Reference
Policies for SharePoint
See the SharePoint inventory reference for the objects these templates work on.
| Policy | Description | Severity | Category | Checks |
|---|---|---|---|---|
| Unused Classic sites ⭐ | Shows classic SharePoint sites | Low | Operation | Site Collection |
| SharePoint Extranet Sites | Sites without MS Teams where External Sharing is active | Information | ExternalAccess | Site Collection |
| SharePoint Libraries with disabled search | Shows SharePoint Libraries where search has been disabled | Information | Operation | List/Library |
| Sites with disabled search | Shows SharePoint Sites where search has been disabled | Information | Operation | Site |
| Classic sites ⭐ | Shows classic SharePoint sites | Information | Operation | Site Collection |
| SharePoint file is shared with external users ⭐ | Detects SharePoint files that have been shared externally, potentially exposing sensitive data. Sharing SharePoint files externally without control can lead to data leaks and compliance risks. Organizations should use Microsoft Purview sensitivity labels and enforce Data Loss Prevention (DLP) policies to protect confidential content. Rencore Governance can automate external file sharing detection and notify administrators for review and action. Establish a need-to-share" policy where data is only shared externally when strictly necessary. | High | Security | File Sharing |
| SharePoint site is inactive for more than 90 days ⭐ | Detects SharePoint sites without activity for a defined period, which could impact content accuracy. Inactive sites may contain outdated content that reduces Microsoft 365 Copilots response accuracy. Implement lifecycle management policies to archive or delete unused sites using Rencore Governance. Automate the identification of stale sites and enforce deprovisioning protocols to ensure only actively used sites remain accessible. | Medium | ResponseAccuracy | Site Collection |
| Site Collections with Subsites | Shows all Site Collections that have more subsites than the root site | Information | Operation | Site Collection |
| SharePoint agent references more than two site collections | Identifies SharePoint agents accessing data from more than two site collections, potentially leading to governance and accuracy issues. Excessive site collection usage increases governance complexity and accuracy risks. Organizations should restrict Copilot agent access to validated sources using Rencore Governance. Limit site collection references per agent and enforce data validation policies. | Medium | ResponseAccuracy | SharePoint Agent |
| SharePoint agent uses outdated site collection | Identifies SharePoint agents linked to site collections that have not been modified in over a year, increasing response inaccuracy risks. Agents using outdated site collections risk generating responses based on obsolete content. Organizations should use Rencore Governance to track stale data sources and enforce periodic content reviews to ensure Copilot agents access only updated SharePoint repositories. | Medium | ResponseAccuracy | SharePoint Agent |
| SharePoint agent uses outdated list | Detects SharePoint agents relying on lists that have not been updated in over a year, affecting AI accuracy. Outdated lists lead to misinformation in Copilot responses. Organizations should implement data freshness policies using Rencore Governance to flag and remove obsolete lists from Copilot agent knowledge bases, ensuring AI provides accurate and relevant information. | Medium | ResponseAccuracy | SharePoint Agent |
| SharePoint file is older than 5 years | Detects SharePoint files that have not been modified in over five years and may be outdated. | Information | ResponseAccuracy | File |
| Unused SharePoint files | Shows SharePoint files that are older than 5 years. | Information | Operation | File |
| SharePoint site collection lacks sensitivity label ⭐ | Detects SharePoint site collections missing sensitivity labels, increasing data security risks. Sensitivity labels protect classified data at scale. Organizations should implement global sensitivity label policies via Microsoft Purview and use Rencore Governance to ensure all site collections follow classification guidelines. | Medium | Security | Site Collection |
| SharePoint Site collections near storage limit | Shows SharePoint Site Collections using more than 90% of their available storage space | High | Costs | Site Collection |
| SharePoint site has broken permission inheritance ⭐ | Detects SharePoint sites where permission inheritance is broken, increasing security risks. Broken inheritance can lead to unexpected data access risks. Organizations should enforce consistent permission structures and monitor deviations using Rencore Governance to maintain security. | Medium | Security | Site |
| SharePoint site collections with disabled owners accounts | Shows SharePoint site collections that have any site owner account currently disabled | Low | UserOffboarding | Site Collection |
| SharePoint site collection is owned by external users | Identifies SharePoint site collections where external users are in ownership roles, increasing security risks. Allowing external users to own SharePoint sites can lead to strategic data exposure risks. Organizations should restrict external ownership and enforce strict permission policies. Rencore Governance can continuously monitor and alert admins of such instances. Regular audits should be performed to identify unauthorized external owners, and ownership roles should be reassigned where necessary. | High | Security | Site Collection |
| SharePoint site collections with less than 2 site owners | Shows SharePoint site collections that have less than 2 site owners | Medium | Operation | Site Collection |
| SharePoint Site Collections without any owners | Shows SharePoint site collections that have no site owner | Medium | Declutter | Site Collection |
| SharePoint site collection contains more than 10 agents | Detects SharePoint site collections containing more than 10 Copilot agents, leading to management challenges and potential security risks. High agent density in a single site collection can cause governance issues and redundant AI interactions. Organizations should use Rencore Governance to track agent numbers per collection, preventing uncontrolled sprawl and enforcing a structured agent deployment strategy. | Medium | Declutter | Site Collection |
| Site collection is unused with more than 1 GB ⭐ | Shows sites which have not been used in last 90 days and are larger than 1 GB | Medium | Costs | Site Collection |
| Sites that have no Hubsite configured | Shows SharePoint sites, that have not been associated with a SharePoint hub site and thus might be not easily discovered | Information | Operation | Site Collection |
| SharePoint file is shared with inactive external user | Highlights SharePoint files shared with external users who have been inactive for over six months. Inactive external users retaining access to SharePoint files present security risks. Organizations should use Rencore Governance to regularly audit external sharing permissions and revoke access for inactive accounts. | Medium | ExternalAccess | File Sharing |
| SharePoint lists/libraries with more than 5000 items/documents | Shows SharePoint lists or libraries with more than 5000 items or documents | Medium | Operation | List/Library |
| Site Collection is near subsite limit | Shows Site Collections that have nearly reached the Subsite limit of 2000 sites per Site Collection | Low | Operation | Site Collection |
| Site Collection is near the List/Library limit | Shows Site Collections that have nearly reached the Subsite limit of 2000 List/Library limit per Site Collection | Low | Operation | Site Collection |
| Site Collections has reached the List/Library limit | Shows Site Collections that have reached the Subsite limit of 2000 List/Library limit per Site Collection | Medium | Operation | Site Collection |
| Site Collection has reached the subsite limit | Shows Site Collections that have reached the Subsite limit of 2000 sites per Site Collection | Medium | Operation | Site Collection |
| SharePoint subsite has unique permissions | Detects SharePoint subsites that have unique permissions, making security management complex. Unique permissions increase complexity and may result in unintended data access. Organizations should enforce permission inheritance and track deviations using Rencore Governance. Regular access audits help maintain compliance and reduce exposure risks. | Medium | Security | Site |
| SharePoint agent references confidential site without approval ⭐ | Identifies SharePoint agents connected to confidential sites without approval, increasing the risk of unauthorized AI-generated responses. Unapproved SharePoint agents referencing confidential sites risk data leaks. Organizations should enforce a mandatory approval process via Rencore Governance to review agent connections before deployment. Limit agent permissions to prevent unauthorized data access. | High | Security | SharePoint Agent |
| SharePoint agent is not approved ⭐ | Identifies SharePoint agents that have not been reviewed or approved before use, posing security risks. Unapproved SharePoint agents could expose sensitive sites to AI interactions, leading to uncontrolled information access. Organizations should implement an approval workflow in Rencore Governance to verify intended uses and permissions before agent activation. Restrict self-service agent creation unless reviewed by IT. | Low | Security | SharePoint Agent |