Skip to main content

AI & Automation

What Copilot Will Surface From Your SharePoint (And Why That Should Worry You First)

Copilot does not create new access — it makes existing access searchable in plain English. Here is how to audit what it would find before you switch it on.

3 min read
What Copilot Will Surface From Your SharePoint (And Why That Should Worry You First)
On this page

    Summary: Copilot respects your existing permissions exactly. That is the problem. Years of "just share it with everyone so the link works" become instantly searchable in natural language, and the first person to discover it is usually not from IT. Here is how to audit what Copilot would surface, before you turn it on.

    Why this is different from a normal search

    Your staff could always technically open those files. What changed is effort. Finding an over-shared salary spreadsheet used to require knowing it existed and hunting for it. Now someone can ask a plain question — "what are the current salary bands?" — and get an answer assembled from whatever they happen to have access to, with a citation.

    No permission was violated. The exposure was always there. Copilot just removed the friction that was accidentally protecting you.

    The five things to check first

    1. "Everyone" and "Everyone except external users" grants. These are the highest-yield finding in almost every tenant. Search your SharePoint sites for them specifically.
    2. Anonymous "anyone with the link" sharing. Often enabled tenant-wide years ago for one file transfer and never revisited. Check whether it is still permitted by policy, and how many live links exist.
    3. Broken inheritance on sensitive libraries. HR, finance and legal folders that were customised once and have drifted from their parent site's permissions ever since.
    4. Orphaned Teams and their SharePoint sites. Every Team creates a site. Projects end; the sites and their membership do not.
    5. Guest access. Former contractors, ex-vendor staff, and people from deals that never closed — all still resolving as valid identities.

    Running the audit

    Microsoft provides most of what you need without buying anything extra: the SharePoint admin centre's sharing reports, Microsoft Purview's content explorer if you are licensed for it, and Entra ID's access reviews for guests. The goal of the first pass is not perfection — it is producing a ranked list of what is exposed and what it would cost you if it surfaced.

    Then fix in order of consequence, not order of ease. Payroll, board material, client contracts and anything with personal data come first. The marketing team's old campaign assets can wait.

    Labels are what make it durable

    Permission cleanup is a point-in-time fix; drift restarts the next day. Sensitivity labels and DLP policies are what hold the line, because they attach protection to the content itself rather than to whichever site it happens to live in. Start with two or three labels people can actually understand — not a taxonomy of eleven that everyone ignores.

    What good looks like before go-live

    • No "Everyone" grants on sites holding regulated or confidential material
    • Anonymous link sharing either disabled or expiring by policy
    • Guest access reviewed within the last quarter
    • Sensitivity labels applied to your highest-consequence content
    • A named owner for every Team and site that survives the review

    This is the work that makes an AI rollout defensible to your board and your insurer. Start with the readiness checklist, or have us run it: AI & Copilot consulting. It pairs naturally with a vulnerability assessment, since both are fundamentally about knowing what is actually exposed.

    Stay ahead of IT trends

    Subscribe to our newsletter for the latest insights on cybersecurity, disaster recovery, and IT management, delivered straight to your inbox.

    Need help with IT in Houston or Stafford?

    ECS provides managed IT services, vCIO planning, and vulnerability assessments.