Overview
The Collaboration Attack Surface Report for Email is a free risk assessment service that gives organizations complete visibility into how much sensitive data is leaving their Microsoft 365 tenant through external email. Think of it as DSPM for Email — it answers questions most organizations have never been able to answer before: How much sensitive data has left through email? Who received it? What is the actual risk? The report is offered to both prospects and existing customers at no charge. It serves as a baseline to understand email-based data exposure and identify remediation opportunities through eSHARE's Secure Mail Gateway.
Note: The scan covers a limited window of email activity.
The Problem This Solves
Organizations have spent years securing data at rest — endpoints, networks, cloud infrastructure, DLP tools — yet the most common external sharing channel of all has grown largely unmonitored: sanctioned email with attachments. Every employee has email. Every day, sensitive files leave the organization as attachments — permanently duplicated, no longer under organizational control, and largely invisible to security teams. Until now, organizations couldn't quantify this risk. The Collaboration Attack Surface Report changes that.
What the Report Shows
The report is anchored by a single headline metric: the Collaboration Attack Surface Score. This score measures the average number of file copies created per external recipient during the scan window — capturing the compounding nature of email-based data exposure. The report structures its insights around the contextual signals of Zero Trust, providing a comprehensive view of email sharing risk across six dimensions.
Who — Senders and Recipients
Identifies internal senders and external recipients of shared data, including unique recipient counts and external domains. Surfaces the top senders driving the highest data volumes and reveals the full scope of third parties with access to the organization's sensitive information.
What — Sensitivity Labels and Content Detection
Surfaces Microsoft Purview sensitivity labels applied to outbound emails and attachments, exposing gaps where emails carry labels but the files inside them do not. Also surfaces Sensitive Information Types (SITs) detected in shared content — flagging financial data, PII, government IDs, medical information, and other regulated categories.
Where — External Domains and Organizations
Shows which external organizations and domains have received data, with a breakdown between corporate domains (business partners, vendors) and consumer domains (Gmail, Yahoo, Outlook.com). Consumer domains present elevated risk as files landing there sit outside DLP, retention, and audit controls.
When — Timestamps and Trends
Provides timestamps for every external email and attachment share, enabling trend analysis and helping identify spikes in sharing activity tied to specific business events or time periods.
How — Share Types and Channels
Distinguishes between how files are shared externally:
Attachments — Physical file attached to the email. Once sent, the file is permanently outside organizational control.
M365 File Link — SharePoint or OneDrive link to a single file. Offers potential for access control if properly configured.
M365 Folder Link — SharePoint or OneDrive link to an entire folder. Often indicates B2B guest access; typically exposes significantly more data than file-level sharing.
Third-Party Cloud Links — Links to Box, Dropbox, ShareFile, WeTransfer, and similar services — the shadow IT signal surfaced in one place.
Every aggregate finding can be drilled down and traced to the specific email and file that produced it. The report provides a complete email details table — subject, sender, recipient count, attachment count and size, timestamp, and sensitivity label — as well as an attachment-level table showing file name, share type, detected SIT, size, file type, and timestamp.


Important Limitations
The assessment covers a fixed limited day scan window of historical email data. The report is a point-in-time assessment. Continuous ongoing monitoring is a planned future capability.
SIT detection can produce false positives. Use SIT findings as starting points for investigation rather than definitive conclusions.
Existing eSHARE Collaborate customers do not receive this capability automatically — it must be requested from your Customer Success Manager.
Getting Started
To enable the Collaboration Attack Surface Report, contact your Customer Success Manager and follow the next steps: Create CAS report