Fix SharePoint Oversharing Before You Turn On Copilot

A young Black woman IT administrator and a friendly robot assistant closing a row of open glowing folder-shaped doors, a friendly robot assistant

Here’s the conversation I keep having with IT directors at mid-size companies. They’re excited to roll out Microsoft 365 Copilot. Licenses are budgeted, a pilot group is picked, leadership is ready to see some AI. Then I ask one question:

“If I searched your SharePoint right now for ‘salary’, ‘pricing’, or ‘termination’, what would I find?”

The room usually goes quiet. Everyone knows the answer: too much. Permissions that were “temporary” in 2019. Sites shared with Everyone except external users because it was easier. A board deck in a legacy team site nobody remembers. An HR spreadsheet one broad link away from the whole company.

For years, that mess was survivable, because finding an overshared file required someone to go looking. Search was mediocre, people were busy, and obscurity did the work your permissions didn’t.

Copilot removes the obscurity

An AI assistant connected to Microsoft 365 reads everything a user can technically access: not what they’re supposed to see, not what they’d ever find on their own. What they can open. Then it volunteers that content, fluently, in answers.

The pricing sheet buried three folders deep in a site from 2021? One question away. “What do we typically discount for enterprise customers?” can now be answered by Copilot, accurately, for anyone in the company, because someone once set a site to org-wide sharing.

This is why, in the readiness assessments I run, unstructured content permissions carry a red flag: it’s the single most common reason I tell teams to delay an assistant rollout. Not cancel. Delay, usually by about 30 days. Here’s how the assessment asks the question, and the 0 to 4 ladder I score it against:

D3. How well organized and permissioned is your unstructured content (SharePoint, Google Drive, file shares, wikis, ticket history)?

  1. Sprawling; we don’t know who can see what
  2. We know there’s oversharing but haven’t addressed it
  3. Permissions cleaned up on some high-risk sites
  4. Most repositories have owners, retention rules, and reviewed permissions
  5. Content is curated and labeled, and permissions are reviewed on a schedule

If you’re honestly at level 0 or 1, and most mid-size organizations I assess are, turning on Copilot converts a dormant permissions backlog into a live disclosure incident on day one. If you’re subject to SOX, HIPAA, or state privacy laws, it can also become a reportable one.

Run the one-hour exposure test first

Before you open a single admin report, find out what an ordinary employee can see. It’s the fastest way to size the problem, and the results are more persuasive than any dashboard when you take them to leadership.

  1. Use a standard account. Pick a test account, or borrow a volunteer, with the same group memberships as a typical employee in sales or operations. Not an admin, and not someone in IT.
  2. Search for the words that should never come back. Salary, compensation, termination, performance review, pricing, discount, acquisition, board, password. Run each one in SharePoint search and note anything the account can open.
  3. Record, don’t fix. Capture the site, the file, and how access was granted: site membership, an org-wide link, or a group nobody remembers. Fixing things during the test hides the pattern.
  4. Count the sites, not the files. Twenty hits usually trace back to three or four sites. Those sites go to the top of your week 1 list.

If the test comes back clean, good: you’ve earned some confidence, and the 30-day plan below will go faster. If it doesn’t, you now have evidence that makes the case for a short delay far better than a policy memo.

Where the exposure usually comes from

When I trace the hits from that test, almost all of them come from the same four patterns:

  • Broad groups on site membership. A site or library granted to Everyone except external users or an all-staff group so that nobody would have to request access.
  • Org-wide sharing links. Someone shares a file with everyone in the organization to save time, and the link outlives the reason for it.
  • Abandoned sites. Project and team sites left over from a reorganization or a migration, with no current owner and permissions nobody has looked at since.
  • Broken inheritance. A folder deep inside a well-run site with its own, much wider permissions, set once as a workaround and never undone.

None of these is exotic, and none of them requires a security failure. They’re the ordinary residue of people trying to get work done, which is exactly why they’re everywhere.

The 30-day cleanup that makes Copilot safe to ship

The good news: you don’t need to boil the ocean, buy a governance suite, or audit every file. You need to contain the highest-risk exposure, and almost all of it concentrates in a handful of sites. Here’s the sequence I give assessment clients.

Week 1: Find out what’s actually exposed

  • Run the sharing reports you already own: SharePoint admin center’s sharing links report, plus the data access governance reports if your plan includes them.
  • Pull the list of sites shared with Everyone, Everyone except external users, or org-wide links.
  • Rank your sites by sensitivity, not size: finance, HR, executive/board, legal, sales pricing. Take the top 20.

Weeks 2–3: Fix the top 20 sites

  • Remove Everyone permissions and kill org-wide sharing links on those sites. Replace with the specific groups that actually need access.
  • Assign a named owner to each of the 20 sites. Not IT, but someone in the business who can answer “who should see this?”
  • Fix the sharing defaults while you’re in there: new links should default to “specific people,” not “anyone in the organization.”

Week 4: Gate the rollout

  • Make “sharing reviewed” a hard gate in your Copilot rollout plan: a checkbox that blocks enablement, not a parallel workstream that quietly slips.
  • Put the long tail of remaining sites on a quarterly review cycle with the site owners you just named.
  • If your Microsoft 365 plan includes Restricted SharePoint Search or restricted content discovery, use it to fence off the sites you haven’t reviewed yet. It’s a blunt tool, but it buys time honestly.

That’s it. Four weeks, mostly admin time, zero new spend for most tenants. It is the most valuable security work your team will do this year, and it’s invisible until the day it saves you.

What to tell leadership about the delay

A 30-day delay is an easy conversation if you frame it correctly. Don’t present it as IT slowing down the AI program. Present it as the AI program’s first deliverable: “We found files an ordinary employee can open that they shouldn’t be able to, and Copilot would surface them in answers. We’re fixing the 20 sites where that matters most, then we launch.” Bring two or three examples from the exposure test, with names removed. Leaders who would argue with a risk rating rarely argue with a screenshot of the salary file.

Then give them a date. A delay with a date is a plan. A delay without one sounds like a veto, and it invites someone to switch the feature on without you.

The part most teams skip

Cleanup without changed defaults just resets the clock; in a year you’ll be overshared again. The durable fix is the boring one: default link types set to specific people, site owners who actually review access, and sensitivity labels on the two or three data types you already know are radioactive (customer records and pricing, usually). Labels plus DLP are what let you say yes to AI features with a straight face, and they’re included in more Microsoft 365 plans than people realize. Check your plan before buying add-ons.

It isn’t only a Microsoft problem

I’ve used Copilot and SharePoint throughout because that’s where most mid-size organizations keep their documents, but the principle applies to any AI assistant or enterprise search tool you connect to your content. If it can read Google Drive, Slack, Confluence, or your ticketing system, it inherits whatever permissions those systems have today. Run the same exposure test on each one before you connect it. A map of where your business data lives tells you which systems to check first.

Where does your team actually stand?

Oversharing is one of 24 questions I score in the AI Readiness assessment, across six dimensions covering data, security, infrastructure, skills, use cases, and governance, each answered on the kind of 0–4 ladder you saw above. The free version takes three minutes and shows you exactly where you’d score.

Get your free AI Readiness Score →

Want to see the depth of the full assessment first? Flip through a complete 38-page sample report; every page is public.

Related guides

Frequently asked questions

Does Microsoft 365 Copilot respect SharePoint permissions?

Yes. Copilot only surfaces content the signed-in user can already access. That is exactly why oversharing matters: anything a user can technically open, including files they would never have found on their own, can appear in Copilot's answers.

How long does an oversharing cleanup take before Copilot?

About 30 days for most mid-size tenants: a week to find exposure using the sharing reports you already have, two weeks to fix your 20 most sensitive sites and assign owners, and a final week to make a sharing review a hard gate in the rollout plan.

Do we need to audit every file before turning on Copilot?

No. Most high-risk exposure concentrates in a handful of sites, such as finance, HR, executive, legal, and pricing. Fix those first, change the sharing defaults, and put the remaining sites on a quarterly review with named owners.

What stops oversharing from coming back after cleanup?

Changed defaults and ownership. Set new sharing links to specific people, give each site an owner who reviews access, and apply sensitivity labels to the few data types you already know are highly sensitive. Cleanup without those changes just resets the clock.

Scroll to Top