1Security
Screens

Sites

See every place your data actually lives - every SharePoint site, Teams site, and personal OneDrive - and find the ones that are abandoned, wide open, or feeding your AI.

Sites

The Sites screen answers a question most organizations can't: "Where does our data actually live - and which of those places are wide open?" Every Team spawns a site. Every private channel spawns another. Every employee carries a personal OneDrive. Most tenants hold several times more sites than IT believes they have - and the ones nobody remembers are exactly the ones nobody is watching.

What You Can Achieve

Inventory the estate you actually have

Every SharePoint site, subsite, and hub, every Teams-connected site including private and shared channel sites, and every personal OneDrive - with owners, members, file counts, and storage in one list.

Find abandoned sites before attackers do

Sites with no owners, no users, or no activity for a year still hold data and permissions. They're unwatched attack surface - and stale food for Copilot answers.

Measure external exposure per site

Instead of auditing files one by one, rank whole sites by external users, sharing links, and anonymous access - and start where the blast radius is biggest.

Prepare sites for AI, deliberately

See which sites are Copilot-enabled and cross that with their sensitive info concentration - so you decide what AI reads instead of discovering it in a generated answer.

The Site Types That Matter

1Security distinguishes the site flavors Microsoft blurs together, because each carries a different governance story:

  • Sites, subsites, and hub sites - classic SharePoint structure.
  • Teams-connected sites - created implicitly whenever someone creates a Team; broken out further into standard, private, and shared channel sites, each with its own membership rules.
  • Personal sites - every user's OneDrive. Corporate data in the thousands of "sites" nobody governs.

Access is split into direct users and indirect users (via groups) - so you can see not just how many people can enter a site, but through which doors.

The Site List

Each row summarizes a site's footprint and risk: members, owners, direct vs. indirect access, external users, groups with access, sharing links, Teams channels (including private and shared), drives, lists, subsites, storage size, sensitivity labels and detected sensitive info, whether Copilot is enabled, and an activity sparkline. Click a site to open its drawer and drill into its files, users, and activity.

The filter drawer narrows by site type, external exposure, orphaned indicators (no activity in the last year, no users, no owners), blocked status, scan coverage, the full sharing-link toolkit (scope, type, passwords, expiration), sensitive info presence, and the sites a specific user can access.

Select sites and choose Run actions to trigger automation workflows on them.

Investigative Patterns

The forgotten-but-open pattern: filter no activity in the last year + external users. Nobody inside touches these sites - but someone outside still can. This list is usually short, shocking, and immediately actionable.

  • Pre-Copilot cleanup - Copilot enabled + with sensitive info, sorted by sensitive detections: the sites to label, restrict, or exclude before AI answers start quoting them.
  • Anonymous doors - sites with anyone sharing links + sensitive info: whole containers reachable by URL alone.
  • Ownerless data - no owners: nobody approves membership or reviews access for these sites. Assign owners or archive them.

On this page