Microsoft Copilot is genuinely useful, and the temptation to turn it on for your team is real — drafting emails faster, summarizing long threads, pulling a quick answer out of a pile of files instead of hunting for it manually. For a lot of small businesses in South Bend, Goshen, and Elkhart, that temptation shows up as “let’s just enable it for a few people and see how it goes.”
Here’s the piece that gets missed in that plan: Copilot retrieves files, emails, and chats using each user’s existing Microsoft 365 permissions. It doesn’t have its own separate access. In most tenants we audit, those existing permissions are broader than anyone has actually mapped out, because access accumulates quietly across years of projects, ad-hoc sharing, and staff changes that nobody ever went back and cleaned up.
Microsoft itself now recommends a specific cleanup before any Copilot trial: map who currently has access to what, fix the permissions that have drifted out of scope, and apply sensitivity labels to confidential content. We walk clients across Michiana through exactly this process before their Copilot rollout, and this post covers what Copilot actually does with your permissions, where oversharing tends to hide in a typical tenant, the kinds of content Copilot can return when permissions are too broad, how to run the audit Microsoft recommends, and what to fix before any rollout goes live.
How Microsoft 365 Copilot accesses your data
Copilot answers questions and generates content by retrieving information through Microsoft Graph, which is the API layer tying together your Microsoft 365 services. When a user asks Copilot a question, it pulls from emails, calendar items, SharePoint documents, OneDrive files, Teams messages, and meeting transcripts that the signed-in user has permission to access.
The critical phrase in Microsoft’s own documentation is short: Copilot can only summarize or reference content that the user is authorized to access.
That statement is accurate, and it’s also exactly where the risk sits. The variable that actually matters is whether each user’s permission set still matches what you assume it covers — not what Copilot is technically capable of, but what your permissions have quietly become over the years.
Why permissions tend to be broader than anyone thinks
For a manufacturer or trades business, most of the data sitting in your Microsoft 365 tenant is operational — inventory records, production schedules, supplier contracts, project files. Some of it is sensitive, but the consequences are usually contained when the wrong employee happens to read a document they shouldn’t have.
At a professional services firm, the dynamic is different. The files are the product itself. Client matters, settlement figures, fee arrangements, deal terms, financial data, and employment records make up the deliverable, and the confidentiality of that material is the entire business model. Yet the same files often live in environments that were never properly scoped to begin with.
The reason is structural, not careless. “Just give them access for the Henderson matter” is how it usually starts. The matter closes, the access is never removed, and eighteen months later that person has read permissions on a folder they have no current reason to be anywhere near. Multiply that across five years of staff changes, project onboarding, ad-hoc Teams channels, and external sharing links that never expired, and you end up with a permission environment that nobody fully understands anymore — including the people who built it.
If the permission exists, Copilot can use it. Whether it was granted with appropriate scope in the first place isn’t part of the calculation Copilot makes.
Microsoft now acknowledges this directly. The company publishes a deployment blueprint for Copilot rollouts organized around three pillars: remediate oversharing, set up guardrails, and meet AI regulatory requirements. Microsoft’s own guidance puts oversharing remediation first, because it’s the pillar that has to be addressed before any rollout produces a result you can actually trust.
What Copilot can return in a tenant with broad permissions
Five examples of what Copilot can return when broad permissions exist and haven’t been audited — these are the kinds of results that turn a helpful pilot into an uncomfortable conversation.
“What is everyone’s salary?” Returns the compensation spreadsheet HR shared with a hiring manager during a recruitment process eighteen months earlier. The file remained shared after the hiring manager got promoted and moved on to other projects.
“Summarize the [client] case.” Pulls content from a SharePoint site set up for a different team. A user added during a one-off project two years ago still has the permission that was never removed, and Copilot returns a summary of the case to them without any additional prompting.
“What deals are we currently working on?” Aggregates content from M&A data rooms that were never properly closed, pipeline trackers in personal OneDrives that got shared once for a partner meeting, and prospect lists sitting in a Teams channel that grew well beyond its original membership. The output is a single consolidated view of the firm’s entire commercial pipeline, handed to whoever asked.
“Find everything mentioning [former employee].” Surfaces the termination memo, the severance calculation, the performance review that preceded the exit, and any email threads saved to SharePoint. Material that was never intended to be findable below partner level shows up in one query, in seconds.
“What’s our markup on [client] engagements?” Outputs the internal pricing sheet that was shared during a proposal process so two people could review it. The link was never restricted, the file was never moved, and the numbers come back the moment Copilot is asked, long after anyone remembers sharing them.
The question of who would actually ask any of these queries is separate from the question of what Copilot can return if asked. Microsoft’s deployment guidance focuses squarely on the second question, and recommends a permissions review before Copilot is enabled at any scale, not after.
Why a “small pilot” is rarely as contained as people think
Running a limited pilot feels like a safe middle ground, but the way most firms set them up tends to produce the highest-risk version of the trial rather than the lowest.
The three or four people picked for a pilot are almost always senior. That’s a natural instinct — you want feedback from people whose time is valuable and whose opinion carries weight. But senior staff have the broadest access of anyone in the firm, which means any searches they run have the widest possible scope. A pilot with three senior partners produces a higher-risk preview of Copilot than a pilot with three junior staff ever would.
And pilots drift over time. Licenses get reassigned when a partner decides they’re not really using theirs. The person who ends up with the license is often just whoever asked most recently, which is not the same thing as whoever has the most appropriate access profile for a first look at the tool.
Microsoft’s audit logs will show you what was asked after the fact, but the asking itself can’t be reversed. Once a Copilot summary has been returned to a user, that information has already been seen, and there’s no taking it back.
The cleanup that should happen before any trial
Before you click “start trial,” four pieces of work make the difference between a genuinely useful test and a disclosure event you’ll spend weeks cleaning up after.
SharePoint sharing audit. SharePoint Advanced Management includes a content management assessment that surfaces permission issues, oversharing patterns, and inactive sites. If your tenant has never been reviewed, this is the first place to look. The report identifies which sites are shared more broadly than they should be, often surprising even the people who set them up.
OneDrive external share review. Look at files shared outside the organization that were never recalled. These are particularly common in legal and accounting firms where files get sent to clients for review and then simply forgotten about once the matter closes.
Teams membership review. Confirm that channel membership still reflects who should actually have access to the files stored there. Channels that grew during an active project and were never trimmed afterward are a frequent source of unintended access down the line.
Sensitivity labels for confidential content. Microsoft Purview sensitivity labels are the mechanism that tells Microsoft 365 which content is confidential in the first place. Once applied, you can use Data Loss Prevention policies to exclude labeled items from Copilot processing entirely, and use encryption settings that block Copilot from reading the content at all without explicit permission. Without sensitivity labels in place, Copilot has no way to treat a client settlement document any differently from a catering invoice — to the system, they look the same.
These four pieces of work generally take four to eight weeks for a firm in the 25-to-100-person range. Some of it can be done by your IT provider on their own. The most sensitive parts, like deciding which document categories deserve which sensitivity label, are best handled with input from the partners or owners who actually understand the material and its stakes.
The one question to send your IT provider
Before you make any decision about Copilot, send this to whoever manages your Microsoft 365 environment, whether that’s us or someone else:
“Can you show me a report of every file in our tenant that’s accessible to more than ten people, and flag the ones containing client names, salary figures, or financial data?”
If they can produce something useful within a few days, your environment has been managed actively. The report won’t be a perfect audit on the first pass, but it will show you the shape of the problem and give you a real starting point to work from.
If the answer is “we’d need to enable some things first,” that itself is informative. It means the SharePoint sharing reports have never been run and the tenant has never been reviewed from a permissions perspective. That’s the real answer to your Copilot readiness question, and the audit needs to happen before any trial does — not alongside it.
Frequently Asked Questions
Does Microsoft 365 Copilot have access to my files by default?
Copilot has access to whatever the signed-in user has access to, scoped by Microsoft Graph and your existing SharePoint, OneDrive, and Exchange permissions. Copilot cannot reach files outside the user’s existing permission set, but that permission set is often broader than anyone realizes.
Can sensitivity labels stop Copilot from reading certain files?
Yes. Microsoft Purview sensitivity labels with encryption can block Copilot from reading the content. Files require the user to have specific usage rights (EXTRACT and VIEW) for Copilot to interact with them. Data Loss Prevention policies can also exclude labeled items from Copilot processing entirely.
Is a small Copilot pilot a safe way to test it?
A pilot is fine if the pilot users have limited access to sensitive content. The common mistake is running a pilot with senior staff, who tend to have the broadest access in the firm and therefore the highest-risk queries.
How long does it take to prepare a tenant for Copilot?
For a firm with several years of accumulated content, the preparation usually takes four to eight weeks. The work involves a SharePoint sharing audit, an external share review, a Teams membership review, and sensitivity label application.
What does Microsoft say about Copilot oversharing risk?
Microsoft publishes a deployment blueprint that organizes Copilot security work around three pillars: remediating oversharing, setting up guardrails, and meeting AI regulatory requirements. The oversharing pillar is the one that should be addressed before any Copilot trial begins.
Graham’s Take
We’re genuinely enthusiastic about Copilot for the right clients — it’s a real productivity gain, not hype. But we always run the permissions audit first, and it’s rarely a quick “nothing to see here.” Most tenants we look at across South Bend and Goshen have some version of the oversharing pattern described above, just at different scales. If you’re considering a Copilot rollout, that one question to your IT provider is the cheapest insurance policy you’ll take out all year.
