Skip to main content

Agent Access Insights Report

The Agent Access Insights report shows administrators how AI agents access content across SharePoint and OneDrive - which sites they touch, how often, and where they concentrate. Part of SharePoint Advanced Management and built on Microsoft 365 unified audit logs, it covers SharePoint-created agents, declarative agents, and custom agents alike. As organizations roll out Copilot and agents, it turns agent activity from invisible background noise into something you can see and govern.
Related
App Insights Report, SharePoint Agent Insights Report, SharePoint Agents, Site Permissions Across Your Organization

Common Use Cases

  • Copilot rollout governance: seeing where AI agents concentrate their reading before and after enabling Copilot
  • Finding exposed sites: spotting sites agents are reading that they should not be, and locking them down
  • Agent activity baselining: establishing what normal agent behavior looks like across the tenant
  • Investigating a specific site: pulling the top 20 agents touching a sensitive site
  • Distribution review: understanding how agent activity splits across SharePoint sites and OneDrive accounts
  • Applying protection in place: applying RAC or RCD policies directly from the report when a site needs restricting

Benefits

  • Visibility into AI access: turns invisible agent activity into a dashboard you can see and govern
  • Covers every agent type: SharePoint-created, declarative, and custom agents in one view
  • Act without leaving the report: apply Restricted access control and Restricted content discovery policies inline
  • Ranked by risk: the top sites by agent activity surface where to look first
  • Audit-log grounded: built on Microsoft 365 unified audit logs, with no extra instrumentation
  • Scales to the tenant: the downloadable report covers up to 1 million sites

Details

  • Feature Category: Search & AI

How It Works

  • Lives in the SharePoint Admin Center: from the Microsoft 365 App Launcher, go to Admin, open the SharePoint admin center, click Agent insights under Reports, then the Agent access tab
  • Create a report: give it a name and choose a duration; PowerShell equivalents exist for starting, viewing, and exporting reports
  • Built on unified audit logs: captures signals like agents reading, searching, and interacting with content
  • Admin only: only SharePoint administrators can create and view it; site owners and regular users have no access
  • Licensing: the tenant needs either the SharePoint Advanced Management add-on license or a Microsoft 365 Copilot license, which includes Advanced Management
  • Output: an on-screen dashboard of the top 100 sites with a top-20 agent view per site, plus a detailed download covering up to 1 million sites

Limits and Nuances

  • Fixed durations: 1, 7, 14, or 28 days, and audit data older than 28 days rolls off, so there is no deep history
  • One report per duration: 4 maximum; a new report for the same range overwrites the old one, so download before re-running, and re-runs are allowed every 24 hours
  • Created with a name and filters: name the report, then search and filter by site template and governance policies
  • Collection prerequisites: without a SAM license, data collection must be enabled first and reports arrive 24 hours later; collection pauses if no report is generated for 3 months
  • Act inline, then refresh: apply Restricted access control or Restricted content discovery directly from the report, but the policy status on an existing report does not refresh afterward, so generate a new report to confirm

Common Questions About the Agent Access Insights Report

What does the Agent Access Insights report show?

How AI agents access SharePoint and OneDrive content over a 1, 7, 14, or 28 day window: the sites with the most agent activity, the top 20 agents on each site, and how agents are distributed across SharePoint sites and OneDrive accounts. It covers SharePoint-created agents, declarative agents, and custom agents.

Where does the data come from?

Microsoft 365 unified audit logs, which capture signals like agents reading, searching, and interacting with content. Because it relies on audit data, the report may not include every event – treat it as a strong picture of agent behavior rather than a forensic record.

What license is required to run this report?

You need either the SharePoint Advanced Management add-on license or a Microsoft 365 Copilot license, which includes Advanced Management. Licensing packages change often, so check Microsoft’s official requirements before planning around it.

How far back does it go?

28 days at most – audit data older than that rolls off. Report durations are fixed at 1, 7, 14, or 28 days, you can keep one report per duration, and a new report for the same range overwrites the previous one, so download anything you want to keep.

Can I act on what I find?

Yes – Restricted access control (RAC) and Restricted content discovery (RCD) policies can be applied directly from the report. One nuance: the policy status shown on an existing report does not refresh after you apply a policy from it; generate a new report to confirm.

Why should I monitor agent access at all?

Agents inherit the access of the people and configurations behind them, and they read far more content, far faster, than any human. Knowing which sites agents concentrate on – and whether those sites are properly protected – is the new baseline of SharePoint governance as Copilot and agents roll out.