Microsoft 365How-To & HardeningRetrospectives

Copilot Oversharing Remediation Checklist

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from September 2024, written in 2026 with the benefit of hindsight.

Use this checklist to remediate oversharing before and during Copilot rollout.

Find

  • DAG reports run: Anyone links, org-wide links, EEEU permissions, labeled content.
  • Content management assessment run.
  • Purview DSPM data risk assessment reviewed.
  • Top 50 high-risk sites listed (sensitive content + broad access).

Contain

  • Restricted Content Discovery applied to the most sensitive sites.
  • DLP for Copilot policies applied to Highly Confidential labels.
  • Restricted SharePoint Search considered as a temporary measure if exposure is widespread.

Fix

  • EEEU and "Everyone" removed from high-risk sites.
  • Org-wide and Anyone links replaced with specific-people links.
  • Broken inheritance corrected.
  • Owners assigned to ownerless sites.
  • Site access reviews completed by owners.
  • Inactive sites archived (Microsoft 365 Archive) or deleted.

Prevent

  • Default link type set to Specific people.
  • Anyone links disabled or limited with expiration.
  • Restricted Access Control enabled for business-critical sites.
  • Sensitivity labels required for new sites.
  • Site ownership and inactive site policies active.

Verify

  • Pilot users tested prompts targeting sensitive topics.
  • DAG reports rerun; metrics improved.
  • Interim restrictions removed once sites are remediated.

Operate

  • Monthly DAG report review.
  • Quarterly site access reviews for sensitive sites.
copilot oversharing remediation checklistCopilot Wave 2 & oversharing controls2024

More on this story