SharePoint Advanced Management, explained for Purview people
Purview protects the content. SharePoint Advanced Management controls who can reach it and whether the site should still exist. Here is the split, why you probably already own it, and the one control that solves Copilot oversharing before you have labelled anything.
One sentence version
Purview looks after the content. SharePoint Advanced Management looks after the container.
Purview answers "what is this file, how sensitive is it, and what should happen to it". SharePoint Advanced Management, usually shortened to SAM, answers "who can reach this site, should it still exist, and who owns it".
They barely overlap, which is why you need both. Almost every Copilot oversharing problem is a container problem wearing a content problem's clothes.
You probably already have it
This is the part that surprises people.
SAM is unlocked for your whole tenant as soon as one person holds a Microsoft 365 Copilot licence. Microsoft is explicit that the person does not even need to be an administrator. One licence, and every SharePoint admin in the tenant gets the features.
It is also included in Microsoft 365 E7, and it can be bought on its own as an add-on if you have no Copilot at all.
What does not include it is E5. That trips people up, because E5 includes almost everything else in this space. E5 on its own gets you a cut-down slice of one report and none of the controls. So if you have Copilot and have never opened SAM, you are leaving paid-for capability switched off.
The control that matters most right now
Restricted Content Discovery. It takes a site out of organisation-wide search and out of Copilot's reach, without changing a single permission.
That last part is the point. People who already had access keep it and can still open the files directly. You are not breaking anyone's work, you are stopping the site being *found* by someone who was never meant to be browsing it.
It also removes the AI entry points from the site itself, so no Copilot button and no agent creation there.
And for a Purview audience, the fact worth knowing: it does not affect eDiscovery or auto-labelling. Your compliance processes carry on seeing the content exactly as before.
Why Purview alone cannot do this
Purview's Copilot controls work on classification. DLP for Copilot keeps content out of Copilot's grounding based on sensitivity labels or sensitive information types. That is precise and it is the right long-term answer.
It is also no help at all on day one, because on day one nothing is labelled yet.
That is the gap SAM fills. Restricted Content Discovery works on the site, so it needs no labels, no classification and no scanning. You point at the HR site and it stops surfacing.
So the honest sequence is: use SAM to stop the bleeding this week, use Purview to fix it properly over the following months, then relax the SAM controls as labelling catches up. Microsoft frames Restricted Content Discovery as temporary for exactly that reason, and warns that leaving it on everywhere degrades how useful Copilot is.
The rest of it, briefly
Beyond that one control, SAM does three jobs Purview has no answer for:
Finding the mess. A one-click assessment that reports inactive sites, sites with no real owner, broken permission inheritance, sites shared with Everyone Except External Users, and where sharing links are being created fastest.
Handing the mess back. Site access reviews push the findings to site owners, who can act at file level. Purview admins are deliberately limited in what they can see item by item, so delegating is the only way this scales.
Keeping sites honest. Policies for minimum ownership, inactive sites, and recurring owner attestation that the site is still needed. Purview retention decides how long content lives; none of it asks whether the site should exist at all.
There is also a hard access boundary called Restricted Access Control, which limits a site to named groups regardless of existing permissions. Think of it as the container equivalent of label encryption.
How to think about the two together
Microsoft's own Copilot readiness guidance names exactly two products, Purview and SAM, and interleaves them. A useful way to hold it:
SAM front-loads. Purview sustains.
SAM is what you reach for in the first few weeks: find the oversharing, contain it by site, get owners to clean up, stop unowned sites accumulating. Blunt, fast, no classification required.
Purview is what keeps it fixed: labels, auto-labelling, DLP on Copilot prompts and grounding, insider risk, retention, eDiscovery. Precise, durable, and dependent on classification being in place.
If you only do the SAM half you have hidden the problem. If you only do the Purview half you will not survive the first month of Copilot. The teams that get this right run both, in that order.
Fourteen questions on visibility, access, classification and oversharing, so you know which half of this you need first.
Check your Copilot readinessPlan this in a tool
Free planners to design and test this before you deploy. No login.