Microsoft 365 Copilot inherits whatever permissions exist in your tenant. If your SharePoint sites are overshared, Copilot will happily surface salary CSVs and M&A memos to anyone who can prompt it. Fix the data layer first.
1. Oversharing audit
- Run a SharePoint "Everyone except external users" search across all sites
- Identify sites with broken inheritance and broad permissions
- Review default site templates — block "Everyone" at provisioning
2. Sensitivity labels & auto-labeling
- Deploy at least three labels: Public, Internal, Confidential
- Enable auto-labeling on Exchange and SharePoint based on classifiers
- Use label-based encryption for Confidential content
3. DLP policies
- Block external sharing of files matching financial, PII, or PHI classifiers
- Add Copilot-aware DLP (preview) where available to restrict prompt context
4. Guest & external access
- Enforce guest expiration and access reviews
- Restrict B2B collaboration domains
- Disable anyone-with-the-link by default; use specific-people links
5. Copilot governance
- Pilot to one department first — measure prompt patterns and exposure events
- Enable Restricted SharePoint Search if oversharing remediation is not yet complete
- Document the rollback path
CloudPair's Copilot Readiness engagement combines a SharePoint exposure scan, a sensitivity-label rollout plan, and a phased deployment roadmap.