A safe Microsoft Copilot rollout starts with a permissions audit, before you turn on a single trial license. Microsoft 365 Copilot pulls files, emails, and chats using each person’s existing Microsoft 365 permissions. In most tenants, those permissions reach further than anyone has actually mapped, because access piles up over years of projects, one-off sharing, and staff changes. Microsoft itself recommends a specific cleanup first: map who can currently see what, fix the permissions that have drifted out of scope, and label your confidential content.
This post covers what Copilot does with permissions, where oversharing usually hides, what Copilot can surface when permissions are broad, how to run the audit Microsoft recommends, and what to fix before any rollout.
How Microsoft 365 Copilot reaches your data
Copilot answers questions and drafts content by pulling information through Microsoft Graph, the layer that connects your Microsoft 365 services. Ask Copilot something and it draws on the emails, calendar items, SharePoint documents, OneDrive files, Teams messages, and meeting transcripts the signed-in person already has permission to open.
The key line in Microsoft’s own documentation is short: Copilot can only summarize or reference content that the user is authorized to access.
That’s accurate, and it’s also where the risk lives. The variable is whether each person’s permissions still match what you think they cover.
Why permissions are usually broader than anyone thinks
For a manufacturer or trades business, most of what sits in your tenant is operational: inventory records, production schedules, supplier contracts, project files. Some of it is sensitive, but the damage is usually contained when the wrong employee opens a document.
At an accounting or professional services firm, it’s a different story. The files are the product. Client matters, settlement figures, fee arrangements, deal terms, financial data, and employment records are the deliverable, and keeping them confidential is the whole business. Yet they often live in spaces that were never properly scoped.
The cause is structural. “Just give them access for the Henderson matter” is how it starts. The matter closes, the access never gets removed, and eighteen months later that person still has read rights to a folder they have no reason to be in. Multiply that across five years of staff changes, project onboarding, ad-hoc Teams channels, and external share links that never expired, and you get a permission setup nobody fully understands.
If the permission exists, Copilot can use it. Whether it was the right scope in the first place isn’t part of the math.
Microsoft acknowledges this directly. Its Copilot deployment blueprint organizes the work around three pillars: remediate oversharing, set up guardrails, and meet AI regulatory requirements. Oversharing comes first, because it has to be handled before a rollout produces anything useful.
What Copilot can surface in a tenant with broad permissions
Five examples of what Copilot can return when broad permissions exist and haven’t been audited:
“What is everyone’s salary?” Returns the compensation spreadsheet HR shared with a hiring manager during a recruitment process eighteen months earlier. The file stayed shared after the hiring manager got promoted.
“Summarize the [client] case.” Pulls content from a SharePoint site set up for a different team. A user added during a one-off project two years ago still has the permission nobody removed, and Copilot hands them a summary of the case.
“What deals are we working on right now?” Aggregates content from data rooms that were never properly closed, pipeline trackers in personal OneDrives that got shared once for a partner meeting, and prospect lists in a Teams channel that grew past its original membership. The output is a single consolidated view of the firm’s commercial pipeline.
“Find everything mentioning [former employee].” Surfaces the termination memo, the severance calculation, the performance review that preceded the exit, and any email threads saved to SharePoint. Material that was never meant to be findable below partner level shows up in one query.
“What’s our markup on [client] work?” Outputs the internal pricing sheet that was shared during a proposal so two people could review it. The link was never restricted, the file was never moved, and the numbers come back when Copilot is asked.
Who would actually ask any of these is a separate question from what Copilot can return. Microsoft’s guidance focuses on what Copilot is capable of returning, and recommends a permissions review before you enable it at any scale.
Why a “small pilot” is rarely as contained as it looks
Running a limited pilot feels like the safe middle ground, but the way most firms set one up produces the riskiest version of the trial.
The three or four people chosen for a pilot are almost always senior. Senior staff hold the broadest access in the firm, so anything they ask has the widest possible reach. A pilot with three partners is a higher-risk preview of Copilot than one with three junior staff.
And pilots drift. Licenses get reassigned when a partner decides they aren’t using one, usually to whoever asked most recently, which isn’t the same as whoever has the most appropriate access.
Microsoft’s audit logs will show you what was asked after the fact, but the asking can’t be undone. Once Copilot has returned a summary to someone, that information can’t be pulled back.
The cleanup that should happen before any trial
Before you click “start trial,” four pieces of work separate a useful test from a disclosure event.
SharePoint sharing audit. SharePoint Advanced Management includes a content management assessment that surfaces permission problems, oversharing, and inactive sites. If your tenant has never been reviewed, start here. The report shows which sites are shared more broadly than they should be.
OneDrive external share review. Look at files shared outside the organization that were never recalled. These pile up in accounting and legal firms especially, where files get sent to clients for review and then forgotten.
Teams membership review. Confirm that channel membership still reflects who should reach the files stored there. Channels that grew during an active project and were never trimmed are a frequent source of accidental access.
Sensitivity labels for confidential content. Microsoft Purview sensitivity labels tell Microsoft 365 which content is confidential. Once they’re applied, Data Loss Prevention policies can keep labeled items out of Copilot, and encryption settings can stop Copilot from reading the content at all unless the user has the right usage permissions. Without labels, Copilot has no way to tell a client settlement document from a catering invoice.
These four pieces generally take four to eight weeks for a firm in the 25-to-100-person range. Your IT provider can handle most of it, and it’s the kind of cleanup we run as part of a cybersecurity engagement. The most sensitive part, deciding which kinds of documents deserve which label, is best done with the partners or owners who actually know the material.
The one question to send your IT provider
Before you decide anything about Copilot, send this to whoever manages your Microsoft 365 environment:
“Can you show me a report of every file in our tenant that’s shared with more than ten people, and flag the ones with client names, salary figures, or financial data?”
If they can produce something useful within a few days, your environment has been actively managed. The report won’t be a perfect audit, but it will show you the shape of the problem and give you a starting point.
If the answer is “we’d need to switch some things on first,” that’s informative too. It means the SharePoint sharing reports have never run and the tenant has never been reviewed for permissions. That’s the real answer to your Copilot-readiness question, and the audit needs to come before the trial.
Frequently asked questions
Does Microsoft 365 Copilot have access to my files by default?
Copilot has access to whatever the signed-in user has access to, scoped by Microsoft Graph and your existing SharePoint, OneDrive, and Exchange permissions. It can’t reach files outside that user’s permission set.
Can sensitivity labels stop Copilot from reading certain files?
Yes. Microsoft Purview sensitivity labels with encryption can block Copilot from reading the content. The user needs specific usage rights (EXTRACT and VIEW) for Copilot to interact with the file, and Data Loss Prevention policies can also keep labeled items out of Copilot.
Is a small Copilot pilot a safe way to test it?
A pilot is fine if the pilot users have limited access to sensitive content. The common mistake is running it with senior staff, who tend to have the broadest access in the firm.
How long does it take to prepare a tenant for Copilot?
For a firm with several years of accumulated content, preparation usually takes four to eight weeks: a SharePoint sharing audit, an external share review, a Teams membership review, and sensitivity label application.
What does Microsoft say about Copilot oversharing risk?
Microsoft publishes a deployment blueprint that organizes Copilot security work around three pillars: remediating oversharing, setting up guardrails, and meeting AI regulatory requirements. The oversharing pillar is the one to address before any Copilot trial.
Sources and further reading
- Microsoft Learn: Microsoft 365 Copilot blueprint for oversharing. Microsoft’s official guidance on managing oversharing risk during a Copilot deployment.
- Microsoft Learn: Configure a secure and governed foundation for Microsoft 365 Copilot. How Copilot accesses data and what controls apply.
- Microsoft Learn: Get ready for Copilot with SharePoint Advanced Management. The SharePoint assessment tool for finding permission and oversharing issues.
- Microsoft Learn: Use Microsoft Purview to manage Copilot security and compliance. How sensitivity labels and DLP policies interact with Copilot.
If you haven’t reviewed your Microsoft 365 tenant in a while, that review is worth doing whether or not Copilot is on your roadmap. Your IT provider should be able to run the SharePoint sharing report and walk you through what it shows. If you don’t have an IT provider, reach out to us and we’ll help you sort it out.
—
Want a straight read on your IT?
Book a 15-minute call and we'll give you an honest take on where you stand — no pressure, no scare tactics. If staying put is the right move for now, we'll tell you that too.