---
title: Sites
description: See every place your data actually lives - every SharePoint site, Teams site, and personal OneDrive - and find the ones that are abandoned, wide open, or feeding your AI.
icon: Globe
---

# Sites

The Sites screen answers a question most organizations can't: **"Where does our data actually live - and which of those places are wide open?"** Every Team spawns a site. Every private channel spawns another. Every employee carries a personal OneDrive. Most tenants hold several times more sites than IT believes they have - and the ones nobody remembers are exactly the ones nobody is watching.

## What You Can Achieve

<Cards>
  <Card
    title="Inventory the estate you actually have"
    description="Every SharePoint site, subsite, and hub, every Teams-connected site including private and shared channel sites, and every personal OneDrive - with owners, members, file counts, and storage in one list."
  />
  <Card
    title="Find abandoned sites before attackers do"
    description="Sites with no owners, no users, or no activity for a year still hold data and permissions. They're unwatched attack surface - and stale food for Copilot answers."
  />
  <Card
    title="Measure external exposure per site"
    description="Instead of auditing files one by one, rank whole sites by external users, sharing links, and anonymous access - and start where the blast radius is biggest."
  />
  <Card
    title="Prepare sites for AI, deliberately"
    description="See which sites are Copilot-enabled and cross that with their sensitive info concentration - so you decide what AI reads instead of discovering it in a generated answer."
  />
</Cards>

## The Site Types That Matter

1Security distinguishes the site flavors Microsoft blurs together, because each carries a different governance story:

- **Sites, subsites, and hub sites** - classic SharePoint structure.
- **Teams-connected sites** - created implicitly whenever someone creates a Team; broken out further into standard, **private**, and **shared** channel sites, each with its own membership rules.
- **Personal sites** - every user's OneDrive. Corporate data in the thousands of "sites" nobody governs.

Access is split into **direct** users and **indirect** users (via groups) - so you can see not just how many people can enter a site, but through which doors.

## The Site List

Each row summarizes a site's footprint and risk: members, owners, direct vs. indirect access, external users, groups with access, sharing links, Teams channels (including private and shared), drives, lists, subsites, storage size, sensitivity labels and detected sensitive info, whether **Copilot is enabled**, and an activity sparkline. Click a site to open its drawer and drill into its files, users, and activity.

The filter drawer narrows by site type, external exposure, **orphaned indicators** (no activity in the last year, no users, no owners), blocked status, scan coverage, the full sharing-link toolkit (scope, type, passwords, expiration), sensitive info presence, and the sites a specific user can access.

Select sites and choose **Run actions** to trigger automation workflows on them.

## Investigative Patterns

<Callout type="info">
  **The forgotten-but-open pattern**: filter **no activity in the last year** +
  **external users**. Nobody inside touches these sites - but someone outside
  still can. This list is usually short, shocking, and immediately actionable.
</Callout>

- **Pre-Copilot cleanup** - **Copilot enabled** + **with sensitive info**, sorted by sensitive detections: the sites to label, restrict, or exclude before AI answers start quoting them.
- **Anonymous doors** - sites with **anyone** sharing links + sensitive info: whole containers reachable by URL alone.
- **Ownerless data** - **no owners**: nobody approves membership or reviews access for these sites. Assign owners or archive them.
