All articles

Which SharePoint Sites Are Your AI Agents Accessing?

Updated 2 min read

Knowing that agents exist is one thing. Knowing where they are actually touching your Microsoft 365 content is much more useful.

Microsoft's July 2026 Copilot update introduced Agent Access Insights for SharePoint and OneDrive, giving administrators a visual way to identify locations with agent activity. I would treat this as an investigation tool, not a red warning light that automatically means something is wrong.

Start with the busiest locations

A heatmap is useful because it helps you decide where to look first. Pick a small number of locations with meaningful agent activity and record the site or OneDrive owner, business purpose, expected audience and the agents you expect to use the content.

Do not start by trying to review the entire tenant in one afternoon. The point of the signal is prioritization.

A project site with an approved agent and a known audience may be exactly what you expect. A forgotten site with broad permissions and unexpected agent activity deserves a different conversation.

Activity is not the same as inappropriate access

This distinction is important. A report showing that an agent accessed a site does not prove that the agent obtained information the user was not entitled to see. Microsoft 365 permissions and the design of the specific agent still matter.

Use the insight to ask better questions: Who owns this site? Are visitors and members still correct? Are old sharing links still needed? Does the agent's intended scope match the content actually stored there?

If the problem is broad access, fix the permissions problem. Do not treat hiding the site from an AI experience as a substitute for proper information architecture.

Review a site with a repeatable checklist

For each selected site, I would check:

  • business owner and last meaningful use;
  • owners, members, visitors and external guests;
  • sharing links and broad groups;
  • sensitivity or business classification;
  • whether the connected agent is expected;
  • a sample of content that appears unusually sensitive for the stated purpose.

Record the action as no change, clean up permissions, remove stale content, investigate the agent, or retire the site. That turns a visual report into something operational.

Combine the signal with existing governance work

This fits naturally with SharePoint Advanced Management and DSPM data assessments. Each tool answers a slightly different question.

One can help you find broad or risky access, another can highlight sensitive information, and Agent Access Insights can show where agent activity is happening. The value comes from combining the signals into a review process instead of collecting three dashboards.

Do not forget OneDrive

Personal storage often contains working copies, exports and documents that never made it into a governed team location. If the report includes meaningful OneDrive activity, decide how you want to handle business-critical information living in personal storage.

The answer is not necessarily to move everything. It is to know which content matters and whether the current ownership model makes sense.

Final thoughts

Agent Access Insights is most useful as a queue: it tells you where to look. Start with the locations that combine high activity, sensitive data or unclear ownership, and turn the findings into ordinary SharePoint governance actions.

Share LinkedInX / Twitter

Comments

No account needed. Your name is optional — leave it blank to post anonymously.

0/4000

Loading comments…

Keep reading