2 July 2026
How to Prepare Microsoft 365 Permissions for a Safe Copilot Rollout

Photo by Abid Shah on Unsplash
A safe Microsoft 365 Copilot rollout starts before anyone opens the app. It starts with a proper look at who can already see what.
At a legal, accountancy or other professional services firm, that question matters more than it does almost anywhere else. The files sitting in a Microsoft 365 tenant aren't just internal admin, they're client matters, fee arrangements, financial data and employment records: the actual product the business sells. Copilot doesn't create any new access to that material. It just makes existing access far easier to use, which is exactly why it's worth checking what that access covers before switching it on.
What Copilot actually does with your files
Copilot answers a question by retrieving information through Microsoft Graph, the layer that connects email, calendar, SharePoint, OneDrive and Teams across a Microsoft 365 tenant. When someone asks it something, it pulls from whatever the signed-in user already has permission to see, then drafts or summarises an answer from that.
That's the reassuring part of how Copilot works, and it's genuinely true: it cannot reach a file the user isn't already authorised to open. The part worth sitting with is the other half of that sentence. Everything depends on whether "authorised to open" still matches what a firm would actually choose today, rather than whatever it happened to drift into over the last few years.
Why permissions end up wider than anyone assumes
Access tends to accumulate rather than get assigned deliberately. Someone gets added to a shared drive for a specific matter, the matter closes, and the access is never removed because removing it was never anyone's job. A Teams channel set up for one project grows past its original membership and stays that way. A file gets shared for a single review and the link never expires.
None of that looks like a mistake at the time. It's the same drift we've written about in the context of staff leaving a business: access that outlives the reason it was granted, multiplied across every project, client and staff change a firm has had since its tenant was first set up. Nobody decided to overshare. It simply built up while nobody was specifically watching.
Copilot doesn't distinguish between access that's still appropriate and access that's just never been revisited. If the permission exists, it's available to search, summarise and draft from.
What that can actually surface
Once broad permissions exist, a handful of everyday questions can return more than the person asking expected.
- A question about pay can return a compensation spreadsheet that was shared with a hiring manager for one recruitment round and never unshared once they moved on.
- A question about a closed matter can pull content from a site set up for a different team, because someone added for a one-off project still has access nobody thought to remove.
- A question about current deals or pipeline can aggregate pricing sheets, prospect lists and data rooms that were each shared once, for one meeting, and never tidied up afterwards.
- A question about a former employee can surface exit paperwork, performance reviews and email threads that were never meant to be found by anyone below whoever handled the departure.
None of this requires anyone to be looking for it deliberately. It's simply what happens when a capable search-and-summarise tool is pointed at a permission structure nobody has audited in years.
A small pilot isn't automatically a safe one
Running Copilot with a handful of licences before rolling it out further feels like the cautious option, but the way most firms pick pilot users tends to work against them. The people chosen for a pilot are usually partners, directors or senior managers, and they're also the people with the broadest access in the business. A pilot limited to three senior staff can end up a higher-risk test than one spread across three junior ones.
Licences drift, too. One gets handed to whoever asks next when someone stops using theirs, and "who asked" isn't the same as "who has an appropriately scoped set of permissions." Audit logs will show what was searched for after the fact, but a Copilot summary can't be un-shown to whoever received it.
What Microsoft actually recommends checking first
Microsoft's own deployment guidance for Copilot is built around three areas: remediating oversharing, setting up guardrails, and meeting AI-related regulatory obligations, with oversharing listed first because it's the one that needs sorting before anything else about the rollout can be trusted.
Two tools do most of the practical work here, both included with a Copilot licence rather than needing anything bought in separately.
SharePoint Advanced Management's Content Management Assessment runs from the SharePoint admin centre and produces a guided report on which sites are overshared, inactive or ownerless, with specific fixes suggested for each. Microsoft recommends rerunning it roughly every 30 days rather than treating it as a one-off.
Data access governance reports, in the same admin area, break the same problem down further: which sites currently carry the widest exposure, exactly which sites a specific person can reach, and where content has recently been shared with the whole organisation rather than a defined group. Between the two, these answer "who can currently see what" without anyone checking site by site by hand.
For content that needs tighter control than a permissions clean-up alone gives you, Microsoft Purview sensitivity labels add a second layer: a file can be labelled so a user is still allowed to open and read it, while Copilot is specifically blocked from summarising or drafting from it. It's the difference between "this person can see the document" and "this document should be searchable by an AI tool", and for genuinely sensitive material, client-privileged files especially, that's worth having as two separate settings rather than one.
The one question worth sending your IT provider
Before deciding anything else about Copilot, ask whoever manages your Microsoft 365 environment one thing: can they show a report of every site or file accessible to more than a handful of people, with anything containing client names, financial data or salary information flagged?
If that report can be produced within a few days, the tenant has been actively managed. If the answer involves switching a few things on first, that's the real answer to the readiness question, since it means the reporting has never been run and the permission structure has never actually been reviewed. Either way, it's worth knowing before a trial starts, not after.
This is the kind of review that sits alongside our Microsoft 365 and cloud work generally, not a one-off project bolted on just for Copilot. If you'd like a second opinion on what your tenant would actually expose before switching it on, get in touch and we'll take a proper look.
