Do Not Roll Out Copilot Until You Have Checked Who Can See What

Do not roll out Microsoft Copilot until you have checked who can see what in Microsoft 365, because Copilot answers each person from whatever they already have permission to open, including the folders nobody remembers sharing. Microsoft says it plainly in its own documentation: Copilot only surfaces data a user already has at least view permission to, and it relies on the Microsoft 365 permission models to keep the right content with the right people. Identity and access is where a Cyber Strength Audit starts, and inSUPPORT has run more than 1,500 of them for Australian businesses: who can reach what, from where, and with what protection. A Copilot rollout asks that same question in front of software that is very good at finding answers.

The pressure to switch it on is real. Someone on the leadership team has used it at home, a client has mentioned it in a meeting, and the licence is one click away in the admin centre. Nobody wants to be the person holding up a productivity tool over permissions that have been sitting quietly for years.

The reality is that those permissions have never been tested by anything as effective as Copilot. Picture a salary spreadsheet shared with the whole company in 2021. It has been safe because nobody knew it was there. Ask Copilot what the business pays its managers and that protection is gone in one prompt, with a citation attached.

The check is finite, though, and Microsoft supplies most of the tooling for it, some of it included with the Copilot licence itself. Below are the seven checks to run before the first licence is assigned, in the order that makes each one easier, and what a clean result looks like at each step.

TL;DR: What to remember

  • ✅ Copilot does not create new access. It uses the access people already have, so every sharing decision nobody has reviewed becomes searchable the day you turn it on.
  • ✅ Seven checks, in order: the permissions baseline, open links and company-wide sharing, stale and departed accounts, admin roles, the sensitive folders, the pilot group and its rules, then the record.
  • ✅ Most of the tooling sits in the Microsoft 365 admin centres, and assigning one Copilot licence gives SharePoint administrators the Advanced Management features that support a Copilot deployment. Not every feature arrives that way, so confirm the specific one you need rather than assuming the toolset.
  • ✅ Restricting a site's discoverability is not the same as fixing its permissions. Microsoft's Restricted Content Discovery buys you quiet while you work; the people who could already open the file can still open it.
  • ✅ The first permissions report can take up to five days to run, so start the check before you promise anyone a go-live date.

Contents

What Copilot Can See, and Why the Order Matters

Microsoft describes Copilot as a processing and orchestration engine that coordinates three things: large language models, the content in Microsoft Graph that the person has permission to access, and the Microsoft 365 apps they work in every day. Their email, their chats, their documents, their meetings. The line that decides your rollout is the one about permission. Copilot presents only the data each individual can already reach, and Microsoft is explicit that it is on you to be using the permission models available in SharePoint and the rest of Microsoft 365 so the right people have the right access to the right content.

So the model is not the risk. The permissions are. Before Copilot, an overshared file needed somebody to go looking for it, and almost nobody ever did. Copilot goes looking on the user's behalf, across everything that user can open, and brings back a tidy summary. That is the entire product, and it is also the entire problem if the business has a decade of sharing decisions nobody has reviewed.

Microsoft's own deployment guidance puts the work in a fixed order: remediate oversharing first, then set up guardrails, then deal with regulation. Step one is to identify the high-risk sites and content, apply interim protections, then fix access and permissions. That ordering comes from the vendor, and it is the same order inSUPPORT gives on its own FAQ page: AI assistants inherit whatever data access the user already has, so a rollout on top of loose permissions will surface things across the business that were never meant to be searchable. Audit data access first, then enable.

One naming note before the steps, because it causes confusion in the middle of a rollout. Microsoft 365 Copilot is now simply named Microsoft Copilot, and Microsoft 365 Copilot Chat is now Microsoft Copilot Chat. Microsoft states there are no changes to security, compliance and privacy for organisations, so licences, documentation and internal policies written under the old name still describe the same thing. The seven checks below are the audit itself, written so a CFO or an operations manager can commission it and judge the result without running a single report personally.

The Seven Checks, in Order

Each step names the report or the setting involved and why it matters once Copilot is on. Run them in sequence: the baseline in step one makes every later step faster, and the record in step seven only works if the earlier steps left one.

1. Get the Permissions Baseline Before You Touch Anything

Start with the site permissions snapshot report in the SharePoint admin centre, under Reports and then Data access governance. It is part of SharePoint Advanced Management, and the licensing there is narrower than the shorthand suggests: assigning at least one Microsoft Copilot licence to a user gives SharePoint administrators the Advanced Management features that support a Copilot deployment, which is where the permission state reports sit. Some features are outside that entitlement and need the Advanced Management add-on, so check the feature you actually want rather than assuming the whole toolset arrived with the licence. For every SharePoint and OneDrive site it captures how many unique people can reach the content, how much of that access arrives through groups, how many items have broken inheritance, whether anything is shared with Everyone or with Everyone except external users, how many guests hold permissions, and how many Anyone links and People in your organisation links exist. The detailed view shows the top 100 sites by number of permissioned users, which is exactly where to look first.

Microsoft's own reason for building the report is the reason for this article. Because Copilot respects existing permissions, understanding the current permission structure is critical before deployment, and sites with many users pose the higher risk of unintended exposure through Copilot. Two practical notes. The first report takes up to five days to complete regardless of your size, later runs finish within 24 hours, the data is up to 48 hours old when it lands, and you can run it again every 30 days. And nothing in the report is a verdict on its own: a site with 200 permissioned users might be the staff intranet, which is fine, or the finance drive, which is not.

Clean looks like this: you can name the owner of every site on that top-100 list and explain why its user count is what it is.

Two shapes of sharing cause most of the trouble. The first is the Anyone link, which lets whoever holds the link open the file without signing in, and which Microsoft notes you cannot track: you do not know who has it or who has used it. The second is content shared with Everyone except external users, a built-in SharePoint group that automatically includes every internal person in the business. Microsoft draws a useful distinction here between current and potential exposure. A link or a company-wide grant is potential exposure until somebody actually accesses the content through it. Copilot is how somebody accesses it.

The baseline from step one gives you the counts per site. Two activity reports in the same place, the sharing links report and the Everyone except external users report, show where new links and company-wide shares were created in the last 28 days, which tells you whether the sprawl is historical or still happening. A further snapshot report lists the individual sites, folders and files exposed through those special groups, so the clean-up can be scripted instead of waiting on site owners. Then go to the tenant sharing settings: Microsoft's guardrail guidance for Copilot is to disable or restrict company-wide sharing groups and Anyone links at the tenant level, and the default link type shown when somebody shares is a setting you control.

Clean looks like this: the Anyone link count is zero, or every remaining link has an expiry date and a reason, and no site is shared with the whole business by accident.

3. Find the Accounts That Should Already Be Gone

Microsoft's guidance on inactive accounts opens with the honest observation that user accounts are not always deleted when people leave, and that those accounts are a security risk. The method is the last sign-in date. In the Microsoft Entra admin centre, open the user list, choose Manage view and then Edit columns, add the column named Last interactive sign-in time, then add a filter with the operator set to less than or equal to your cut-off date. Microsoft notes that in many organisations a reasonable window is between 90 and 180 days, which allows for long leave. Read the licensing before you promise a full report: pulling the last successful sign-in property through Microsoft Graph requires a Microsoft Entra ID P1 or P2 licence.

Why this belongs in a Copilot readiness check rather than a general tidy-up: an account that can still sign in is a person Copilot will serve, with everything that account can open. Old guest accounts count too. While you are in the list, confirm that a password on its own cannot reach any of this from the internet. That is a bigger subject than one step, and multi-factor authentication done properly deserves its own read, but a Copilot rollout is a poor moment to discover that a forgotten account with no second factor still works.

Clean looks like this: every enabled account maps to a person who works for you today, and every exception has a written end date.

4. Count Who Holds the Keys

The administrators decide what Copilot is allowed to do, so they are the next list. Microsoft's guidance on access reviews puts three questions in front of you: how many people have administrative access, how many of those are Global Administrators, and whether any invited guest or partner who was given an admin role for one task was ever removed afterwards. In Copilot terms, the admins control the sharing settings from step two, they run the reports, they set the interim protections in step five, and they decide what is allowed into the tenant at all.

This is also the work a managed provider should have done in week one. inSUPPORT publishes exactly that list as its first-week lockdown: administrator access nobody needed, unmanaged devices, and the accounts that were never closed when people left. Formal access reviews are a Microsoft Entra ID Governance feature and may well be more than a 50-person business needs. A named list, checked by a human, does the job.

Clean looks like this: a short list of administrators, a reason written against each name, and no shared admin account that three people know the password to.

5. Deal With the Sensitive Folders Directly

There are places in every business that should never appear in a Copilot answer for the wrong person: payroll, board papers, customer records holding personal information, anything to do with a sale or an acquisition, and the folder where the disputes live. Microsoft's guidance is to apply sensitivity labels to those sites so the label drives the sharing controls, and to assign or confirm an owner for every site you remediate, because a site nobody owns is a site nobody reviews.

Two interim controls are worth knowing about while the clean-up runs, and the first one has to be understood precisely, because half-understanding it undoes the whole exercise. Restricted Content Discovery, part of SharePoint Advanced Management, limits discovery of a site's content in organisation-wide search results and in Copilot responses, and it takes the AI entry points off that site, so people stop seeing the Copilot button and the AI actions menus there. What it does not do is change a single permission. Microsoft states it plainly: site permissions stay the same, users who already have access can continue to access the content, users can still discover content they own or have recently interacted with, and nothing is removed from the search index. It also does not affect searches that start from inside the site itself, or experiences working on a document the person already has open.

That distinction is the whole argument of this article in one setting. A restriction on discovery is not a restriction on access. Microsoft describes Restricted Content Discovery as a temporary governance control that gives you time to review and right-size access while the rollout continues, and that is exactly how to sell it internally: it buys quiet on the sites you are worried about, it does not make them safe, and the permissions work still has to happen. Treat it as a permission fix and you have built the same false confidence the whole rollout was supposed to remove. Microsoft also cautions against using it broadly, because content that cannot be discovered cannot help anyone either.

The second control is data loss prevention for Copilot, in Microsoft Purview, which can stop labelled content being used to ground an answer. Microsoft's instruction for both is to apply them temporarily and remove them once the access and permissions underneath are actually fixed, which is the discipline that separates a clean-up from a permanent workaround. Two licensing cautions: Microsoft writes this part of its guidance for Microsoft 365 E3 and E5, and the sensitivity-label capability inside SharePoint Advanced Management is listed as requiring E5. If you are on a Business plan, get a straight answer on which of these controls your tenant actually has before any of them go into the plan.

Clean looks like this: you can say which sites are under a discovery restriction, why, when it comes off, and who owns lifting it, and nobody in the business has mistaken that restriction for a permission fix.

6. Choose the Pilot Group and Write the Rules for What Goes In

This is where the Australian privacy regulator has a view. The Office of the Australian Information Commissioner's guidance on using commercially available AI products, published in October 2024 and updated in January 2025, says privacy obligations apply to any personal information put into an AI system and to the output it generates, and that due diligence before adopting a product should include who will have access to personal information input or generated when the product is used. It also says that due diligence should not be a set-and-forget exercise. Under APP 6 personal information is used for the purpose it was collected for, and under APP 11 the business takes reasonable steps to protect it from unauthorised access. Both bear directly on which staff get Copilot first and what they put into it.

Worth being precise about one thing, because it gets flattened in a lot of commentary. The OAIC's recommendation to keep personal information, and particularly sensitive information, out of AI tools is aimed at publicly available chatbots and generative AI tools. Copilot working over your own tenant is a different arrangement, and Microsoft states that prompts, responses and data reached through Microsoft Graph are not used to train its foundation models. That is a reason to be accurate rather than a reason to relax: the obligations under APP 6 and APP 11 still apply to what your staff put in and what comes back out. Practically, pick a pilot group whose data is already tidy after steps one to five, and write a one-page rule on what may and may not go into a prompt.

Clean looks like this: a named pilot group, a written usage rule, and someone who owns reviewing both after the first month.

7. Write It Down, Then Switch It On

The record is the point of the exercise. For every site you touched: the owner, what changed, what exception remains and when it ends. For the tenant: the sharing settings as they now stand, the administrator list, the sites excluded from Copilot and why. Microsoft recommends running the snapshot reports quarterly and the activity reports monthly, so put those dates in a calendar while somebody still cares, and take the interim protections off once the access underneath them is fixed.

Then assign the licences to the pilot group rather than to everyone, and let the first month tell you what the reports missed. A rollout run this way produces a document a board can read in five minutes, which is the difference between a Copilot readiness check and a hope that nothing was shared with the wrong people in 2021.

What This Looks Like in a 30 to 300 User Business

The checks are the same at 40 users as at 400. What changes is which button you press, because the reports and controls above are spread across the Copilot licence, Microsoft Entra ID P1 and P2, and the Microsoft 365 E3 and E5 plans Microsoft writes its guidance for. A business on a Business plan will have some of that tooling and not all of it, and the honest version of the plan says which is which. Ask whoever runs your Microsoft environment to state, check by check, which report or setting they used and what your licence includes. If the answer comes back as a screenshot of a security score, that score is a work queue rather than a grade, and it will not tell you who can open the payroll folder.

The provider question is the useful one: who ran this check before the licences were assigned, and what did the reports actually say? inSUPPORT publishes data-access auditing before AI goes live alongside Copilot rollouts within its managed IT services, and Microsoft licensing through its Microsoft Cloud Services accreditation sits beside it. For managed clients the remediation an audit finds is included in the support fee rather than billed back as a surprise project. That matters here, because steps two and three routinely produce a longer list than anyone expected, and a longer list should not mean a second invoice.

On timing, be realistic with the board. The first permissions report alone can take up to five days, and the clean-up depends entirely on how much sharing sprawl a decade produced, so nobody should be quoting you a finish date before the baseline is in. What a business this size can reasonably expect is a ranked list inside the first fortnight and a pilot group with tidy permissions soon after. The order is what protects you: baseline, links, accounts, administrators, sensitive sites, pilot rules, record. Then Copilot.

Copilot Readiness Questions, Answered Plainly

Is Microsoft Copilot safe to turn on for my staff?

It is as safe as your permissions. Copilot does not create access, it uses the access each person already has, and Microsoft states that it only surfaces content a user already has at least view permission to. Microsoft also states that prompts, responses and data reached through Microsoft Graph are not used to train its foundation models. The exposure that matters is internal: files shared too widely years ago that nobody has reviewed since. Run a Copilot readiness check, start with a pilot group whose data is tidy, and the answer becomes yes for that group, with a record that shows why.

Should our IT provider run the Copilot readiness check, and what should we ask for?

Yes, if they can produce the evidence rather than describe it. Ask for the site permissions report output with the top sites and their owners, the list of accounts with no sign-in inside your cut-off, the list of administrators with a reason against each, the tenant sharing settings as they now stand, and which sites are excluded from Copilot and why. A verbal assurance that the tenant is tidy is a statement of intent. The reports are the evidence, and a provider who runs your environment should already be able to produce them.

How long does the check take before we can roll Copilot out?

Longer than the licensing step, which is the point. Microsoft notes the first site permissions report takes up to five days to complete, with later runs finishing within 24 hours. The clean-up that follows depends on how much sharing sprawl the report finds, so treat any fixed timeframe quoted before the baseline exists with suspicion. A sensible shape is the baseline in week one, the links and accounts closed over the following week or two, and a pilot group live once its data is tidy. Re-run the report before you widen the rollout.

We have already rolled Copilot out. Where do we start?

In the same place, with more urgency. Microsoft's guidance covers both preparing for Copilot and adjusting the controls after it is enabled, so nothing here is closed to you. First step today: put the interim protections on the sensitive sites, using Restricted Content Discovery where your licence includes it, so payroll and board folders stop surfacing in organisation-wide search and Copilot responses while you work. Be precise with everyone about what that buys you, because it is the point people get wrong: it restricts discovery, it does not change permissions, and anybody who could already open those files still can. Then run the baseline report and follow the seven checks in order. If nobody in the business can produce those reports, an independent audit of identity and access is the fastest way to get the list.

Find Out Who Can See What Before Copilot Does

A Cyber Strength Audit opens on identity and access: who can reach what, from where, and with what protection. It hands you the findings ranked by what would actually hurt, with a costed path to closing each one. inSUPPORT works with Australian businesses of roughly 30 to 300 users and has run more than 1,500 cyber audits, and for managed clients the remediation those audits find is included in the support fee rather than quoted back as a separate project. If Copilot is on the roadmap and nobody can tell you today what the permissions report would say, that is the audit to book first.

Book a Cyber Strength Audit →

Sources

  • "Data, Privacy, and Security for Microsoft Copilot", Microsoft Learn, last updated 18 August 2026. Confirms that Copilot only surfaces data to which a user has at least view permission, that it relies on the Microsoft 365 permission models, that prompts, responses and Microsoft Graph data are not used to train foundation models, and that Microsoft 365 Copilot is now named Microsoft Copilot. learn.microsoft.com
  • "Configure a secure and governed foundation for Microsoft Copilot", Microsoft Learn, last updated 18 August 2026. The vendor's ordered guidance: remediate oversharing, set up guardrails, meet regulations. Also the two interim protections, Restricted Content Discovery and DLP for Copilot, the instruction to remove them once access and permissions are remediated, and the Microsoft 365 E3 and E5 licensing the guidance assumes. learn.microsoft.com
  • "Restrict discovery of SharePoint sites and content", Microsoft Learn, last updated 15 September 2026. The precise scope of Restricted Content Discovery: it limits discovery in organisation-wide search and Copilot responses and removes the AI entry points from the site, but site permissions stay the same, users keep the access they already have, users can still discover content they own or have recently interacted with, nothing leaves the search index, and searches originating from site context are unaffected. Microsoft describes it as a temporary governance control. learn.microsoft.com
  • "SharePoint Advanced Management features in Microsoft Copilot licenses", Microsoft Learn, last updated 18 August 2026. Assigning at least one Microsoft Copilot licence gives SharePoint administrators the Advanced Management features that support a Copilot deployment, including the permission state reports and Restricted Content Discovery. It also names what is not included: restricted site creation by apps needs the Advanced Management Plan 1 add-on, and the sensitivity-label capability is listed as requiring E5. learn.microsoft.com
  • "Data access governance reports - get site permission states snapshot report for SharePoint sites", Microsoft Learn, last updated 16 July 2026. What the site permissions report captures, the top-100 view, the up-to-five-day first run, 24-hour later runs, 48-hour data age and 30-day re-run, the current versus potential exposure distinction, and Microsoft's statement that because Copilot respects existing permissions the permission structure must be understood before deployment. learn.microsoft.com
  • "Data access governance reports for SharePoint sites", Microsoft Learn, last updated 30 July 2026. The sharing links and Everyone except external users activity reports covering the last 28 days, the report that lists the individual items exposed through those special groups, and the quarterly snapshot and monthly activity cadence. learn.microsoft.com
  • "Manage sharing settings for SharePoint and OneDrive in Microsoft 365", Microsoft Learn, last updated 30 June 2026. Anyone links open files without the person authenticating and cannot be tracked, plus the tenant-level sharing options, link expiry and the default link type. learn.microsoft.com
  • "How to manage inactive user accounts", Microsoft Learn, last updated 23 February 2025. Accounts are not always deleted when people leave and represent a security risk; detection by last sign-in date; the 90 to 180 day window many organisations use; the Microsoft Entra ID P1 or P2 licence needed for the last successful sign-in property through Microsoft Graph. learn.microsoft.com
  • "What are access reviews?", Microsoft Learn, last updated 12 March 2026. The recommendation to check how many users hold administrative access, how many are Global Administrators, and whether invited guests or partners assigned an administrative task were ever removed. learn.microsoft.com
  • "Guidance on privacy and the use of commercially available AI products", Office of the Australian Information Commissioner, published 21 October 2024 and updated 17 January 2025. Privacy obligations apply to personal information input into and generated by AI; due diligence includes who will have access to that information and is not a set-and-forget exercise; APP 6 and APP 11 obligations; and the recommendation against entering personal information is directed at publicly available generative AI tools. oaic.gov.au
Kane Nawrocki, Founder and CEO of inSUPPORT

About the author: Kane Nawrocki is the founder and CEO of inSUPPORT. He has spent more than 25 years in IT and built inSUPPORT to give Australian businesses managed IT, security and compliance as one model, with the remediation an audit finds included in the support fee rather than billed back as a surprise project.

Content reviewed by Probably Genius for accuracy and relevance.

Want to discuss this topic more?
CLICK HERE