Copilot does not grant anyone a single permission they did not already have. That reassurance is technically true and practically misleading, because what it does do is make every permission mistake in your tenant findable by anyone, in seconds, by asking a question in plain English.
In short: Before enabling Copilot, work through the sharing and permission problems that were previously hidden by the difficulty of finding anything. The highest value checks are: anyone links, org wide shares, the Everyone except external users group, permission inheritance broken at file level, stale Teams and their SharePoint sites, guest access that outlived its project, OneDrive folders shared to the whole company, sites with no owner, sensitivity labels not applied to the material that matters, and default sharing settings that quietly allow all of the above to recur.
Why this stops being theoretical
Historically, an overshared payroll spreadsheet in a forgotten site was protected by obscurity. You had to know the site existed, then navigate to it. Search helped a bit, if you guessed the right filename.
Copilot removes that friction completely. "Summarise what we pay the senior leadership team" is a reasonable sounding question that will happily traverse anything the asker technically has access to. The permission was always wrong. Copilot is simply the first tool efficient enough to find it.
"The permissions were already broken. Copilot is just the first thing to read every file you forgot you shared."
The ten checks
Work down in order. The first four fix most of the exposure.
- Anyone links. Sharing links that require no sign in are the highest risk item in most tenants, because they work for whoever holds the URL, forever. Report on them, expire them, and then turn the default down so new ones need a sign in.
- Org wide shares. Files and folders shared with everyone in the company. Usually created for one genuine reason years ago, then inherited by every file added since.
- The Everyone except external users group. Check where this has been granted, particularly on site collections. It is the single fastest way for something sensitive to become tenant readable, and it rarely appears deliberate.
- Broken inheritance at file and folder level. Unique permissions set in a hurry that nobody unwound. These are invisible from the site level, which is exactly why they persist.
- Stale Teams and their sites. Every Team has a SharePoint site behind it. Teams created for a bid three years ago still hold the content, still have the membership, and nobody is watching either.
- Guest access past its purpose. External members who joined for a project that finished. Review by last activity, not by name, because the names will all look plausible.
- OneDrive shared to the whole business. People share a working folder to make life easy and never revisit it. OneDrive content is in Copilot's reach for the owner and anyone they shared with.
- Sites with no owner. When the owner leaves, the site does not. Ownerless sites accumulate content with nobody responsible for who can see it.
- Sensitivity labels on what actually matters. You do not need to label everything. You need HR, finance, legal and commercial material labelled, so that protection travels with the file and Copilot respects it.
- The default sharing settings themselves. Fix the ten items above without changing defaults and you will be doing it again next year.

Use the tooling rather than clicking through
Doing this by hand does not scale beyond a small tenant. SharePoint Advanced Management includes a content management assessment that surfaces oversharing patterns across the estate, including anyone links and org wide sharing, which turns this from an archaeology project into a report you can work through.
Microsoft is also moving these controls closer to where admins already work. Purview data security capabilities for Copilot, including oversharing signals and recommended remediation, are targeted to appear inside the Microsoft 365 admin centre from around October 2026. That is worth knowing, but it is not a reason to wait: the remediation work is the same either way, and doing it before you switch Copilot on is considerably less stressful than doing it after.
A sensible sequence
- Run the assessment first, so you are working from data rather than instinct about where the problems are.
- Fix defaults before content. Otherwise you clean up while new problems are still being created behind you.
- Pilot Copilot with a small group whose data you have already cleaned, rather than a group chosen for enthusiasm. It gives you a real signal without betting the tenant on it.
- Put a recurring review in place. Sharing decays. This is one of the items on our quarterly tenant health check.
None of this is a reason not to adopt Copilot. It is a reason to spend a fortnight first. Our Copilot readiness checklist for SMBs covers the wider picture including licensing and data, the Copilot readiness assessment is the structured version, and where the tenant needs real remediation work our Microsoft 365 team does exactly this.



