Copilot Oversharing Remediation Checklist
Retrospective: this article looks back at events from September 2024, written in 2026 with the benefit of hindsight.
Use this checklist to remediate oversharing before and during Copilot rollout.
Find
- DAG reports run: Anyone links, org-wide links, EEEU permissions, labeled content.
- Content management assessment run.
- Purview DSPM data risk assessment reviewed.
- Top 50 high-risk sites listed (sensitive content + broad access).
Contain
- Restricted Content Discovery applied to the most sensitive sites.
- DLP for Copilot policies applied to Highly Confidential labels.
- Restricted SharePoint Search considered as a temporary measure if exposure is widespread.
Fix
- EEEU and "Everyone" removed from high-risk sites.
- Org-wide and Anyone links replaced with specific-people links.
- Broken inheritance corrected.
- Owners assigned to ownerless sites.
- Site access reviews completed by owners.
- Inactive sites archived (Microsoft 365 Archive) or deleted.
Prevent
- Default link type set to Specific people.
- Anyone links disabled or limited with expiration.
- Restricted Access Control enabled for business-critical sites.
- Sensitivity labels required for new sites.
- Site ownership and inactive site policies active.
Verify
- Pilot users tested prompts targeting sensitive topics.
- DAG reports rerun; metrics improved.
- Interim restrictions removed once sites are remediated.
Operate
- Monthly DAG report review.
- Quarterly site access reviews for sensitive sites.