IT & AI engineering for US businesses · 16 practices
Modern Workplace · June 2026 · 6 min read

Microsoft 365 Copilot readiness: the permissions problem nobody mentions

Copilot inherits your sharing model. If SharePoint permissions have drifted for a decade, it'll happily surface that drift to everyone. A practical pre-rollout checklist.

Copilot doesn't grant anyone new access. It simply makes existing access discoverable. The salary spreadsheet shared with "Everyone except external users" in 2017 was always technically visible; now it's one natural-language question away.

Where oversharing hides

  • Sites and libraries shared with "Everyone" or "Everyone except external users".
  • "Anyone with the link" sharing that was never expired.
  • Teams created for a project years ago, still public, still full of files.
  • Broken inheritance on folders nobody remembers creating.

A pre-rollout checklist

  1. Run a sharing report. Use SharePoint Advanced Management or Microsoft Purview to list sites with broad access and anonymous links.
  2. Classify your sensitive content. Apply sensitivity labels to HR, finance, legal and customer data — even a simple three-tier scheme helps.
  3. Fix the top 20 sites first. Oversharing is concentrated; a handful of sites usually holds most of the risk.
  4. Restrict search for sensitive sites while you remediate, so Copilot can't ground on them.
  5. Pilot with a representative group — not only IT — and ask them to try to find things they shouldn't.
  6. Set a review cadence. Access reviews for Teams and sites every quarter stop the drift from coming back.

For regulated industries

If you handle PHI under HIPAA or controlled unclassified information under CMMC, do this work before any licenses are assigned — and document it. It becomes evidence for your next assessment.