External Sharing Risk Scanner
To find oversharing in SharePoint before Copilot, start with what's shared outside the organisation. The External Sharing Risk Scanner, a free TechRam tool, lists every file shared outside your tenant, who shared it and whether the link still works. It deploys into your own Microsoft 365 in under 30 minutes and is yours to keep.
- Deploys in under 30 min
- Runs in your own tenant
The job it does
Lists every file shared outside your tenant, who shared it and whether the link still works.
What this does for your AI
Knowing what is reachable from outside is the first guardrail.
Where it leads
Where you want the full picture rather than one slice of it, this is the Environment Baseline engagement.
Deploys in under 30 min into your own Microsoft 365 tenant, on the licences you already hold. Nothing leaves your environment and there is nothing to buy.
How to read what it finds: Running the sharing scanner →
Common questions
01. What does the External Sharing Risk Scanner read, and what does it change?
It reads and reports. It does not revoke a link, change a permission or move a file. What to do about what it finds stays your decision, taken once you can see the list.
02. What permissions does the External Sharing Risk Scanner need?
Read access across the sites it reports on, which in practice means a global reader plus SharePoint administrator. Read-only is the whole point, so nothing it does requires write access.
03. Does it find links shared by people who have left?
Yes, and those are usually the ones worth acting on first. The report names who shared each link, so anything left behind by a departed account shows up against a name your directory no longer has.
04. Will running it show up in our audit log?
It will, and it looks like a process touching every site, which is exactly what monitoring exists to flag. Tell your IT provider before the first run.
05. Is the External Sharing Risk Scanner a trial for something paid?
No, and there is no paid version of the scanner. Where you want the sharing posture fixed rather than measured, that is an Environment Baseline engagement.
06. How do we find oversharing in SharePoint before rolling out Copilot?
Check both directions. Outside first: the External Sharing Risk Scanner lists every file shared beyond your tenant, who shared it and whether the link still works. Then inside, because Copilot can reach anything a person can open: the Permission Visualiser shows who can actually get into each site, and through which group, link or inherited permission. Both are free and run in your own tenant.