# SharePoint Advanced Management ships with Copilot: what it covers, and what it does not see

> A Microsoft 365 Copilot licence unlocks SharePoint Advanced Management. Here is honestly what SAM covers, and the four blind spots that remain.

Source: https://olyteck.com/blog/sharepoint-advanced-management-included-copilot-gaps
Published: 2026-08-19
Author: Oleg Garasym, Olyteck (France, EU-hosted)
Product: Olyteck Cyber
Topics: sharepoint, copilot, microsoft 365, governance, permissions, sam, onedrive, audit
License: free to quote with attribution to Olyteck and a link to the source URL.

---

Ever since Microsoft started including **SharePoint Advanced Management** with
every Microsoft 365 Copilot licence, one sentence keeps appearing in meetings:
*"we have Copilot, so governance is handled"*.

It is half true, and the true half is bigger than most vendors in this market
will admit. So let us say it first: **if your exposure sits entirely inside
SharePoint and you already hold Copilot licences, SAM covers most of what you
need.** This article is not for you, and nobody should be selling you anything
else.

The rest of the time, there are four blind spots worth knowing about before you
consider the subject closed.

## What SAM covers, and it is a lot

Per Microsoft's documentation, a Copilot licence unlocks among other things:

**Sprawl control**

- site ownership policy, inactive sites policy, site attestation policy, each
  available in simulation mode and then in active mode

**Oversharing control**

- sharing links reports
- **EEEU insights** ("Everyone Except External Users"), meaning content open to
  the whole organisation
- **Restricted Content Discovery**, to remove a site from Copilot and search
  discovery
- Restricted Access Control, block download policy
- permission state reports, site access review
- compare site policies, content management assessment
- enterprise app insights, SharePoint agent insights
- sensitivity labels, subject to an E5 or G5 licence

**Content lifecycle**

- catalog management, change history for site settings, recent admin actions

That is a serious toolset. Five years ago half of that list meant buying a
third-party product.

## Blind spot 1: SAM governs SharePoint, and only SharePoint

This is the structural limit, and it is in the name.

SAM does not cover **Teams and Teams channels**, does not cover **Power Platform**
(Power Automate, Power Apps), and largely leaves **OneDrive out** of the data
access governance reports.

In a 100 to 300 seat company, though, the finding that makes an executive
committee sit up is almost never in SharePoint alone. It is the OneDrive of
someone who left eighteen months ago, whose account is disabled but whose data is
still there, with sharing links they created that still resolve. It is an
ownerless Teams team, shared externally, that nobody can account for.

## Blind spot 2: Copilot Studio agents

SAM provides insights on **SharePoint agents**. It does not provide an inventory
of **Copilot Studio agents**, which can be created from several different surfaces
by any licensed user.

That is an awkward gap: the licence that gives you SAM is the same licence that
lets your users build agents, and governing those agents belongs to a different
product with its own price.

## Blind spot 3: the 100-site ceiling

**Data Access Governance** reports in the admin center cap at **100 sites**.
Beyond that you use the CSV export, which goes much higher but is no longer
reading a report, it is processing data.

For a 40-site tenant, irrelevant. For a tenant with ten years of history, several
hundred sites and subsites inherited from three reorganisations, you hit the
ceiling on day one. And that is exactly the tenant profile where oversharing is a
real problem.

## Blind spot 4: finding is not proving

This is the least discussed limit and the most expensive one.

SAM shows you a state. It does not do **automated remediation**, it does not tell
you the **week-over-week delta**, and it does not produce a **timestamped evidence
chain** showing that a problem was found, fixed, by whom and when.

An auditor does not ask for a screenshot of a report. They ask for proof that the
gap identified last quarter was closed. As one IT manager we work with puts it:

> Finding the problem is half the job. Proving it was fixed, with the date and the
> person, is what the auditor will ask you for.

One dated item belongs to the same family: **Restricted SharePoint Search is
retired on 31 January 2027**, replaced by Restricted Content Discovery, whose
logic is inverted (a block list instead of an allow list). Organisations that used
RSS as an emergency brake before a Copilot rollout have a migration with a date on
it, and a specific risk attached: content that was invisible becoming
discoverable again.

## So do you need anything else?

The honest table:

| Your situation | Our answer |
|---|---|
| Exposure entirely in SharePoint, Copilot licences already bought, under 100 sites | **SAM is enough.** Do not buy anything else |
| You do not have Copilot licences | Then you do not have SAM either. Different conversation |
| The scope includes OneDrive, leaver residue, Teams, OAuth apps or identity posture | SAM does not cover that ground |
| You have to **prove** a fix to an auditor or a parent company | This is where SAM stops |
| Several hundred sites | The admin center's 100-site ceiling will get in your way quickly |

## Where Olyteck sits

We do not claim to replace SAM inside SharePoint. We cover what SAM does not look
at, and we add the proof half.

Concretely, Olyteck Cyber is a **read-only** scanner, no agent, through Microsoft
Graph, **hosted in France** on Scaleway, revocable in one click. What it adds
next to SAM:

- **OneDrive of disabled accounts** still holding data
- **OAuth applications** and the permissions they were actually granted
- **MFA and Conditional Access posture**
- **Teams and Microsoft 365 Groups hygiene**, including ownerless teams
- **one person's real access** across all of that in a single view, with the
  coverage line stated: *"858 of 868 accounts analysed"*
- **the week-over-week delta** and a timestamped, exportable audit trail

First report in **2 minutes**, measured on a 200-employee tenant with 170
SharePoint sites. On a 400-employee tenant with 1,200 sites and no governance
history, the full deep scan runs for hours in the background. We would rather
publish both numbers than only the flattering one.

What we do not do, and will not claim: we do not read the contents of your files,
so we do not classify data; we do not audit Purview sensitivity labels; we do no
threat detection and no Copilot forensics; and we do not inventory your Copilot
Studio agents. We show what an agent could reach, because that is the same
permissions question.

We do not need to read your files to tell you who can read them.

## FAQ

### Is SharePoint Advanced Management really included with Copilot?

Yes, a Microsoft 365 Copilot licence unlocks most SAM capabilities. One known
exception: restricting site creation by apps still requires the SharePoint
Advanced Management Plan 1 add-on.

### Do I need E5 to audit Microsoft 365 permissions?

Mostly no. SAM's access governance reports arrive with the Copilot licence, and a
read-only third-party scanner works on E3. Sensitivity labels, on the other hand,
do require E5 or G5.

### Does SAM cover OneDrive?

Partially, and not in the data access governance reports, where OneDrive is
largely left out. Worth checking early, because leaver residue lives precisely
there.

### What happens when Restricted SharePoint Search retires?

RSS is retired on 31 January 2027 and replaced by Restricted Content Discovery,
which works as a block list rather than an allow list. If you used RSS to limit
what Copilot could index, plan the migration: without it, previously invisible
content becomes discoverable again.

### Does Restricted Content Discovery block access to a site?

No. RCD affects **discoverability**, not permissions. A user who knows the URL and
holds the rights still gets in. Useful, but not an access control.

## Sources

- Microsoft Learn, *SharePoint Advanced Management features included with
  Microsoft 365 Copilot licenses*, and *SharePoint Advanced Management
  prerequisites*
- Microsoft Learn, *Restricted Content Discovery*

*Reflects Microsoft documentation as of 19 August 2026. SAM's scope moves quickly:
check the Microsoft Learn page before relying on any of these limits in a
purchasing decision.*

## Read next

- [Microsoft 365 Copilot readiness: the permissions checklist to run first](/blog/microsoft-365-copilot-readiness-permissions-checklist)
- [How to find "anyone-with-the-link" sharing in Microsoft 365](/blog/find-anonymous-sharing-links-microsoft-365)
- [AI agents in Microsoft 365: the new attack surface to audit](/blog/ai-agents-microsoft-365-security)

