SharePoint Advanced Management ships with Copilot: what it covers, and what it does not see
Key takeaways
- A Microsoft 365 Copilot licence unlocks SharePoint Advanced Management, and that already covers a lot - sharing links reports, EEEU insights, Restricted Content Discovery, site access review, inactive site policies.
- SAM governs SharePoint. It does not cover Teams, Power Platform or Copilot Studio agents, and it largely leaves OneDrive out of the data access governance reports.
- Data Access Governance reports in the admin center cap at 100 sites; beyond that you are exporting CSV, which is data processing rather than reading a report.
- SAM does not do automated remediation and does not tell the week-over-week delta story, which is what an auditor actually asks for.
- If your exposure is entirely inside SharePoint and you already have Copilot, SAM is probably enough. That should be said out loud before anyone sells you anything else.
Ever since Microsoft started including SharePoint Advanced Management with every Microsoft 365 Copilot licence, one sentence keeps appearing in meetings: "we have Copilot, so governance is handled".
It is half true, and the true half is bigger than most vendors in this market will admit. So let us say it first: if your exposure sits entirely inside SharePoint and you already hold Copilot licences, SAM covers most of what you need. This article is not for you, and nobody should be selling you anything else.
The rest of the time, there are four blind spots worth knowing about before you consider the subject closed.
What SAM covers, and it is a lot #
Per Microsoft's documentation, a Copilot licence unlocks among other things:
Sprawl control
- site ownership policy, inactive sites policy, site attestation policy, each
available in simulation mode and then in active mode
Oversharing control
- sharing links reports
- EEEU insights ("Everyone Except External Users"), meaning content open to
the whole organisation
- Restricted Content Discovery, to remove a site from Copilot and search
discovery
- Restricted Access Control, block download policy
- permission state reports, site access review
- compare site policies, content management assessment
- enterprise app insights, SharePoint agent insights
- sensitivity labels, subject to an E5 or G5 licence
Content lifecycle
- catalog management, change history for site settings, recent admin actions
That is a serious toolset. Five years ago half of that list meant buying a third-party product.
Blind spot 1: SAM governs SharePoint, and only SharePoint #
This is the structural limit, and it is in the name.
SAM does not cover Teams and Teams channels, does not cover Power Platform (Power Automate, Power Apps), and largely leaves OneDrive out of the data access governance reports.
In a 100 to 300 seat company, though, the finding that makes an executive committee sit up is almost never in SharePoint alone. It is the OneDrive of someone who left eighteen months ago, whose account is disabled but whose data is still there, with sharing links they created that still resolve. It is an ownerless Teams team, shared externally, that nobody can account for.
Blind spot 2: Copilot Studio agents #
SAM provides insights on SharePoint agents. It does not provide an inventory of Copilot Studio agents, which can be created from several different surfaces by any licensed user.
That is an awkward gap: the licence that gives you SAM is the same licence that lets your users build agents, and governing those agents belongs to a different product with its own price.
Blind spot 3: the 100-site ceiling #
Data Access Governance reports in the admin center cap at 100 sites. Beyond that you use the CSV export, which goes much higher but is no longer reading a report, it is processing data.
For a 40-site tenant, irrelevant. For a tenant with ten years of history, several hundred sites and subsites inherited from three reorganisations, you hit the ceiling on day one. And that is exactly the tenant profile where oversharing is a real problem.
Blind spot 4: finding is not proving #
This is the least discussed limit and the most expensive one.
SAM shows you a state. It does not do automated remediation, it does not tell you the week-over-week delta, and it does not produce a timestamped evidence chain showing that a problem was found, fixed, by whom and when.
An auditor does not ask for a screenshot of a report. They ask for proof that the gap identified last quarter was closed. As one IT manager we work with puts it:
Finding the problem is half the job. Proving it was fixed, with the date and the person, is what the auditor will ask you for.
One dated item belongs to the same family: Restricted SharePoint Search is retired on 31 January 2027, replaced by Restricted Content Discovery, whose logic is inverted (a block list instead of an allow list). Organisations that used RSS as an emergency brake before a Copilot rollout have a migration with a date on it, and a specific risk attached: content that was invisible becoming discoverable again.
So do you need anything else? #
The honest table:
| Your situation | Our answer |
|---|---|
| Exposure entirely in SharePoint, Copilot licences already bought, under 100 sites | SAM is enough. Do not buy anything else |
| You do not have Copilot licences | Then you do not have SAM either. Different conversation |
| The scope includes OneDrive, leaver residue, Teams, OAuth apps or identity posture | SAM does not cover that ground |
| You have to prove a fix to an auditor or a parent company | This is where SAM stops |
| Several hundred sites | The admin center's 100-site ceiling will get in your way quickly |
Where Olyteck sits #
We do not claim to replace SAM inside SharePoint. We cover what SAM does not look at, and we add the proof half.
Concretely, Olyteck Cyber is a read-only scanner, no agent, through Microsoft Graph, hosted in France on Scaleway, revocable in one click. What it adds next to SAM:
- OneDrive of disabled accounts still holding data
- OAuth applications and the permissions they were actually granted
- MFA and Conditional Access posture
- Teams and Microsoft 365 Groups hygiene, including ownerless teams
- one person's real access across all of that in a single view, with the
coverage line stated: "858 of 868 accounts analysed"
- the week-over-week delta and a timestamped, exportable audit trail
First report in 2 minutes, measured on a 200-employee tenant with 170 SharePoint sites. On a 400-employee tenant with 1,200 sites and no governance history, the full deep scan runs for hours in the background. We would rather publish both numbers than only the flattering one.
What we do not do, and will not claim: we do not read the contents of your files, so we do not classify data; we do not audit Purview sensitivity labels; we do no threat detection and no Copilot forensics; and we do not inventory your Copilot Studio agents. We show what an agent could reach, because that is the same permissions question.
We do not need to read your files to tell you who can read them.
FAQ #
Is SharePoint Advanced Management really included with Copilot? #
Yes, a Microsoft 365 Copilot licence unlocks most SAM capabilities. One known exception: restricting site creation by apps still requires the SharePoint Advanced Management Plan 1 add-on.
Do I need E5 to audit Microsoft 365 permissions? #
Mostly no. SAM's access governance reports arrive with the Copilot licence, and a read-only third-party scanner works on E3. Sensitivity labels, on the other hand, do require E5 or G5.
Does SAM cover OneDrive? #
Partially, and not in the data access governance reports, where OneDrive is largely left out. Worth checking early, because leaver residue lives precisely there.
What happens when Restricted SharePoint Search retires? #
RSS is retired on 31 January 2027 and replaced by Restricted Content Discovery, which works as a block list rather than an allow list. If you used RSS to limit what Copilot could index, plan the migration: without it, previously invisible content becomes discoverable again.
Does Restricted Content Discovery block access to a site? #
No. RCD affects discoverability, not permissions. A user who knows the URL and holds the rights still gets in. Useful, but not an access control.
Sources #
- Microsoft Learn, *SharePoint Advanced Management features included with
Microsoft 365 Copilot licenses, and SharePoint Advanced Management prerequisites*
- Microsoft Learn, Restricted Content Discovery
Reflects Microsoft documentation as of 19 August 2026. SAM's scope moves quickly: check the Microsoft Learn page before relying on any of these limits in a purchasing decision.
Read next #
- Microsoft 365 Copilot readiness: the permissions checklist to run first
- How to find "anyone-with-the-link" sharing in Microsoft 365
- AI agents in Microsoft 365: the new attack surface to audit
One useful Microsoft 365 email a month
New guides, findings from real tenants, and the occasional checklist. No sales sequence, unsubscribe in one click.