20+ years with Microsoft 1,100+ organisations under management 131 countries invoiced locally 5 of 6 Solutions Partner designations 4-hour first response
IT Partner.Microsoft Solutions Partner +44 20 8142 5752 Talk to us Get a quote

HomeServices › Copilot oversharing

AssessmentSecurityCopilot

The salary file somebody shared with everyone, three years ago

Microsoft 365 Copilot oversharing assessment and remediation

Copilot does not break your permissions. It removes the friction that used to hide them: nobody had to know which site to search or which link somebody pasted into a chat two years ago. Three weeks to find what it would surface to the wrong person, fix the agreed set with the owners rather than behind their backs, and leave you evidence that it is fixed.

Typical timeline3 weeks
PriceFixed, after scoping
Licence neededOne Copilot licence in the tenant
Invoiced inEUR or GBP
01 — Overview

What this engagement is

Ask anyone who has just bought Microsoft 365 Copilot what worries them and the answer is always the same: what will it show the wrong person? The honest reply is that it will show them whatever they can already open — and in most tenants that is a good deal more than anybody would defend if they sat down and looked at it today.

A sales manager asks for the discounts the company has agreed internally, and gets a tidy answer with citations: a pricing workbook opened to the whole organisation during a migration, a sharing link pasted into a chat two years ago, and a board deck in a team whose membership was widened for a week and never narrowed again. Every one of those was already reachable. What changed is that nobody now has to know where to look.

In Europe that is not only an embarrassment. Personal data reaching colleagues with no business reason to see it is a matter for your data-protection duty, and in Germany, Austria and the Netherlands it is a matter for the works council, who will ask what the assistant can reach before they agree to it being switched on. The same body, the same question, a different rollout.

The tools are Microsoft’s own, and here is what each one is

Microsoft Purview Data Security Posture Management is the reporting built into Microsoft 365 that says which sites hold sensitive material, whether it is labelled and how widely it is shared. Without it, the answer to “where is our sensitive content and who can reach it?” is somebody’s guess. How deep it looks depends on what you are licensed for, which we confirm in your tenant rather than assume — the difference between the Microsoft 365 plans is on our plan comparison.

SharePoint Advanced Management is an add-on that Microsoft gives your administrators once a single Copilot licence is assigned anywhere in the tenant. It produces the reports that matter here: which sites are open to everyone in the company, where sharing links have piled up, where a site stopped inheriting its parent’s permissions, which sites have no owner at all, and which guests are still in a team after the project ended. It also sends each site owner a notice about the specific problem on their own site, which turns a cleanup into something owners do rather than something done to them.

Restricted Content Discovery is a per-site switch that keeps a site out of Copilot, out of agents and out of organisation-wide search without changing who can open the files. It is containment, not a fix: the right tool for a human-resources or acquisition site that must never surface in a chat while the permissions underneath are being corrected. Every site we put behind it goes on a register with a date to revisit. The older tenant-wide allow list, Restricted SharePoint Search, is being retired by Microsoft, so we do not build on it.

No third-party scanner is involved, and nothing is installed. We read permissions, sharing metadata, group membership and the classification results Microsoft has already produced — not the contents of your documents.

This engagement is delivered jointly with the engineering team in our group’s other offices, and invoiced by the entity that covers your country — euro or sterling for Europe and the United Kingdom.

02 — Outcomes

What you get out of it

01A register of every site, shared drive and team that is exposed, ranked by how sensitive the content is multiplied by how many people can reach it — not an alphabetical list of findings
02The agreed set of sites actually remediated, up to twenty-five of them inside the fixed price, each one confirmed by its owner before anything changed
03Broad grants replaced with role-based groups, sharing links removed or narrowed to named people, and inherited permissions restored where the break was never a decision anybody made
04The sites that must never appear in a chat kept out of Copilot and organisation-wide search while their permissions are corrected, and verified afterwards by asking Copilot again
05Sensitivity labels applied or corrected from the set you already have — we work with your taxonomy and do not design a new one
06Dead sites archived rather than deleted, inside Microsoft’s recovery windows, with every action logged and reversible
07A monthly check your own administrator runs in under a morning, written for them rather than for us, and run together once before we leave
08Everything beyond the twenty-five costed and prioritised, so the next decision is a budget decision rather than another investigation
03 — Deliverables

What you receive

Exposure register. Every flagged site, shared drive and team with its exposure type, where the evidence came from, the named owner and the recommended action.
Licensing and capability map. What your current licences unlock, what a higher tier would add, and where a setting change does the job so no upgrade is recommended at all.
Remediation plan for the agreed set. Per-site actions, owner, sequence, and the confirmation each one waits for.
Owner notices and their answers. What each owner was told about their own site, what they decided, and what they declined.
Change log. Every link removed, permission restored, group resized, label applied and site archived — with the time, who confirmed it and how to undo it.
Containment register. Which sites are being kept out of Copilot, why, and the date to look at lifting it.
Prompt tests, before and after. The questions real people in real roles asked Copilot, what it cited, and which site each citation came from.
Evidence pack. Dated exports of the same reports run before and after, arranged so an auditor, an insurer or your board can re-check any claim without taking our word for it.
Monthly check runbook. Which reports to open, what the thresholds are, who gets notified and who owns each step.
Costed backlog for everything outside the agreed set, and a live walkthrough with your information technology, security and data owners.
04 — Plan

How the three weeks unfold

Days 1–2

Scope, licences, access

Agree the tenant, the workloads and the domains that lead the ranking — human resources, finance, legal, executive, anything to do with an acquisition. Confirm what your licences actually unlock. Take time-bound, least-privilege access that you approve and that expires on its own.

Days 3–6

Find it

Run the assessments and reports across sites, shared drives and teams, inventory the ownerless, oversized and guest-heavy workspaces, and sit down with three to five of your own people in real roles while they ask Copilot ordinary questions about their work. Every citation it returns traces back to a site, a link or a membership.

Days 7–8

Rank it and agree

Build the register, walk it with you, and agree which sites are remediated now, which are contained while their permissions are corrected, and which go into the costed backlog. Owners are notified at this point, not after their site changes.

Days 9–13

Fix it

Work through the plan with each owner confirming their own site: links, inherited permissions, group membership and second owners, labels, guests whose project ended, dead sites archived. Nothing is bulk-deleted and every change is logged with how to reverse it.

Day 14

Prove it

Re-run the same reports, ask the same questions of Copilot again, and package the before-and-after evidence with dates on it.

Day 15

Hand it over

Run the first monthly check together with your administrator, walk through the runbook and the containment register, and deliver the readout and the backlog.

05 — Before we start

What we need from you

A Microsoft 365 tenant with SharePoint, OneDrive and Teams in use, and a rough count of sites and teams so we can confirm the price before starting.
At least one Microsoft 365 Copilot licence assigned in the tenant — it is what entitles your administrators to the reporting add-on and what Microsoft requires for the containment switch. Without one the assessment still runs on the standard administration reporting, and we tell you plainly which controls are off the table. Copilot licences and prices.
An existing set of sensitivity labels if labels are to be applied or corrected. We work with your taxonomy; designing one is a different piece of work.
Named owners for the sensitive domains, with the authority to confirm or decline each change, and somebody to escalate to when an owner does not answer.
Three to five people in real roles — sales, human resources, finance, a project manager, support — free for two short sessions, before and after.
Administrative access granted for the three weeks and time-bound, through delegated administration that you approve and can withdraw.
06 — Working together

Who does what

We do

  • Run the assessments, the reports and the prompt tests, and build the ranked register.
  • Propose what to fix and what to contain, and explain the risk in anything we recommend leaving alone.
  • Execute the agreed changes with owner confirmation, logging every one with its rollback.
  • Re-run everything and assemble the dated evidence.
  • Write the monthly runbook for your administrator and run the first cycle together.
  • State the limits of what was assessed and what remains, in the readout, in writing.

You do

  • Grant the time-bound access, give us the site and team counts and the existing label set, and name the data owners.
  • Decide what is remediated and what is contained; owners confirm or decline inside the agreed window.
  • Provide the people for the prompt tests and somebody to escalate to.
  • Own the residual risk for anything deliberately left open, and the backlog beyond the agreed set.
  • Run the monthly check after handover, or ask us to quote for running it.
  • Own the Microsoft licensing decisions and their cost.
07 — Scope

What is not included

×Deciding whether to buy Copilot at all, and building the business case. That is the return-on-investment calculator and a conversation, not a paid engagement.
×Designing a sensitivity-label taxonomy, or rolling labels out across the tenant. Here we apply and correct the labels you already have.
×Building data-loss-prevention policies, or a governance programme at tenant scale. Both are separate work and we will say so rather than fold them in.
×Redesigning your information architecture, hub structure or team lifecycle policy beyond the sites in the agreed set.
×Remediation beyond the agreed set, moving content between sites, or restructuring libraries. Quoted from the backlog, in writing, before any of it starts.
×Training people to use Copilot well, and driving adoption afterwards.
×Mailbox content, third-party document repositories, and any promise that every exposure in the tenant has been found. We report what the evidence shows and what remains.
×Microsoft licences themselves. They are yours to decide and to buy; if you buy them through us they are on our published price list, and the decision is made before the work begins.
08 — Fine print

Limitations and technical notes

!It is a point in time. Sharing links, memberships and new sites change daily. The evidence pack is dated and says so, and the monthly check exists because a tidy tenant does not stay tidy by itself.
!Depth follows licensing. What the assessments can see differs between the Microsoft 365 plans, and some controls need the reporting add-on for the people who keep access. We confirm in your tenant at kickoff and the capability map says which findings would need more.
!Microsoft’s own limits apply. The item-level assessment covers a limited number of sites and does not yet cover personal shared drives at that depth, so for anything larger we combine it with the site-level reports and scripted inventory rather than pretending one console sees everything.
!Containment is not a fix. Keeping a site out of Copilot does not change who can open the files, and reindexing takes up to three days. Every contained site is on the register with a date to revisit.
!We read permissions, not documents. Whether a file belongs on a site at all is the owner’s call, which is why owners confirm each action and why the audit log shows exactly what we touched.
!Remediation moves at the speed of owner decisions. A site whose owner does not answer inside the window is contained and escalated rather than changed quietly — and it still counts towards the agreed set.
!Microsoft changes this area every quarter. Feature names, limits and licensing rules on this page are checked each time the service is reviewed. Where Microsoft’s current documentation disagrees with us, Microsoft is right.
09 — Questions

Asked on almost every first call

Is Copilot bypassing our permissions?

No. It grounds only on what the person asking can already open, and it honours label protection. What it removes is the work of knowing where to look. That is why the fix is the permissions and sharing model rather than a setting inside Copilot.

How do you find what it would show the wrong person?

Three ways that check each other. The reporting says which sites hold sensitive material and how widely it is shared. The administration reports show which sites are open to everyone, where links have piled up, where inheritance is broken and which sites have no owner. And your own people ask Copilot ordinary questions about their work, and every citation it returns traces back to a site, a link or a membership.

What does it cost?

A fixed price, quoted in writing after a short scoping call, and you pay after you approve delivery. It is driven by the size of the estate and how much of it you want remediated inside the fixed scope. Scoping costs nothing.

What counts as one site, and what if we have more than the agreed set?

One site, or one personal shared drive with a flagged exposure; a team counts as the one site behind it. The assessment covers the whole tenant however many sites there are — the cap is on how much is remediated inside the fixed price. Anything beyond it is costed in the backlog and quoted before it starts, and if your estate looks like it will exceed the cap we say so at the scoping call rather than in week two.

Will this break how people work?

It is built not to. Broad grants are replaced with role-based groups rather than simply removed, links are narrowed to the people who genuinely need them, sites are archived rather than deleted, and every change waits for the owner and is logged with how to undo it. A lockdown that pushes people into private copies of everything would be a worse outcome than the oversharing.

Do you read our documents?

No. Permissions, sharing metadata, group membership and the classification results Microsoft already produces. Access is least-privilege, granted for the three weeks, approved by you and visible in your audit log.

Does it cover Copilot Chat and agents too?

Yes, because they read the same permissions underneath. What this engagement does not do is govern the agents themselves — what they connect to and who may publish them — which is a different piece of work.

Could we do this ourselves?

Yes. The reports and controls are Microsoft’s and this page names them. What you are buying is three weeks of somebody who has run them before: knowing which findings matter, what to do about each without breaking a team, how to get owners to decide, and how to prove it afterwards. The runbook is yours either way, and nothing about this ties you to us afterwards.

What happens after the three weeks?

Your administrator runs the monthly check from the runbook, and we run the first one together on the last day. If you would rather we ran it every month, that is a separate quote — asked for, not assumed.

10 — Related

Worth reading next

Scoping costs nothing

Tell us roughly how big the estate is and which sites worry you

How many sites and teams, whether any Copilot licences are assigned yet, and which areas keep you up at night. You get back a written scope, a sequence and a fixed price — usually within one business day, and nobody rings you unless you ask.