Security assessment
Getting a tenant ready for Microsoft 365 Copilot: oversharing and data governance first
Copilot respects existing permissions, which is exactly why permissions matter. A practical sequence for finding overshared content, tightening access and putting governance in place before rollout.
Part of our guide: Microsoft 365 security assessment checklist (2026)
On this page
- Before you start: prerequisites and ownership
- Where oversharing hides
- Step 1: Find the exposure
- Step 2: Fix permissions where it matters most
- Step 3: Use temporary controls while you work
- Step 4: Classify and protect sensitive content
- Step 5: Put lasting governance in place
- Step 6: Roll out in waves
- Readiness checklist
- Common questions
- Measuring readiness
- How M365Assessments helps
Before Copilot, a salary spreadsheet accidentally shared with the whole company was a latent problem: someone had to stumble on it. With an AI assistant that searches everything a user can reach, a question like "what are the salaries in the finance team?" may surface it in seconds. The permission problem was always there; Copilot removes the obscurity that was hiding it.
Microsoft is clear that Copilot works within existing permissions. See data, privacy and security for Microsoft 365 Copilot. Readiness is therefore mostly about making those permissions right.
Before you start: prerequisites and ownership
- Technical requirements. Licensing, apps and network requirements are in Microsoft's Microsoft 365 Copilot requirements.
- An owner for the data work. IT can change settings, but deciding who should see HR, finance or legal content needs the business. Name a sponsor.
- Security basics in place. Copilot inherits your identity posture: if accounts can be taken over, so can everything Copilot can reach. The Conditional Access baseline and strong MFA come first.
Where oversharing hides
| Source | Why it's a problem |
|---|---|
| "Everyone except external users" on sites and folders | Grants access to every internal account, often added years ago for convenience. |
| Public Microsoft 365 groups and teams | Anyone in the organization can join, and their files are visible to all. |
| "People in your organization" sharing links | Work for anyone internal who has the link, and are discoverable once shared broadly. |
| Broken permission inheritance | Individual folders or files shared differently from their site, hard to see at a glance. |
| OneDrive files shared widely | Personal working files shared "with the company" to get feedback, never unshared. |
| Ownerless sites and teams | Nobody reviews who has access. |
External sharing matters too, and it's covered in safe external sharing and guest access.
Step 1: Find the exposure
Start with what's sensitive. List the sites and teams that hold HR, finance, legal, executive and customer data. These are the ones to get right first.
Use the reports available to you. SharePoint Advanced Management's data access governance reports show sites with content shared with "everyone" or through organization-wide links, and the most-shared sites. Check SharePoint Advanced Management for current licensing; Microsoft has made some of its features available to Copilot customers.
Use Microsoft Purview if you have it. Data Security Posture Management for AI can highlight oversharing risks and sensitive data used in AI interactions, depending on licensing.
Ask site owners. A short attestation ("who should have access to this site?") catches what reports can't judge.
Microsoft also publishes guidance for this exercise in its secure and governed data foundation for Copilot.
Step 2: Fix permissions where it matters most
- Remove "Everyone" and "Everyone except external users" from sensitive sites, folders and libraries; grant access through the site's own groups.
- Make sensitive teams and groups private, and review their membership.
- Expire or remove organization-wide links on sensitive content.
- Restore inheritance where unique permissions aren't needed.
- Assign at least two current owners to every sensitive site and team.
- Change the default sharing link to Specific people so new oversharing slows down.
Step 3: Use temporary controls while you work
Permission clean-up takes time. Microsoft provides controls that reduce what Copilot and search surface while it happens:
- Restricted content discovery (SharePoint Advanced Management) excludes specific sites from Copilot and organization-wide search results, without changing who can open them directly.
- Restricted SharePoint Search limits organization-wide search and Copilot to an allowed list of sites plus the content users own or have interacted with.
Treat these as scaffolding. They reduce discovery, not access: anyone with a direct link and permission can still open the content, so the permission fixes in step 2 are still needed.
Step 4: Classify and protect sensitive content
Sensitivity labels give content a classification that travels with it. With encryption applied, labels can restrict who can open a file regardless of where it's stored, and Copilot honors those usage rights. A practical start:
- Publish a small label set (for example Public, General, Confidential, Highly Confidential) with clear descriptions.
- Apply labels to sensitive sites and teams so their sharing and privacy settings follow the classification. See labels for Teams, groups and sites.
- Set a default label for new documents in sensitive libraries.
- Use data loss prevention policies for the data types that matter to you, starting in test mode.
Step 5: Put lasting governance in place
- Site lifecycle: inactive-site and ownerless-site policies, so abandoned content is archived or removed.
- Access reviews for sensitive groups and sites, quarterly.
- Retention policies so old content that should have been deleted isn't there for Copilot to find.
- App access: Copilot extensions and connectors can bring in more data; review them like any other app. See finding risky OAuth apps.
- Audit: confirm audit logging is on so Copilot interactions can be reviewed if needed.
Step 6: Roll out in waves
Start with a pilot group whose data you've reviewed, such as IT and a willing business team. Collect questions about what Copilot surfaced that surprised people: each surprise is an oversharing finding. Fix, then widen the rollout. Keep usage in view with Microsoft 365 usage reports, and reclaim licenses from people who don't use them.
Readiness checklist
- Identity baseline in place: MFA, Conditional Access, no legacy authentication.
- Sensitive sites and teams identified, with owners.
- "Everyone" access removed from sensitive locations.
- Default sharing link is Specific people.
- Temporary discovery controls in place for sites still being fixed.
- Sensitivity labels published and applied to sensitive content.
- Retention and lifecycle policies cover old content.
- Pilot group chosen, with a way to report surprises.
Common questions
Does Copilot give people access to things they couldn't see before?
No. It works with the signed-in user's existing permissions. The risk is that it makes content people could technically already open much easier to find.
Can we wait until the clean-up is finished?
You can, but clean-ups rarely finish. A better approach is to fix the most sensitive locations first, use temporary discovery controls for the rest, and pilot with a group whose data you've reviewed.
Is this only about Copilot?
No. The same oversharing affects organization-wide search, and any compromised account can reach the same content. Fixing it reduces risk whether or not you roll out Copilot.
Measuring readiness
Pick a few numbers you can re-check each month: sensitive sites with "everyone" access, organization-wide links on sensitive content, ownerless sites and teams, and the share of sensitive sites with a sensitivity label applied. Report the trend alongside Copilot adoption, so leadership sees data governance and rollout progressing together rather than as competing projects.
How M365Assessments helps
M365Assessments includes a Copilot readiness view alongside its security findings: Microsoft 365 Copilot license and usage data from the Core module, and, with the early-access SharePoint & OneDrive module, tenant sharing settings, site inventory and anonymous links in sampled sites. The Exchange & Security module adds Purview signals such as sensitivity labels and DLP policies. See M365Assessments for IT teams and modules explained.