Every explanation of Copilot security arrives at the same reassurance: it only surfaces what the user could already open. That is accurate, and it is the reason the first week goes badly. Copilot inherits your SharePoint permissions exactly as they stand. A business whose sharing has never been tidied has just given every member of staff a search engine pointed at it. Nothing new was exposed. What changed is that finding it no longer requires knowing where to look.

Copilot inherits your SharePoint permissions exactly as they are

Microsoft states the mechanism plainly in its guidance on configuring a secure data foundation: Copilot enhances responses ‘using data that the user already has permission to access’. There is no second layer of judgement underneath that. No relevance filter decides a document is too sensitive to return.

Before Copilot, a permission granted in error was protected by obscurity. The file sat in a site nobody visited, under a name nobody would search for, and the person with access never knew they had it.

A prompt removes that. Someone asking what the business pays its sales team is not simply browsing, and they do not need to know that site exists.

A separate governance exercise should cover who can build Copilot agents and what those agents can access. Our governance starter pack for Copilot agents explains that wider layer in more detail. Permissions come first, because every control above them assumes the content state underneath is sound.

The five conditions that cause oversharing

Microsoft’s own assessment tooling looks for five specific states, and they are worth reading as a checklist of what to go and find.

Audiences that are too large. Sites shared with far more people than the content warrants, generally because that was easier than deciding who needed it.

EEEU usage. Everyone Except External Users is the built-in group that covers every licensed person in the business. We believe this is the most common cause. It is often selected because it appears as the default suggestion when someone wants a site to be findable internally. Microsoft’s remediation instruction is to remove excess users, groups and company-wide sharing links including EEEU.

Broken inheritance. A subsite or folder whose permissions were detached from its parent at some point, so the tidy structure above it no longer governs what sits below.

Inappropriate sharing. Microsoft names the condition without defining it. On our reading the practical shape is Anyone links and company-wide sharing groups, both of which Microsoft separately recommends disabling or restricting at tenant level.

Inactive or ownerless sites. A site whose owner left the business has no one to ask, no one to review it, and no one who would notice if its permissions were wrong.

That list is useful because it is finite and every item on it is findable. The fifth is the only one that ends in a question for HR.

Microsoft Purview’s posture management adds another layer of insight. It can identify overshared sites containing sensitive data, risky sharing links and content that is accessed frequently. Volume of exposure matters less than what sits inside the exposed thing.

Restricted Content Discovery buys time, and does not fix anything

SharePoint Advanced Management includes Restricted Content Discovery, which limits whether a named site surfaces in Copilot. Read its scope before relying on it: Microsoft describes it as preventing sites from appearing in Microsoft 365 Copilot Business Chat, and it carries a carve-out for users who have interacted with the content recently. It restricts discovery through one surface, and it leaves the underlying access untouched.

So, it is the right tool for the week before a deployment, but not for the quarter after it.

The underlying permissions remain unchanged. People who should not have access can still retain it.

Microsoft groups the work into three pillars: first, remediating oversharing; second, putting guardrails in place; and third, meeting regulatory obligations. Exclusion sits within the first pillar as a temporary holding action.

Where it earns its place is buying an honest delay. A finance site excluded on Monday buys the time to fix its membership properly, instead of choosing between a rushed permissions change and a postponed rollout.

Treat it as the thing you do while the real work is scheduled, and put a date on the review.

Whether you get the reporting depends on two licences, not one

This is the part that catches smaller businesses.

The assessment and the reports named above are SharePoint Advanced Management features, and Microsoft’s prerequisites set two conditions that both have to hold. The organisation needs a qualifying base subscription, listed as Office 365 E3, E5 or A5, or Microsoft 365 E1, E3, E5 or A5, or the government equivalents. Then it needs one of three things on top, and the easiest is a single Microsoft Copilot licence assigned to any one user, who does not have to be an administrator.

The second condition is cheap. The first is the one that decides it, and Business Premium is absent from that list. Our reading is that a Business Premium tenant does not reach the reporting however much Copilot it buys, and it is worth confirming that against your own tenant before you plan around it. How the tiers compare against each other sits in the Microsoft 365 licence audit.

Where the reports are out of reach, the same five conditions are still findable through the standard SharePoint admin centre, one site at a time. That is an afternoon for a business with a handful of sites and a project for one with hundreds. Knowing which of those you are is the first useful output.

What to do before anyone types a prompt

Four steps. If you can only do one, do the fourth.

  1. List every SharePoint site the business owns, with its owner. Any site with no living owner goes on a separate list.
  2. Find everywhere EEEU or a company-wide link grants access, and decide in each case whether that was intended.
  3. Turn off Anyone links at tenant level unless something specific depends on them.
  4. Take the sites holding payroll, HR records, board papers and commercial terms, and check their membership by name.

The question step four answers is a narrow one. Never mind whether your permissions are perfect: are the four things that would genuinely embarrass you reachable by somebody who asks the right question in plain English?

Copilot is worth deploying, and the preparation is unglamorous work that is easy to skip because nothing appears to be wrong. Nothing is wrong, until the search box arrives.

We manage Microsoft 365 tenants for businesses across the North East. Our Microsoft 365 configuration and security management service covers tenant setup, configuration and ongoing support. If you are considering Copilot, start by checking your current site access and sharing setup. It is a sensible first step before you commit to licences.