Cyber

SharePoint Advanced Management ships with Copilot: what it covers, and what it does not see

Key takeaways

  • A Microsoft 365 Copilot licence unlocks SharePoint Advanced Management, and that already covers a lot - sharing links reports, EEEU insights, Restricted Content Discovery, site access review, inactive site policies.
  • SAM governs SharePoint. It does not cover Teams, Power Platform or Copilot Studio agents, and it largely leaves OneDrive out of the data access governance reports.
  • Data Access Governance reports in the admin center cap at 100 sites; beyond that you are exporting CSV, which is data processing rather than reading a report.
  • SAM does not do automated remediation and does not tell the week-over-week delta story, which is what an auditor actually asks for.
  • If your exposure is entirely inside SharePoint and you already have Copilot, SAM is probably enough. That should be said out loud before anyone sells you anything else.

Ever since Microsoft started including SharePoint Advanced Management with every Microsoft 365 Copilot licence, one sentence keeps appearing in meetings: "we have Copilot, so governance is handled".

It is half true, and the true half is bigger than most vendors in this market will admit. So let us say it first: if your exposure sits entirely inside SharePoint and you already hold Copilot licences, SAM covers most of what you need. This article is not for you, and nobody should be selling you anything else.

The rest of the time, there are four blind spots worth knowing about before you consider the subject closed.

What SAM covers, and it is a lot #

Per Microsoft's documentation, a Copilot licence unlocks among other things:

Sprawl control

  • site ownership policy, inactive sites policy, site attestation policy, each

available in simulation mode and then in active mode

Oversharing control

  • sharing links reports
  • EEEU insights ("Everyone Except External Users"), meaning content open to

the whole organisation

  • Restricted Content Discovery, to remove a site from Copilot and search

discovery

  • Restricted Access Control, block download policy
  • permission state reports, site access review
  • compare site policies, content management assessment
  • enterprise app insights, SharePoint agent insights
  • sensitivity labels, subject to an E5 or G5 licence

Content lifecycle

  • catalog management, change history for site settings, recent admin actions

That is a serious toolset. Five years ago half of that list meant buying a third-party product.

Blind spot 1: SAM governs SharePoint, and only SharePoint #

This is the structural limit, and it is in the name.

SAM does not cover Teams and Teams channels, does not cover Power Platform (Power Automate, Power Apps), and largely leaves OneDrive out of the data access governance reports.

In a 100 to 300 seat company, though, the finding that makes an executive committee sit up is almost never in SharePoint alone. It is the OneDrive of someone who left eighteen months ago, whose account is disabled but whose data is still there, with sharing links they created that still resolve. It is an ownerless Teams team, shared externally, that nobody can account for.

Blind spot 2: Copilot Studio agents #

SAM provides insights on SharePoint agents. It does not provide an inventory of Copilot Studio agents, which can be created from several different surfaces by any licensed user.

That is an awkward gap: the licence that gives you SAM is the same licence that lets your users build agents, and governing those agents belongs to a different product with its own price.

Blind spot 3: the 100-site ceiling #

Data Access Governance reports in the admin center cap at 100 sites. Beyond that you use the CSV export, which goes much higher but is no longer reading a report, it is processing data.

For a 40-site tenant, irrelevant. For a tenant with ten years of history, several hundred sites and subsites inherited from three reorganisations, you hit the ceiling on day one. And that is exactly the tenant profile where oversharing is a real problem.

Blind spot 4: finding is not proving #

This is the least discussed limit and the most expensive one.

SAM shows you a state. It does not do automated remediation, it does not tell you the week-over-week delta, and it does not produce a timestamped evidence chain showing that a problem was found, fixed, by whom and when.

An auditor does not ask for a screenshot of a report. They ask for proof that the gap identified last quarter was closed. As one IT manager we work with puts it:

Finding the problem is half the job. Proving it was fixed, with the date and the person, is what the auditor will ask you for.

One dated item belongs to the same family: Restricted SharePoint Search is retired on 31 January 2027, replaced by Restricted Content Discovery, whose logic is inverted (a block list instead of an allow list). Organisations that used RSS as an emergency brake before a Copilot rollout have a migration with a date on it, and a specific risk attached: content that was invisible becoming discoverable again.

So do you need anything else? #

The honest table:

Your situationOur answer
Exposure entirely in SharePoint, Copilot licences already bought, under 100 sitesSAM is enough. Do not buy anything else
You do not have Copilot licencesThen you do not have SAM either. Different conversation
The scope includes OneDrive, leaver residue, Teams, OAuth apps or identity postureSAM does not cover that ground
You have to prove a fix to an auditor or a parent companyThis is where SAM stops
Several hundred sitesThe admin center's 100-site ceiling will get in your way quickly

Where Olyteck sits #

We do not claim to replace SAM inside SharePoint. We cover what SAM does not look at, and we add the proof half.

Concretely, Olyteck Cyber is a read-only scanner, no agent, through Microsoft Graph, hosted in France on Scaleway, revocable in one click. What it adds next to SAM:

  • OneDrive of disabled accounts still holding data
  • OAuth applications and the permissions they were actually granted
  • MFA and Conditional Access posture
  • Teams and Microsoft 365 Groups hygiene, including ownerless teams
  • one person's real access across all of that in a single view, with the

coverage line stated: "858 of 868 accounts analysed"

  • the week-over-week delta and a timestamped, exportable audit trail

First report in 2 minutes, measured on a 200-employee tenant with 170 SharePoint sites. On a 400-employee tenant with 1,200 sites and no governance history, the full deep scan runs for hours in the background. We would rather publish both numbers than only the flattering one.

What we do not do, and will not claim: we do not read the contents of your files, so we do not classify data; we do not audit Purview sensitivity labels; we do no threat detection and no Copilot forensics; and we do not inventory your Copilot Studio agents. We show what an agent could reach, because that is the same permissions question.

We do not need to read your files to tell you who can read them.

FAQ #

Is SharePoint Advanced Management really included with Copilot? #

Yes, a Microsoft 365 Copilot licence unlocks most SAM capabilities. One known exception: restricting site creation by apps still requires the SharePoint Advanced Management Plan 1 add-on.

Do I need E5 to audit Microsoft 365 permissions? #

Mostly no. SAM's access governance reports arrive with the Copilot licence, and a read-only third-party scanner works on E3. Sensitivity labels, on the other hand, do require E5 or G5.

Does SAM cover OneDrive? #

Partially, and not in the data access governance reports, where OneDrive is largely left out. Worth checking early, because leaver residue lives precisely there.

What happens when Restricted SharePoint Search retires? #

RSS is retired on 31 January 2027 and replaced by Restricted Content Discovery, which works as a block list rather than an allow list. If you used RSS to limit what Copilot could index, plan the migration: without it, previously invisible content becomes discoverable again.

Does Restricted Content Discovery block access to a site? #

No. RCD affects discoverability, not permissions. A user who knows the URL and holds the rights still gets in. Useful, but not an access control.

Sources #

  • Microsoft Learn, *SharePoint Advanced Management features included with

Microsoft 365 Copilot licenses, and SharePoint Advanced Management prerequisites*

  • Microsoft Learn, Restricted Content Discovery

Reflects Microsoft documentation as of 19 August 2026. SAM's scope moves quickly: check the Microsoft Learn page before relying on any of these limits in a purchasing decision.

OG
Written by Oleg Garasym
Founder, Olyteck - Microsoft 365 security and AI, Nantes, France

One useful Microsoft 365 email a month

New guides, findings from real tenants, and the occasional checklist. No sales sequence, unsubscribe in one click.

See it on your own Microsoft 365

A 20-minute call, or start free in your browser. EU-hosted, GDPR-aligned, no credit card.