SharePoint site inventory

You have 3-5x more SharePoint sites than you think. Here is the list.

Every Team creates a site. Every private channel creates another one, with its own membership. Every employee has a OneDrive. In a typical tenant the real site count is three to five times the number IT would quote, and most of the extra ones have no owner, no visitor in a year, or both. 1Security lists all of them, with owners, members, storage, last activity and external users on every row.

  • 3-5x
    more sites than IT expects once channel sites and OneDrives are counted
  • 1 year
    without activity is the abandonment threshold on every site row
  • ~10 min
    for a new site or a new sharing link to appear in the list

The problem

Nobody has the list.

Ask an admin how many sites the tenant has and the answer is usually low by a multiple.

Sites in Microsoft 365 are a side effect of collaboration, not a decision. Someone creates a Team and a site appears. Someone adds a private or shared channel and a second site collection appears, with its own membership, that no parent site lists. Someone joins the company and a personal OneDrive appears. None of it passes through a request queue, so none of it lands on a list.

Storage and a last-activity date per site are easy to come by. The hard part is everything else on the same row: who can get in from outside, how many sharing links a site carries, how much sensitive data sits inside - and seeing personal OneDrives in the same list. Without that, the long tail stays invisible: in a typical tenant more than half of all files sit in sites nobody has opened in a year, and a good share of those sites still have external users or anyone links attached.

1Security builds the inventory from the tenant itself - every site type, every OneDrive - and puts the governance columns next to the name: owners, last activity, storage, external users, sharing links, sensitive info and whether Copilot can read it. Sorting that list is the review.

What you get

One row per site, with everything you need to decide.

Enough on the row to triage without opening anything: who owns it, who visits it, who can get in from outside, what is inside.

  • Every site type, kept apart

    Classic sites, subsites and hubs; Teams-connected sites split into standard, private and shared channel sites; personal OneDrives. Site type is a filter, so a review of only SharePoint or only OneDrive is one click.

  • Abandonment, three ways

    No owners, no members, no activity in the last year - three separate filters, because a site with owners on paper and no visitor for four quarters is a different problem from a site with nobody responsible at all.

  • External exposure per site

    External users, SharePoint-only guests, anyone links and organization-wide links counted per site, each count clickable. Rank whole sites by how open they are instead of auditing file by file.

  • Storage and activity on the row

    Storage size, file count, drives, lists, subsites and an activity sparkline. Sort by storage and filter to no activity in a year: the top of that list is usually single sites holding terabytes.

  • Sensitive data and Copilot, side by side

    Detected sensitive info (300+ types, OCR included) and Purview labels per site, next to the Copilot-enabled flag - the exact inputs of a pre-rollout cleanup list.

  • Act on a selection

    Select sites and run an automation: assign owners, expire external access, block Copilot search, archive. Proposals stage behind a 72-hour review window before anything changes.

How deep it goes

The abandoned-but-open list, in one filter.

One combination finds more in five minutes than a quarter of manual auditing.

Filter Sites to no activity in the last year, then add external users. Nobody inside has touched these sites - but somebody outside still can. In a typical tenant the list is 20 to 200 sites: short enough to work through in an afternoon and uncomfortable enough that it usually gets done.

The Copilot version of the same move: Copilot enabled plus sensitive info present, sorted by detection count. Those are the sites to label, restrict or block from org-wide search before AI answers start quoting them. Mid-size tenants usually find 30 to 80.

The third pass is ownerless data: sites with no owner at all. Nobody approves membership, nobody reviews access, and the permissions keep working. Assign an owner or archive - either way it is a decision instead of another year of drift.

In practice

A first inventory pass, start to finish.

What the first afternoon on the Sites screen usually looks like.

  1. 01

    Get the real count

    The scan lists every site collection, including private and shared channel sites and every personal OneDrive. The number is usually 3-5x the one in the last IT presentation.

  2. 02

    Split governed from drifting

    Apply the three orphan filters - no owners, no members, no activity in a year. Together they typically cover 40-60% of the sites.

  3. 03

    Sort the drifting half by exposure

    Sort by external users, then by anyone links. That ordering is the work queue: the abandoned sites somebody outside can still enter go first.

  4. 04

    Hand it to an automation

    Select the rows and enable a suggested automation - assign owners, expire external access, archive. Each proposal waits 72 hours for review, owners can be asked to confirm, and every executed action lands in Actions.

Beyond a site list

A list of sites is a start. This is a list of exposure.

Everything below sits on the same row as the site name, so the review is a sort, not a project.

  • Private and shared channel sites listed as the separate site collections they are, with their own membership
  • Personal OneDrives in the same list as SharePoint sites, same columns, same filters
  • External users, SharePoint-only guests, anyone links and org-wide links counted per site, not per file
  • Direct versus indirect members, so you see through which group people get in
  • Sites with no activity in a year that still hold live permissions and external access
  • Sensitive info counts per site from two engines - 1Security detectors and Purview labels
  • The Copilot-enabled flag on the same row as the sensitive info count
  • An activity sparkline that makes a suddenly busy dormant site obvious

Scale

The long tail is the point.

An inventory is only useful if it covers the sites nobody registered, so 1Security walks the whole tenant instead of the list an admin already knows about. It runs on the read-only connection, on standard Microsoft 365 licensing, with nothing to install - and it keeps up with tenants that hold tens of thousands of sites and tens of millions of files.

  • 500M+
    files in the largest tenants the inventory keeps current
  • 8
    live inventories on one graph - sites, files, users, groups, apps, agents, devices, emails
  • 0
    agents to install; read-only consent is all the inventory needs

Related

Where this fits

Sites are where the data sits, files are what sits in them, and governance is what you do about it. The same permission graph answers all three.

  • File permissions

    Who can open a given document, and the group or link that made it so.

    See files
  • SharePoint governance

    Turning the site list into ranked exposure and staged, reviewed fixes.

    See governance
  • Copilot security

    What AI can read today, counted per site before the rollout rather than after.

    See Copilot

FAQ

Questions teams ask first

Does the inventory include personal OneDrive?

Yes. Every user has one and it holds company data like any site, so OneDrives are listed with the same columns - external users, links, sensitive info, storage, activity. Site type is a filter, so you can exclude them when a review is only about SharePoint.

Are private channel sites really separate sites?

They are. Microsoft provisions a separate site collection for every private and shared channel, with its own membership. A review that only walks the parent site misses them - which is why they are broken out here.

How is "abandoned" decided?

Three independent signals rather than one score: no owners, no members, no activity in the last year. They overlap but not completely - a site can have owners on paper and no human activity for four quarters, which is a different problem from a site nobody is responsible for. Each is its own filter.

Can I see which sites Copilot can read?

Yes. Copilot-enabled is a column and a filter. Crossed with the sensitive info count it gives you the pre-rollout cleanup list - the most useful single report before widening an AI deployment.

Do we need write permissions or E5 to get the list?

No. The inventory runs on the read-only connection and standard Microsoft 365 licensing, with no agent to install. Actions on sites are a separately consented module, and even then every change stages behind a review window.

See how many sites you actually have.

Connect read-only and the full list - channel sites and OneDrives included - is ready the same day, with owners, activity, storage and external users on every row.

Or keep quoting the number from the last presentation.