SharePoint Advanced Management
By Emil Björk · Microsoft ecosystem consultant, Gothenburg
SharePoint Advanced Management adds governance, oversharing controls, and Copilot-ready controls to SharePoint Online.
3 min read
Share as imagePNGSharePoint Advanced Management (SAM) is a paid add-on for Microsoft 365 that ships extra governance, security, and lifecycle features on top of SharePoint Online. It's become especially important since Microsoft 365 Copilot launched — many of SAM's features are also bundled into Copilot prerequisites.
What's in SAM
The major capabilities, grouped:
Oversharing visibility
- Data access governance (DAG) reports for sites with too many people, "Everyone except external" usage, or sensitivity-label drift.
- Site lifecycle reports — inactive sites, sites with too many owners or none.
- Permissions reports scoped to a site, library, or item.
Sharing controls
- Restricted access controls at the site level — only specific Entra ID groups can access a given site, overriding sharing links.
- Block download policies — preview-only access from the browser, no local copies.
- Default sharing link types at site granularity.
- Site-level conditional access that ties into Intune compliance.
Lifecycle
- Inactive site policies — auto-flag, remind owners, and archive sites that haven't been touched in N days.
- Site archive — move a site to a low-cost archive state, recoverable, while removing it from active search and Copilot grounding.
Microsoft 365 Copilot readiness
SAM provides the inputs to two important Copilot-related reports: which sites are oversharing, and which should be excluded from Copilot grounding. Restricted access controls and archive policies are the two main levers.
Licensing
SAM is sold per user per month, with availability via a standalone SKU and as part of higher-tier plans and Copilot bundles. Tenants on E5 or Microsoft 365 Copilot increasingly find it included or heavily discounted.
Where SAM fits in your governance stack
SAM lives alongside:
- Microsoft Purview for retention, sensitivity labels, DLP, and eDiscovery.
- Entra ID Identity Governance for access reviews and entitlement management of the groups behind site permissions.
- Microsoft 365 admin center for the base lifecycle of groups and licences.
None of these replaces the others. SAM specifically handles SharePoint-level controls that the broader Purview and Entra tools can't see in granular detail.
For any organisation rolling out Copilot, SAM is no longer optional. It's the difference between an informed rollout and surprise oversharing.
Frequently asked questions
Do we need SAM if we're not deploying Copilot? The lifecycle and oversharing-visibility features (inactive site reports, permissions reports, restricted access controls) are useful on their own for any SharePoint estate that's grown past the point where admins can eyeball every site's permissions — Copilot is what made SAM urgent for most tenants, but the governance value stands independently of it.
How is SAM different from the sharing settings already in the SharePoint admin center? The baseline SharePoint admin center controls set tenant-wide defaults (external sharing on/off, link types). SAM operates at a finer grain — per-site restricted access tied to specific Entra ID groups, block-download policies, and reporting that surfaces which sites and files are actually oversharing right now, rather than just what the default policy theoretically allows.
What's the fastest first action with SAM? Run a data access governance report against the tenant's most active sites and look specifically for "Everyone except external users" grants and sites with an unusually high sharing-link count — those two signals catch the majority of real oversharing risk before any Copilot-specific tuning is needed.
Does restricting a site with SAM's access controls break existing sharing links? Restricted access controls scope who can reach the site at all, layered on top of (not replacing) whatever sharing links already exist — a link shared with someone outside the newly-restricted group stops resolving for them even though the link itself is technically still valid, which is the intended tightening but is worth testing on a pilot site before applying broadly, since it can surprise site owners who assumed existing links would keep working unconditionally.
Does SAM apply to OneDrive as well as SharePoint sites? Several SAM capabilities extend to OneDrive — notably block-download policies and some of the oversharing reports — since OneDrive for Business is itself built on the same SharePoint platform underneath. It's worth checking the specific feature's documented scope rather than assuming every SAM capability covers both uniformly, since a handful remain SharePoint-site-only.
Was this useful?
Spot something wrong or want a topic covered? Send it through the contact form.