Skip to main content

Data Access Governance (DAG) Reports

Data Access Governance reports, part of SharePoint Advanced Management, help administrators find the sites most likely to be oversharing before that content reaches Copilot or organization-wide search. The reports surface risk patterns: sites shared through anyone links, content opened to Everyone Except External Users, and sites holding potentially sensitive information. Instead of auditing thousands of sites by hand, an admin gets a ranked picture of where to look first, and newer AI insights suggest next steps. In a Copilot world, this is how you spot problems before users do.
Related
Copilot in SharePoint, Restricted Content Discovery (RCD), Restricted SharePoint Search, SharePoint Admin Agent, SharePoint Advanced Management (SAM), Site Permissions Across Your Organization

Common Use Cases

  • Copilot readiness: finding oversharing before AI surfaces it
  • Anyone links: spotting sites shared with anonymous links
  • Broad access: flagging content open to Everyone Except External Users
  • Sensitive content: highlighting sites with labeled or risky data
  • Prioritization: ranking where to focus remediation
  • Ongoing governance: monitoring access risk over time

Benefits

  • Risk visibility: oversharing patterns made visible at scale
  • Prioritized: the riskiest sites surface first
  • Copilot-ready: reduces surprises when AI is switched on
  • AI insights: recommendations on where to act
  • Less manual audit: no site-by-site checking by hand
  • Part of SAM: integrated with advanced management controls

Details

  • Feature Category: Governance & Compliance

How It Works

  • Scans sharing patterns: reports analyze how content is shared
  • Categories of risk: anyone links, broad access, sensitive content
  • Ranked output: sites are surfaced by potential risk
  • AI insights: patterns and next steps are highlighted
  • Admin-run: generated from the SharePoint admin center
  • Feeds remediation: results drive controls like RCD

Limits and Nuances

  • Licensing required: DAG reports are a SharePoint Advanced Management capability
  • Indicators, not verdicts: reports flag risk to review, not guilt
  • Scale considerations: very large tenants generate large reports
  • Point in time: results reflect when the report was run
  • Remediation is separate: reports identify, you still act
  • Admin role needed: running them requires the right permissions

Common Questions About Data Access Governance (DAG) Reports

What are Data Access Governance reports in SharePoint?

Data Access Governance reports, part of SharePoint Advanced Management, help administrators identify the sites most likely to be oversharing content. They surface risk patterns such as anyone links, access granted to Everyone Except External Users, and sites holding potentially sensitive information, giving a ranked picture of where to focus rather than requiring a manual audit of every site.

Why do DAG reports matter for Copilot?

Because Copilot and organization-wide search make content far easier to find, any pre-existing oversharing becomes much more likely to surface. DAG reports let administrators spot and tighten the riskiest sites before that happens, so AI returns relevant answers without exposing content that should have been restricted. They are a core part of getting an environment ready for Copilot.

What kinds of risk do the reports highlight?

They focus on patterns that suggest content is too widely accessible, including sites shared via anyone links, content opened to Everyone Except External Users, and sites that may contain sensitive or labeled data. Newer AI insights can analyze these findings to highlight access-risk patterns and recommend next steps, helping admins move from a long list to a clear plan.

Do DAG reports fix the oversharing themselves?

No. The reports identify and prioritize risk, but remediation is a separate step. Once a report shows where the problems are, administrators act on them – tightening permissions, removing broad links, or applying controls like Restricted Content Discovery. The value of the reports is turning an overwhelming, tenant-wide question into a focused list of sites to address.

What is required to use DAG reports?

Data Access Governance reports are a SharePoint Advanced Management capability, so they require the appropriate licensing, and running them needs administrator permissions in the SharePoint admin center. Because they can be large in big tenants and reflect a point in time, organizations typically run and review them periodically as part of ongoing governance rather than just once.

How should organizations use DAG reports?

Use them as the starting map for a permissions cleanup, especially ahead of Copilot. Greg Zelfond, the consultant behind LookBook 365, treats DAG reports as the first step in getting Copilot-ready: find the oversharing, prioritize the riskiest sites, and apply the right controls before AI makes everything effortlessly findable. Run regularly, they keep access risk in view rather than letting it quietly accumulate.