Skip to main content

Cornell University

Security Reviews for SharePoint Sites

Protect information which may unintentionally be visible to the entire Cornell community through search and AI tools.

This article applies to: SharePoint

SharePoint owners need to protect information which may unintentionally be visible to the entire Cornell community through search and AI tools. Here's how to review and respond to email notices.

SharePoint Sites Include Teams Channels

When you create a Teams channel Microsoft automatically creates a SharePoint site within its ecosystem. Use the steps under Review Shared Teams Permissions below.

Review SharePoint Permissions Following an Email Prompt

Always check the Cornell Verified Communications to confirm you have received a legitimate email. Email notices sent to owners of SharePoint sites look similar to the following:

your Sharepoint administrator has requested you to review the permissions on this site

If the email you receive refers to a Teams channel or a Team, "Connected to Teams" appears below the site name. Follow these instructions for a Teams channel or a Team.

""

To review a SharePoint site:

  1. From the email, click the Site name in the table row.
  2. In the SharePoint site, the Action column is at the far right edge.  This web application does not provide a horizontal scroll bar to access the column. Expand the browser window to its widest width or reduce the content in order to find that column.
  3. Select the pencil iconby Manage Access in the Action column to change settings.
  4. Modify any permissions no longer needed.
  5. Select the blue Complete Review button when permission changes are satisfactory.
Screenshot of SharePoint site permissions

Review Teams Channel Permissions Following an Email Prompt

Always check the Cornell Verified Communications to confirm you have received a legitimate email. Email notices sent to owners of SharePoint sites look similar to the following:

your Sharepoint administrator has requested you to review the permissions on this site

If the email you receive refers to a Teams channel or a Team, "Connected to Teams" appears below the site name.

""

You need to do the following:

  1. In Teams go to the channel (or Team) and click on the triple dots to the right of the channel name. (This might be hidden under a date.)

    ""
  2. Click Manage Channel (or Manage Team).

    ""
  3. Review Owners, Members, and Teams. (For a Team, click on Members to review Members and Members and guests.)

    ""
  4. If you do not want to change permissions, then raise awareness in your Team or channel about file sharing in the age of AI.

Review SharePoint Sites At Any Time

To review the settings on a SharePoint site that you own: 

  1. Go to your SharePoint site
  2. Click Settings (Gear icon) at the top right

    The gear icon appears to the left of the profile image
  3. Click either Shared With or Site Permissions

    ""
  4. Click either Advanced or Advanced Permissions Settings 

    Advanced permissions is the last menu item
    TIP: if a folder’s permissions are set to “Everyone except external users” then all files in that folder will be visible to the same group. Once you change the folder’s permissions, files in that folder will now reflect that new status. 

As generative AI use at the university expands, files that lack appropriate viewing permissions will be exposed to individuals and uses for which they were not intended. Our goal is to help you prevent this unintended exposure. If you need help with site permissions, please contact the IT Service Desk. Here are some additional resources to help you manage your data.

Comments?

To share feedback about this page or request support, log in with your NetID

At Cornell we value your privacy. To view
our university's privacy practices, including
information use and third parties, visit University Privacy.