ES
All articles
  • Copilot
  • SharePoint
  • Security
  • Purview

Copilot didn't leak it, it just found it: oversharing in Microsoft 365

Copilot respects permissions, including the ones nobody remembers granting. What to review in SharePoint, OneDrive and Teams before switching it on.

Cover: padlock icon on a black and gold background, oversharing in Microsoft 365 before Copilot

Picture a file called Salaries_2021_FINAL_v3.xlsx. Someone shared it with "People in your organization" on a Friday afternoon in 2021, to save a colleague a couple of clicks. Nobody has opened it since. Nobody remembers it exists.

For three years it was protected by the most popular security control in Microsoft 365: nobody knew where it was.

Then Copilot arrives.

Is Copilot a data leak risk?

Not in the way people usually fear. According to Microsoft, Copilot only surfaces organisational data that each user can already access with at least view permissions. It doesn't break permissions, bypass them or invent new ones.

That is the good news. The bad news is that it respects all of them: the sharing link created in 2021, the site where "Everyone except external users" was added "just for the project", and the Team whose owner left the company two years ago.

Before Copilot, finding that spreadsheet meant knowing it existed and where to look. With Copilot, someone just has to ask the right question. The permission was always wrong; Copilot simply makes it findable.

So the useful question before a rollout isn't "is Copilot secure?" but "are our permissions what we think they are?".

Where does oversharing usually hide?

In our experience, in four places. None of them needs a new licence to check.

Links set to "Anyone" or "People in your organization" in libraries with HR, finance, legal or management content. They're convenient, they don't expire unless someone configures it, and they're invisible to whoever didn't create them.

What to do: in the SharePoint admin center (Policies › Sharing), set the default link type to Specific people and add an expiry to "Anyone" links, or turn them off. Then review the existing links on sensitive sites.

2. "Everyone except external users"

This group includes every internal account in the tenant. When it's a member of a site, or has access to a folder, that content is effectively open to the whole company.

What to do: find where it has been granted and replace it with the groups that actually need access.

3. Teams and sites without an owner

A Team without an active owner is a Team nobody reviews. Members come and go, guests stay and the content keeps growing.

What to do: make sure every Team and site has at least two active owners, and turn on the ownerless group policy in the Microsoft 365 admin center so it doesn't silently happen again.

4. Sensitivity labels that only exist on paper

Many tenants have labels published. Far fewer have them applied to the content that matters. A label nobody uses protects nothing.

What to do: start with a small set of labels people understand, apply them by default to the most sensitive sites, and only then think about automatic labelling.

Which tools help, and which do you already have?

  • Data access governance reports (SharePoint Advanced Management): sharing links created in the last 28 days, content shared with "Everyone except external users" and a snapshot of site permissions across the organisation.
  • Restricted Content Discovery: keeps a site out of organisation-wide search and Copilot without touching its permissions. Ideal for containing the worst sites while you clean them up.
  • Microsoft Purview DSPM: its data risk assessments show which sensitive content is overshared and where Copilot and agents could reach it.

The first two come with SharePoint Advanced Management, which is included when the tenant has Microsoft 365 Copilot licences.

In what order should you tackle it?

  1. Measure: run the reports and list the ten most exposed sites.
  2. Contain: if Copilot is already live, apply Restricted Content Discovery to the worst ones.
  3. Fix: remove broad groups and links, assign owners, apply labels.
  4. Prevent: change the sharing defaults and schedule periodic access reviews.

This isn't a six-month project. For most small and mid-sized tenants, the first pass is a few days of focused work. The hard part is deciding to look.

Our take

Copilot doesn't create new data risks: it turns the ones you already had into answers. If you're about to roll it out, or already have without reviewing permissions first, start with a sharing report. You'll probably find your own Salaries_2021_FINAL_v3.xlsx.

If you'd like an outside view of your tenant before (or after) switching Copilot on, tell us in three lines.

Frequently asked questions

Can Copilot show a user files they don't have access to?
No. Copilot only uses content the user can already open with at least view permissions. The problem is that many users can open far more than anyone thinks.
Do I need an extra licence to find oversharing?
Not to get started. The SharePoint admin center and site permissions are available in any plan, and SharePoint Advanced Management (data access governance reports, Restricted Content Discovery) is included when the tenant has Microsoft 365 Copilot licences.
Should I wait to roll out Copilot until everything is clean?
Not necessarily. Fix the most exposed sites first and use Restricted Content Discovery on the ones you can't clean up in time. Copilot can go live while the rest of the review continues.
What does Restricted Content Discovery actually do?
It keeps a site out of organisation-wide search and Copilot results without changing its permissions. People who use the site keep working as usual. It is a way to contain, not a fix: the permissions still need reviewing.
Share

Need a hand with this?

Tell us your case in three lines and we'll tell you where to start.

Get in touch

Don't miss the next articles

We publish when we have something useful to say: security, licensing, Copilot and automation in Microsoft 365, no filler.

The feed works with any news reader (Feedly, Outlook, Thunderbird…).