- SharePoint & OneDrive oversharing exposure scan
- Sensitivity labels and auto-labeling rollout plan
- DLP policies tuned for Copilot prompt context
- Phased pilot → production rollout plan with measurable guardrails
What we review
- Oversharing audit: "Everyone except external" exposure across SharePoint and OneDrive
- Sensitivity labels: Public / Internal / Confidential rollout with auto-labeling
- DLP: financial, PII, PHI classifiers; Copilot-aware DLP where available
- Identity: Conditional Access scope for Copilot apps; guest and external sharing posture
- Restricted SharePoint Search: enable as a compensating control during cleanup
Deliverables
- Exposure report: top oversharing risks ranked by sensitivity
- Labeling and DLP rollout plan with policy artifacts
- Phased Copilot rollout schedule with success metrics
- Executive read-out and admin handoff
Why this matters
Copilot is only as safe as your weakest SharePoint permission. We've seen tenants expose salary data, M&A memos, and signed contracts to every employee via Copilot — none of it new, all of it surfaced for the first time. Fix the data layer first, then enable Copilot with confidence.
Related services
- Microsoft 365 Security Assessment — Senior-led Microsoft 365 security assessment covering identity, mail flow, Defender, Purview, and Intune — with a 30/60/90-day remediation roadmap.
- Exchange Online & Hybrid Migration — Senior-led Exchange Server to Exchange Online migration: hybrid coexistence, mailbox moves, mail-flow cutover, and post-migration decommission for enterprise.