Reference

Policies for SharePoint

See the SharePoint inventory reference for the objects these templates work on.

Policy Description Severity Category Checks
Unused Classic sites ⭐ Shows classic SharePoint sites Low Operation Site Collection
SharePoint Extranet Sites Sites without MS Teams where External Sharing is active Information ExternalAccess Site Collection
SharePoint Libraries with disabled search Shows SharePoint Libraries where search has been disabled Information Operation List/Library
Sites with disabled search Shows SharePoint Sites where search has been disabled Information Operation Site
Classic sites ⭐ Shows classic SharePoint sites Information Operation Site Collection
SharePoint file is shared with external users ⭐ Detects SharePoint files that have been shared externally, potentially exposing sensitive data. Sharing SharePoint files externally without control can lead to data leaks and compliance risks. Organizations should use Microsoft Purview sensitivity labels and enforce Data Loss Prevention (DLP) policies to protect confidential content. Rencore Governance can automate external file sharing detection and notify administrators for review and action. Establish a need-to-share" policy where data is only shared externally when strictly necessary. High Security File Sharing
SharePoint site is inactive for more than 90 days ⭐ Detects SharePoint sites without activity for a defined period, which could impact content accuracy. Inactive sites may contain outdated content that reduces Microsoft 365 Copilots response accuracy. Implement lifecycle management policies to archive or delete unused sites using Rencore Governance. Automate the identification of stale sites and enforce deprovisioning protocols to ensure only actively used sites remain accessible. Medium ResponseAccuracy Site Collection
Site Collections with Subsites Shows all Site Collections that have more subsites than the root site Information Operation Site Collection
SharePoint agent references more than two site collections Identifies SharePoint agents accessing data from more than two site collections, potentially leading to governance and accuracy issues. Excessive site collection usage increases governance complexity and accuracy risks. Organizations should restrict Copilot agent access to validated sources using Rencore Governance. Limit site collection references per agent and enforce data validation policies. Medium ResponseAccuracy SharePoint Agent
SharePoint agent uses outdated site collection Identifies SharePoint agents linked to site collections that have not been modified in over a year, increasing response inaccuracy risks. Agents using outdated site collections risk generating responses based on obsolete content. Organizations should use Rencore Governance to track stale data sources and enforce periodic content reviews to ensure Copilot agents access only updated SharePoint repositories. Medium ResponseAccuracy SharePoint Agent
SharePoint agent uses outdated list Detects SharePoint agents relying on lists that have not been updated in over a year, affecting AI accuracy. Outdated lists lead to misinformation in Copilot responses. Organizations should implement data freshness policies using Rencore Governance to flag and remove obsolete lists from Copilot agent knowledge bases, ensuring AI provides accurate and relevant information. Medium ResponseAccuracy SharePoint Agent
SharePoint file is older than 5 years Detects SharePoint files that have not been modified in over five years and may be outdated. Information ResponseAccuracy File
Unused SharePoint files Shows SharePoint files that are older than 5 years. Information Operation File
SharePoint site collection lacks sensitivity label ⭐ Detects SharePoint site collections missing sensitivity labels, increasing data security risks. Sensitivity labels protect classified data at scale. Organizations should implement global sensitivity label policies via Microsoft Purview and use Rencore Governance to ensure all site collections follow classification guidelines. Medium Security Site Collection
SharePoint Site collections near storage limit Shows SharePoint Site Collections using more than 90% of their available storage space High Costs Site Collection
SharePoint site has broken permission inheritance ⭐ Detects SharePoint sites where permission inheritance is broken, increasing security risks. Broken inheritance can lead to unexpected data access risks. Organizations should enforce consistent permission structures and monitor deviations using Rencore Governance to maintain security. Medium Security Site
SharePoint site collections with disabled owners accounts Shows SharePoint site collections that have any site owner account currently disabled Low UserOffboarding Site Collection
SharePoint site collection is owned by external users Identifies SharePoint site collections where external users are in ownership roles, increasing security risks. Allowing external users to own SharePoint sites can lead to strategic data exposure risks. Organizations should restrict external ownership and enforce strict permission policies. Rencore Governance can continuously monitor and alert admins of such instances. Regular audits should be performed to identify unauthorized external owners, and ownership roles should be reassigned where necessary. High Security Site Collection
SharePoint site collections with less than 2 site owners Shows SharePoint site collections that have less than 2 site owners Medium Operation Site Collection
SharePoint Site Collections without any owners Shows SharePoint site collections that have no site owner Medium Declutter Site Collection
SharePoint site collection contains more than 10 agents Detects SharePoint site collections containing more than 10 Copilot agents, leading to management challenges and potential security risks. High agent density in a single site collection can cause governance issues and redundant AI interactions. Organizations should use Rencore Governance to track agent numbers per collection, preventing uncontrolled sprawl and enforcing a structured agent deployment strategy. Medium Declutter Site Collection
Site collection is unused with more than 1 GB ⭐ Shows sites which have not been used in last 90 days and are larger than 1 GB Medium Costs Site Collection
Sites that have no Hubsite configured Shows SharePoint sites, that have not been associated with a SharePoint hub site and thus might be not easily discovered Information Operation Site Collection
SharePoint file is shared with inactive external user Highlights SharePoint files shared with external users who have been inactive for over six months. Inactive external users retaining access to SharePoint files present security risks. Organizations should use Rencore Governance to regularly audit external sharing permissions and revoke access for inactive accounts. Medium ExternalAccess File Sharing
SharePoint lists/libraries with more than 5000 items/documents Shows SharePoint lists or libraries with more than 5000 items or documents Medium Operation List/Library
Site Collection is near subsite limit Shows Site Collections that have nearly reached the Subsite limit of 2000 sites per Site Collection Low Operation Site Collection
Site Collection is near the List/Library limit Shows Site Collections that have nearly reached the Subsite limit of 2000 List/Library limit per Site Collection Low Operation Site Collection
Site Collections has reached the List/Library limit Shows Site Collections that have reached the Subsite limit of 2000 List/Library limit per Site Collection Medium Operation Site Collection
Site Collection has reached the subsite limit Shows Site Collections that have reached the Subsite limit of 2000 sites per Site Collection Medium Operation Site Collection
SharePoint subsite has unique permissions Detects SharePoint subsites that have unique permissions, making security management complex. Unique permissions increase complexity and may result in unintended data access. Organizations should enforce permission inheritance and track deviations using Rencore Governance. Regular access audits help maintain compliance and reduce exposure risks. Medium Security Site
SharePoint agent references confidential site without approval ⭐ Identifies SharePoint agents connected to confidential sites without approval, increasing the risk of unauthorized AI-generated responses. Unapproved SharePoint agents referencing confidential sites risk data leaks. Organizations should enforce a mandatory approval process via Rencore Governance to review agent connections before deployment. Limit agent permissions to prevent unauthorized data access. High Security SharePoint Agent
SharePoint agent is not approved ⭐ Identifies SharePoint agents that have not been reviewed or approved before use, posing security risks. Unapproved SharePoint agents could expose sensitive sites to AI interactions, leading to uncontrolled information access. Organizations should implement an approval workflow in Rencore Governance to verify intended uses and permissions before agent activation. Restrict self-service agent creation unless reviewed by IT. Low Security SharePoint Agent

Last updated: 7/19/2026