Your input shapes our product. Suggest a feature now →
  1. Home
  2. Alerts
  3. SharePoint Advanced Management New Admin Role

SharePoint Advanced Management Gets a Dedicated Admin Role

Published 26 July 2026. Sources: Microsoft Tech Community - SharePoint Admin Agent showcase; Vlad Talks Tech - SAM 2026 overview.

SharePoint Advanced Management now has a dedicated administrator role that global administrators do not hold by default. Organisations running SAM for governance need to assign this role explicitly, or their governance team will not be able to access the suite's newest and most detailed reports.

What is the SharePoint Advanced Management Administrator role?

The "SharePoint Advanced Management Administrator" is a new Entra ID role introduced as part of the 2026 SAM expansion. It is separate from the standard SharePoint Administrator role and is not granted automatically to Global Administrators or SharePoint Administrators. Its primary purpose is to gate access to the file-level governance reports now available in SAM, including the new oversharing reports described below. An admin who needs to pull these reports but lacks this role will see them as inaccessible even with full SharePoint Admin rights.

To assign the role:

  1. Go to the Microsoft 365 admin center and navigate to Users, then Active users.
  2. Select the team member who needs governance report access.
  3. Choose Manage roles and search for "SharePoint Advanced Management Administrator".
  4. Assign the role and save.
Tip: assign the SAM Administrator role to every team member who runs monthly access reviews or produces compliance reports, not only the primary SharePoint admin. The role is scoped for governance work and does not carry full SharePoint admin authority, so it is safe to grant broadly within your governance team.

The SharePoint Admin Agent: governance from a chat interface

The headline addition to SharePoint Advanced Management in 2026 is the SharePoint Admin Agent, an AI assistant that reasons over SAM data and Microsoft 365 admin center information. Rather than exporting a CSV of inactive sites or running PnP PowerShell to find overshared libraries, admins can query the agent directly and receive analysis with recommended remediation steps.

The agent launched with 15 to 20 supported actions, with a stated Microsoft target of approximately 150 actions over time. Current capabilities include:

  • Tenant-wide permissions analysis with natural language explanations of oversharing risks and root causes
  • Surfacing inactive, ownerless, or high-risk sites with clear cleanup recommendations and exportable reporting
  • Storage usage analysis with optimisation suggestions across site collections
  • Multi-Geo configuration status checks
  • Backup management status review

The conversational agent interface requires a Microsoft 365 Copilot license. The underlying SAM reports and dashboards remain available without a Copilot license; the AI-driven query and chained-action execution layer is what requires it.

File-level oversharing reports

SharePoint Advanced Management now includes file-level oversharing reports that identify which specific files have been shared with the "Everyone Except External Users" built-in group. This is one of the most common and least-reviewed sharing patterns in Microsoft 365 tenants: a user grants broad internal access to a single file, and that exposure accumulates silently over months or years.

The reports are downloadable as Excel or Power BI datasets, making them compatible with existing spreadsheet-based governance workflows. Access is gated behind the new SAM Administrator role described above. Once you have the role assigned and pull the first report, the recommended workflow is to schedule a monthly review and assign remediation tasks to site owners via the SAM governance hub page.

For the broader picture of how shared links create governance risk, the guide to auditing SharePoint shared links covers the full audit process. ShareMaster's Report Master produces permission matrix exports at the library level, which complements the SAM file-level oversharing reports and gives a complete picture of who has access to what across all site collections.

What SharePoint admins should do now

  • Assign the SAM Administrator role to every governance team member who runs access reviews or produces compliance reports. Do this before pulling the new reports, as the role gate will otherwise make them appear inaccessible.
  • Open the SharePoint admin center and look for the Admin Agent interface. If your organisation holds Microsoft 365 Copilot licenses, run a few test governance queries before using the agent for production decisions.
  • Pull the first file-level oversharing report and identify which files are shared broadly with "Everyone Except External Users". Create a remediation queue from the output and schedule this as a recurring monthly review.
  • Review the SAM Catalog Management feature, which lets you organise sites into categories and groups, then scope reports and lifecycle policies to that structure. Set it up before enabling automated policy enforcement.

Explore Report Master for permission and storage reporting