Microsoft 3659 min read

Fix SharePoint oversharing before you turn Copilot on

Copilot does not bypass your permissions. It reflects them — which is why the first week of a rollout surfaces files nobody meant to share. The cleanup runs on a tool you already own.

En bref. Copilot ne contourne pas vos permissions : il les reflète. Un déploiement fait donc remonter des années de partages négligents en quelques jours. La bonne nouvelle, c'est que l'outil qui règle ça — SharePoint Advanced Management — est inclus dès que vous détenez une seule licence Copilot. Cet article donne l'ordre des opérations : trouver les sites surpartagés, les retirer de l'index Copilot sans casser les accès, corriger les permissions, puis lever la restriction.

Copilot did not create the problem

A Microsoft 365 Copilot rollout goes wrong in a specific, repeatable way. Week one, someone in finance asks Copilot a routine question and gets back a summary that cites a document they were never meant to see. A salary band. A draft reorganisation. A contract with a client's commercial terms in it.

The instinct is to blame Copilot. That is the wrong diagnosis, and it leads to the wrong fix.

Copilot respects the permissions already in place. It cannot read a file the user could not already open. What it does is remove the only thing that was protecting that file: the fact that nobody knew it was there. A document sitting in a SharePoint site shared with "Everyone except external users" was always readable by the whole company. It took a search nobody thought to run. Copilot runs that search on every question.

Concentric AI puts 16% of business-critical data in an overshared state, averaging around 802,000 exposed files per organisation. EPC Group finds 150 to 300 overshared SharePoint sites in a typical enterprise tenant. Those numbers describe estates that had no incident and no complaint. The exposure was simply never queried.

Where oversharing actually comes from

Almost none of it is malicious, and very little of it is recent. Four patterns account for most of what a first pass finds.

"Everyone except external users." Usually written EEEU. It is offered as a convenient default when someone shares a site, and it means every licensed person in the tenant. A site created for one project in 2022 with EEEU on it is a company-wide library that nobody has looked at since.

Broken inheritance. A subsite or a folder had its permissions detached from its parent to grant one person access, and it never re-inherited. The parent was tightened later; the child was not.

Default-open sharing links. "Anyone with the link" was the tenant default for years. Those links do not expire unless somebody configured expiry, and they survive the departure of whoever created them.

Ownerless sites. The person who owned a site left. Nobody inherited it, nobody reviews it, and it keeps serving whatever it was serving.

None of these are Copilot problems. All of them become visible the moment Copilot indexes the tenant.

The tool you already own

This is the part most organisations do not know, and it is worth stating plainly.

SharePoint Advanced Management is included with Microsoft 365 Copilot at no additional cost. One Copilot licence in the tenant switches it on for the whole tenant. Microsoft bundled it precisely because the oversharing problem was making rollouts fail.

If you have bought Copilot, you are already paying for the tool that finds this. In most tenants we look at, it has never been opened.

Two capabilities carry the work.

Data Access Governance reports enumerate the exposure. They surface sites with broad permissions, sites shared via EEEU, sharing-link usage, and sensitivity-label coverage. This is the inventory step, and it is the one that tells you whether you are looking at twelve sites or three hundred.

Restricted Content Discovery is the one that changes your project plan. It removes a site from Copilot and organisation-wide search results without altering a single permission. People who could open the site can still open it. Copilot stops surfacing it. Microsoft positions it explicitly as a temporary control that buys time to review and right-size access.

That distinction matters more than it sounds. Without it, the only safe sequence is fix everything, then deploy — which for three hundred sites means deferring the rollout by a quarter or more. With it, you can contain the high-risk sites on day one and remediate them while Copilot is live everywhere else.

The order of operations

Run it in this sequence. Each step depends on the one before it.

1. Inventory the exposure. Run the Data Access Governance reports in the SharePoint admin centre. Sort by EEEU exposure and by site permission breadth. Do not start fixing yet — you need the whole picture to decide what is worth fixing first, and the report will usually be longer than expected.

2. Rank by content, not by count. A site shared with everyone that holds meeting notes is noise. A site shared with everyone that holds HR files, salary data, board material, client contracts or anything under Loi 25 is the reason this project exists. Rank on what is in the site, not on how exposed it is.

3. Apply Restricted Content Discovery to the top of that list. This is the containment step. The sites at the top of your ranking come out of Copilot's reach immediately, with no change to who can open them and no disruption to anyone working in them.

4. Remediate for real. Remove EEEU where it was never intended. Re-establish inheritance where it was broken for a reason that has since expired. Expire or revoke standing sharing links. Assign owners to ownerless sites, or archive them. This is the slow part, and it is unavoidable — Restricted Content Discovery hides content from Copilot, it does not fix permissions.

5. Lift the restriction, site by site. As each site is genuinely cleaned, remove it from Restricted Content Discovery and let Copilot index it. This is also the checkpoint that proves the remediation worked rather than assuming it.

6. Set the defaults so it does not recur. Tenant-level sharing defaults, link expiry, site creation policy, and a recurring access review. Without this step you will run the same cleanup again in two years.

The gate worth holding

The decision that costs the most money is the one made before any of this: how many licences to buy, and when to turn them on.

A Copilot licence is CA$28.50 per person per month on top of the Microsoft 365 subscription you already pay for. For twenty-five people that is CA$8,550 a year. Buying them and then discovering the tenant is not ready means paying for a rollout that has to be paused — and pausing it after people have been told it is coming is worse than starting late.

The sequence that works is: inventory first, contain the high-risk sites, then license the teams who will actually use it. The inventory costs nothing but time, and it tells you both whether the tenant is ready and which teams the rollout is genuinely for.

What this does not cover

Restricted Content Discovery is a containment control, not a remediation. A site under it is invisible to Copilot and fully accessible to anyone who could already open it. If the exposure is a compliance problem rather than a discovery problem, hiding it from Copilot does not address the obligation.

SharePoint Advanced Management also does not reach everything. It governs SharePoint and OneDrive. Teams chat, Exchange mailboxes and the contents of connected third-party systems are governed elsewhere, and an agent with a connector into one of those inherits whatever that system allows.

And none of this substitutes for knowing what the data is. A permissions tool can tell you a site is open to the whole company. It cannot tell you that the spreadsheet in it is the payroll file. That is a labelling and classification job, and it is the thing that makes the ranking in step 2 reliable rather than intuitive.

In short

Copilot did not overshare your data. Your permissions did, years ago, and Copilot is the first thing that ever looked.

The cleanup is well understood and the tooling is already paid for. What decides whether a rollout goes well is whether the inventory happens before the licences are bought, or after the first person asks Copilot a question and gets an answer they should not have.

Want help putting this into practice?

We work alongside your team to design, build, and operate the controls described above.