Microsoft 365Platform ChangesRetrospectives

Microsoft 365 Copilot Goes GA for Enterprise (Nov 2023): The Oversharing Problem Arrives

By OnCloudSec Research Team · Published Oct 6, 2026 · 5 min read

Facts in this article were checked against the sources listed below as of Oct 5, 2026.

Retrospective: this article looks back at events from November 2023, written in 2026 with the benefit of hindsight.

On November 1, 2023, Microsoft 365 Copilot became generally available to enterprise customers worldwide. At launch it required a minimum purchase of 300 seats at $30 per user per month on an annual commitment; Microsoft removed the seat minimum in early 2024. Large companies began pilots within weeks.

How it unfolded
  1. General availabilityNovember 1, 2023: Microsoft 365 Copilot becomes available to enterprise customers, initially with a 300-seat minimum.
  2. Grounding in Microsoft GraphCopilot retrieves emails, files, chats and meetings the signed-in user can already access.
  3. Oversharing surfacesPilots reveal sensitive files reachable through broad groups and org-wide links.
  4. Rollouts pauseOrganizations stop expansion while they fix permissions.
  5. Governance toolingMicrosoft adds SharePoint Advanced Management and Purview controls and publishes oversharing guidance.

Many of those pilots ran into the same issue, and it had nothing to do with AI quality. Copilot was doing exactly what it was designed to do: finding everything the user was allowed to see.

How Copilot uses your data

Microsoft 365 Copilot combines a large language model with Microsoft Graph — the index of your organization's email, files, chats, meetings and calendars. When a user asks a question, Copilot retrieves relevant content the user already has permission to access and uses it to compose an answer. Microsoft states that customer data isn't used to train its foundation models and that Copilot honors existing permissions and sensitivity labels.

"Honors existing permissions" is the key phrase. Copilot doesn't create access. It makes existing access fast.

The oversharing problem

In most Microsoft 365 tenants, existing access is much broader than anyone intends:

  • Sites and libraries shared with "Everyone except external users" (EEEU), a group that includes every employee.
  • Files shared through "People in your organization" links that anyone with the link — inside the company — can open.
  • Broken permission inheritance, where a folder deep in a site has different access than its parent and nobody remembers why.
  • Ownerless and inactive sites from projects that ended years ago.
  • HR, finance, legal and executive content stored in places with broad access.

Before Copilot, finding that content required knowing where to look. With Copilot, a user can simply ask about salaries, a reorganization or an acquisition — and receive a summary drawn from files they were technically able to open all along.

Why it mattered

Pilots stalled. When early users found sensitive content, rollouts paused while IT investigated, and expensive licenses sat underused.

Data governance became urgent. Copilot turned years of permission sprawl — much of it from the rushed shift to remote work in 2020 — into a visible risk that leadership could understand.

Microsoft shifted its guidance. The message evolved from "Copilot respects permissions" to "here is how to fix your permissions." SharePoint Advanced Management (now included with Copilot licenses) and Microsoft Purview gained oversharing reports, Restricted Content Discovery, site access reviews and data loss prevention for Copilot.

What to do now

Microsoft's current guidance organizes Copilot readiness into three areas: remediate oversharing, set up guardrails, and meet regulations. A practical sequence:

  1. Find high-risk sites. Run SharePoint Advanced Management data access governance reports for sharing links, EEEU permissions and sensitivity-labeled content, plus the content management assessment for oversized audiences, broken inheritance and ownerless or inactive sites. Use Microsoft Purview DSPM data risk assessments to find overshared sites containing sensitive information.
  2. Apply interim protections. Use Restricted Content Discovery to exclude the most sensitive sites from Copilot and organization-wide search while you remediate, and DLP for Microsoft 365 Copilot to keep content with specific sensitivity labels out of Copilot processing.
  3. Fix access. Remove EEEU from sensitive sites, replace org-wide links with specific-people links, correct broken inheritance and assign owners. Use site access reviews so business owners confirm who should have access.
  4. Set secure defaults. Make "Specific people" the default sharing link, restrict or disable "Anyone" links, use Restricted Access Control for business-critical sites and require sensitivity labels on new sites.
  5. Label and protect. Publish a simple sensitivity label taxonomy, configure default and auto-labeling, and apply encryption to highly confidential labels.
  6. Monitor and govern. Confirm audit logging captures Copilot interactions, define retention for those interactions, and review Purview DSPM for AI reports.
  7. Roll out in waves. Start with a pilot group, test with prompts targeting sensitive topics (with a consenting test user), fix what you find, then expand.

How to monitor Copilot once it's live

Readiness isn't a one-time project. After rollout:

  • Confirm Copilot interactions are audited. Copilot interaction events appear in Microsoft Purview Audit; make sure your retention meets legal and investigation needs.
  • Review Purview DSPM for AI. It shows how users interact with Copilot, which sensitive information appears in prompts and responses, and where risky usage is concentrated.
  • Rerun oversharing reports monthly. New sites and new sharing links appear constantly. Data access governance reports show whether exposure is shrinking or growing.
  • Watch DLP alerts for the Microsoft 365 Copilot location.
  • Track AI vulnerabilities. In 2025, researchers disclosed EchoLeak (CVE-2025-32711), a zero-click prompt injection issue in Copilot that Microsoft fixed server-side. Include Copilot advisories in your vulnerability management process even when no action is required.

Common mistakes

  • Licensing first, governance later. Buying broadly and fixing permissions afterward usually stalls the rollout.
  • Restricting everything indefinitely. Restricted SharePoint Search and similar controls are meant to be temporary. Leaving them on permanently makes Copilot much less useful.
  • Making IT own every permission decision. Site owners know who should have access; site access reviews put the decision with them.
  • Ignoring agents. Copilot agents and connectors extend what Copilot can reach. Review them in the Microsoft 365 admin center.

Metrics that show readiness

Track a few numbers each month: sites with "Everyone except external users" access, files with org-wide sharing links, sensitive sites without a named owner, percentage of confidential content carrying a sensitivity label, and completion of site access reviews. When those trends move the right way, expand Copilot to the next group.

Questions for leadership

  • How much of our content is shared with the whole company?
  • Which sites hold HR, finance, legal and executive information, and who can open them?
  • What did our Copilot pilot reveal, and who owns fixing it?
  • Is each rollout wave tied to a governance milestone?

Key takeaways

  • Copilot answers using whatever a user can already access — it doesn't create oversharing, it exposes it.
  • Broad groups, org-wide links, broken inheritance and ownerless sites are the usual culprits.
  • Microsoft now includes oversharing tools with Copilot licenses; use them before expanding.
  • Treat Copilot readiness as a data governance project with business owners, not an IT checkbox.

Sources

  1. Microsoft Tech Community: Microsoft 365 Copilot is generally available
  2. Microsoft Learn: Configure a secure and governed foundation for Microsoft Copilot
  3. Microsoft Learn: Data access governance reports (SharePoint Advanced Management)
microsoft 365 copilot securityMicrosoft 365 Copilot GA2023

More on this story