SharePoint Online is a widely recognized collaborative service that handles a vast volume of data flowing in and out of its environment every day. Crucial monitoring is essential to ensure the security and compliance of this data. This is where the data access governance reports step in. These reports play a pivotal role in facilitating a comprehensive review of data sharing, access, and classification within SharePoint Online. By leveraging these reports, you can effectively evaluate and manage the way data is accessed within the SharePoint Online environment.
This blog covers everything about the data access governance reports within the SharePoint admin center. Ready to explore? Then, here we go!
Data Access Governance Reports for SharePoint Sites
As SharePoint sites often house a vast amount of data, the data access governance (DAG) insights dashboard within the SharePoint admin center serves as a valuable tool. It helps in detecting instances of excessive resource sharing within SharePoint Online. Identifying the top 100 and top 10,000 sites among millions containing sensitive content enables admins to easily detect potential risks. They can take proactive measures to ensure proper governance and security.
Currently, there are three types of data access governance reports in SharePoint Online.
- Sharing links
- Sensitivity labels applied to files
- Sites and files shared via special SharePoint groups
Who Can Access the Data Governance Reports in the SharePoint Admin Center?
In the SharePoint admin center, the data access governance reports are typically accessible to SharePoint administrators, global administrators, and other user accounts that are assigned admin permissions.
Accessing the SharePoint Data Governance Reports
To access the data governance reports in SharePoint Online, follow the steps given below.
- Visit the SharePoint admin center.
- Navigate to Reports.
- Select ‘Data access governance’.

Sharing Links Reports in SharePoint
These reports provide a comprehensive overview of SharePoint sites where users created the highest number of sharing links which include the following.
Anyone links: Anonymous/Anyone links are public links that can be accessed by anyone with the link. This report lists sites that have the highest number of Anyone links created for the past 30 days.
People in the organization links: These links are also known as organization links, and they allow anyone in your organization to access the content. This report lists sites with the highest number of “People in the organization” links for the past 30 days.
Specific people links: These links can be shared with anyone, people inside and outside of your organization, but restricted only to specified individuals or groups. Using this report, admins can get details about the SharePoint site that has the highest number of specific people links created for the past 30 days.
Note: Before getting the latest data about the sharing links, you must first run the report using the ‘Run’ option.

After running the report, you have to wait for a few hours for the process to be completed. You can select ‘Refresh status’ to successfully see the status updated after a few hours. It is important to note that each report can be run only once in 24 hours.

When the report is ready, you get to view the following information about the site.
- Site name,
- URL to the site,
- Number of links created (last 30 days),
- Primary admin of the site,
- Site sensitivity,
- Unmanaged device policy, and
- External sharing status for that site.

The reports can be sorted by site sensitivity, unmanaged device access (No access, Limited web-only access, and Full access), and whether external sharing is enabled or disabled.
Note that this list view lists only up to 100 sites. You can download detailed reports using the ‘Download detailed report’ button into a .csv file to get information for up to 10,000 sites.

Sensitivity Labels for Files Reports
These reports help you monitor sensitive content roaming around SharePoint by reviewing the sites with sensitivity labels application. To view sensitivity labels for file reports, the first step is to add reports by selecting the sensitivity labels and then run the reports. You can add a report for each sensitivity label you want to monitor.
Note: The data access governance reports in SharePoint Online can only be generated for sensitivity labels that have been applied specifically to files.

As mentioned above, you have to run the report first and wait for a few hours to get the report ready.

When the report is ready, you can download it in the form of a .csv file. This report includes up to 10,000 sites covering the following information.
- Site ID
- Site URL
- Primary admin name
- Primary admin email
- Number of labeled files
- Site sensitivity label ID,
- Site sensitivity label name
- Unmanaged device policy
- External sharing status for the site.

IMPORTANT: To ensure the data access governance reports function correctly, you need to enable identifiable usernames in the Microsoft 365 admin center and uncheck the option that says, “Display concealed user, group, and site names in all reports.” This will enable the reports to show the actual names instead of pseudonyms for improved clarity and understanding.
Points to Remember
- The data in these reports may experience delays of up to 48 hours.
- For new tenants, it might take a few days for these reports to be generated successfully.
Sites and Files Shared via Special SharePoint Groups
Microsoft is planning to introduce a new report that helps you identify all the sites, files, and folders shared through special groups in SharePoint Online. These special groups include Everyone and Everyone except external users.
Earlier, admins could identify sites shared with these special groups. Now, these reports provide more targeted visibility into the content shared through these groups. They help you identify overexposed content across SharePoint Online and OneDrive and remediate unnecessary exposure without changing the existing permissions.
From the Data Access Governance section, you can access these reports by clicking View report under Sites and Folders Shared via SharePoint Groups.

Here, you’ll find two report types:
- Content Shared with Everyone Group – Identifies all sites, files, and folders shared with the ‘Everyone’ group.
- Content Shared with Everyone Except External Users Group – Retrieves all sites, files, and folders shared with the ‘Everyone except external users’ group.
Now, select Run report for the required report and track its status until it becomes Report available. Once the report is ready, you can view the report generated date and the number of sites found.

Next, click Download report for the required group. The downloaded ZIP file contains a list of items where the selected group has direct or indirect access. The report provides the following information:
- Tenant ID – Unique identifier of the Microsoft 365 tenant.
- Site ID – Unique identifier of the SharePoint site.
- Web ID – ID of the root web of the site collection or subsite.
- List ID – ID of the list, when available.
- Scope ID – ID of the specific permission scope in SharePoint or OneDrive.
- UniqueID – Unique identifier of the specific file or folder.
- ListItemID – Position of the item within the list.
- ItemURL – URL of the item, including its name and path.
- Role Definition – Permission level assigned to the item, such as Full Control, Read, Edit, Contributor, Creator, or Viewer.
- LinkId – ID of the sharing link, when applicable.
- LinkScope – Permission scope of the sharing link, such as Read, Write, or Edit.
- Recipient – The special group that has access, such as Everyone or Everyone except external users.
- UserPrincipalName – User principal name associated with the access entry.
- ParentObjectID – Microsoft Entra object ID of the parent entity when access is inherited or indirect.
- ParentGroupName – Name of the parent group when access is indirect.
- ParentGroupEmail – Email address of the parent group, when applicable.
- ParentGroupType – Type of the parent group, such as Security group, SharePoint group, or Microsoft 365 group.
- TotalUserCount – Number of users who have accessed the item at least once. Since the item is shared with all internal users or everyone, this helps admins understand the actual exposure of the content.
- ReportDate – Date and time when the report was generated.
Note: This report does not include permissions granted to Everyone Except External Users (EEEU) or Everyone for system files and system groups.
What’s New for SharePoint Data Access Governance?
Microsoft announced in a recent article that they are adding new enhancements to SharePoint Data Access Governance insights to power up the process of monitoring top sites that require attention. The enhancements include,
- Site access reviews: Helps SharePoint admins identify sites with potentially excessive access and ask site owners to review the current access patterns. Site owners can then confirm whether the access is expected or needs to be addressed.
- Integration with restricted access control (RAC) policy: Admins can enable RAC policies for the sites to limit access and reduce unnecessary exposure. This helps admins quickly act on sites identified as over-shared from the Data Access Governance insights.
These features require a Microsoft Syntex- SharePoint Advanced Management license and it is waiting to be generally available soon. We will update the blog once it’s rolled out. Stay tuned!
I hope this blog will help you gain a greater understanding of SharePoint reports for sharing, access, and data classification. For further assistance, feel free to reach us in the comments.






