External Sharing Risk Scanner

To find oversharing in SharePoint before Copilot, start with what's shared outside the organisation. The External Sharing Risk Scanner, a free TechRam tool, lists every file shared outside your tenant, who shared it and whether the link still works. It deploys into your own Microsoft 365 in under 30 minutes and is yours to keep.

  • Deploys in under 30 min
  • Runs in your own tenant

The job it does

Lists every file shared outside your tenant, who shared it and whether the link still works.

What this does for your AI

Knowing what is reachable from outside is the first guardrail.

Where it leads

Where you want the full picture rather than one slice of it, this is the Environment Baseline engagement.

Deploys in under 30 min into your own Microsoft 365 tenant, on the licences you already hold. Nothing leaves your environment and there is nothing to buy.

Get External Sharing Risk Scanner

Tell us where to send it and we'll get you access. No trial, no licence, and it deploys into your own tenant.

How to read what it finds: Running the sharing scanner →

Common questions

01. What does the External Sharing Risk Scanner read, and what does it change?

It reads and reports. It does not revoke a link, change a permission or move a file. What to do about what it finds stays your decision, taken once you can see the list.

02. What permissions does the External Sharing Risk Scanner need?

Read access across the sites it reports on, which in practice means a global reader plus SharePoint administrator. Read-only is the whole point, so nothing it does requires write access.

03. Does it find links shared by people who have left?

Yes, and those are usually the ones worth acting on first. The report names who shared each link, so anything left behind by a departed account shows up against a name your directory no longer has.

04. Will running it show up in our audit log?

It will, and it looks like a process touching every site, which is exactly what monitoring exists to flag. Tell your IT provider before the first run.

05. Is the External Sharing Risk Scanner a trial for something paid?

No, and there is no paid version of the scanner. Where you want the sharing posture fixed rather than measured, that is an Environment Baseline engagement.

06. How do we find oversharing in SharePoint before rolling out Copilot?

Check both directions. Outside first: the External Sharing Risk Scanner lists every file shared beyond your tenant, who shared it and whether the link still works. Then inside, because Copilot can reach anything a person can open: the Permission Visualiser shows who can actually get into each site, and through which group, link or inherited permission. Both are free and run in your own tenant.

External Sharing Risk Scanner does one thing. Environment Baseline is the rest of it.

Run it. If what it shows you is bigger than one tool can fix, that is a Environment Baseline conversation — scoped against what you actually found rather than against a template.

See Environment Baseline →