Sites
See every place your data actually lives - every SharePoint site, Teams site, and personal OneDrive - and find the ones that are abandoned, wide open, or feeding your AI.
Sites
The Sites screen answers a question most organizations can't: "Where does our data actually live - and which of those places are wide open?" Every Team spawns a site. Every private channel spawns another. Every employee carries a personal OneDrive. Most tenants hold several times more sites than IT believes they have - and the ones nobody remembers are exactly the ones nobody is watching.
What You Can Achieve
Inventory the estate you actually have
Every SharePoint site, subsite, and hub, every Teams-connected site including private and shared channel sites, and every personal OneDrive - with owners, members, file counts, and storage in one list.
Find abandoned sites before attackers do
Sites with no owners, no users, or no activity for a year still hold data and permissions. They're unwatched attack surface - and stale food for Copilot answers.
Measure external exposure per site
Instead of auditing files one by one, rank whole sites by external users, sharing links, and anonymous access - and start where the blast radius is biggest.
Prepare sites for AI, deliberately
See which sites are Copilot-enabled and cross that with their sensitive info concentration - so you decide what AI reads instead of discovering it in a generated answer.
The Site Types That Matter
1Security distinguishes the site flavors Microsoft blurs together, because each carries a different governance story:
- Sites, subsites, and hub sites - classic SharePoint structure.
- Teams-connected sites - created implicitly whenever someone creates a Team; broken out further into standard, private, and shared channel sites, each with its own membership rules.
- Personal sites - every user's OneDrive. Corporate data in the thousands of "sites" nobody governs.
Access is split into direct users and indirect users (via groups) - so you can see not just how many people can enter a site, but through which doors.
The Site List
Each row summarizes a site's footprint and risk: members, owners, direct vs. indirect access, external users, groups with access, sharing links, Teams channels (including private and shared), drives, lists, subsites, storage size, sensitivity labels and detected sensitive info, whether Copilot is enabled, and an activity sparkline. Click a site to open its drawer and drill into its files, users, and activity.
The filter drawer narrows by site type, external exposure, orphaned indicators (no activity in the last year, no users, no owners), blocked status, scan coverage, the full sharing-link toolkit (scope, type, passwords, expiration), sensitive info presence, and the sites a specific user can access.
Select sites and choose Run actions to trigger automation workflows on them.
Investigative Patterns
The forgotten-but-open pattern: filter no activity in the last year + external users. Nobody inside touches these sites - but someone outside still can. This list is usually short, shocking, and immediately actionable.
- Pre-Copilot cleanup - Copilot enabled + with sensitive info, sorted by sensitive detections: the sites to label, restrict, or exclude before AI answers start quoting them.
- Anonymous doors - sites with anyone sharing links + sensitive info: whole containers reachable by URL alone.
- Ownerless data - no owners: nobody approves membership or reviews access for these sites. Assign owners or archive them.
Files
Answer the question every access review stalls on - who has access to our files, and why - for every user, link, app, and AI agent across Microsoft 365.
Groups
See what membership in any group actually unlocks - nested members, hidden external users, and the files and sites a single group grants access to.