Find external exposure
Identify guest users, Anyone links, organization links, and specific-people links in the review scope.
Protect helps administrators find SharePoint access paths that could expose content through Microsoft 365 experiences, including old guests, broad groups, sharing links, and custom permissions.
A permission review is not a review of prompts or responses. It is the practical work of understanding who can reach the underlying SharePoint content, why that access exists, and whether it still belongs before broader AI adoption.
Identify guest users, Anyone links, organization links, and specific-people links in the review scope.
Understand group-based access together with its level, content location, and permission source.
Separate inherited permission paths from unique boundaries that require an explicit decision.
Use Protect Pro to change or remove selected excess access under the administrator's existing rights.
Choose the workspaces and sensitive content that matter for the planned Copilot rollout.
Filter for guests, links, broad groups, custom permissions, and ownerless workspaces.
Confirm the business reason, responsible owner, access level, and exact content location.
Correct access and retain exportable evidence of the review for governance stakeholders.
Microsoft 365 experiences use the access available to the signed-in person. Protect focuses on reviewing and correcting that underlying SharePoint permission layer.
No. Protect reviews Microsoft 365 workspace and SharePoint permission information, not Copilot prompts or generated responses.
Common priorities include external guests, broad groups, Anyone and organization links, custom permission boundaries, stale workspaces, and missing owners.