What Copilot can actually reach in Microsoft 365
Copilot does not break permissions. It obeys them — which is exactly the problem, because most tenants have no idea what their permissions currently allow.
The rule, stated once
Copilot can surface, summarise and cite anything the person asking could already open themselves. It adds no access. It removes the friction that used to hide access nobody had audited.
That distinction matters, because it means a Copilot rollout does not create a new security problem. It reveals one you already had, instantly, to every employee at once.
Where the exposure actually comes from
In practice, four patterns account for most of what surprises people.
1. Organisation-wide sharing links
A link created as "anyone in the organisation" is permanent, transferable and invisible in most reporting. Ten years of them accumulate. Each one is a document Copilot can now quote to anybody who asks a question near enough to its contents.
2. Company-wide groups used as convenience
"Everyone except external users" started as a shortcut for one intranet page. It is now attached to sites nobody remembers granting. This is the single most common cause of a Copilot answer that contains something a colleague should not have seen.
3. Inherited permissions on old sites
A site created from a template in 2019 inherits an access model designed for a team that no longer exists. Nobody checks, because nothing surfaced it — until something did.
4. Personal OneDrive sprawl
People store things in OneDrive precisely because it feels private, then share a folder once to collaborate on one file. The folder stays shared.
Why native reporting does not answer this
You can retrieve sharing information per workload, per site, in separate reports. What you cannot easily get is the question you actually need answered: for this person, what would Copilot be able to reach, and which of that is sensitive?
That requires joining the sharing surface to the permission model to the sensitivity of what sits behind it — across SharePoint, OneDrive, Teams and the groups underpinning all three. It is a crawl, not a report.
What to do before you roll out
- Inventory the sharing surface across every workload, not one at a time.
- Find the org-wide links and company-wide groups first. They are the highest blast radius per item and usually the easiest to fix.
- Score by sensitivity, not count. Four hundred shared lunch menus do not matter. One shared HR folder does.
- Fix the top of the list, then re-run. Sharing sprawl regenerates; a one-off clean-up decays within months.
- Keep the evidence. The scan that proves you fixed it is the same artefact your auditor wants next quarter.
The uncomfortable part
Restricting Copilot tenant-wide — turning off search scope, delaying the rollout — treats the symptom and costs you the value you paid for. The exposure was there before Copilot and will outlast it. The links, the stale guests and the forwarding rules are a data-access problem that happens to have become visible.