Guide
Before you roll out Microsoft 365 Copilot: an oversharing and permissions checklist
Microsoft 365 Copilot only surfaces organisational data a user already has at least view permission to, so the risk before rollout is access that is wider than anyone meant it to be. Microsoft’s own deployment guidance puts remediating oversharing first. Find the overshared, ownerless and inactive sites. Keep the riskiest out of Copilot with Restricted Content Discovery and data loss prevention for Copilot while the fix runs. Then remove company-wide access such as “Everyone except external users”, rescope sharing links, repair broken inheritance, label sensitive sites and files, and send site owners access reviews. Finally, set defaults so new sites do not reopen the problem.
Microsoft 365 Copilot oversharing. Oversharing, for Microsoft 365 Copilot, is content in SharePoint, OneDrive or Teams that more people can open than should, which Copilot can then use to answer their prompts.
Checked . Microsoft Learn’s pages on Copilot data and privacy, the secure and governed foundation guidance, SharePoint sharing links and settings, Restricted Content Discovery, Restricted SharePoint Search, restricted access control, data access governance reports, site access reviews, SharePoint Advanced Management, Purview DLP and sensitivity labels, and Microsoft Entra access reviews, and the GDS Copilot experiment report on GOV.UK, were read on this date. Microsoft’s newer pages call the product Microsoft Copilot.
The checklist: eight checks before Copilot goes live
Run the assessment
Run SharePoint Advanced Management’s content management assessment and the data access governance reports, and list every site that is open to everyone, shared by broad links, broken in its inheritance, ownerless or inactive.
Protect the riskiest sites for now
Put Restricted Content Discovery on the high-risk sites under review and a Copilot data loss prevention policy on your most sensitive labels, then ask Copilot for their content as an ordinary user to prove both work.
Remove company-wide access
Take “Everyone except external users” out of SharePoint groups and off individual items, and rescope sharing links to named people or groups.
Repair inheritance and ownership
Fix broken permission inheritance on libraries and folders, and give every site an owner who is still in the business.
Send owners their reviews
Start site access reviews so owners check exposure down to the file, and schedule Microsoft Entra access reviews for the groups that grant the access.
Label what is sensitive
Enable sensitivity labels for files in SharePoint and OneDrive, label sites as well as files, and use encryption where Copilot has to respect usage rights.
Make new sites start closed
Set the default sharing link narrower than the organisation-wide link, expire Anyone links or turn them off, require a label when a site is created and use restricted access control on business-critical sites.
Lift the interim controls, then keep watching
Take Restricted Content Discovery off each site once its access is fixed, then watch Copilot activity in Purview and rerun the assessment every 30 days.
| Dimension | What “not ready” looks like |
|---|---|
| Run the assessment | Nobody can say which sites are open to the whole company. |
| Protect the riskiest sites for now | The rollout waits for a perfect tenant, or goes ahead with HR and finance content in reach. |
| Remove company-wide access | “Everyone except external users” still sits in the members group of a sensitive site. |
| Repair inheritance and ownership | Folders with unique permissions nobody can explain, and sites whose only owner has left. |
| Send owners their reviews | A one-off clean-up by administrators, with no owner sign-off and no date to repeat it. |
| Label what is sensitive | A label scheme in a policy document, and unlabelled files in the tenant. |
| Make new sites start closed | Every new site starts as open as the last one. |
| Lift the interim controls, then keep watching | Sites restricted months ago with no owner and no date to come out. |
Why Copilot turns old sharing mistakes into answers
Microsoft’s position is precise. Copilot only surfaces organisational data that an individual user has at least view permission to, and its Semantic Index only reaches content the current user is authorised to access [1]. None of that is wrong. The trouble is what view permission means in a tenant that has been collaborating for years: the HR site shared with the whole company for one policy launch, the finance folder whose inheritance was broken for a project that ended, the team made public because private was one more click.
While finding a file meant knowing it existed, most of that access sat unused. Copilot does the finding, on every prompt, so access that was technically open and practically hidden becomes an answer. Microsoft’s deployment guidance for Copilot treats this as step one, ahead of guardrails and regulatory work: remediate oversharing, then set guardrails, then meet regulations [2].
The UK government flagged the same risk at scale. In its cross-government Microsoft 365 Copilot experiment, with 20,000 government employees from 30 September to 31 December 2024, the Government Digital Service reported that Copilot’s searching with a user’s access “may highlight issues when users have access to files they shouldn’t”, and told organisations to bring their information and knowledge management up to date [3].
My view is that this clean-up belongs at the start of a Copilot rollout, and a plan that leaves it for after launch is the wrong plan. Switching licences on over an unreviewed tenant is an expensive way to run an access review, because your staff find the problems before your administrators do. If Copilot is not yet settled as your assistant, a side-by-side of the ChatGPT and Claude enterprise plans covers what each of those vendors publishes on admin controls and data location.
Where the oversharing actually sits
Oversharing is rarely one bad decision. It is a handful of small mechanisms, and Microsoft’s reports find each of them separately. This is what to look for, how each one reaches Copilot and which report shows it.
| Dimension | How it reaches Copilot | What finds it |
|---|---|---|
| “Everyone except external users” | A built-in SharePoint group holding every internal user. Content shared with it, or a SharePoint group that contains it, is open to the whole organisation at once | The site permissions snapshot report and the 28-day activity report for content shared with this group |
| “Specific people” links | The item appears in search and is reachable through Copilot for every user and security group member added to the link | The sharing links activity report |
| “People in your organization” links | Nothing until someone opens the link. Sending it from SharePoint, OneDrive, Outlook or a Teams chat redeems it for up to 100 individual recipients | The sharing links activity report and the content management assessment |
| “Anyone” links | No sign-in and no audit of who used it. Not in search or Copilot until redeemed, but the file is out of your control once the link travels | The sharing links activity report |
| Broken inheritance | Libraries, folders and files carrying their own permissions, which a review of the site’s members never sees | The content management assessment’s broken inheritance report |
| Ownerless and inactive sites | Nobody left to say who should have access, and stale content feeding answers | The content management assessment’s site ownership report and its inactive sites report (no activity in 180 days) |
The link rows are from Microsoft’s explanation of how shareable links work [6], and the group, inheritance and ownership rows from its pages on data access governance reports and the content management assessment [4, 5]. The detail on “People in your organization” links matters. They only become Copilot’s business once redeemed, but posting one in an email to a hundred colleagues redeems it for each of them [6].
Two points are my reading rather than Microsoft’s words. “Everyone except external users” is the one to fix first, because it opens a site to everybody at once without any link having to travel. And ownerless sites are the ones that stall the whole project, because the review process Microsoft offers is addressed to a site owner [14].
Hide the riskiest sites while you fix them
The access fix runs at the pace of site owners, and the rollout rarely waits for it. Microsoft’s answer is interim protection: keep sensitive sites out of Copilot’s reach while their access is corrected, check that it holds, then take it off [2]. There are two tools for this, and they do different jobs.
- Restricted Content Discovery
- A site-level setting that keeps a SharePoint site’s content out of organisation-wide search and Copilot responses, and removes the Copilot entry points from the site. It changes no permissions: people with access still open files directly, and still find content they own or used recently. It covers SharePoint sites, not OneDrive, and on a site with more than 500,000 items a change can take more than a week to reach search and Copilot.
- Data loss prevention for Copilot
- A Microsoft Purview DLP policy on the Microsoft 365 Copilot and Copilot Chat location can stop Copilot processing files and emails that carry the sensitivity labels you name. The item can still appear in a response’s citations, but its content is not used. Other rules keep prompts that contain chosen sensitive information types off web search and, in preview, stop Copilot answering such prompts at all or using email from outside senders.
The Restricted Content Discovery detail is from Microsoft’s page on it [9], and the DLP detail from Purview’s page on the Copilot location [11]. Microsoft now points to Restricted Content Discovery in place of Restricted SharePoint Search, the older allow-list approach capped at 100 sites, which it is retiring: new enablement has been blocked since 31 July 2026 [10], so a tenant still running it should plan its removal into the same project.
Microsoft asks for Restricted Content Discovery to be used selectively, because every site behind it makes Copilot’s answers less complete [9]. I agree, and I would add a date: each restricted site gets an owner and a target date to come out, or interim becomes permanent. Then prove the protection works by asking Copilot, as an ordinary user, for something the site holds, and confirm it in Purview’s audit records, which Microsoft’s guidance also asks for [2].
Two DLP details catch people out. A policy change can take up to four hours to reach Copilot, and DLP does not scan files a user uploads straight into a prompt, only the text they type [11].
Fix the access itself
Interim protection buys time. The fix is removing access nobody should have, and Microsoft’s guidance splits the work between administrators and site owners [2].
- Take the baseline
- Run the site permissions snapshot report first, then the sharing links and “Everyone except external users” activity reports, which cover the last 28 days. Microsoft suggests the snapshot quarterly and the activity reports monthly.
- Remove company-wide access
- Take “Everyone except external users” out of SharePoint groups and off individual files and folders, and rescope sharing links to named people or groups.
- Hand sites to their owners
- A site access review emails the owner a request tailored to the problem found, with a page showing exposure down to the file. Administrators can start reviews for up to 100 sites from the report view, use PowerShell beyond that, and start up to 1,000 a month from the site permissions report. Reviews cover SharePoint sites, not OneDrive.
- Repair inheritance and ownership
- Correct broken permission inheritance on libraries and folders, and confirm an accountable owner for every site you remediate with a site ownership policy.
- Lock the business-critical sites
- Restricted access control limits a site to the members of up to 10 Microsoft 365 or Microsoft Entra security groups. Someone outside those groups cannot open the site, even with a direct permission or a link, and Copilot and organisation-wide search honour the restriction.
The baseline is from Microsoft’s page on data access governance reports [5], the removals and ownership steps from its Copilot foundation guidance [2], the reviews from its page on site access reviews [14] and restricted access control from its own page [15].
Restricted access control is stronger than Restricted Content Discovery, because it changes who can get in rather than what search shows. It is also blunter. Membership of the control group grants nothing on its own, and a user needs both the site permission and the membership [15], so test it with the people who actually do the work before it goes on a busy site.
Group membership is the other half, because most SharePoint access runs through groups. Microsoft Entra access reviews ask group owners or named reviewers to recertify who is in a group on a schedule, guests included [16]. The cleaner answer for staff is to stop managing membership by hand and drive it from the HR record, so leavers lose access because a record changed rather than because somebody remembered. A worked example of provisioning access from the HR record, for more than 1,000 users across 600 groups, is in the case files.
What sensitivity labels do for Copilot, and what they do not
Labels come up in every Copilot plan, and they are credited with more than they do. Microsoft describes what they add for AI [12]. When a labelled file or email is open in Word, Excel, PowerPoint or Outlook, the app shows the label and its markings. Where the label applies encryption, a user needs the EXTRACT usage right as well as VIEW for Copilot to return that data.
So a label without encryption removes nobody’s access and does not stop Copilot using the file for someone who can open it. To keep labelled content out of Copilot’s answers you need the DLP rule above, which acts on the label [11]. Labels and DLP are one control in practice, and I would design them together.
Two settings make labels count against oversharing. Enable sensitivity labels for Office files in SharePoint and OneDrive, because without it the encrypted files Copilot can reach are limited to files open in Office apps on Windows [12]. And label sites and teams as well as files: a container label can set privacy, external sharing and access from unmanaged devices and, through PowerShell, the default sharing link [13]. Microsoft’s guidance is to require a site label when a site is created, so the sharing settings are right from the first day [2].
One trade-off to decide deliberately: some container label settings hand site owners control of external sharing that was otherwise an administrator’s, because applying or changing the label changes the setting [13].
What each control needs
Microsoft ties several of these tools to the Copilot licence itself. Once at least one Copilot licence is assigned, SharePoint administrators get the SharePoint Advanced Management features that support a Copilot deployment, which include the assessment, the reports, site access reviews, Restricted Content Discovery and restricted access control [18].
| Dimension | Where it is set up | What it needs |
|---|---|---|
| Content management assessment | SharePoint admin center, Advanced Management | SharePoint Advanced Management, included with Copilot licences |
| Data access governance reports | SharePoint admin center, Reports | SharePoint Advanced Management. Microsoft 365 E5 without it gets activity reports only, for up to 10,000 sites, with no snapshot reports or remedial actions |
| Site access reviews | SharePoint admin center, from a data access governance report, or PowerShell | SharePoint Advanced Management; SharePoint sites only |
| Restricted Content Discovery | SharePoint admin center or PowerShell, site by site | A Copilot licence and SharePoint Advanced Management; SharePoint sites only |
| Restricted access control | SharePoint admin center or PowerShell, site by site | SharePoint Advanced Management |
| Sensitivity labels and DLP for Copilot | Microsoft Purview portal | Microsoft 365 or Office 365 E3 or E5 for the core Purview features the foundation guidance uses; some features it mentions are in E5 |
| Group access reviews | Microsoft Entra admin center | Microsoft Entra ID Governance or Microsoft Entra Suite; some capabilities work with Microsoft Entra ID P2 |
The rows are from Microsoft’s pages on each control [4, 5, 9, 14, 15, 16], its list of the Advanced Management features in Copilot licences [18] and its Copilot foundation guidance [2]. The one Advanced Management feature Microsoft lists as outside the Copilot licence is restricted site creation by apps, which needs the Plan 1 add-on [18].
Keep new sites from reopening the problem
A clean tenant drifts back if nothing changes how new sites are created and shared. Microsoft’s second step is exactly that: secure defaults at the point of creation, and guardrails that keep being checked [2].
- Defaults at creation
- Restricted access control on business-critical sites when they are created, a site sensitivity label required at creation, and company-wide sharing groups and Anyone links restricted or turned off for the tenant.
- Narrower default links
- Set the default link type narrower than the organisation-wide link, for the tenant and for sensitive sites, while leaving people free to choose a wider link when they need one. Where Anyone links stay on, make them expire and limit them to view.
- Owners and lifecycle
- Site ownership, inactive site and site attestation policies keep owners accountable and flag sites nobody uses, and Microsoft 365 Archive keeps inactive but valuable content out of Copilot’s reach.
- Watch the usage
- Purview’s activity explorer shows Copilot prompts and responses and the sensitive data in them, an Insider Risk Management policy can flag risky Copilot use, and the content management assessment can be rerun every 30 days.
The defaults, archive and monitoring steps are from Microsoft’s Copilot foundation guidance [2], the link settings from its pages on the default link type and on sharing settings [8, 7], the lifecycle policies from its SharePoint Advanced Management overview [17] and the 30-day rerun from the assessment page [4].
The part software does not solve is ownership. Every one of these controls ends in a person who approves access or answers a review, and if nobody in the business owns that job, the tenant drifts back however good the admin work was. For the policy that names those owners, a template for an AI policy with an owner on every clause is a place to start.
Where 1AYM fits
We roll out Microsoft 365 Copilot, and this checklist is the first workstream of how we do it. We run the assessment, put interim protection on the sites that need it, work through the access fixes with site owners, and set the labels, DLP rules and defaults that keep the tenant closed after launch, before the pilot and the wider rollout. That is our AI governance implementation engagement applied to Microsoft 365: permissions and data rules the tenant enforces, rather than ones written into a policy nobody reads. The nearest published work is our engagement file on AI platform enablement at a large international marketing agency, where we hold the lead architect role on the platform underneath its organisation-wide AI programme.
We work with clients across the UK, the US and the Gulf, and we do not resell Microsoft licences, so the advice on what to switch on is not tied to what we sell. A fixed-scope clean-up can start within a day of the scope being signed, and if you already have a scoped job, we can resource it on contract from the collective of associates who work with us, held to the same standard. The call is booked from the end of this page.
For engineers: the PowerShell, the DLP location rules and a leak test
The admin detail behind the checklist, from Microsoft Learn as read on the date above. Cmdlets are SharePoint Online PowerShell unless stated.
- Restricted Content Discovery
- Set-SPOSite -Identity <site-url> -RestrictContentOrgWideSearch $true turns it on for a site, and $false turns it off. Start-SPORestrictedContentDiscoverabilityReport and Get-SPORestrictedContentDiscoverabilityReport list the sites that have it. Enabling, disabling and each justification are written to the Purview audit log.
- Delegation
- Set-SPOTenant -DelegateRestrictedContentDiscoverabilityManagement $true lets site admins manage Restricted Content Discovery for their own sites, with a justification required for every change. Restricted access control has its own switch, -DelegateRestrictedAccessControlManagement.
- Restricted access control
- Allow it for the tenant with Set-SPOTenant -EnableRestrictedAccessControl $true, which can take up to an hour, then per site with Set-SPOSite -RestrictedAccessControl $true and -AddRestrictedAccessControlGroups. Shared and private channel sites are separate site collections and need their own policy.
- DLP location rules
- The Microsoft 365 Copilot and Copilot Chat location is only in the Custom policy template, disables every other location in the same policy and does not support admin units. One rule cannot combine sensitive information types and sensitivity labels, so use two rules. In Word, Excel and PowerPoint the policy is evaluated when the file opens, so a label applied mid-session takes effect at the next open.
- Least-privilege roles
- The Purview Data Security AI Admin role can edit Copilot DLP policies without reading the prompts and responses of AI interactions, which keeps policy authors out of conversation data. Keep Global Administrator for the few who need it.
- Reading the exposure counts
- The number of permissioned users in a site access review is not deduplicated: a user with direct access and link access is counted twice. Use it to rank items by exposure, not as a headcount.
- A leak test
- Keep a fixed set of prompts that ask for content from the sites under review, run it as test accounts from different departments before and after each change, and record what Copilot cites. It turns a belief that a site is fixed into a result you can repeat after every policy change.
- Propagation
- Restricted Content Discovery waits on the index, so a large site can keep appearing for a while after the setting changes; check the item count before assuming it failed. DLP policy changes take up to four hours to reach Copilot.
Sources
- [1]Microsoft Learn, Data, privacy, and security for Microsoft Copilot, read 30 September 2026
- [2]Microsoft Learn, Configure a secure and governed foundation for Microsoft Copilot, read 30 September 2026
- [3]Government Digital Service, Microsoft 365 Copilot Experiment: Cross-Government Findings Report (June 2025), read 30 September 2026
- [4]Microsoft Learn, Assess your organization’s content management status, read 30 September 2026
- [5]Microsoft Learn, Data access governance reports for SharePoint sites, read 30 September 2026
- [6]Microsoft Learn, How shareable links work in OneDrive and SharePoint in Microsoft 365, read 30 September 2026
- [7]Microsoft Learn, Manage sharing settings for SharePoint and OneDrive in Microsoft 365, read 30 September 2026
- [8]Microsoft Learn, Change the default sharing link for a site, read 30 September 2026
- [9]Microsoft Learn, Restrict discovery of SharePoint sites and content, read 30 September 2026
- [10]Microsoft Learn, Restricted SharePoint Search, read 30 September 2026
- [11]Microsoft Learn, Microsoft Purview DLP for Microsoft 365 Copilot and Copilot Chat, read 30 September 2026
- [12]Microsoft Learn, Microsoft Purview data security and compliance protections for Microsoft 365 Copilot and other generative AI apps, read 30 September 2026
- [13]Microsoft Learn, Use sensitivity labels to protect collaborative workspaces (groups and sites), read 30 September 2026
- [14]Microsoft Learn, Initiate site access reviews for data access governance reports, read 30 September 2026
- [15]Microsoft Learn, Restrict SharePoint site access with Microsoft 365 groups and Microsoft Entra security groups, read 30 September 2026
- [16]Microsoft Learn, What are access reviews? (Microsoft Entra ID Governance), read 30 September 2026
- [17]Microsoft Learn, SharePoint Advanced Management overview, read 30 September 2026
- [18]Microsoft Learn, SharePoint Advanced Management features in Microsoft Copilot licenses, read 30 September 2026
Questions IT and security leads ask
Does Microsoft 365 Copilot let people see files they could not open before?
No. Microsoft says Copilot only surfaces organisational data that a user has at least view permission to, using the same access controls as the rest of Microsoft 365. The risk is the files people could already open without knowing it, which Copilot now finds for them.
What is Restricted Content Discovery?
A SharePoint Advanced Management setting that keeps a SharePoint site’s content out of organisation-wide search and Microsoft 365 Copilot responses while its permissions are reviewed. It changes no permissions, does not cover OneDrive and still lets people find content they own or used recently. Microsoft designs it as a temporary control.
Can we still use Restricted SharePoint Search?
Only where it is already on. Microsoft is retiring Restricted SharePoint Search, blocked new enablement from 31 July 2026 and points to Restricted Content Discovery instead. A tenant that still runs it should plan to turn it off once permissions are fixed.
Do sensitivity labels stop Copilot reading a file?
In two cases. If the label encrypts the file, a user needs the EXTRACT and VIEW usage rights for Copilot to return it. If a Purview DLP policy for the Copilot location names the label, Copilot does not use the file’s content, though the file can still appear as a citation. A label with neither changes what people see, not what Copilot can use.
Do “People in your organization” links expose files to Copilot?
Not when they are created. Microsoft says the link only gives access once someone opens it, but sending it from SharePoint, OneDrive, Outlook or a Teams chat redeems it for up to 100 individual recipients. “Specific people” links make the file reachable through Copilot for everyone named on the link.
Do we need to buy SharePoint Advanced Management for Copilot?
Mostly not. Microsoft says that once at least one Microsoft Copilot licence is assigned, SharePoint administrators get the Advanced Management features that support a Copilot deployment, including Restricted Content Discovery, restricted access control, the content management assessment and site access reviews. Restricted site creation by apps still needs the separate Plan 1 add-on.
How long does the clean-up take?
It depends on how many sites are overshared and how quickly their owners answer, so size it after the assessment rather than before. Microsoft’s own timings set the floor: the content management assessment takes between 2 and 72 hours to run, and a Restricted Content Discovery change can take more than a week on a site with over 500,000 items.
More in this topic
- ChatGPT Enterprise rolloutRollout guide
The same rollout discipline for OpenAI’s assistant: sign-in, provisioning and connectors before the first broad invite.
Office agents that read and write files, and the admin switches Anthropic, OpenAI and Microsoft each give you.
- ChatGPT Work vs Claude CoworkComparison guide
The two vendors’ office agents side by side, with a short section on Microsoft’s Copilot Cowork.
Further
- AI strategy and roadmap · Deciding which assistant to buy, for whom, before the licences and the clean-up are committed.
We build these systems for a living. See the engagement files for what that looks like in practice, or write to us if yours is the next one.
Last reviewed · 1AYM