Microsoft 365Platform ChangesRetrospectives

Microsoft 365 Copilot Wave 2 (Sept 2024): New Oversharing Controls in SharePoint

By OnCloudSec Research Team · Published Oct 6, 2026 · 5 min read

Facts in this article were checked against the sources listed below as of Oct 5, 2026.

Retrospective: this article looks back at events from September 2024, written in 2026 with the benefit of hindsight.

On September 16, 2024, Microsoft announced Microsoft 365 Copilot Wave 2. The headline features were Copilot Pages — a persistent canvas for collaborating with Copilot and colleagues — and Copilot agents that automate business processes within the Microsoft 365 service boundary, plus expanded capabilities across Excel, PowerPoint, Teams and Outlook. Agents in SharePoint, connected to specific sites or folders, followed in preview in October.

How it unfolded
  1. Pilots stallEarly Copilot users surface overshared HR, finance and executive content.
  2. Wave 2 announcedSeptember 16, 2024: Microsoft introduces Copilot Pages, agents and expanded app features.
  3. Governance toolsSharePoint Advanced Management adds oversharing reports and AI-focused access controls.
  4. Targeted restrictionsRestricted Content Discovery hides specific sensitive sites from Copilot while they're remediated.
  5. Owner-led cleanupSite access reviews let business owners confirm who should have access.

Alongside the new features came something many customers needed more: practical tools to address oversharing, the issue that had stalled pilot after pilot since Copilot's launch in November 2023.

Why pilots stalled

Copilot answers questions using content the user can already access. In tenants with years of broad sharing, that meant early users could ask about salaries, reorganizations or acquisitions and receive answers drawn from files they had technically been able to open all along. Rollouts paused while IT investigated, and expensive licenses sat underused.

What Microsoft added

SharePoint Advanced Management (SAM) became central to Copilot readiness, adding oversharing reports and AI-focused access controls; it was later included with Copilot licenses. Key capabilities:

  • Data access governance reports showing sites with "Anyone" and "People in your organization" sharing links, sites using the "Everyone except external users" group, and sites containing sensitivity-labeled content shared broadly.
  • Restricted Content Discovery, which removes specific sites from Copilot and organization-wide search while leaving them accessible to their members — a targeted alternative to the broader, temporary Restricted SharePoint Search Microsoft had offered earlier in 2024.
  • Site access reviews, which ask site owners to confirm or remove access, putting decisions with the people who know the content.
  • Restricted Access Control and lifecycle policies for ownerless and inactive sites.

Microsoft Purview added data security posture management for AI and data loss prevention integration for Copilot, and Microsoft published deployment guidance focused on oversharing.

Why it mattered

Wave 2 marked a shift in how Microsoft talked about Copilot readiness: from "Copilot respects permissions" to "here is how to fix your permissions." It also introduced agents, which extend what Copilot can reach and do — adding a new governance surface just as organizations were getting a handle on the first one.

A practical playbook for scaling Copilot

  1. Measure exposure. Run data access governance reports for sharing links, EEEU permissions and labeled content. Export the results and rank sites by sensitivity and audience size.
  2. Contain the worst sites. Apply Restricted Content Discovery to your most sensitive sites while you remediate. In SharePoint Online PowerShell, the setting is applied per site (for example Set-SPOSite -Identity <url> -RestrictContentOrgWideSearch $true).
  3. Fix permissions with owners. Start site access reviews for high-risk sites so owners remove EEEU, replace org-wide links with specific-people links and correct broken inheritance.
  4. Set better defaults. Make "Specific people" the default link type, restrict "Anyone" links, apply Restricted Access Control to business-critical sites and require sensitivity labels for new sites.
  5. Protect confidential content. Use DLP for Microsoft 365 Copilot to exclude content with highly confidential labels from Copilot processing.
  6. Govern agents. Review agents and integrated apps in the Microsoft 365 admin center, restrict who can create and publish them, and apply data policies to Copilot Studio environments.
  7. Remove interim restrictions once sites are remediated, so Copilot becomes more useful rather than permanently limited.
  8. Repeat per wave. Each expansion of licenses should follow a fresh exposure check.

How to track progress

  • Trend the reports. Rerun data access governance reports monthly and track the number of sites with EEEU access, org-wide links and broadly shared labeled content.
  • Watch Copilot usage and risk. Purview DSPM for AI shows sensitive information in prompts and responses.
  • Audit Copilot interactions. Confirm Copilot interaction events are captured and retained.
  • Measure owner engagement. Track completion of site access reviews by department.

Common mistakes

  • Using restrictions as the fix. Restricted SharePoint Search and Restricted Content Discovery buy time; they don't fix permissions.
  • Letting IT make every access decision. Owners must be accountable for their sites.
  • Rolling out agents without governance. Agents can connect to more data and take actions; review them like apps.
  • Skipping the business case for cleanup. Removing obsolete content also improves Copilot's answers.

Agents change the governance picture

Wave 2's agents — and Copilot Studio agents built by business teams — extend Copilot beyond answering questions. Agents can be connected to specific SharePoint sites, external data sources through connectors, and actions in other systems. That means two new questions for every agent: what data can it reach, and what can it do?

Treat agents like applications. Require an owner, review the knowledge sources and connectors each agent uses, restrict who can publish agents broadly, and apply data policies in Copilot Studio environments to block risky connectors. In 2025, Microsoft introduced Entra Agent ID to give agents their own identities, which makes inventory and least privilege easier as agent numbers grow.

A realistic timeline

For a mid-sized tenant, a typical sequence is two to three weeks to measure exposure and apply interim protections, four to eight weeks of owner-led remediation for the highest-risk sites, then a pilot expansion. Larger or older tenants take longer. Setting expectations early keeps leadership from judging Copilot on a pilot that was never given clean data.

Questions for leadership

  • What did our Copilot pilot reveal, and what's the remediation plan?
  • Are we using the governance tools that come with our Copilot licenses?
  • Who approves new Copilot agents, and what can they access?

Key takeaways

  • Copilot Wave 2 added Pages and agents, plus tools to address oversharing.
  • Data access governance reports, Restricted Content Discovery and site access reviews are the core cleanup toolkit.
  • Interim restrictions buy time; owner-led permission fixes solve the problem.
  • Tie each Copilot expansion to governance milestones, and govern agents as they appear.

Sources

  1. Microsoft: Microsoft 365 Copilot Wave 2 — Pages, Python in Excel, and agents
  2. Microsoft Learn: Data access governance reports
  3. Microsoft Learn: Restricted Content Discovery
  4. Microsoft Learn: Site access reviews
copilot wave 2Copilot Wave 2 & oversharing controls2024

More on this story