Governance Guide · Microsoft Copilot Readiness

Microsoft Copilot readiness: fix oversharing before you turn it on.

Microsoft Copilot was formerly named Microsoft 365 Copilot.

Steve Buckner
Steve Buckner

Cloud Systems Engineer · MCT · PMP · Azure Solutions Architect Expert. 40+ years in IT and operations. Builder of the AI Capability Rollout Framework.

Published September 2026 · About Steve →

Microsoft Copilot only shows people content they already have permission to see. So the risk isn’t that Copilot breaks your permissions — it’s that it reveals how loose they already are. Before you roll Copilot out widely, find the SharePoint and OneDrive content that’s shared far more widely than intended, hide the riskiest sites from Copilot while you work, fix the permissions, and set defaults so new content starts protected. Microsoft’s own deployment guidance follows the same order.

Microsoft product and feature names in this article were verified against Microsoft Learn as of 30 September 2026. Microsoft renames features often, and some screens still show older names during the transition.


Why does oversharing matter more with Copilot?

Most organizations have years of content shared more widely than anyone intended: a finance folder open to “Everyone except external users”, an old HR site with no owner, an “Anyone” link sent once and never expired. Until now, that content stayed hidden because nobody knew where to look.

Copilot changes that. When someone asks a question, it searches everything that person can open and uses it in the answer. Microsoft states that Copilot only surfaces organizational data the individual user has at least view permission for — which is exactly why forgotten oversharing suddenly becomes visible. Copilot doesn’t create the exposure. It removes the obscurity that was hiding it.


What are the steps to get ready?

1. Find the risk

Use the reports you already have. Microsoft Purview Data Security Posture Management (DSPM) runs data risk assessments that flag overshared sites holding sensitive data. SharePoint Advanced Management’s content management assessment and its data access governance reports show sites with oversized audiences, “Everyone except external users” access, broken permission inheritance, and inactive or ownerless sites. Rank what you find: sensitive content with broad access comes first.

2. Contain it while you fix it

Two temporary controls reduce exposure while the real fix happens. Restricted Content Discovery hides selected SharePoint sites from Copilot and organization-wide search. A Microsoft Purview data loss prevention policy can stop Copilot using files and emails that carry your most sensitive labels. Check the audit log afterwards to confirm it’s working.

3. Fix the access

Ask site owners to review and remove excess access — SharePoint Advanced Management’s site access reviews delegate this to them. Remove “Everyone” and “Everyone except external users” permissions, narrow “Anyone” and company-wide links, fix broken inheritance, make sure every site has accountable owners, and apply sensitivity labels to the sites you’ve cleaned up.

4. Keep it clean

Fixing today’s oversharing is wasted if new sites are created the old way. Restrict company-wide sharing and “Anyone” links by default, require a sensitivity label when a site or team is created, set default labels, and deal with inactive sites so stale content doesn’t resurface in answers.


What does Restricted Content Discovery do — and not do?

It hides a site from Copilot and organization-wide search while you review it. It doesn’t change permissions: anyone with access can still open the site directly, and people can still find content they own or recently worked on. It works on SharePoint sites only, not OneDrive, and on very large sites Microsoft says an update can take more than a week to take full effect. Treat it as temporary and remove it once a site is fixed — overusing it makes Copilot’s answers less complete.

If you’re using Restricted SharePoint Search, note that Microsoft is retiring it: new enablement has been blocked since 31 July 2026, and Microsoft points to Restricted Content Discovery instead.


How should you roll Copilot out?

In phases, tied to the clean-up rather than to the calendar:

  1. Prepare — find and contain the high-risk sites, set the secure defaults, and put a workplace AI policy in place.
  2. Pilot — license a small group, such as IT, AI champions and owners of sites already fixed, and watch the audit log.
  3. Clean-up waves — department by department: review access, fix permissions, apply labels, lift the temporary restrictions, then license the department.
  4. Broader rollout — license everyone else, with the announcement and policy acknowledgement done properly.

What do you need?

Copilot licences for the people who’ll use it, and Microsoft 365 E3 or E5 (or Office 365 E3 or E5) for the SharePoint, OneDrive and Purview features above — some of Microsoft’s recommended Purview features need E5. According to Microsoft’s deployment guidance, SharePoint Advanced Management is included with Copilot licences. You’ll also want a SharePoint administrator, a Purview compliance administrator and your site owners working together.

Sources (Microsoft Learn, verified as of 30 September 2026): Configure a secure and governed foundation for Microsoft Copilot; Data, Privacy, and Security for Microsoft Copilot; Restrict discovery of SharePoint sites and content; Restricted SharePoint Search; SharePoint Advanced Management overview.

Going further

The Executive Suite’s Rollout & Operations Kit includes the Microsoft Copilot Readiness Guide — a 15-step pre-enablement checklist with where to find each setting, secure defaults for new content, a data-class-to-sensitivity-label map, phased rollout exit criteria and a monitoring plan.

Choosing between AI platforms more broadly? See why your organization should use business or enterprise AI plans. To see where Copilot fits in a wider rollout, start with the free AI Readiness Score or the AI implementation roadmap.


Related resources.

Business and Enterprise AI Plans →

Why company data belongs on business and enterprise AI plans.

AI Guardrails Guide →

The working rules your team needs before Copilot goes wide.

Workplace AI Policy →

Put the rules in writing before the broader rollout.


Common questions.

No. Microsoft states that Copilot only surfaces organizational data a person already has at least view permission for. What changes is how easy that content is to find — which is why overshared files and sites become a real risk once Copilot is switched on.

Content that’s accessible to far more people than it should be. Common causes are sites or files shared with “Everyone” or “Everyone except external users”, “Anyone” and company-wide sharing links that never expire, broken permission inheritance, and old sites nobody owns.

A SharePoint Advanced Management setting that hides selected SharePoint sites from Microsoft Copilot and organization-wide search while you review them. It doesn’t change permissions — people with access can still open the site — and it’s designed to be temporary. It requires your organization to be licensed for Copilot.

Microsoft is retiring it. New enablement has been blocked since 31 July 2026, and Microsoft recommends Restricted Content Discovery for controlling what Copilot can discover. Verified against Microsoft Learn, 30 September 2026.

Microsoft states that prompts, responses and data accessed through Microsoft Graph aren’t used to train the foundation models Microsoft Copilot uses. Verified against Microsoft Learn, 30 September 2026.

It’s the main set of tools Microsoft recommends for finding and fixing SharePoint oversharing — content management assessment, data access governance reports, site access reviews and Restricted Content Discovery — and Microsoft’s deployment guidance says it’s included with Copilot licences.

It depends on how much content you have and how widely it’s shared, not on a fixed timeline. Tie each rollout phase to clean-up milestones — for example, every high-risk site fixed or restricted before the pilot, and each department’s sites fixed before that department is licensed — rather than to a date.

Get the full Copilot readiness checklist.

The Microsoft Copilot Readiness Guide in the Executive Suite’s Rollout & Operations Kit turns these four steps into a 15-step checklist, with secure defaults and a phased rollout plan.

See the Rollout & Operations Kit → Take the Free Assessment