Explainer

Everyone except external users (EEEU) in SharePoint, explained

"Everyone except external users" — EEEU for short — is a built-in Microsoft 365 group that resolves to every authenticated account in your tenant except B2B guests. Grant it on a file, and every internal person can open that file. Sometimes that's exactly the intent; sometimes it's a much broader reach than whoever clicked "share" realised. TRACER365 surfaces the grant so the choice is visible either way.

What EEEU actually grants

  • Tenant-wide internal reach. EEEU expands to all internal users — potentially thousands of accounts — in a single grant. It's the internal counterpart to "broad", one step short of a true organisation-wide link.
  • Not external. EEEU explicitly excludes external and guest accounts, so an EEEU grant is not external sharing. That's why TRACER365 treats it as an internal condition, not an external exposure.
  • Read or edit. Like any grant it carries a permission level. "Everyone can edit" is a materially bigger deal than "everyone can view".

A specific named condition — not an access map

It's worth being precise about what this finding is and isn't. The EEEU finding flags one thing: a direct grant to the built-in EEEU group on an item. It is not a map of who inside your organisation can reach what — TRACER365 does not build a complete internal-access picture, and that isn't what the product claims to do. It surfaces this one named, recognisable condition because a tenant-wide internal grant is worth seeing on purpose.

Why it's flagged even when intentional

On a communication site — an intranet news page, a company-wide policy library — an EEEU grant may be a deliberate "everyone should read this" choice. TRACER365 still reports it, for two reasons: what's intentional on a comms site is often accidental on a working document library, and a scanner can't read intent. Severity is a uniform MEDIUM today; a future refinement may calibrate it per site type, but for now every EEEU grant is surfaced at the same level so none is silently dropped. Reported-even-when-intentional is the honest default — you decide which ones are fine.

How TRACER365 surfaces it

TRACER365 emits EEEU as its own MEDIUM-severity finding type wherever the group is granted directly on a file, folder, list, or page. The grant is tracked over time, so a change — a new EEEU grant, or a jump from view to edit — shows up as a change rather than blending in. Because EEEU is internal by definition, it never counts toward the external-sharing totals; it's a separate, clearly-labelled internal condition, sitting alongside the external findings without being confused for one.

What to do about it

  1. Check the permission level first: tenant-wide view is one conversation, tenant-wide edit is a more urgent one.
  2. Ask whether the container fits the grant: broad read on an intranet page is plausible; broad access on a working document library usually isn't.
  3. Re-scan on a schedule — EEEU grants get added quietly, and a level can climb from view to edit without a new share.

See every tenant-wide internal grant

EEEU surfaced as its own MEDIUM finding — reported even when intentional, tracked as it changes, never mistaken for external sharing. Free 30-day trial at launch.