Native gap

Data Access Governance reports without a Copilot licence

You went looking for SharePoint's oversharing or "who can access this" reports and hit a licence wall: Data Access Governance requires SharePoint Advanced Management— sold as a per-user add-on, or included with a Microsoft 365 Copilot licence. Paying per user, per month, to see your own tenant's sharing state is a hard sell. Here are your options.

What's actually behind the wall

Data Access Governance (DAG) lives in the SharePoint admin center and reports on sharing links, sensitivity-labelled content exposure, and "everyone except external users" usage — the reports Microsoft points at whenever oversharing comes up (they gained prominence as Copilot-readiness checks: what Copilot can read is whatever your permissions allow).

Even with the licence, note what DAG is and isn't:

  • It's an admin-center surface — IT-only, not something a business reviewer works in.
  • Reports are periodic snapshots you request and export, not a continuously maintained, reviewable findings list.
  • It's cloud-side: the analysis of your sharing state happens in the service.

Option 1 — buy the add-on anyway

If you already have Copilot licences, DAG is included: use it. If your organisation needs the other Advanced Management features (restricted access control, advanced policies), the add-on may earn its keep. For the single question "who can access what, externally?" it's an expensive door key.

Option 2 — PowerShell

Everything DAG reports about sharing is derivable from site, item, and permission data you can read with scripts — see our walkthrough of the scripted route. Complete, free, and a genuine engineering project you'll own forever.

Option 3 — a focused tool without the licence wall

TRACER365 answers the external who-can-access-what question with none of the above trade-offs:

  • No per-user licensing. One flat $490/year per installation — not a per-seat add-on across your whole tenant.
  • Runs locally, read-only. A Windows app in your environment with verifiable read-only scopes. The analysis runs on your own host rather than cloud-side, and the findings it produces stay in your environment — no vendor cloud in the path.
  • A working list, not a CSV. Severity-ranked findings with de-duplication (roughly 91% of raw findings collapsed as duplicates in our testing), review states, scheduled email reports, and history — plus a viewer role so a business owner can look at their own exposure.

The honest boundary: DAG can report on sensitivity-label exposure —TRACER365 doesn't read sensitivity labels today, and we won't pretend otherwise. If label-driven reporting is your requirement, Advanced Management is the tool. If the requirement is "show me exactly what's shared externally, keep it current, and make it reviewable", that's what TRACER365 is for.

The who-can-access-what answer, without the add-on

Flat $490/year, local and read-only. Free 30-day trial at launch — get notified.