Oversharing
A file does not have to be stolen to leak. It only needs a sharing link that reaches further than anyone intended: an "Anyone" link forwarded past its first recipient, a folder shared with the whole organization instead of one team, or a guest account that kept its access long after the project it was invited for ended.
Oversharing scans SharePoint, OneDrive and Teams for exactly this class of exposure and reports every file or folder that is shared more broadly than it should be, so you can narrow access before it becomes an incident instead of after.
Requires a paid plan
Oversharing is included with paid plans. Without a paid plan the page shows an upgrade prompt instead of results. See the plans page for what each plan includes.
What it checks
Oversharing evaluates every sharing permission it can read against five risk categories and raises one finding per affected file or folder (or once tenant-wide, for the sharing default). Each flagged item appears in the inventory with the group it belongs to and its risk level.
Anonymous "Anyone" links
OVERSHARE.ANYONE_LINK (Critical). The item is shared through an anonymous link: anyone who has the URL can open it, no sign-in required. This is the broadest exposure a file can have.
Remediation. Remove the link, or replace it with one scoped to specific people, from the SharePoint admin center or the item's Share panel.
Organization-wide links
OVERSHARE.ORG_LINK (High). The item is shared with everyone in the tenant through an organization-wide link. Sometimes deliberate for genuinely tenant-wide content, but it is easy to create by accident when a narrower audience was intended.
Remediation. Confirm the content is really meant for the whole organization. If not, replace the link with one scoped to specific people or a smaller group.
External guest access
OVERSHARE.EXTERNAL_GUEST (High). The item is shared directly with an external guest account.
Remediation. Confirm the external collaboration is still active. Remove the grant once the external party no longer needs access.
Link expiration
OVERSHARE.GUEST_NO_EXPIRY (Medium). A sharing link on the item has no expiration date, so access never lapses on its own.
Remediation. Set an expiration date on the link, either per-link or through a tenant-wide default expiration policy, in the SharePoint admin center, so stale access is revoked automatically.
Tenant sharing default
OVERSHARE.TENANT_ANYONE_DEFAULT (High). The tenant's default sharing setting permits anonymous "Anyone" links tenant-wide, so every new share starts from the broadest possible option unless someone narrows it.
Remediation. Tighten the default in the SharePoint admin center (Policies > Sharing) to "New and existing guests" or stricter, unless anonymous sharing is a deliberate business requirement.
Consent and coverage
Oversharing today fully covers Team-connected document libraries: the SharePoint drives behind your Microsoft 365 Groups (Teams), plus your tenant's default sharing settings. That coverage does not require any consent beyond the standard tenant connection.
Inspecting sharing on every SharePoint site, including ones not connected to a Team, needs the Sites.Read.All Microsoft Graph permission. Most tenants have not granted it as part of the initial connection, and the scan cannot request it silently.
While that permission is missing, the scan raises OVERSHARE.CONSENT.REQUIRED (Medium) instead of claiming a clean result it cannot back up, and continues to report everything it can see in the Team-connected slice. To close the gap, re-run admin consent from the Connect page; once Sites.Read.All is granted, the next scan picks up every SharePoint site automatically.
Running a scan
Open Oversharing in the dashboard and select Run scan. Results appear on the same page with a severity summary, so you can see at a glance how many Critical, High and Medium findings need attention before drilling into the list.