Back to Top

#InsideIT

The KAUST Information Technology Department blog

Before Copilot Arrives, Check Who Can Access Your Files

05 August, 2026

As KAUST IT prepares for the rollout of Microsoft Copilot, now is a good time to review how you have shared files and folders in OneDrive and SharePoint.

Many of us use broad sharing options because they are quick and convenient. A link that works for anyone who receives it, or for anyone at KAUST with the link, can be useful when circulating an event agenda, workshop materials, public guidance, or other information intended for a large audience.

The difficulty is that sharing permissions can remain in place long after the original event, project, or collaboration has ended. A file shared broadly several years ago may still be accessible today, even if you have forgotten that the link exists.

Copilot changes discovery, not permissions.

Copilot cannot bypass Microsoft 365 permissions or open files that someone is not authorized to access. It can, however, make it easier for people to find, summarize, or reference information they already have permission to see.

Why this matters

Today, someone may need to know that a document exists, remember where it was stored, or receive the original sharing link before they can find it.

With Copilot, someone may be able to ask a question such as:

“Find the workshop planning document and summarize the proposed activities.”

If that person already has access because the document was shared with a broad group, Copilot may be able to help them discover and use it. This is why it is important that your current sharing permissions still reflect what you intended.

Before-and-after comparison showing overly broad file sharing permissions and more intentional access settings in OneDrive and SharePoint
Reviewing old sharing links helps ensure files remain available only to the people who genuinely need them.

What we are asking you to do

You do not need to review every document you have ever created. Start with files and folders that are most likely to have been shared broadly:

  • Files shared using an Anyone link
  • Files shared with Anyone at KAUST or People at KAUST with the link
  • Old project, committee, SharePoint, or Teams folders
  • Materials from completed events, workshops, or initiatives
  • Files or folders shared separately from the rest of a SharePoint site
  • Folders that allow people to edit, upload, move, or delete content

For each item, ask one simple question: Do all of these people still need access?

Review files you have shared in OneDrive

  1. Open OneDrive in your web browser.
  2. Select Shared from the left-hand menu.
  3. Open the Shared by you view.
  4. Select a file or folder, then open Manage access.
  5. Remove sharing links or people who no longer need access.

View Microsoft’s illustrated guide to finding files you have shared

Review files and folders in SharePoint and Teams

Files shared through Microsoft Teams are normally stored in the connected SharePoint site, so the same access review applies.

  1. Open the SharePoint site or the document library connected to your Team.
  2. Select the file or folder you want to review.
  3. Select Share, then open Manage access.
  4. Review the people, groups, and sharing links that provide access.
  5. Check whether access comes from a sharing link, direct access, or membership of the SharePoint site or Team.
  6. Remove links or direct access that are no longer needed. Site and Team membership should be reviewed by the relevant site or Team owner.

View Microsoft’s guide to reviewing access in SharePoint

SharePoint access may come from more than one place

A person may be able to open a file because it was shared with them directly, through a sharing link, through a SharePoint group, or because they are a member of the site or connected Team. Removing one link may not remove access received through another route.

Choose the smallest audience that genuinely needs access

Broad sharing is not automatically wrong. The right option depends on the information and why it is being shared.

Sharing optionWhen it may be appropriateWhat to keep in mind
Specific peopleDocuments intended for named colleagues, collaborators, or reviewersUsually the safest choice when only a defined group needs access
SharePoint site or Team membersOngoing work owned and managed by an established department, project, research group, or teamSite and Team owners should regularly review membership and remove people who no longer need access
People at KAUST with the linkInformation that anyone in the KAUST community may legitimately needThe link may be forwarded to other KAUST community members
Anyone with the linkPublic or temporary information that is appropriate to share without requiring sign-inAnyone who receives or is forwarded the link may be able to open it
Department or team websiteInformation that should remain available to a large audience over timeProvides a clearer permanent home than a long-lived personal sharing link

Check whether editing is really needed

When someone only needs to read a document, use Can view rather than Can edit. Editing access may allow people to change files and, when applied to a folder, may also allow them to add, move, rename, share, or delete its contents.

Temporary sharing? Make the access temporary too

If access is only needed for a limited period, use an expiration date when that option is available for the type of link you are creating.

This can be useful when sharing:

  • Workshop materials for a limited time
  • A draft for a short review period
  • Information related to an upcoming event
  • Documents for a temporary collaboration

After the expiration date, the link stops working automatically. This removes the need to remember to return later and disable it manually.

Learn how to configure sharing links, permissions, and expiration dates

Permanent information deserves a permanent home

OneDrive is designed primarily for files owned and managed by an individual. A personal sharing link may not be the best long-term home for information that a department, division, research group, or team needs to maintain indefinitely.

SharePoint and Teams are better suited to information owned by a group, but the site or Team still needs a clear owner and appropriate membership.

For information intended to remain available to a large audience, consider publishing it through an appropriate shared location, such as:

  • Your department or team’s SharePoint site
  • A SharePoint communication site
  • Your division, department, or team website on Sitefinity

This gives the information a clear owner and a stable location, rather than leaving an important resource dependent on one person’s OneDrive account or an old sharing link.

Copilot will not give people new access

Microsoft Copilot respects the access controls already used across Microsoft 365. It does not change your sharing settings, grant additional permission, or allow someone to bypass restrictions applied to a file or site.

If your permissions are correct, Copilot will continue to respect them.

The purpose of this review is simply to make sure that permissions applied in the past still match your intentions today.

A simple rule for future sharing

Share with the smallest audience that genuinely needs access, give people only the level of access they need, and use an expiration date when the access is temporary.

Need help?

Microsoft provides illustrated guidance for checking who can access a file and changing or removing permissions: