Skip to content
For Microsoft 365 · Built for MSPs

Find every overshared file before Copilot does.

TrueNorth Exposure Scan is a read-only check of SharePoint, OneDrive and Teams. In about ten minutes it finds public links, company-wide shares, stale guests and excess admins, then hands you a scored report with the fix for each one.

Read-only permissions Never opens file contents Revoke in one click
The problem

Copilot doesn't create new access. It reveals the access you already gave away.

Copilot answers from anything a user can open. Years of "share with anyone" links, company-wide folders and forgotten guests turn into answers anyone can get by asking.

  • 01
    Links nobody remembers"Anyone" links need no sign-in. When one gets forwarded, the file is effectively public.
  • 02
    Org-wide by defaultBudgets, HR files and acquisition notes shared with "everyone" become searchable through Copilot.
  • 03
    Guests who never leftFormer vendors and MSPs often keep access, and sometimes admin rights, long after the contract ends.
How it works

Connect, scan, fix. No agents, no change requests.

STEP 1 · 5 MIN

Admin approves read-only access

A Global Admin reviews four read-only Microsoft Graph permissions and clicks Accept. That's the whole install.

STEP 2 · ~10 MIN

The scan maps your exposure

Every site, library and shared item is checked for link type, scope and expiry, along with guests, admin roles and tenant sharing settings.

STEP 3 · SAME DAY

You get a scored fix list

An A–F grade, a Copilot readiness verdict, and plain-language fixes ranked by risk. Export to PDF or CSV.

What it checks

Nine checks that matter most before Copilot.

Critical

Sensitive files on public links

Payroll, SSN, contract, tax and legal file names exposed through Anyone links.

Critical

Guests holding admin roles

Outside identities that can administer your tenant.

High

All "Anyone" links

Every unauthenticated link across SharePoint, OneDrive and Teams.

High

Tenant-level sharing

Whether your organization allows Anyone links at all.

High

Too many Global Admins

Microsoft recommends fewer than five. Most small businesses have more than that.

Medium

Links that never expire

Public links that stay live long after the project ends.

Medium

Org-wide sharing

Content every employee and Copilot can reach.

Medium

Direct external shares

Files shared with outside email addresses.

Medium

Stale guests

Guest accounts with no sign-in for 90+ days.

Trust by design

It can look. It can't touch.

The scanner is built so that the worst case is a list of file names. It has no write permissions, never downloads documents, and blocks every write call in code.

  • Metadata only: names, paths, link scopes, and who has access
  • Encrypted in transit and at rest, hosted in U.S. Azure regions
  • Scan data deleted automatically after 90 days
  • Revoke anytime by deleting the app in Microsoft Entra

Read the security overview →

MICROSOFT GRAPH PERMISSIONS REQUESTED
Sites.Read.AllRead site and file sharing metadata
Directory.Read.AllRead guests, admin roles and licences
AuditLog.Read.AllRead guest last sign-in dates
SharePointTenantSettings.Read.AllRead tenant sharing policy

0 WRITE PERMISSIONS · 0 FILE DOWNLOADS

Pricing

Start with one review. Keep watch for less than an hour of IT time.

Copilot Readiness Review

$2,500 one-time
  • Full tenant scan and scored report
  • 45-minute findings walkthrough
  • Prioritized fix plan
  • Rescan after fixes
Book a review

MSP Partner

$79 / client tenant / month
  • White-label reports under your brand
  • Multi-tenant onboarding links
  • $2,000 wholesale Readiness Review
  • You keep the client relationship
Become a partner

Founding partner offer: the first five MSPs get 50% off monitoring for six months, plus one free client review. Annual plans get two months free. Prices exclude applicable taxes.

Questions

What admins ask first.

Can the scanner change anything in our tenant?

No. It requests only read permissions, and the code refuses any write request. Nothing is modified, deleted or re-shared. You make the fixes, or your MSP does.

Do you read our documents?

No. We read sharing metadata, such as a file's name, location, link type and who it is shared with. We never download file contents, email or chat.

We don't use Copilot yet. Is this still useful?

Yes. Public links and stale guests are a data-leak risk with or without AI. Copilot just makes them easier to find.

How do MSPs use it?

You send each client an onboarding link, the client admin approves, and reports come out under your logo. You set the resale price and keep the relationship.

How do we remove access?

Delete the "TrueNorth Exposure Scan" enterprise application in Microsoft Entra ID. Access ends immediately, and we delete your data within 30 days.

Know what Copilot will see, before it sees it.

Book a Readiness Review, or have your MSP request partner access.

Book a review Sample report