Access Reviews in Microsoft 365 systematically verify who has access to Teams, SharePoint libraries, sharing links, and groups — and remove permissions that are no longer needed. Microsoft provides two separate tools for this: SharePoint Advanced Management for oversharing analysis and Entra ID Governance for group memberships. Without regular reviews, permissions accumulate over months, expand the attack surface, and block a clean Copilot rollout.
When an IT administrator needs to maintain oversight of permissions across hundreds of Teams and SharePoint sites, they need a structured system that automatically identifies oversharing risks and delegates targeted reviews to the right people — so sensitive documents don't remain permanently accessible to everyone, and a Copilot rollout doesn't fail because of uncontrolled permissions.
Why should you run Access Reviews in Microsoft 365?
Access Reviews reduce the attack surface in Microsoft 365 by applying the Zero Trust principle of "Least Privilege": every person should only be able to access the content they actually need for their current task. Without regular reviews, permissions systematically grow over the course of employment — and rarely shrink.
Two developments make this problem more acute today. First, phishing attacks and AI-generated deepfakes have become so sophisticated that employees can barely recognize them: industry-specific messaging, convincingly authentic senders, contextually relevant content. A compromised account with accumulated permissions causes exponentially more damage than one limited to only the currently necessary access. Second, Copilot for Microsoft 365 fails in practice not because it finds too little — but because it finds too much. Copilot respects Microsoft 365 permissions: if a document is accessible to everyone, Copilot can surface it for everyone. Unaddressed permission sprawl means confidential project data, salary information, or strategy documents can suddenly appear in AI-generated summaries.
Where do permission layers sit in Microsoft 365 and Teams?
Microsoft 365 has multiple permission layers that must be managed independently. Running Access Reviews only at the top level systematically misses risks on the layers beneath.
Teams membership list. The central starting point: owners and members are listed here with their Teams permissions. When an external consultant leaves a project or an intern moves to a different department, the change must happen here.
SharePoint site permissions. Every Team automatically creates a SharePoint Site Collection in the background. This inherits Teams permissions but also has its own separate permission system. Via "Share site only", people can be granted access to the SharePoint site without appearing in Teams — making them invisible in the normal Teams membership list.
Document libraries, folders, and individual documents. Each of these levels can carry its own permissions that deviate from the team-level permissions. In practice, this creates permission islands: individual files that remain accessible for years to people who have long since left the project.
Sharing links. The most underestimated permission channel. Microsoft 365 has four link types:
| Link type | Access | Important detail |
|---|---|---|
| Anyone (anonymous) | Everyone with the link, internal and external | Snowball effect possible — forwardable |
| Organization | All internal users after redemption | No expiry date set by default |
| People with existing access | No new permissions granted | Equivalent to copying a browser URL |
| Specific people | Named individuals, internal and external | Permission applies immediately — even without sending the link |
Everyone except External Users. This special Microsoft group grants all internal users access to content. It is also used by the system — for example, to make a Public Team public. External contractors working with an internal account fall under this group and therefore gain access to all content shared this way.
How do Access Reviews work with SharePoint Advanced Management?
SharePoint Advanced Management (SAM) is a Microsoft add-on that visualizes oversharing risks at the site level and can trigger targeted Access Reviews. It is available for $3 USD per user per month — or at no additional cost if at least one actively used Copilot license exists in the tenant.
SAM provides two report types in the SharePoint Admin Center:
Snapshot Reports show a point-in-time view of the current oversharing state. The top 100 site collections are sorted by oversharing risk: sites with the most Anyone links, Org links, Unique Permissions, and Everyone-Except-External assignments appear at the top. The report can only be regenerated once every 30 days and may take several days to complete depending on tenant size. For more than 100 sites, a CSV export is required — and all further processing happens manually outside the UI.
Activity Reports show which sharing links and Everyone-Except-Externals assignments were newly created in the last 28 days. The 28-day window is an important parameter: triggering reviews more frequently than every 28 days means seeing the same links twice; reviewing less frequently means missing older links in this report.
From both report types, administrators can trigger an Access Review for individual site collections with a single click. Site owners receive an email with a customizable message, see all items with changed permissions or set sharing links in a dedicated portal, and can clean up or approve each one individually. They complete the process by clicking "Complete Review."
What SAM does not do: The system does not verify whether owners actually completed the review — clicking "Complete Review" closes it regardless of whether all items were addressed. Escalation mechanisms, automated reminders for non-response, or rule-based archiving when a review is not completed are absent and would need to be organized manually. SAM also only covers sharing links and unique permissions — not the regular group memberships of Teams.
How do Access Reviews work with Entra ID Governance?
For reviewing regular group memberships — that is, who is a member of a Team or Microsoft 365 group — Microsoft Entra ID Governance provides a standalone Access Review module. It is not connected to SharePoint Advanced Management and requires an Entra ID P2 license for everyone who conducts the review (not for the people being reviewed).
Entra ID Governance offers significantly more configuration depth for group reviews than SAM:
- Scope definitions: Review all M365 groups with guests, or specific groups; filter for inactive users
- Reviewer selection: Automatically assign group owners — or define manual reviewers
- Recurrence: One-time, weekly, monthly, semi-annual, or annual
- Non-response behavior: Configurable as "no change", "remove access", "implicit approval", or "apply recommendations"
- Decision helpers: The system flags users as removal candidates if they haven't signed in for an extended period, or if their organizational unit doesn't match the group composition (user-to-group affiliation)
The review process runs through a dedicated portal: reviewers see all group members with the system's recommendation (Approve/Deny) and can decide individually or via bulk action. The requirement to provide justification for changes is configurable and audited.
What are the limitations of Microsoft's standard tools?
Both Microsoft tools solve part of the Access Review problem — but not the complete picture.
| Criterion | SharePoint Advanced Management | Entra ID Governance |
|---|---|---|
| Coverage | Sharing links, unique permissions, Everyone groups | Group memberships |
| Permission layers | SharePoint level | Teams/group level |
| Integration | Standalone, no connection to Entra | Standalone, no connection to SAM |
| Escalation | Not available | Configurable |
| Completeness check | Not available | Not available |
| Top-N limitation | Top 100 sites in UI | None |
| Time window | 28 days (Activity Reports) | Freely configurable |
| License | SAM add-on or Copilot | Entra ID P2 |
The critical gap: No single tool shows the membership list and SharePoint item-level permissions of a site in one place. A complete Access Review for a team requires checking Teams memberships in Entra ID Governance, sharing links in SAM, and unique permissions separately — with manual coordination between the systems. A dedicated access review campaign platform closes this gap by consolidating all permission layers into a single, risk-prioritized process.
How do I run Access Reviews in Microsoft 365 step by step?
A structured approach prevents Access Reviews from becoming a one-time compliance event and establishes a repeatable process.
Step 1: Risk inventory with Snapshot Report
Start with the SharePoint Snapshot Report in SAM. Identify the top 20 sites by oversharing score — those where the combination of many Unique Permissions, Org links, Anyone links, and large user numbers indicates the highest risk. Add any Teams whose memberships haven't been reviewed in more than 6 months.
Step 2: Trigger Access Reviews for high-risk sites
Trigger Access Reviews for the top 10 sites directly from the Snapshot Report. Customize the owner email: briefly explain what owners should check and include a link to your internal governance policies. Set a clear deadline — two weeks is a practical starting point for a first review.
Step 3: Configure group membership reviews in Entra ID Governance
Set up a recurring Access Review for all M365 groups with external members — semi-annual is a good starting cadence for most organizations. Enable Decision Helpers and configure "Deny" as the default action on non-response if you want a more conservative security posture.
Step 4: Clean up Everyone-Except-Externals assignments
Check the Activity Report to identify which content is accessible via Everyone Except Externals — and which of those should actually be public. Public Teams are a legitimate use case; confidential project documents are not. Replace Everyone-Except-Externals assignments with dedicated security groups wherever possible.
Step 5: Define and communicate a recurrence schedule
Access Reviews are not a one-time project. Define how frequently which review types should occur: sharing link reviews monthly for high-risk sites, group membership reviews semi-annually, Snapshot Reports quarterly. Communicate the process to site and team owners — and make clear that "review completed" does not mean "everything approved."
Frequently asked questions about Access Reviews in Microsoft 365
-
Why isn't checking the Teams membership list enough?
The Teams membership list only shows direct group membership. Via "Share site only," people can be granted SharePoint access without appearing in Teams. Individual libraries, folders, and documents can carry their own permissions. Sharing links grant access independently of membership. A complete Access Review must cover all four layers.
-
Who needs an Entra ID P2 license for Access Reviews?
The Entra ID P2 license is required for the people who conduct the Access Review — that is, the reviewers and administrators who configure the process. The people whose memberships are being reviewed do not need this license. Certain advanced functions within Access Reviews additionally require the Entra ID Governance or Entra ID Suite license.
-
What happens if an owner doesn't respond to an Access Review?
In SharePoint Advanced Management, nothing happens without manual follow-up from the administrator. In Entra ID Governance, you can configure what should happen on non-response: no change, automatic access removal, implicit approval, or application of system recommendations. The right choice depends on your risk tolerance and the sensitivity of the content in question.
-
How often should Access Reviews be conducted?
A practical rule of thumb: sharing link reviews monthly for high-risk sites, group membership reviews semi-annually, Snapshot Reports quarterly. Teams with external members or particularly sensitive content warrant shorter intervals. More important than the exact frequency is consistency — a review that actually happens every six months is more valuable than a planned monthly review that never gets done.
-
What is the difference between SharePoint Advanced Management and Entra ID Governance for Access Reviews?
SharePoint Advanced Management covers oversharing risks at the content level: sharing links, unique permissions on libraries, folders, and documents, and Everyone-Except-Externals assignments. Entra ID Governance covers group memberships: who is an owner or member of a Team or M365 group. Both tools are independent and solve different parts of the overall problem. A complete Access Review requires both layers.
-
Does the system verify whether an owner actually completed the review?
No. In SharePoint Advanced Management, an owner can mark a review as complete without having gone through all items. The system does not verify completeness. Responsibility for a thorough review lies with the owner. If you want to ensure reviews are actually completed in full, you need an overarching process with admin-level oversight — or a tool that takes on this verification automatically.
Conclusion
Access Reviews in Microsoft 365 are not a compliance project to check off once — they are a continuous process that keeps permissions aligned with current reality. Microsoft provides SharePoint Advanced Management and Entra ID Governance as two separate tools, each functional on its own, but not connected to each other. Anyone who wants to bring both layers — content and group memberships — together in one structured process, prioritized by risk classification, without overwhelming owners with complete site lists, will quickly hit the limits of Microsoft's standard tooling.
Book a demo now: See how Valprovia runs Access Reviews with automatic risk classification, a complete permission overview across all layers, and a focused view on actual problem cases.
Book a meeting with Valprovia to explore solutions for Microsoft 365 governance, automation and compliance. Instant confirmation.
