Microsoft 365 Copilot oversharing: fix permissions before you switch it on
Microsoft 365 Copilot can summarize a contract, draft a reply from a long email thread, or answer “what did we agree with this client last quarter?” by searching across your email, Teams chats, SharePoint and OneDrive.
That last part is where the risk lies.
Copilot does not break permissions. It exposes them
Copilot only returns content the signed-in user can already access. That sounds safe until you consider how permissions build up over the years in a typical Microsoft 365 tenant:
- A salary spreadsheet shared with an “anyone in the organization” link years ago, to make it easy to send to one manager.
- A SharePoint site created for a project, with access set to “everyone except external users”.
- A departed executive’s OneDrive files, shared broadly and never cleaned up.
- Teams channels that started private and gradually gained everyone.
Before Copilot, nobody stumbled across these files because nobody knew where to look. With Copilot, a junior employee asking “what are the salary bands for managers?” may get an answer.
Step 1: Find the oversharing
Start with the biggest exposures:
- Sites and teams open to everyone. Look for SharePoint sites and Teams whose membership includes “Everyone” or “Everyone except external users”.
- Broad sharing links. Review “Anyone” (anonymous) and “People in your organization” links, especially on files in finance, HR, legal and leadership locations.
- Sensitive data locations. Identify where payroll, HR records, client files, contracts and health or financial information actually live.
- Stale content. Old project sites and departed users’ files are frequently overshared and rarely needed.
Microsoft provides reporting for sharing and site access in the SharePoint admin centre and Microsoft Purview. The tooling available depends on your licences.
Step 2: Fix the defaults and the worst exposures
- Change the default sharing link type from organization-wide to “specific people”.
- Remove or restrict organization-wide access on sensitive sites, and assign owners who review membership.
- Expire or remove anonymous and organization-wide links on sensitive content.
- Archive or delete stale sites that no longer serve a purpose.
Step 3: Label and protect what matters most
Permissions get messy again over time. Sensitivity labels travel with the file. A document labelled Confidential – HR can be encrypted and restricted to specific groups wherever it ends up. Pair labels with data loss prevention policies to stop sensitive information being shared externally.
Start small: three or four labels that staff understand will be used more than a dozen nobody remembers.
Step 4: Roll out in stages
Do not switch Copilot on for everyone at once.
- Start with a pilot group, ideally including someone from HR or finance who knows what should not be visible.
- Have the pilot group deliberately ask questions about sensitive topics and report what comes back.
- Fix what they find, then expand by department.
Step 5: Write the rules down
An AI acceptable-use policy should cover:
- Which AI tools are approved, and which are not
- What data must never be entered into any AI tool, such as client confidential information, health information and credentials
- That AI output must be checked by a person before it is relied on or sent to a client
- Who to ask when unsure
This matters even if you never buy Copilot. Staff are already using free AI tools, and the policy is what keeps client data out of them.
Where to start
If you are considering Copilot, or suspect staff are already pasting company data into public AI tools, our Secure AI Adoption service starts with an oversharing and permissions report that ranks fixes by risk. If your Microsoft 365 tenant has never had a security review, start with Cloud & Microsoft 365.
Frequently asked questions
Can Copilot show users files they do not have permission to see?
No. Copilot works within each user's existing permissions. But if a file has been shared with the whole organization, or sits on a site everyone can access, that user does have permission. Copilot just makes it much easier to find.
What is the quickest way to reduce oversharing risk?
Find sites and libraries that are open to everyone in the organization, review organization-wide and anonymous sharing links on sensitive content, and restrict the default sharing link type. Then label and protect your most sensitive data, such as HR, finance, legal and client files.
Do we need a policy for ChatGPT and other public AI tools?
Yes. Staff often paste company data into free AI tools that may retain it. An acceptable-use policy should list approved tools, define data that must never be entered, and explain how to check AI output before relying on it.