Preventing Copilot Oversharing: Fix Permissions First
By Gordon Graff · Published
Microsoft 365 Copilot only accesses content that the individual user already has permission to access. Copilot does not bypass permissions – Microsoft states this explicitly in its data, privacy and security documentation.
That is exactly where the risk lies: in many tenants, files and sites have been shared far more widely over the years than intended. Content that used to stay buried in SharePoint is found and summarised by Copilot in seconds – salary lists, draft contracts or HR records, for example.
The most common causes of oversharing
- Permissions granted to “Everyone except external users” or similar organisation-wide groups.
- Organisation-wide sharing links (“People in your organisation with the link”) that spread.
- Public Microsoft 365 groups and teams whose files every employee can read.
- Sites without a clear owner whose permissions nobody oversees anymore.
Step 1: create visibility
SharePoint Advanced Management provides data access governance reports, for example on sites with many organisation-wide links or with permissions for “Everyone except external users”. Availability and scope depend on your licensing.
Microsoft Purview (content search, activity explorer) and a simple prioritisation help as well: which sites hold particularly sensitive data, and who has access there?
Step 2: clean up and protect
- Reduce organisation-wide permissions to specific groups and assign site owners.
- Use private rather than public teams for confidential topics.
- Set the tenant-wide default sharing link to “Specific people”.
- Classify confidential content with sensitivity labels and encrypt where needed – Copilot respects the usage rights of encrypted content.
- Introduce site access reviews by site owners so permissions stay maintained over time.
Interim measure: Restricted SharePoint Search
If the clean-up takes time, Restricted SharePoint Search can limit organisation-wide search and the Copilot experience to a curated list of sites. Microsoft explicitly describes this as a temporary measure – it does not replace a sound permission structure.
Pilot instead of big bang
A Copilot pilot with a manageable group from different departments quickly shows whether content still appears where it should not. The findings feed into the clean-up before Copilot is rolled out broadly.
Key takeaway
Rolling out Copilot is primarily a permissions project. Creating visibility up front, reducing organisation-wide sharing and classifying confidential content lets you use Copilot safely – and improves data security across the whole tenant along the way.