Microsoft 365 Copilot can summarise meetings, draft documents and answer questions across email, chats and files. To do that, it draws on the content each user already has access to in your tenant. That is exactly how it should work, and it is also why many organisations discover uncomfortable things during their first pilot.
A spreadsheet of salaries in a site shared with the whole company may have gone unnoticed for years. Ask Copilot about salaries, and it can find it in seconds. Copilot does not create new access, but it makes existing access far easier to use. Getting permissions in order before a broad roll-out is the most important step in Copilot readiness.
Copilot works with the permissions you already have
Microsoft is clear on the principle. Copilot only surfaces organisational data to which an individual user has at least view permission, using the same access controls as the rest of Microsoft 365. It operates within the Microsoft 365 service boundary, and prompts, responses and data accessed through Microsoft Graph are not used to train foundation models.
So the security model is sound. The risk lies in the permissions themselves. In most tenants, years of collaboration have left a trail of sites shared with large groups, links that work for anyone in the organisation, teams nobody owns any more and files copied to places they should not be. This is oversharing, and Copilot makes it visible.
One setting deserves a deliberate decision as well. When web search is enabled, Copilot generates search queries from the user’s prompt and sends them to the Bing search service. That is often useful, but decide whether, and for whom, it should be on, and explain the choice to users.
Where oversharing usually hides
- Broad groups on sites and libraries: sites or folders shared with Everyone except external users or with all-staff groups, often for convenience during a project that ended long ago.
- Wide sharing links: links that work for anyone in the organisation, or anyone with the link, which travel far beyond the original recipients.
- Public teams and groups: teams created as public, where anyone in the organisation can reach the files.
- Ownerless and inactive sites: sites whose owner has left, so nobody reviews who has access or whether the content is still needed.
- OneDrive sharing: files shared from personal storage for a quick task and never unshared.
- Sensitive content without labels: HR, finance, legal and board material stored without classification, so no policy can protect it.
A practical clean-up approach
Trying to fix every permission in a large tenant before switching anything on rarely works. A risk-based approach does.
- Find the riskiest content first. SharePoint Advanced Management offers data access governance reports that identify sites with potentially overshared or sensitive content, and Microsoft Purview Data Security Posture Management can run oversharing assessments on your most-used SharePoint sites.
- Fix the defaults. Narrow the default sharing link type, review guest access and decide who may create public teams.
- Restrict what must not be found. As a temporary measure while you clean up, Restricted Content Discovery keeps selected sites out of Copilot and organisation-wide search, and Restricted Access Control limits a site to members of specified groups.
- Assign owners and review access. Give every active site an accountable owner, ask owners to review membership, and archive or delete inactive content.
- Keep it clean. Site lifecycle policies and regular access reviews stop the problem from returning.
Some of these capabilities depend on your licences, so check what your agreement includes before you plan around them.
Sensitivity labels and Microsoft Purview
Permissions decide who can open a file. Sensitivity labels describe how sensitive it is and can enforce protection wherever it goes. Copilot honours them: when a label applies encryption, a user needs both the view and extract usage rights for Copilot to return the content. When Copilot in Word, PowerPoint or Outlook creates new content from a labelled file, the new content inherits the label.
Microsoft Purview adds further controls. Data loss prevention policies can stop Copilot from processing files and emails with selected labels, or prompts that contain sensitive information. Prompts and responses are captured in the unified audit log and can be retained and searched with eDiscovery, which matters for compliance and investigations.
A simple label scheme that staff actually understand, combined with automatic labelling of the most sensitive data, goes a long way. Elaborate schemes with a dozen labels tend to be ignored, and unlabelled content stays unprotected.
Pilot, adoption and measuring value
Readiness is not only about security. Licences that are bought but barely used are a common outcome when Copilot is handed out without a plan. Treat the roll-out as a change in how people work, not a software installation.
- Pilot with a purpose: choose a few roles with clear, recurring knowledge work, such as sales, project management or finance, and define the tasks Copilot should help with.
- Train on real scenarios: short, role-specific sessions on prompts that work for that job are worth more than generic feature tours.
- Appoint champions: a few keen users in each department help colleagues and report back on what works.
- Measure: use the Copilot usage reports in the Microsoft 365 admin centre and the Copilot Dashboard to follow adoption, and combine them with a simple baseline, such as time spent on recurring tasks, to judge value.
- Scale on evidence: extend licences to the roles where the pilot showed value, rather than buying for everyone at once.
How Altechy can help
Our Copilot Readiness Check, part of Microsoft 365 & Collaboration, is a fixed-scope review of your tenant that shows whether your data and permissions are ready for Copilot and what to fix first. Where it uncovers wider exposure, our Cloud, Network & Data Security specialists can help with data classification, data loss prevention and access controls.
Altechy coordinates the right specialists from our partner network and stays your single point of contact from readiness to adoption. To talk it through, book a free 60-minute idea session.
