Skip to main content
Arif Mughal

Oversharing Is the Real Copilot Risk: Fix Permissions and Labels Before You Roll Out AI

Microsoft Copilot respects existing permissions, which means it finds existing oversharing faster than any user ever did. This guide explains where excess access comes from, what SharePoint Advanced Management and Microsoft Purview actually do about it, why Restricted SharePoint Search is retiring, and a phased remediation plan, with every status checked against Microsoft's documentation in September 2026.

Arif Mughal9 min readAI Security

Published 23 September 2026. Every product claim, licence and availability status below was checked against Microsoft's own documentation on 19 September 2026. Where Microsoft's pages disagree, I say so rather than pick one. One of the controls below is retiring, so check the linked source before you plan around anything here.

Most Copilot security conversations start with the model: prompt injection, data leaving the tenant, hallucinated answers. Those are real questions. But the risk that shows up first in a pilot is usually older and more ordinary. In a typical pattern (an illustrative composite, not a specific case), someone asks Copilot a reasonable question and the answer quotes a board paper or an HR case they were technically allowed to open all along.

The one idea that organizes the work

Copilot does not create oversharing. It removes the obscurity that was hiding it.

Microsoft is clear on the mechanics. Copilot "only surfaces organizational data to which individual users have at least view permissions," and the semantic index "honors the user identity-based access boundary." Both statements are reassuring, and both mean the same thing: if your permissions say everyone can read a file, Copilot agrees.

Before Copilot, an overshared site was protected by the fact that nobody knew its name. Copilot reasons across everything a user can reach and summarizes it in one answer. Obscurity does not survive a good retrieval system.

Where excess access comes from

SourceWhy it matters to Copilot
"Everyone except external users" (EEEU) on sites, groups or foldersGrants access to every employee at once, with no action from them
Broken permission inheritanceLibraries and folders drift from the site's model and nobody reviews them
Stale and ownerless sitesOld content with old permissions, and no one to ask
Large groups with edit or read rightsMembership grows faster than anyone removes it
Widely redeemed sharing linksEach click adds a person with real access

One correction to a common claim. Creating a People in your organization link does not, by itself, expose a file to Copilot. Microsoft states that such a link "doesn't make the associated file or folder appear in search results or make it accessible through Copilot." Access starts when someone clicks it. The same applies to Anyone links. The risk is a link pasted into a large channel and opened by hundreds of people. EEEU is different: it gives everyone access immediately.

How oversharing reaches a Copilot answer, and where each control acts. On the left, sources of excess access: Everyone except external users, broken inheritance, stale and ownerless sites, and redeemed sharing links. These feed SharePoint and OneDrive permissions, which are reflected in Microsoft Graph and the semantic index, which ground the Copilot answer. Controls act at three points. Fixing access at the source: site access reviews, Restricted Access Control, inactive site policies and site sensitivity labels. Limiting discovery in the index: Restricted Content Discovery, with Restricted SharePoint Search retiring. Limiting what the answer uses: Purview DLP for Copilot on labelled files, and encryption usage rights.
Figure 1: Oversharing is a permissions problem that Copilot turns into a discovery problem. Controls work at the source, the index or the answer.

What Microsoft now recommends

Microsoft published "Address oversharing in Microsoft 365 Copilot," described as "a Microsoft deployment blueprint," in January 2025. That guidance now lives on Microsoft Learn as Secure and govern Microsoft Copilot: Foundational deployment guidance, updated in August 2026. It has three pillars: remediate oversharing, set up guardrails, and meet regulations.

The order within the first pillar is the part I would copy: find high-risk sites, apply interim protections, fix access, then "remove interim Copilot protections once access and permissions are remediated." That last step is the one programs skip.

A naming note: Microsoft's privacy page now says Microsoft 365 Copilot "is now named Microsoft Copilot," while many admin pages still use the old name. They are the same product.

The SharePoint Advanced Management toolkit

SharePoint Advanced Management (SAM) used to be a separate purchase. Microsoft now states that if an organization assigns at least one Microsoft Copilot licence, SharePoint admins get the SAM features. It is also available as the SAM Plan 1 add-on and in Microsoft 365 E7. One feature, restricted site creation by apps, still needs Plan 1.

FeatureWhat it doesWorth knowing
Data access governance reportsSnapshot of site permissions, EEEU and "Everyone" exposure, labels; 28-day sharing-link and EEEU activityMicrosoft suggests snapshots quarterly, activity monthly
Content management assessmentGuided assessment of oversized audiences, EEEU, broken inheritance, inactive and ownerless sitesWhere I start discovery
Site access reviewsSends the site owner a review tailored to the issue foundUp to 100 sites from the report view, PowerShell beyond that; 1,000 a month from the org-wide report
Restricted Content DiscoveryHides a site from org-wide search and CopilotDoes not change permissions; up to 20,000 sites; not OneDrive
Restricted Access ControlOnly members of up to 10 groups can reach the siteOverrides prior permissions and links; Copilot honors it
Inactive site policiesNotify owners, then read-only or archiveMicrosoft 365 Archive keeps content out of Copilot

Status as of 19 September 2026: none of these carries a preview label in Microsoft's documentation.

The distinction that matters most is between hiding and fixing. Restricted Content Discovery hides. People with access can still open the files directly and still see content they own or recently used. Microsoft itself calls it "a temporary governance control." Restricted Access Control and site access reviews fix. Budget the program around fixing.

Restricted SharePoint Search is retiring

Restricted SharePoint Search was the first emergency brake: an allow list of up to 100 sites that search and Copilot could draw from. Microsoft always said it "isn't a security boundary." It is now retiring.

  • 31 July 2026: new enablement blocked.
  • 31 January 2027: full retirement, "no extensions or exceptions," according to message center post MC1395311.
  • Not migrated: Microsoft will not move RSS settings to Restricted Content Discovery, and warns that "restricted content may become discoverable after RSS retirement."

The Learn page, last updated in July, mentions only the July date. If your tenant still relies on an allow list, treat January 2027 as the day your temporary control disappears.

Where Purview fits

SAM works on sites. Purview works on the content itself, which is what you want once remediation reaches file level.

Sensitivity labels carry protection with the file. When a label applies encryption, users need both VIEW and EXTRACT usage rights for Copilot to return the data. Copilot in Word, PowerPoint and Outlook passes a source file's label to new content it creates. Manual labelling is in E3. Default labels, auto-labelling and site labels are listed for E5.

DLP for Copilot can stop Copilot using files and emails with chosen labels. That is generally available. The item still appears in citations, but its content is not used. Policy changes can take up to four hours to apply.

Data Security Posture Management (the current version; the older one is now "DSPM for AI (classic)") runs a default data risk assessment weekly over your top 100 sites by usage, and offers remediation from there: label, restrict, notify the owner, or start a site access review. A hundred sites is a sample, not an inventory.

Microsoft's own pages disagree on one point. The deployment guidance lists a DLP policy for sensitive information in prompts as a standard guardrail. The DLP documentation marks that capability as preview. Plan for it, but do not write it into a control statement yet.

A phased remediation plan

This plan is my own construct, built on Microsoft's guidance but not Microsoft documentation.

A five-phase remediation roadmap proposed by the author. Phase 1, pilot: a small licensed group, with Restricted Content Discovery on known sensitive sites. Phase 2, discovery: content management assessment, data access governance reports and a DSPM data risk assessment. Phase 3, remediate: site access reviews, removal of Everyone except external users, fixing broken inheritance and assigning owners. Phase 4, label and guard: sensitivity labels, auto-labelling, DLP for Copilot and Restricted Access Control by default. Phase 5, expand: widen licences, remove interim controls, and run reports on a schedule. A note warns that Restricted SharePoint Search is fully retired on 31 January 2027.
Figure 2: Hide first, fix next, then remove the hiding. Each phase names the tools that do the work.
PhaseGoalExit test
1. PilotLearn with a small group; hide the obvious risksKnown sensitive sites under Restricted Content Discovery
2. DiscoveryRank sites by exposure and sensitivityTop sites listed with owner and finding
3. RemediateFix access where the risk is highestEEEU and broken inheritance cleared on those sites
4. Label and guardProtect content, not only sitesLabels and DLP for Copilot live for regulated data
5. ExpandWiden licences; remove interim controlsReports run on a schedule; hidden sites fixed and restored

What I would actually do

Run the content management assessment and the EEEU report before buying another licence. The results tell you how long the program will take.

Put Restricted Content Discovery on the sites you already know are sensitive, and log each one with a date for its removal. A hiding control with no end date becomes permanent.

Send the fixing work to site owners through site access reviews. IT cannot judge whether a finance folder should be open to everyone. The owner can.

Retire any Restricted SharePoint Search allow list now, not in January. For how the same "Everyone" risk appears in Copilot connectors, see choosing a Microsoft 365 Copilot extensibility path. For the wider principle of treating access as a continuous decision, see designing Zero Trust beyond a product checklist.

If you are preparing a Copilot rollout, or already have one and are unsure what it can see, that is work Avalon does: oversharing assessments with SharePoint Advanced Management and Purview, remediation programs run with site owners, sensitivity label and DLP design, and plans to move off Restricted SharePoint Search before it retires. It is part of my enterprise AI and security practice, and the contact page is the best way to start a conversation.

Sources

All checked on 19 September 2026. Where two Microsoft pages disagree, the text names the disagreement.

Copilot and permissionsData, privacy and security for Microsoft Copilot (opens in a new tab) · Microsoft Purview for Microsoft 365 Copilot (opens in a new tab) · How shareable links work (opens in a new tab)

Microsoft deployment guidanceAddress oversharing in Microsoft 365 Copilot (blueprint, January 2025) (opens in a new tab) · Secure and govern Microsoft Copilot: foundational deployment guidance (opens in a new tab) · Configure a secure and governed foundation (opens in a new tab) · E3, E5 and E7 feature comparison (opens in a new tab)

SharePoint Advanced ManagementSAM features in Copilot licences (opens in a new tab) · SAM prerequisites (opens in a new tab) · Get ready for Copilot with SAM (opens in a new tab) · Data access governance reports (opens in a new tab) · Site access reviews (opens in a new tab) · Restricted Content Discovery (opens in a new tab) · Restricted Access Control (opens in a new tab) · Site lifecycle management (opens in a new tab)

Restricted SharePoint SearchRestricted SharePoint Search (opens in a new tab) · MC1395311 retirement notice (message center archive) (opens in a new tab)

PurviewDLP for Microsoft 365 Copilot (opens in a new tab) · Data Security Posture Management (opens in a new tab) · DSPM data risk assessments (opens in a new tab)


Published 23 September 2026; sources checked on 19 September 2026. Licensing and availability for Copilot data controls change often, so check Microsoft Learn before making a commitment. The remediation plan is guidance I propose, not Microsoft documentation. No client, employer or engagement is named in this article, and any scenario described is an illustrative composite rather than a description of specific customer work.

AI Security

Agentic AI Security Architecture: Securing Autonomous Agents in the Enterprise

A research-grounded enterprise reference architecture for autonomous AI agents: agent identity, task-bound authorization, tool and MCP gateways, memory security, runtime containment, observability, and incident response — with an OWASP agentic Top 10 mapping, a bounded-autonomy model, and a 38-control matrix.

71 min read

AI Security

MCP Servers in the Enterprise: How to Vet, Host and Govern Model Context Protocol Tools

Every MCP server is two things at once: text your model will read, and code that acts with someone's credentials. This guide covers the current MCP specification and its OAuth 2.1 authorization model, five risk classes, a vetting checklist, where Microsoft's MCP hosting and gateway options stand in September 2026, and an allow-list model that holds up in an audit.

10 min read