| A Microsoft 365 permissions audit is a review of who can currently reach every site, file, mailbox and shared drive in a tenant. It maps access that was deliberately granted against access that arrived by inheritance, by a company-wide group or by a sharing link nobody set to expire. |
A partner at a Christchurch law firm typed a question into Copilot in her first week with it. She asked what the firm had agreed with a supplier about payment terms.
The answer came back with a figure from a spreadsheet she had never opened. It sat in a project site from 2022, shared with the whole company on the day the project started. She had never been given access to that file; the site it lived in had simply not been touched since the job closed.
That example is illustrative, though the behaviour behind it is documented by Microsoft and the housekeeping failure is an ordinary one. Project sites get opened wide on day one and stay that way long after the last day.
That habit is easier to weigh up with numbers against it. Stay with the illustrative firm, put it at 48 people across three offices, and assume nobody has checked who can reach what since the tenant was built.
One oversharing incident in the past two years cost it $9,200 in investigation, legal advice and clean-up. Spread over those two years that runs to roughly $4,600 a year.
Setting permissions by hand on new client work takes about two and a half hours a site, and the firm opens roughly 24 project sites a year. At $95 an hour that is $5,700.
Tracing what a leaver can still reach takes about two hours a person, across 12 leavers a year, which comes to about $2,300.
Added together, those three lines come to about $12,600 a year, none of which appears as a line item. The money is spread across incident costs, project setup and offboarding. No owner has ever seen it as a single number.
Permissions get set in the moment somebody needs something, then stay put. A tenant that has run for six years carries six years of those decisions.
Copilot reads those same permissions and answers with whatever the person asking is already allowed to open, which turns six years of housekeeping into a search result. A Microsoft 365 permissions audit tells a business what that search result would contain, before the assistant is switched on for anybody.
What Is a Microsoft 365 Permissions Audit?
A Microsoft 365 permissions audit is a structured review of who can reach every site, library, mailbox and shared drive in a tenant, and of how that access was granted. It ends with a ranked list of findings and an order to fix them in.
The work is closer to stocktaking than to security testing. Nothing is attacked and nothing is broken into. The job is to write down what is already true, which most businesses have never had written down.
Access gets granted in the moment, by whoever was administering Microsoft 365 that year. The reason is almost never recorded, so the next administrator inherits a set of decisions with no explanation attached.
What does a permissions audit look at first?
An audit starts with the access that no person ever decided on. Inherited folders, company-wide site membership and old sharing links account for most of what a first pass turns up.

- Sites and libraries where the whole company was added at creation and never trimmed.
- Sharing links with no expiry date, sitting in email threads and chat histories from years back.
- Folders that took their permissions from a parent site that has not been reviewed in years.
- Mailboxes and shared drives carrying delegated access granted to a role two people ago.
- Sites with no named owner, which leaves the access on them unconfirmed.
- Teams whose membership grants the whole document library behind them, including files stored before the person joined.
- OneDrive accounts holding shared work files, which sit outside site governance and inside Copilot’s reach.
Each of those is a different problem needing a different fix, which is why grouping them is the first thing an audit does. An undifferentiated list of permissions is useless for deciding anything.
Does an audit cover Teams and OneDrive as well as SharePoint?
Yes, and a scope that stops at SharePoint misses most of the risk. Business content sits in four places: SharePoint sites, OneDrive accounts, Exchange mailboxes, and the Teams that sit on top of SharePoint sites.
Teams are the awkward one. Adding a person to a team hands them its entire document library, including everything filed before they joined, and team owners rarely think of it as a permission decision.
Administrative permissions are a different question from data permissions. An audit records who holds Global Administrator and the other Entra ID roles, then hands the ongoing discipline back to the access management routine above.
How is an audit different from managing access every month?
An audit is a one-off snapshot and a clean-up, while access management is the standing process that stops the mess returning. A business needs both. The audit comes first, because a monthly review over an untrusted baseline achieves very little.
The audit ends, with a scope, a finding list, a remediation sprint and a sign-off date.
What follows it is routine. Our guide to managing access as a standing discipline covers joiners, movers and leavers, and the review cycle that keeps a tenant from drifting back.
Why Does Copilot Make Permissions Urgent?
Because Copilot answers using the files the person asking is already allowed to open, so anything overshared becomes findable in one sentence. Microsoft’s Copilot privacy documentation is direct about it: Copilot only surfaces organisational data to which individual users have at least view permissions.
Before Copilot, an overshared file was theoretically reachable. Finding it meant knowing it existed and then hunting through a site that gets no traffic. A prompt removes the hunting.
For what Copilot does across Microsoft 365, including how it is licensed and where it appears, our Copilot page covers the product, while this post covers the permission state it will meet.
Does Copilot change who can see what?
No. Copilot grants no new access. The same identity boundary that governs SharePoint and Exchange governs what it can retrieve.
The change is in how easily existing access gets used, so a permission that sat idle for four years becomes a source in an answer. Copilot pulls those answers through Microsoft Graph, which holds a tenant’s mail, files, chat and calendar in one place, then ranks them using the Semantic Index. Nothing in that path adds a permission.
What a business gets back is therefore set by the tidiness of its own tenant.
This is why the audit belongs in front of the pilot. Where prompts and outputs travel once Copilot is running is a separate question, answered in our guide to keeping AI data secure.
What does an over-permissioned tenant look like in practice?
It looks like a company-wide group sitting on sites that were only ever meant for one team. In SharePoint that group is called Everyone except external users, shortened to EEEU. It takes in every internal account.
Microsoft’s guidance on EEEU sharing notes that access granted to that group reaches all current and future employees. A site opened to it in 2021 is open to the person who starts next Monday.
Abandoned project sites produce the same result by a different route: client work finishes, the site stays behind, its contents keeping whatever access the project needed. An orphaned site is worse again, because its named owner has left and the review request now goes to an empty mailbox.
What Does a Microsoft 365 Permissions Audit Find?
An audit turns up five recurring problems, in roughly this order of volume: company-wide site access, sharing links with no expiry, inherited project folders, delegated mailbox access, and shared drives with no owner. A first audit on a tenant of forty to sixty people usually finds all five.
Two terms cover most of what turns up. Privilege creep is access piling up as somebody moves between roles. Stale access is permission that outlived the reason it was granted.

A large count does not mean a large risk. Two hundred inherited folders inside a team’s own site matter less than one payroll library open to everybody.
So the list has to be ranked before anyone starts work. The audit orders its findings by what the exposed data would cost the business, then remediation follows that order. The industry calls the whole category SharePoint oversharing, which Microsoft reports on separately from ordinary permission changes.
Why is inherited access treated differently from access somebody granted?
Because it was never a decision. Permission inheritance means a folder or file takes its access from the site above it, which works while a site is tightly scoped and stops working the moment its purpose drifts.
Breaking inheritance corrects it in a deliberate step that detaches an item from its parent, so access can be set on the item alone. The state it leaves behind is called broken inheritance, and permission reports flag it as a category of its own. Do it too often and a tenant becomes unmanageable.
Once a site carries hundreds of individually permissioned items, reviewing it by hand stops being possible.
Which sharing links cause the most trouble?
The worst are Anyone links with no expiry date. These work without the recipient signing in, so a link forwarded twice is a link the business can no longer trace.
Microsoft’s sharing settings documentation sets out the control: an administrator can require all Anyone links to expire and specify the maximum number of days allowed. The same page notes that existing links keep their current expiry when the new setting is longer, and update only when it is shorter.
Turning on anyone link expiry across the tenant takes five minutes. Finding the links already issued takes longer, and that work belongs in the audit. Guest accounts sit alongside them, because a site shared with a contractor for one job usually still lists that contractor.
What does delegated mailbox access grant?
Delegated access comes in three forms that businesses regularly confuse. Full Access lets somebody open the mailbox and read everything in it, Send As lets them send mail that appears to come from the account holder, and Send on Behalf shows both names.
Full Access matters most here, because it exposes the contents of a mailbox to an assistant acting for the delegate. A manager given access to a departing staff member’s mailbox three years ago usually still has it.
Shared mailboxes carry the same issue at greater scale. Everyone on the accounts inbox can read every supplier dispute that has ever landed in it.
How Do You Fix What a Permissions Audit Finds?
In four moves, decided finding by finding: remove it, scope it, fix it before the pilot, or queue it for phase two. The decision takes about a minute per finding once the rule is agreed.

- Remove it, where the access is no longer needed, which covers most closed project sites and most old tender folders.
- Scope it, where the access is inherited and the item needs its own permission set. Break inheritance on the item, then grant access to the named group and to nobody wider than that.
- Fix it before the pilot, where the site or mailbox falls inside the group of people who get Copilot first.
- Queue it for phase two, where the exposure is real and sits outside the pilot group.
The order saves money. A remediation sprint aimed at the pilot group runs to about a fortnight. Aimed at the whole tenant it runs to a quarter.
Somebody has to make the calls, though not always the person running the tooling. An administrator can prepare the finding list and execute the changes, while only a department head can say whether the finance team should still reach a 2021 tender folder.
Staging the removals matters: take access away in a batch, wait a week, and see who asks for it back.
Microsoft also ships two controls for sites that cannot be tidied in time. Restricted Content Discovery keeps a site out of Copilot answers and organisation-wide search without changing anybody’s permissions. Restricted Access Control limits a site to a named group whatever prior permissions or shared links exist.
Both need a Copilot licence and SharePoint Advanced Management. Microsoft frames the first as a temporary measure while owners review access. For a business mid-rollout they buy time without stopping the pilot.
What has to be fixed before a Copilot pilot?
Fix anything the pilot group can reach that they should not already be reading. Payroll, board papers, employment files, client work under confidentiality restrictions and anything holding personal information covered by the Privacy Act.
The pilot group is small, which keeps the scope small. Ten people in one department reach far less than the whole company does.
Sensitivity labelling and controls on what can leave the tenant sit under data loss prevention, which is a separate piece of work. An audit does not replace it. A business running a pilot usually wants both.
What can wait until phase two?
Phase two takes the access held by people outside the pilot group, along with low-sensitivity content that is overshared without exposing anything. A marketing site open to the whole company is untidy and it is not urgent.
Phase two also carries the structural work, which moves more slowly because it needs decisions from people. A site without an owner needs one, and finding the right person takes a conversation with a department head.
Site layout is a separate question, answered in our guide to structuring a SharePoint intranet. An audit works with the sites a business already has. Write phase two down with a date against each item, because a finding queued without one rarely gets fixed.
How Do You Know a Permissions Audit Worked?
Run a query test. Ask Copilot, or tenant search, for the things a person should be unable to find, and read what comes back.
A report showing zero remaining findings only proves the tool ran. Measuring Copilot data access from a real staff account shows the permission state as that person will meet it.
SharePoint Advanced Management produces data access governance reports, shortened to DAG reports, which show sites with the heaviest company-wide sharing and the most sharing links created. Re-running the same report after remediation gives a second, independent read.
What does a query test look like?
It is a short list of prompts, run from an ordinary staff account. Administrator accounts see too much to make a useful test. Ask for salary information, for the last board pack, for a named client’s fee arrangement, and for anything under a confidentiality restriction.
Write the prompts down before remediation and run the same list afterwards. The two sets of answers give a board something it can read without a briefing. Three prompts that used to return payroll and now return nothing carry more weight with a board than any remediation report.
Who signs off that a site is correct?
The site owner, in writing, once a year. SharePoint Advanced Management can send a site access review straight to that owner, which turns the sign-off into a task in their inbox.
Site owners know who should see their content. Administrators know how permissions work. A delegated review puts the two kinds of knowledge in the same place, with any ownerless site given an owner first.
Does a Permissions Audit Help With Privacy Act Compliance?
Yes, in one specific way. Information privacy principle 5 of the Privacy Act 2020 requires an agency holding personal information to protect it with security safeguards that are reasonable in the circumstances, including against access and disclosure the agency has not authorised.
Inherited access and a stale anyone link both sit inside that wording. So does a shared mailbox that a former contractor can still open. The predecessor was the Privacy Act 1993, which carried the same duty at principle 5 under a name people still search for.
An audit will not make a business compliant on its own. It produces a record of what was checked and what was fixed, which the Office of the Privacy Commissioner will ask for after a breach.
How Much Does a Microsoft 365 Permissions Audit Cost?
An audit costs between $3,500 and $9,000 for most New Zealand businesses, with remediation charged separately. Tenant size and the number of sites carrying unique permissions drive most of the variation.
| What you are paying for | What it covers | Indicative range |
|---|---|---|
| Tenant permission scan | Site, library, mailbox and shared-drive access mapped and grouped into findings | $3,500 to $9,000 once |
| Sharing link review | Anyone links and guest accounts listed, with expiry set at tenant level | Included in the scan |
| Remediation sprint, pilot scope | Removals, inheritance breaks and owner assignment for the pilot group | $2,500 to $5,000 once |
| Remediation, whole tenant | The same work across every site, staged over a quarter | $8,000 to $20,000 once |
| SharePoint Advanced Management | Data access governance reports and delegated site access reviews | Licensed per user as an add-on |
| Quarterly permission review | Owner sign-off, new findings, and expiry settings rechecked | $1,500 to $2,500 a year |
Scanning is the small line here. The cost sits in remediation, because somebody has to decide, site by site, who should still be there.
What does that net out at for the illustrative firm?
About $2,300 avoided in the first year, then about $10,700 a year after that. Return to the illustrative 48-person Christchurch firm carrying about $12,600 a year in incident costs, manual permission work and leaver tracing.
Its audit comes in at about $4,800, with a remediation sprint scoped to the pilot group plus the worst tenant-wide findings adding about $3,600. The quarterly review runs about $1,900 a year.
Year one costs about $10,300 against $12,600, so about $2,300 comes back. From year two the one-off lines fall away and about $10,700 a year does. Most of that sits in the incident line, which only counts once remediation has reached the sites holding personal information.
What Is on a Microsoft 365 Permissions Audit Checklist?
Six items, and the first three need no budget and can be finished this month, before anybody quotes for the work.
- Turn on expiry for anyone links at tenant level, and set guest access to expire as well.
- List the sites where the whole company has access, and ask each owner whether that was intended.
- Name an owner for every site that has none, because a site with no owner cannot be reviewed by anybody.
- Run the permission scan and group the findings, so the list turns into decisions.
- Remediate the pilot scope first, then queue the rest with a date against each item.
- Run a query test from an ordinary staff account before the pilot opens, and keep the answers.
Steps one to three can be done by whoever already administers Microsoft 365. Steps four to six need a decision about who owns the permission state across the business.
Book a Microsoft 365 Permissions Audit
Exodesk has supported South Island businesses since 1989 and works with clients across Canterbury, Otago and Southland from offices in Christchurch and Dunedin. Our AI team runs a permission audit as the first step of any Copilot work, so the first answers a business sees are ones it is happy for its staff to have.
Contact us today to discuss how we can help your business or connect with us on LinkedIn to stay updated with more insights.
Frequently Asked Questions
What is oversharing in Microsoft 365?
Oversharing is the industry’s term for content in a tenant that more people can open than the business intended. It usually arrives without anyone deciding on it, through company-wide site membership, links that never expired, or folders taking their access from a parent site. Oversharing matters more once an AI assistant is switched on, because the exposed content becomes easy to find.
What does “Everyone except external users” mean in SharePoint?
Everyone except external users, shortened to EEEU, is a built-in SharePoint group that automatically includes every internal account and excludes guests. Adding it to a site makes that content visible to the whole organisation, including staff who have not started yet.
Is a permissions audit the same as a security audit?
No. A security audit looks at controls such as patching, backups, firewalls and staff training, while a permissions audit looks only at who can reach which data inside Microsoft 365. The two overlap at access control and are usually bought separately.
How long does a permissions audit take from start to finish?
Two to four weeks for a business of forty to sixty people, from kick-off to a ranked list of findings. The scan itself runs in a day or two. Most of the time goes into interpreting the results and agreeing with each site owner what the access should be. Remediation is a separate piece of work and usually runs a fortnight for a pilot scope.
Can I audit SharePoint permissions myself?
Yes, in part, because the Microsoft 365 and SharePoint admin centres expose sharing reports and site permission data that a capable internal administrator can work from. An external audit adds the ranking by business risk and the discipline of getting each owner to decide.
Do you need SharePoint Advanced Management to audit permissions?
No, though it makes the work considerably faster. A permissions audit can be run without it using admin centre reports and PowerShell, and SharePoint Advanced Management adds data access governance reports and delegated site access reviews, which earn the licence in tenants above roughly fifty users or with heavy external sharing.
Will removing access break work for staff?
No, provided removals are staged. Take access away in batches and keep a fast route to restore anything that turns out to be needed. Most businesses see a handful of requests in the first fortnight and very few after that.
Should a business delay Copilot until permissions are clean?
No, a full clean-up is not a prerequisite. Waiting for one stalls rollouts for a year. Fix what the pilot group can reach, start with ten people, and remediate the rest while the pilot runs.
What happens to files a leaver can still reach?
Access granted to a leaver’s account ends when the account is disabled, though three things usually survive. Sharing links they created keep working for whoever holds them, delegated access they granted to others stays in place, and files synced to a personal device already sit outside the tenant. A permissions audit lists all three so the offboarding checklist can be corrected. Correcting the checklist matters more than chasing the individual leaver.
Is a permissions audit worth it for a small business?
Yes, and it costs less at that size. Expect $2,500 to $4,000 for a twenty-person business, because there are fewer sites to work through. Smaller tenants often have the worst inheritance problems, since everything was set up quickly by one person and never revisited. The audit pays for itself the first time it stops payroll or client pricing turning up in a search result.
Who runs permissions audits for Christchurch and Dunedin businesses?
Exodesk runs Microsoft 365 permissions audits for businesses across Canterbury, Otago and Southland, working from offices in Christchurch and Dunedin. The work covers mapping site, mailbox and shared-drive access, listing sharing links and guest accounts, ranking the findings, and remediating what matters before a Copilot pilot. Exodesk has operated since 1989 and supports IT, cloud, cyber security and AI for New Zealand businesses. An audit is the usual starting point before any Copilot rollout.

