Published On: October 1, 2026

Author

Prem Chandran

The Haunted SharePoint Site: 5 Things Lurking in Your Tenant

Every organization has a digital attic nobody has opened in years: a forgotten project site, an old shared folder, or a permission nobody remembers granting.

None of it got there because someone was careless. It is what naturally builds up when a Microsoft 365 environment has been busy for a few years. Projects end, people change roles, and cleanup keeps slipping down the list.

This Halloween, we are skipping the generic security reminders and shining a light on five things that could be hiding in your tenant, why they matter, and what you can do next.

Grab a flashlight.

1. The Site That Time Forgot

Every tenant has one: a SharePoint site created for a project that ended years ago, still holding the files, members, and sharing settings it had on launch day.

Nobody is using it, which is exactly why nobody is watching it.

Why it matters: An inactive site is not necessarily an empty site. It may still contain contracts, project plans, financial information, or other business content. Without an active owner, outdated access can remain in place longer than intended.

What to do: Start with your oldest or least active sites. Confirm that each one has:

  • A named business owner
    A recently reviewed access list
    A clear decision to keep, archive, or delete it

Some inactive-site management and access-review capabilities require SharePoint Advanced Management or eligible Microsoft 365 licensing.

When you open one of those forgotten sites, the next problem may already be waiting inside.

2. Anonymous Link, Anonymous Reader

“Anyone” links make sharing easy. The recipient does not need to sign in, and the link can be forwarded to someone else.

That convenience is also the risk.

Why it matters: Access through an Anyone link cannot be tied to an authenticated individual. If the link is forwarded or stored somewhere unexpected, someone outside the intended audience could use it until it expires or is revoked.

What to do: Review active Anyone links and remove those that no longer have a clear business purpose. Where unauthenticated sharing is required, use expiration policies and more restrictive sharing defaults to reduce unnecessary exposure.

Ask a simple question:

Would we still create this link today?

If the answer is no, it probably should not still be active.

Some sharing-link reporting capabilities require SharePoint Advanced Management or eligible Microsoft 365 licensing.

Sharing links are one way access can linger. People and group memberships are another.

3. The Ghost Permission

People move between departments. Contractors finish their assignments. Guest accounts remain active. Permissions inherited through groups are easy to overlook.

Over time, an access decision that once made sense can become difficult to explain.

Why it matters: Stale permissions and group memberships can leave people with access they no longer need. That increases exposure and makes it harder to demonstrate that access follows the principle of least privilege.

What to do: Make SharePoint, Teams, OneDrive, and shared-folder access an explicit part of offboarding and role-change processes. Regularly review:

  • Active guest accounts
  • Membership in permission groups
  • Direct access to sensitive sites
  • Files and folders with unique permissions

The goal is not to remove collaboration. It is to make sure access still reflects how people work today.

Attackers know users trust Microsoft 365 sharing experiences, which brings us to the next thing hiding in plain sight.

4. The Costume That Fools Everyone

A fake “Someone shared a file with you” message can look remarkably similar to a legitimate Microsoft 365 notification.

That disguise works because real sharing emails arrive all the time.

Why it matters: One convincing phishing message can lead someone to a fake sign-in page and expose their credentials. If that account is compromised, the attacker may gain access to the same sites and files the user can reach.

What to do: Encourage people to pause before opening unexpected sharing links, especially when the message creates a sense of urgency.

When something feels off:

Check the sender and destination carefully
Confirm the request through another channel
Open SharePoint or Teams directly instead of using the email link

A few extra seconds can prevent a much larger problem.

5. Could Copilot Find What You Forgot?

Here is the twist: Copilot does not create permission problems, and it does not bypass access controls. It works with the access a person already has.

That is what makes Copilot useful, but it also makes permissions, ownership, and content governance more important than ever.

Why it matters: Information that once stayed unnoticed because it was difficult to find may become easier for an authorized user to surface through a natural-language request. The underlying exposure already existed. Copilot can make it more visible.

What to do: Before expanding Copilot adoption, review access to your most sensitive and business-critical SharePoint sites. Confirm that owners, members, guests, links, and unique permissions still match a legitimate business need.

Where should you start?

If you only tackle one thing this week, begin with your oldest and least active SharePoint sites. Forgotten sites are where outdated content, abandoned links, unclear ownership, and stale access often come together. Reviewing them gives you a practical starting point without turning security cleanup into a haunted-house-sized project.

You do not need to fix everything overnight. You need visibility into what is there, clarity about who should have access, and a repeatable way to keep it under control.

Do you know what is hiding in your Microsoft 365 environment?Where should you start?

Creospark Secure Cloud helps organizations identify and reduce access and data-protection blind spots across Microsoft 365, so your people can collaborate confidently without leaving sensitive information unnecessarily exposed.

See how Secure Cloud can help you strengthen access, protect your data, and prepare for AI