. - Remove 'Everyone except external users' from groups if necessary:
- 1. Selecting the SharePoint group opens the group membership page that displays all members of this SharePoint group.
- 2. Select **Everyone except external users** and **Actions** and choose to **remove users from group**.
+ 1. Open the SharePoint group membership page.
+ 2. Select **Everyone except external users**, select **Actions**, and select **Remove users from group**.
:::image type="content" source="./media/data-access-governance/manage-sharepoint-group-membership.png" alt-text="Screenshot that shows displays sharepoint group members" lightbox="./media/data-access-governance/manage-sharepoint-group-membership.png"::: - **Individual items (files/folders/lists):**
- - See items shared with 'Everyone except external users' in the last 28 days.
- - View sharing details (who shared and when).
+ - View items shared with 'Everyone except external users' in the last 28 days.
+ - See sharing details (who shared and when).
- Manage access and remove permissions as needed: 1. Select **Manage access**.
- 1. Under the 'Everyone except external users' group in the **Groups** tab, select the group and select **remove access**. See [Stop sharing OneDrive or SharePoint files or folders, or change permissions](https://support.microsoft.com/office/stop-sharing-onedrive-or-sharepoint-files-or-folders-or-change-permissions-0a36470f-d7fe-40a0-bd74-0ac6c1e13323) for more information.
+ 1. Under the 'Everyone except external users' group in the **Groups** tab, select the group and select **Remove access**. See [Stop sharing OneDrive or SharePoint files or folders, or change permissions](https://support.microsoft.com/office/stop-sharing-onedrive-or-sharepoint-files-or-folders-or-change-permissions-0a36470f-d7fe-40a0-bd74-0ac6c1e13323) for more information.
+
+ :::image type="content" source="./media/data-access-governance/site-owner-view-foreeeu-files.png" alt-text="Screenshot that shows view for site owner regarding items shared with eeeu." lightbox="./media/data-access-governance/site-owner-view-foreeeu-files.png":::
+
+### Review 'Sharing link' reports
+
+Once the site owner opens the email, they're redirected to a detailed sharing links report. This report shows:
+
+- Files for which links were generated, with the date and the user who created the link.
+- The **Manage access** button allows site owners to remove or modify permissions.
+
+The following screenshot shows the detailed sharing links report:
+
- :::image type="content" source="./media/data-access-governance/site-owner-view-foreeeu-files.png" alt-text="Screenshot that shows view for site owner regarding items shared with eeeu" lightbox="./media/data-access-governance/site-owner-view-foreeeu-files.png":::
+### Review 'Oversharing baseline using permissions' reports
-#### Review 'Sharing link reports' site access review requests (for site owners)
+When site owners select the email, they're redirected to the site access review page, where they can see the oversharing baseline using permissions report. This report helps site owners identify items with excessive permissions and take necessary actions.
-Once the site owner selects the email, they're redirected to the site access review detailed report generated for the site.
-The site owner gets a view of files for whom links were generated along with the exact time of generation and who generated the links. The 'Manage access' button can be used to navigate to the link section and remove it/modify the permissions.
+The SharePoint admin views the number of users with permissions to a site in the Data access governance report. Site owners can see this number, along with how permissions are distributed across different site items. Items with the highest number of permissioned users are shown first, allowing the site owner to address the most exposed items.
-The following image shows an email notification about the sharing links report using permissions:
+### Understanding the permissions report
-#### Review 'Oversharing baseline using permission reports' site access review requests (for site owners)
+#### Number of permissioned users
-Once the site owner selects the email, they're redirected to the site access review detailed report generated for the site.
+This column shows the total number of users who have permissions to a specific scope (Site, List, Folder, or File). It reflects the exposure of that item compared to others. However, it's important to note that this number isn't uniqueΓÇöif the same user has both direct and indirect permissions, they're counted multiple times.
-The following image shows an email notification about oversharing baseline report using permissions:
+**Example**:
-The SharePoint admin views the unique number of permissioned users for this site in the Data access governance report and that number is also visible to site owner in the site access review email. This list shows how those users are distributed across the site content in terms of permissions and scopes.
+Imagine a folder "F" with the following permissions:
-All items created in the site, by default, inherit permissions of the site and thus the 'site' acts like a parent. However, if the inherited permissions are broken due to sharing of an item by creating links, providing direct access to individuals or groups, removing users/groups etc., a unique scope is created for that item. Now this item acts as a new 'parent' and its children inherit its permissions. The site access review page is a list of such uniquely permissioned 'parents' with the appropriate scope and name. It's not the list of all items/files/folders in the site. The item with the highest number of permissioned users is shown first. Up to 100 items are shown in descending order so that site owner can focus on items with highest 'exposure' first.
+- 40 users from Group ΓÇ£AΓÇ¥
+- 10 users with direct permissions
+- 20 users with permissions via sharing links
-##### Understanding the site access review report for permission based reports
+The total number of permissioned users for folder "F" would be 80 (40 from Group ΓÇ£AΓÇ¥ + 10 direct + 20 via sharing links). No deduplication is applied, so if the same user is in both Group ΓÇ£AΓÇ¥ and has access via a sharing link, they're counted twice.
-**Number of permissioned users:** This column represents the number of users permissioned to that scope (Site/List/Folder/File) and hence illustrates the current 'exposure' for that item, as compared to other items. However, this number is NOT a unique number of users. In case the same user has both direct and indirect permissions to this item, the user is double counted.
+Additionally, the total number of permissioned users across all scopes might exceed the number of users shown in the email or Data Access Governance report. This happens because users can have permissions on multiple items. While a user might be counted once at the site level, they're counted separately for each item they have access to.
-For example, a folder 'F' was shared to a group ΓÇ£AΓÇ¥ consisting of 40 members and is directly shared with 10 individuals and 20 more individuals arrived using sharing links. The number of permissioned users is the sum of all users - 80 (40+10+20). No deduplication is done to see if the same user exists in groups or came via sharing links as well.
+#### Number of groups
-Also, the sum of permissioned users across all scopes might not equal the number of users in the email and/or Data access governance report and could be greater. This scenario can happen when a user has permissions across multiple items. At the site-level, such a user is counted once. However, at an item-level, that user is counted individually.
+This column shows how many groups have permissions to a specific item or scope. Often, a large portion of exposure comes from permissions granted to groups, especially those with many members. Reducing exposure can be achieved by adjusting group memberships or removing unnecessary groups from permissions.
-**Number of groups:** As the name suggests, this shows the number of groups having permissions to this scope/item. Usually, the exposure is caused by groups containing many users. Reducing exposure removes the permissions of groups and can edit their memberships. Select **Group number** to view the membership count of each group and identify which groups to target.
+Select on the **Group number** to see the membership count of each group. This helps you identify which groups to target for reducing permissions.
-The other columns show the number of ALL existing links (Anyone, PeopleInOrg) and the presence of EEEU/Everyone. If the number of links are high, or the EEEU/Everyone column says yes, the site owner can immediately target the relevant item/scope for reducing permissions.
-**Manage Access:** The 'Manage access' button allows the site owner to remove individual users, groups, delete links, or modify permissions accordingly. For a 'SharePoint site' scope, the button directs the site owner to SharePoint group management page, whereas for individual items, it uses the existing 'Manage access' experience.
-With this report, a site owner gets an overview of 'exposure' of parent items in their sites, can gauge the contribution of exposure and act via 'manage access' without having to manually iterate through every permission of every item in the site.
+#### Links and EEEU/Everyone
-#### Complete site access review requests (for site owners)
+This section displays:
-Once the site owner takes the necessary actions like modifying or removing permissions, the site owner should:
+- The number of links (for example, "Anyone" or "People in your organization") that have been shared for the scope.
+- Whether the item is exposed to Everyone or EEEU (Everyone Except External Users).
+
+If the number of links is high or the EEEU/Everyone column says "Yes," this is an immediate indicator that the item has broad exposure, and the site owner should focus on reducing permissions for that item.
+
+#### Manage Access
+
+The Manage Access button provides a way for the site owner to take action by:
+
+- Removing individual users
+- Modifying group memberships
+- Deleting links
+- Adjusting permissions
+
+For a SharePoint site, selecting this button redirects to the **SharePoint group management** page. For individual items, it opens the **Manage Access** interface, allowing for more granular control over permissions.
+
+### Complete site access reviews
+
+Once the site owner makes necessary changes (like modifying or removing permissions), they should:
1. Select **Complete review**. 2. Add any relevant comments.
-3. Submit the completed review.
-
- Comments are shared back to the IT administrator who raised the review request. The review request is then marked as completed.
+3. Submit the review.
-#### Manage multiple site access review requests (for site owners)
+Comments are sent back to the IT administrator, and the review will be marked as completed.
-A site owner can receive review requests for multiple sites, or receive multiple reviews for different scenarios for the same site. A site owner can track all requests by selecting the **Site reviews** page found in the left panel.
+### Manage multiple site access reviews
+Site owners can receive and handle multiple site access review requests simultaneously. To track all review requests:
-For site owners handling multiple reviews:
+ :::image type="content" source="./media/data-access-governance/site-review-master-page.png" alt-text="Screenshot that shows Master page to track all site review for a site." lightbox="./media/data-access-governance/site-review-master-page.png":::
-1. Access the 'site reviews' page via:
+1. Go to the **Site reviews** page via:
- The link in the review email. - The gear icon on the site home page:
- 1. Select **Site settings**.
- 1. Select **Site reviews**.
- :::image type="content" source="./media/data-access-governance/site-review-from-gear-icon.png" alt-text="Screenshot that shows path to site review page from site home page under gear icon" lightbox="./media/data-access-governance/site-review-from-gear-icon.png":::
-1. View all pending site access reviews.
-1. Complete reviews as necessary.
+ 1. Select **Site settings**.
+ 1. Select **Site reviews**.
+
+ :::image type="content" source="./media/data-access-governance/site-review-from-gear-icon.png" alt-text="Screenshot that shows path to site review page from site home page under gear icon." lightbox="./media/data-access-governance/site-review-from-gear-icon.png":::
+ 1. View all pending site access reviews.
+ 1. Complete reviews as necessary.
## Related topics
-[Data access governance](data-access-governance-reports.md)
+[Data access governance reports](data-access-governance-reports.md)
[Microsoft SharePoint Premium - SharePoint advanced management](advanced-management.md)
SharePoint Teams Connected Sites https://github.com/MicrosoftDocs/OfficeDocs-SharePoint/commits/public/SharePoint/SharePointOnline/teams-connected-sites.md
Here are the basic parts of Teams and SharePoint and how they relate to each oth
- **SharePoint site** - A SharePoint site is a web site in SharePoint where you can create web pages and store and collaborate on files. SharePoint sites can be used independently and are also used by Teams for file storage (called *Teams-connected sites*). A Teams-connected site is created automatically whenever you create a team. - **Team** - A team is a place in Teams where you can invite others to collaborate. Each team is connected to one or more SharePoint sites. These sites are where the team's files are stored.-- + - **Public team** - A public team is a team that anyone in the organization can join. Public teams don't require a team owner to invite someone to the team. - **Private team** - A private team is a team that a person can only join when invited by a team owner. Both public teams and private teams offer the same channel types - standard, private, and shared. - **Parent site** - The SharePoint site that is created when you create the team. This site is used for file storage for all standard channels. All team owners and members have access to this site.--
+
- **Channel** - A channel is a location in a team where you can collaborate with others on a specific thing. A team can have multiple channels for different purposes. For example, you might have a team for marketing with different channels for different products or events. There are three types of channels in Teams: *standard*, *private*, and *shared*. - **Standard channel** - A standard channel is a channel that all members of a team have access to. Each team comes with a standard channel called "General." Team owners and members can add additional standard channels. It always shows up first in a team's list of channels, and it can't be deleted (every team must have at least one channel).