AI

Before you turn on Microsoft 365 Copilot, fix your oversharing

Copilot only shows people what they can already access. That is exactly the problem in most tenants. Here is how to find overshared SharePoint and OneDrive content, clean up permissions and links, and run a sensible pilot before rolling Copilot out.

September 25, 2026 7 min read AIMicrosoft 365CopilotSharePointdata governance

Microsoft 365 Copilot does not break your permissions. It follows them. When someone asks Copilot a question, it looks through the email, files, chats, and meetings that person already has access to, and builds an answer from those. It does not reach into content the user cannot open.

That sounds reassuring, and it is. It is also the whole problem. In most small business tenants, people can access far more than anyone realizes. A salary spreadsheet shared with “everyone” three years ago. A folder of client contracts linked with an “anyone with the link” URL. A former manager’s OneDrive shared broadly during a handover and never tightened. None of that was secret before. It was simply hard to find.

Copilot makes things easy to find. Someone types “what are we paying the new operations hire” and, if a document they can technically open contains the answer, Copilot may surface it. Nothing was hacked. Nothing was broken. The oversharing was already there, and now it is visible.

So the most important Copilot readiness work has little to do with AI. It is permissions housekeeping, and it is worth doing whether you turn Copilot on or not.

How oversharing happens

Nobody sets out to overshare. It accumulates through ordinary, reasonable decisions.

Broad default groups. SharePoint sites and Teams often get shared with large groups like “Everyone except external users” because it was the quickest way to give a new team access. Anything saved there inherits that reach.

Convenient links. Sharing a file with a link is fast. Depending on your tenant settings, those links may be “anyone with the link,” which needs no sign-in at all, or “people in your organization,” which means every account in the company. Both get forwarded and pasted and forgotten.

Handover shortcuts. When someone leaves or changes role, their files often get shared widely so the work does not stop. The temporary sharing becomes permanent.

Sites nobody owns. A project site from years ago, still live, still shared broadly, with no current owner who would notice what is in it.

Step one: see what you have

Before changing anything, get a picture. You do not need perfect visibility; you need to find the worst exposures.

  • List your SharePoint sites and Teams, and who they are shared with. Flag anything shared with company-wide groups.
  • Look for sharing links, particularly “anyone” links and organization-wide links on folders rather than single files.
  • Check who owns each site. Sites with no owner or an owner who has left go on the review list.
  • Search for obviously sensitive content yourself: payroll, salary, contract, SIN, health, performance review, termination. If you can find it and you should not be able to, others can too.
  • Review the sharing reports in the SharePoint admin centre and the Microsoft 365 admin tools. What is available depends on your licences, and Microsoft has been adding oversharing reports aimed specifically at Copilot readiness, so check what your tenant includes today.

Step two: tighten permissions

Start with the high-risk content you found and work outward. The goal is simple: people should have access to what their job needs, and not much more.

  • Remove company-wide groups from sites and libraries holding sensitive material. Replace them with specific groups for the teams that need access.
  • Expire or remove “anyone” links on internal content. Consider changing the tenant default so new links are scoped to specific people rather than everyone.
  • Assign an owner to every active site. Someone who knows what belongs there and will notice when it does not.
  • Archive or delete dead sites. An old project site nobody uses is risk with no benefit.
  • Move genuinely sensitive files like HR and finance records into restricted locations with a short, named access list.

This does not have to happen in one sweep. A small business can usually get the worst of it done in a few focused sessions, then keep going as part of regular maintenance.

Step three: label what matters

Sensitivity labels, managed through Microsoft Purview, let you tag documents as confidential or internal and attach protections to that tag, such as encryption or restrictions on who can open a file. Copilot is designed to respect these labels and their protections.

For a small business, keep it simple. Two or three labels are plenty: something like Public, Internal, and Confidential. Apply Confidential to HR, finance, and client-sensitive material first. Which labelling features you get, and whether any of it can be automatic, depends on your Microsoft 365 plan, so confirm what your licences include before designing anything elaborate.

Labels do not replace permissions cleanup. They are a second layer that follows documents around.

Step four: sanity-check licensing and settings

Copilot for Microsoft 365 is a paid add-on on top of an eligible business plan, and Microsoft has changed its packaging and pricing more than once. Before you buy seats, confirm what your current plan includes, what the add-on costs today, and whether the free Copilot Chat experience that comes with many plans already covers what your team actually wants to do.

Also check the basics that should already be in place: multi-factor authentication on every account, admin accounts separate from everyday accounts, and retention settings that match your obligations. Copilot will make a tidy tenant more useful and an untidy one more awkward.

Step five: pilot with a small group

Do not turn Copilot on for everyone at once.

  • Pick three to five people from different roles, including at least one who handles sensitive information and one sceptic.
  • Brief them on what to look for. Ask them to note anything Copilot surfaces that they did not expect to see, and report it without digging further.
  • Run the pilot for a few weeks. Collect real examples of time saved and real examples of oversharing found.
  • Fix what they find before expanding. Each surprise is a permissions problem you would rather discover in a pilot than across the whole company.
  • Decide on evidence. If the pilot group is not saving meaningful time, that is useful information before you pay for more seats.

A readiness checklist

  • Company-wide groups removed from sensitive sites and libraries
  • “Anyone” links reviewed, and the tenant default tightened
  • Every active site has a named owner; dead sites archived
  • HR, finance, and client-sensitive files in restricted locations
  • A small set of sensitivity labels defined and applied to the most sensitive content
  • Licensing confirmed against what your plan includes today
  • MFA enforced and admin accounts separated
  • Pilot group chosen, briefed, and given a way to report surprises

Where this fits

The payoff from this work is bigger than Copilot. A tenant where people can reach what they need and nothing else is easier to secure, easier to audit, and easier to hand to a new staff member. If you are still weighing platforms, our comparison of Microsoft 365 and Google Workspace covers the broader choice. If you want a structured look at whether and where AI tools will pay off for your team, our fixed-scope AI-readiness sprint starts there, device management covers the Microsoft 365 administration underneath, and managed services keeps the permissions tidy afterwards.

Write us a short brief about your Microsoft 365 setup and what you hope Copilot will do, and we will reply in writing within one business day.

— Newsletter

Get the writing by email.

An occasional note from the team — case studies, new free tools, engineering essays. Never daily.

Three fields, no tracking. Privacy policy.

Esc