"Everyone except external users" — EEEU for short — is a built-in Microsoft 365 group that resolves to every authenticated account in your tenant except B2B guests. Grant it on a file, and every internal person can open that file. Sometimes that's exactly the intent; sometimes it's a much broader reach than whoever clicked "share" realised. TRACER365 surfaces the grant so the choice is visible either way.
What EEEU actually grants
- Tenant-wide internal reach. EEEU expands to all internal users — potentially thousands of accounts — in a single grant. It's the internal counterpart to "broad", one step short of a true organisation-wide link.
- Not external. EEEU explicitly excludes external and guest accounts, so an EEEU grant is not external sharing. That's why TRACER365 treats it as an internal condition, not an external exposure.
- Read or edit. Like any grant it carries a permission level. "Everyone can edit" is a materially bigger deal than "everyone can view".
A specific named condition — not an access map
It's worth being precise about what this finding is and isn't. The EEEU finding flags one thing: a direct grant to the built-in EEEU group on an item. It is not a map of who inside your organisation can reach what — TRACER365 does not build a complete internal-access picture, and that isn't what the product claims to do. It surfaces this one named, recognisable condition because a tenant-wide internal grant is worth seeing on purpose.
Why it's flagged even when intentional
On a communication site — an intranet news page, a company-wide policy library — an EEEU grant may be a deliberate "everyone should read this" choice. TRACER365 still reports it, for two reasons: what's intentional on a comms site is often accidental on a working document library, and a scanner can't read intent. Severity is a uniform MEDIUM today; a future refinement may calibrate it per site type, but for now every EEEU grant is surfaced at the same level so none is silently dropped. Reported-even-when-intentional is the honest default — you decide which ones are fine.
How TRACER365 surfaces it
TRACER365 emits EEEU as its own MEDIUM-severity finding type wherever the group is granted directly on a file, folder, list, or page. The grant is tracked over time, so a change — a new EEEU grant, or a jump from view to edit — shows up as a change rather than blending in. Because EEEU is internal by definition, it never counts toward the external-sharing totals; it's a separate, clearly-labelled internal condition, sitting alongside the external findings without being confused for one.
What to do about it
- Check the permission level first: tenant-wide view is one conversation, tenant-wide edit is a more urgent one.
- Ask whether the container fits the grant: broad read on an intranet page is plausible; broad access on a working document library usually isn't.
- Re-scan on a schedule — EEEU grants get added quietly, and a level can climb from view to edit without a new share.