How to Prepare SharePoint Permissions Before Turning On Copilot
Retrospective: this article looks back at events from November 2023, written in 2026 with the benefit of hindsight.
Copilot surfaces any content a user can access. Before broad rollout, fix the SharePoint and OneDrive permissions that would expose sensitive data. Here is a practical sequence based on Microsoft's deployment guidance.
Step 1: Identify high-risk sites
Use SharePoint Advanced Management (included with Copilot licenses):
- Run data access governance reports for sites with sharing links ("Anyone," "People in your organization"), sites shared with "Everyone except external users" (EEEU), and sites with sensitivity-labeled content.
- Run the content management assessment to find oversized audiences, broken inheritance, inactive and ownerless sites.
Use Microsoft Purview DSPM data risk assessments to find overshared sites containing sensitive information.
Step 2: Apply interim protections
For the highest-risk sites while you fix them:
- Restricted Content Discovery to exclude sites from Copilot and organization-wide search.
- DLP for Copilot to exclude content with specific sensitivity labels from Copilot processing.
Step 3: Fix permissions
- Remove EEEU and "Everyone" from sensitive sites.
- Replace org-wide links with specific-people links.
- Fix broken inheritance.
- Assign owners and run site access reviews so owners confirm who should have access.
Step 4: Set secure defaults
- Default sharing link type: Specific people.
- Restrict or disable "Anyone" links.
- Use Restricted Access Control for business-critical sites.
- Require sensitivity labels for new sites.
Step 5: Pilot Copilot
License a pilot group, test with prompts targeting sensitive topics, and fix anything Copilot surfaces unexpectedly.
Step 6: Expand in waves
Repeat assessments as you expand.