Guidance for remediating oversharing across Microsoft 365 (SharePoint, OneDrive, Teams, Exchange) using the Secure & Governed Data Foundation blueprint - a three-pillar program (remediate…

MITAuto-check passedDocuments & Office

Install M365 Oversharing

skills CLI
$ npx skills add vinayaklatthe/microsoft-security-skills --skill m365-oversharing -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install vinayaklatthe/microsoft-security-skills m365-oversharing --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/vinayaklatthe/microsoft-security-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/m365-oversharing .claude/skills/m365-oversharing && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
m365-oversharing
GitHub stars
175
Token cost
~1.8k tokens
SKILL.md length
737 words
Files
1
Skills in repo
50
Repo updated
First seen
Licence
MIT

At a glance

Guidance for remediating oversharing across Microsoft 365 (SharePoint, OneDrive, Teams, Exchange) using the Secure & Governed Data Foundation blueprint - a three-pillar program (remediate…

  • Works in 7 steps: Assess (DAG reports) - Run SharePoint… → Apply interim restrictions - For the… → Engage site owners - Notify owners with… → …
  • Copilot-specific readiness framing only (use purview-copilot-oversharing)
  • SKILL.md covers When to use, The three pillars, Approach and Guardrails, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

M365 Oversharing is an agent skill from vinayaklatthe/microsoft-security-skills. Guidance for remediating oversharing across Microsoft 365 (SharePoint, OneDrive, Teams, Exchange) using the Secure & Governed Data Foundation blueprint - a three-pillar program (remediate oversharing, set up guardrails, meet regulations) built on SharePoint Advanced Management data access governance, sensitivity and container labels, secure-by-default labelling, Restricted Access Control, and Microsoft Purview. WHEN: Microsoft 365 oversharing, M365 oversharing, secure and governed data foundation, oversharing…

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Documents & Office, covering Cloud office suites. It works with Microsoft 365, Microsoft SharePoint and Microsoft OneDrive. The repository describes itself as: Curated Microsoft Security skills for AI agents - Defender, Sentinel, Entra, Purview, Intune, Security Copilot. The licence is MIT.

When your agent uses it

  • Copilot-specific readiness framing only (use purview-copilot-oversharing)
  • Building a broad DLP program (use purview-dlp-policy)

Example prompts

  • “/m365-oversharing”

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Assess (DAG reports) - Run SharePoint Advanced Management data access governance
  2. Apply interim restrictions - For the highest-risk sites, apply **Restricted Access
  3. Engage site owners - Notify owners with the expected fix; don't strip permissions centrally
  4. Classify & label - Apply sensitivity labels to sensitive content and container labels to
  5. Secure by default - Use secure-by-default labelling (derive labels from SharePoint
  6. Govern lifecycle - Apply site lifecycle and inactive-site policies plus access reviews so
  7. Meet regulations & monitor - Use Purview Audit and Compliance Manager to close audit/legal

What it can do on your machine

Read from SKILL.md and the folder at commit 15f16df. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • learn.microsoft.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

M365 Oversharing loads about 1.8k tokens when it runs. Until then it costs about 238 tokens; SKILL.md has 737 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~238
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from vinayaklatthe/microsoft-security-skills at commit 15f16df, republished under its MIT licence (© vinayaklatthe). 737 words, ~1,823 tokens.

Download SKILL.mdSave it as .claude/skills/m365-oversharing/SKILL.md (or your agent's skills folder).
name
m365-oversharing
description
Guidance for remediating oversharing across Microsoft 365 (SharePoint, OneDrive, Teams, Exchange) using the Secure & Governed Data Foundation blueprint - a three-pillar program (remediate oversharing, set up guardrails, meet regulations) built on SharePoint Advanced Management data access governance, sensitivity and container labels, secure-by-default labelling, Restricted Access Control, and Microsoft Purview. WHEN: Microsoft 365 oversharing, M365 oversharing, secure and governed data foundation, oversharing blueprint, too many people have access to SharePoint, EEEU everyone except external users, tighten permissions, data access governance report, restricted content discovery, secure by default labels, prepare data foundation, reduce sharing link sprawl, governed data estate. DO NOT USE for Copilot-specific readiness framing only (use purview-copilot-oversharing) or building a broad DLP program (use purview-dlp-policy).
license
MIT
metadata.author
Microsoft
metadata.version
0.1.0

Microsoft 365 Oversharing Remediation

Oversharing - content shared more broadly than it should be - is the root cause of most data exposure in Microsoft 365 and the biggest risk amplified by AI. Microsoft's Secure & Governed Data Foundation blueprint structures remediation into three pillars: remediate oversharing, set up guardrails, and meet regulations. The work is powered by SharePoint Advanced Management (SAM, included with a Microsoft 365 Copilot license), sensitivity and container labels, and Microsoft Purview.

When to use

Building a secure, well-governed Microsoft 365 data estate - reducing who can reach what across SharePoint, OneDrive, Teams, and Exchange, then keeping it that way with enforceable defaults. Applies whether or not Copilot is in scope; it is the data-foundation work every AI or data program depends on.

Do not use this skill when the question is purely Copilot rollout readiness framing (use purview-copilot-oversharing), monitoring sensitive data in AI prompts (use purview-dspm-ai), or designing a tenant-wide DLP program (use purview-dlp-policy).

The three pillars

PillarGoalPrimary levers
Remediate oversharingFind and reduce existing over-broad access fastSAM data access governance (DAG) reports, EEEU cleanup, sharing-link cleanup, Restricted Access Control / Restricted Content Discovery
Set up guardrailsPrevent regression with enforceable defaultsSensitivity + container labels, secure-by-default labelling, default sharing settings, site lifecycle policies
Meet regulationsClose audit/legal and AI-regulatory gapsPurview Audit, Compliance Manager assessments, data hygiene

Rule of thumb: assess -> classify -> restrict -> default-secure -> govern. Skipping the assess (DAG report) step is the most common failure; encrypting everything "to be safe" is the second.

Approach

  1. Assess (DAG reports) - Run SharePoint Advanced Management data access governance reports to find the riskiest sites: "Everyone Except External Users" (EEEU) on too many sites, broadly shared sites, sharing-link sprawl, and permissioned-but-sensitive content. Verify: DAG report ranks top-N risky sites with named owners.
  2. Apply interim restrictions - For the highest-risk sites, apply Restricted Access Control / Restricted Content Discovery as a fast interim guardrail while owners remediate. Verify: a restricted site no longer surfaces in a test user's search/Copilot results.
  3. Engage site owners - Notify owners with the expected fix; don't strip permissions centrally without owner context - that breaks legitimate collaboration and erodes trust. Verify: owner remediation tickets opened with deadlines.
  4. Classify & label - Apply sensitivity labels to sensitive content and container labels to sites; reserve encryption for genuinely sensitive content. Verify: a top-tier label encrypts and blocks unauthorised access.
  5. Secure by default - Use secure-by-default labelling (derive labels from SharePoint sites) and tighten default sharing settings so new content is protected without relying on users to remember to label. Verify: newly created content inherits a default label/sharing scope.
  6. Govern lifecycle - Apply site lifecycle and inactive-site policies plus access reviews so oversharing doesn't creep back; this is ongoing governance, not a one-time cleanup. Verify: inactive sites archived or owners re-attested on cadence.
  7. Meet regulations & monitor - Use Purview Audit and Compliance Manager to close audit/legal and AI-regulatory gaps, and monitor for new oversharing continuously. Verify: audit/regulatory assessment shows reducing exposure over time.
Show full SKILL.md (246 more words)Show less

Guardrails

  • Remediate before broad enablement of AI/Copilot; a clean, scoped pilot can proceed, but tenant-wide turn-on without assessment generates complaints fast.
  • Assess first - running remediation without the DAG report means you fix the wrong things.
  • Don't encrypt everything with the top label "to be safe" - it breaks external collaboration and legitimate sharing; secure-by-default labelling plus exception handling scales better.
  • Coordinate with site owners; centralised bulk permission stripping breaks collaboration.
  • SAM is licensed (included with Microsoft 365 Copilot, or a standalone/E5 SKU) - confirm availability before assuming reports exist.
  • Oversharing control is continuous governance - new sites and sharing links appear daily.

Common anti-patterns

  • Running the DAG report once, fixing the top 20 sites, and declaring done.
  • Enabling Copilot or a new data program tenant-wide and remediating oversharing afterwards.
  • Restricted Content Discovery applied across half the tenant - users complain search is useless.
  • Training users on "when to protect" instead of deriving secure-by-default labels.
  • Ignoring sharing-link sprawl because the report is long.

Example prompts

  • Remediate oversharing across Microsoft 365 using the secure and governed data foundation blueprint.
  • Use SharePoint Advanced Management data access governance to find over-broad access.
  • Set up secure-by-default labelling so new SharePoint content is protected automatically.
  • Clean up "Everyone except external users" and sharing-link sprawl.
  • Build enforceable guardrails to stop oversharing regression.

Microsoft Learn

© vinayaklatthe, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/m365-oversharing of vinayaklatthe/microsoft-security-skills.

Open the folder on GitHubat commit 15f16df

Compare with similar skills

M365 Oversharing next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

M365 Oversharing compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
M365 Oversharing this skillvinayaklatthe/microsoft-security-skills175—~1.8kAutomated safety check: PassMIT
Msgraphcodemie-ai/codemie-code294—~4.1kAutomated safety check: PassApache-2.0
aai-cli Microsoft 365aai-labs/agent-barn109—~1.2kAutomated safety check: PassApache-2.0
Workiqmicrosoft/work-iq1k—~15kAutomated safety check: PassCustom licence
Workiq Previewmicrosoft/work-iq1k—~3.3kAutomated safety check: PassCustom licence
Msgraph Filesautomateyournetwork/netclaw676—~1kAutomated safety check: PassApache-2.0

Similar skills

  • Msgraph

    codemie-ai/codemie-code

    Work with Microsoft 365 services via the Graph API — emails, calendar events, SharePoint sites (read and write), Teams chats and channel messages, OneDrive files, OneNote notebooks, Planner task…

    294 GitHub stars~4.1k tokensUpdated 2 days ago
    Documents & OfficeAuto-check passed
  • aai-cli Microsoft 365

    aai-labs/agent-barn

    Guides work with Outlook, OneDrive, SharePoint, Teams, Excel, To Do and Planner through aai-cli's Microsoft Graph commands, starting from which service owns the data.

    109 GitHub stars~1.2k tokensUpdated yesterday
    Documents & OfficeAuto-check passed
  • Workiq

    microsoft/work-iq

    Official

    WorkIQ tools for Microsoft 365 workplace data and actions. An agent skill from microsoft/work-iq.

    1k GitHub stars~15k tokensUpdated yesterday
    Documents & OfficeAuto-check passed
  • Workiq Preview

    microsoft/work-iq

    Official

    WorkIQ tools for Microsoft 365 workplace data and actions. An agent skill from microsoft/work-iq.

    1k GitHub stars~3.3k tokensUpdated yesterday
    Documents & OfficeAuto-check passed
  • Msgraph Files

    automateyournetwork/netclaw

    Read OneDrive and SharePoint files via the Microsoft 365 MCP server — list folder contents, fetch item metadata, inspect versions and sharing permissions.

    676 GitHub stars~1k tokensUpdated yesterday
    Documents & OfficeAuto-check passed
  • Msgraph Visio

    automateyournetwork/netclaw

    Upload and retrieve Visio (.vsdx) and other diagram files in OneDrive/SharePoint via the Microsoft 365 MCP server.

    676 GitHub stars~1k tokensUpdated yesterday
    Documents & OfficeAuto-check passed

More from vinayaklatthe/microsoft-security-skills

All 50 skills in this repo
  • API Security Design

    vinayaklatthe/microsoft-security-skills

    Guidance for designing secure APIs on Azure - authentication, authorization, gateway controls, input validation, rate limiting, secret management, and runtime threat detection - aligned to OWASP API…

    175 GitHub stars~2.2k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure App Service Security

    vinayaklatthe/microsoft-security-skills

    Guidance for securing Azure App Service web apps and APIs — managed identity, Easy Auth with Microsoft Entra ID, network isolation via private endpoints + VNet integration, HTTPS / TLS hardening…

    175 GitHub stars~1.9k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Arc

    vinayaklatthe/microsoft-security-skills

    Guidance for Azure Arc — projecting on-premises, multicloud (AWS/GCP), and edge servers, Kubernetes, and data services into Azure Resource Manager for unified governance, security, and management.

    175 GitHub stars~1.9k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Bastion Jit

    vinayaklatthe/microsoft-security-skills

    Guidance for secure remote VM management in Azure using Azure Bastion combined with Defender for Cloud just-in-time (JIT) VM access.

    175 GitHub stars~2.2k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Confidential Computing

    vinayaklatthe/microsoft-security-skills

    Guidance for Azure Confidential Computing — protecting data in use through hardware-based Trusted Execution Environments (TEEs).

    175 GitHub stars~2.4k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Ddos Protection

    vinayaklatthe/microsoft-security-skills

    Guidance for Azure DDoS Protection — Network Protection (per-VNet) and IP Protection (per public IP) tiers built on the same always-on Microsoft platform.

    175 GitHub stars~2k tokensUpdated 3 mo ago
    Auto-check passed

Questions about M365 Oversharing

What does M365 Oversharing do?

Guidance for remediating oversharing across Microsoft 365 (SharePoint, OneDrive, Teams, Exchange) using the Secure & Governed Data Foundation blueprint - a three-pillar program (remediate…. M365 Oversharing is an agent skill from vinayaklatthe/microsoft-security-skills. Guidance for remediating oversharing across Microsoft 365 (SharePoint, OneDrive, Teams, Exchange) using the Secure & Governed Data Foundation blueprint - a three-pillar program (remediate oversharing, set up guardrails, meet regulations) built on SharePoint Advanced Management data access governance, sensitivity and container labels, secure-by-default labelling, Restricted Access Control, and Microsoft Purview.

When should I use M365 Oversharing?

M365 Oversharing fits situations like: copilot-specific readiness framing only (use purview-copilot-oversharing); building a broad DLP program (use purview-dlp-policy).

How do I install M365 Oversharing in Claude Code?

Run `npx skills add vinayaklatthe/microsoft-security-skills --skill m365-oversharing -a claude-code`. Or copy the skill folder (skills/m365-oversharing in vinayaklatthe/microsoft-security-skills) into .claude/skills/m365-oversharing in your project. Claude Code loads it when a task matches its description.

How do I install M365 Oversharing in Codex?

Run `npx skills add vinayaklatthe/microsoft-security-skills --skill m365-oversharing -a codex`. Or copy the skill folder (skills/m365-oversharing in vinayaklatthe/microsoft-security-skills) into .agents/skills/m365-oversharing in your project. Codex loads it when a task matches its description.

Can I use M365 Oversharing in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add vinayaklatthe/microsoft-security-skills --skill m365-oversharing -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/m365-oversharing, .gemini/skills/m365-oversharing, .github/skills/m365-oversharing and .opencode/skills/m365-oversharing in your project.

What does M365 Oversharing need to run?

SKILL.md names no scripts, command-line tools or credentials: M365 Oversharing is instructions for the agent only.

Does M365 Oversharing access the network?

SKILL.md names 1 domain. As links in the text: learn.microsoft.com. This is read from the text; nothing was executed.

Is M365 Oversharing safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does M365 Oversharing use?

M365 Oversharing is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does M365 Oversharing use?

About 1.8k tokens (SKILL.md is roughly 7.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to M365 Oversharing?

Skills that share tags, products or a category with M365 Oversharing: Msgraph (codemie-ai/codemie-code, 294 stars), aai-cli Microsoft 365 (aai-labs/agent-barn, 109 stars), Workiq (microsoft/work-iq, 1k stars) and Workiq Preview (microsoft/work-iq, 1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains M365 Oversharing?

vinayaklatthe (a GitHub user) maintains it in vinayaklatthe/microsoft-security-skills, which has 175 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on June 18, 2026.

Source: vinayaklatthe/microsoft-security-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.