Implementation

Microsoft 365 Copilot Readiness: Audit Permissions First

Microsoft 365 Copilot Readiness: Audit Permissions First

Document library folders with padlocks and a magnifying glass, representing a permissions audit before Microsoft 365 Copilot is switched on

Copilot Reads the Permissions You Already Have

Microsoft 365 Copilot readiness is mostly a permissions problem. Microsoft's own privacy documentation says it plainly: Copilot "only surfaces organizational data to which individual users have at least view permissions." It does not bypass SharePoint security. It reads the same access control lists your file shares, Teams and OneDrive have been accumulating for years, and it reads them faster and more thoroughly than any person would.

That is the whole risk in one sentence. A salary spreadsheet saved to a Teams channel in 2021, a board pack shared with "People in your organisation" so a director could open it on a phone, an HR site nobody has owned since a restructure. Before Copilot, finding those files took effort and luck. After Copilot, a staff member types "what are the executive salaries this year" and the answer arrives with a citation.

The Australian Government saw this early. The Digital Transformation Agency's evaluation of the whole-of-government Copilot trial (more than 60 agencies, about 7,600 users, January to June 2024) found that "Copilot may magnify poor data security and information management practices" and recommended that agencies "must configure their information systems, permissions, and processes to safely accommodate generative AI products." That finding applies to any organisation running SharePoint, whether it is a council, a law firm, an engineering contractor or a hospital network.

This guide covers the audit to run before you buy licences: which reports to pull, which settings to change, which temporary controls Microsoft provides, how the Privacy Act bears on it, and how to structure a pilot that measures something real.

A note on names. Microsoft has renamed Microsoft 365 Copilot to "Microsoft Copilot" and Microsoft 365 Copilot Chat to "Microsoft Copilot Chat", with older names persisting in licences and admin screens during the transition (Microsoft Learn). This article uses "Copilot" for the licensed product that grounds answers in your tenant's data.


Why Oversharing Becomes Visible Overnight

Most Microsoft 365 tenants in Australia grew one project at a time. A team was created for a tender, a SharePoint site for a merger, a folder broken out of inheritance so a contractor could see one drawing set. Each decision was reasonable. Nobody went back.

The patterns that matter for Copilot are well documented. Microsoft's SharePoint Advanced Management Content Management Assessment looks specifically for "sites with oversized audiences, EEEU usage, broken inheritance, inappropriate sharing, and those that are inactive or ownerless" (Microsoft Learn). EEEU is "Everyone except external users", a built-in SharePoint group that automatically includes every internal account. Grant a site or folder to EEEU and every staff member in the tenant can read it, which means every Copilot user can be answered from it.

Common Tenant Settings: Inherited Default vs Copilot-Ready

Metric
Typical inherited state
Copilot-ready state
Improvement
Default sharing link typePeople in your organisationSpecific peopleEach new share reaches named users only
'Everyone except external users' grantsUnreviewed, often on HR and finance sitesRemoved or justified site by siteCloses the widest internal exposure
Site ownershipOwners have left the organisationTwo accountable owners per siteSomeone can approve access reviews
Inactive sitesStill searchableArchived or excluded from CopilotStale content stops grounding answers
Sensitivity labelsNot deployed, or optionalDefault and auto-labelling for key contentCopilot honours encryption usage rights
Anyone linksEnabled tenant-wideDisabled or time-limitedRemoves anonymous access paths

These settings have been sitting in the admin centre for years. Copilot raises the cost of leaving them at their defaults.


The Australian Obligations Behind the Audit

Privacy Act APP 11 still applies inside your own tenant

Australian Privacy Principle 11 requires entities to take reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure. Unauthorised access includes your own staff opening records they have no business reason to see. If payroll files, client health information or HR investigation notes sit on an overshared site, Copilot makes that access easier, and the APP 11 question becomes whether your steps were reasonable once you knew the tool was coming.

The OAIC's Guidance on privacy and the use of commercially available AI products (published 21 October 2024) sets the expectation. Its first takeaway is that "privacy obligations will apply to any personal information input into an AI system, as well as the output data," and it asks organisations to conduct due diligence before adoption, including who will be able to access input and generated data (OAIC). A permissions audit is the most direct evidence of that due diligence for a Copilot rollout. For the broader Privacy Act picture, see our guide to Privacy Act compliance and AI.

Data residency: storage is in Australia, processing may not be

For a tenant whose default geography is Australia, Microsoft's Product Terms data residency commitment covers Exchange Online, SharePoint and OneDrive, Teams, and Microsoft 365 Copilot and Copilot Chat, with Australian data centres listed in Sydney and Melbourne (Microsoft Learn, data residency overview). Copilot was added as a covered workload on 1 March 2024. Prompts, responses and the activity history are stored in line with your other Microsoft 365 content.

The processing side is different. Microsoft states that Copilot calls to the language model are routed to the closest data centres but "can call into other regions where capacity is available," and that "customers outside the EU may have their queries processed in the US, EU, or other regions" (Microsoft Learn). If your board or a government contract requires in-country processing as well as storage, raise it before the purchase. Microsoft also states that prompts, responses and data accessed through Microsoft Graph are not used to train foundation models.


The Pre-Licence Permissions Audit

The audit follows the same order as Microsoft's foundational deployment guidance: find exposure, contain it temporarily, fix it at source, then set defaults so it does not return.

Copilot Permissions Audit Workflow

Discover
Site permissions, EEEU and sharing link reports
Prioritise
Rank sites by audience size and sensitivity
Contain
Restricted Content Discovery on high-risk sites
Remediate
Owner-led site access reviews and inheritance fixes
Label
Sensitivity labels and DLP for Copilot
Monitor
Activity reports and Copilot interaction audit

Step 1: Pull the data access governance reports

In the SharePoint admin center, under Reports, the Data access governance reports give you the baseline (Microsoft Learn):

  • Site permissions across your organization: a snapshot of the permission structure across all SharePoint and OneDrive sites, surfacing sites with thousands of users, external guests or EEEU permissions.
  • Sites and files shared via special SharePoint groups: identifies the exact sites, folders and files exposed through EEEU or "Everyone", so cleanup can be scripted instead of left to site owners.
  • Sharing links, and Shared with 'Everyone except external users': activity reports covering the last 28 days, which catch new oversharing as it happens.
  • Sensitivity label applied to files: shows where labelled content lives, so you can check the site protecting it matches the label.

Microsoft recommends running snapshot reports quarterly and activity reports monthly. One licensing detail matters here: SharePoint Advanced Management is included with Copilot licences, while Microsoft 365 E5 admins without SAM get the activity reports only, without snapshot reports or remedial actions. If you are auditing before any Copilot licence exists, check which of these reports your current licence exposes, because that determines whether the audit is a report run or a PowerShell exercise.

Step 2: Rank sites by blast radius

Not every overshared site matters equally. A marketing asset library open to the whole organisation is fine. A finance site open to the whole organisation is not. Score each flagged site on two axes, audience size and content sensitivity, and work the top-right quadrant first. Microsoft Purview Data Security Posture Management data risk assessments help with the sensitivity axis by identifying overshared sites that contain sensitive information types.

I worked on data platform and Power BI reporting programs for BHP, Rio Tinto and Senex Energy while employed by previous consulting firms, and every access model I saw followed the same path: security designed once at go-live, then eroded one exception at a time by project teams, contractors and reorganisations. Row-level security in a reporting model and permissions on a SharePoint site drift for the same reason. What holds them in place is an owner who reviews access on a schedule, and a one-off clean-up without that owner decays within a year or two.

Step 3: Contain high-risk sites while you fix them

Remediation on a large site can take weeks. Microsoft provides temporary controls so the Copilot rollout is not held hostage to the slowest site owner.

Restricted Content Discovery (RCD) is a site-level setting that stops a site's content appearing in organisation-wide search and Copilot responses without changing anyone's permissions (Microsoft Learn). Users who already have access can still open the content directly. Two caveats from the documentation: it applies only to SharePoint sites, not OneDrive, and for sites with more than 500,000 items an update "could take more than a week to fully process." Apply it to your largest high-risk sites early so the propagation delay runs while other work continues.

Restricted SharePoint Search is the older allow-list approach, limited to 100 sites. Microsoft has announced it is retiring and that from 31 July 2026 new enablement is blocked (Microsoft Learn). If a vendor proposal or an older readiness checklist recommends it, that advice is out of date.

Microsoft Purview DLP for Copilot can exclude files and emails carrying specific sensitivity labels from Copilot grounding, and can stop Copilot responding to prompts that contain specified sensitive information types.

Which Control Fits This Site?

What did the audit find on this site?
Sensitive content, broad audience, owner available
→ Site access review now, RCD until it is complete
Sensitive content, broad audience, no owner
→ Assign ownership, apply Restricted Access Control, then review
Inactive site with records value
→ Microsoft 365 Archive or retention labels to exclude it from Copilot
Specific labelled files must never ground answers
→ Purview DLP for Copilot policy on that label
Broad audience, non-sensitive content
→ Leave discoverable; it improves Copilot answers

Step 4: Fix access at source

Temporary controls only buy time. SharePoint Advanced Management site access reviews send flagged sites to their owners, who can remove excess users and groups, delete company-wide sharing links including EEEU grants, and correct broken inheritance down to file level. Sites without an owner need one assigned before any review can happen, and a site ownership policy keeps that from slipping again. Once a site is remediated, remove RCD, because Microsoft warns that excessive use "can reduce the amount of content available" and make Copilot answers less complete.

Step 5: Set defaults so the problem does not return

At tenant level, change the default link type to Specific people, disable or restrict Anyone links and company-wide sharing groups, and require a site sensitivity label at creation so privacy and sharing settings follow the label. Configure default and auto-labelling with Purview Information Protection for the content types you care about. When a file is encrypted through a sensitivity label, Copilot honours the usage rights granted to the user, so labels become an enforcement layer on top of site permissions.

For a wider view of how access controls apply when AI tools act on business data, our post on AI agent governance, data access and human override covers the same principles beyond Microsoft 365.


A Realistic Readiness Roadmap

Timelines depend more on how many site owners respond than on tenant size. The roadmap below assumes a dedicated internal lead and engaged business owners. Use it as a planning shape and adjust once you see how quickly owners respond.

Copilot Readiness Roadmap

1
Week 1-2
Discover
Run data access governance reports, list ownerless and inactive sites, confirm current licences and data location
2
Week 3-4
Contain
Rank sites by audience and sensitivity, apply Restricted Content Discovery to the highest-risk sites, change tenant sharing defaults
3
Week 5-8
Remediate
Owner-led site access reviews, fix broken inheritance, deploy sensitivity labels and DLP for Copilot
4
Week 9-14
Pilot
Licence a defined cohort, baseline tasks before go-live, review Copilot interactions in Purview
5
Ongoing
Operate
Monthly activity reports, quarterly snapshots, inactive site policy, decide expansion on measured results

Choosing the pilot cohort

Pick people whose work Copilot is good at. The DTA trial found use concentrated on summarising information and rewriting content, with Word and Teams the most used and most favourably viewed. Participants estimated time savings of up to an hour a day on summarising, first drafts and searching for information, yet only a third used Copilot daily. Broad, untargeted licensing produces the second number without the first.

A strong cohort spans roles with heavy meeting load, document drafting and information retrieval: project managers, contract administrators, policy writers, executive assistants, bid teams. Include at least one person from each high-sensitivity area (finance, HR, legal) so the pilot tests whether your containment worked. Ask them, in week one, to try to find things they should not be able to see. That test is cheaper before go-live than after.

Our AI change management guide covers the adoption side, including why trained champions matter more than licence counts.


Measuring Value Without Fooling Yourself

Usage dashboards show who opened Copilot and how often, which says little about whether the work got better or faster. Before the pilot starts, choose three to five recurring tasks per role and record how long they take now: minutes from a two-hour meeting, a first-draft tender response, a monthly status report. Measure the same tasks again at the end of the pilot, and have a reviewer score quality blind to which version used Copilot.

Track the risk side as well. Purview DSPM Activity Explorer shows Copilot prompts, responses and sensitive data activity, and Purview Audit records interactions. A pilot that saved time but surfaced a payroll file has not succeeded. The DTA evaluation also notes that time saved was partly spent reviewing AI output for errors, so record the time after review and correction.

On licence cost. Copilot is sold as a per-user add-on to an eligible Microsoft 365, Office 365 or other qualifying plan, with separate Copilot Business and enterprise offerings (Microsoft Learn, licence options). Web-grounded Copilot Chat comes with eligible subscriptions at no extra cost, while work-grounded chat over your tenant data needs the Copilot licence. Pricing and bundles change, so confirm current Australian pricing with Microsoft or your licensing partner before building a business case.

If you want a structured way to frame the investment decision, our AI strategy service starts from the use cases and data readiness, then works back to which licences earn their place.


What Usually Goes Wrong

Treating the audit as an IT task

IT can run reports. Only business owners can say whether the finance team should see a site. Site access reviews fail when owners do not know they own the site.

Using the temporary control as the permanent fix

RCD and the retiring Restricted SharePoint Search both leave permissions unchanged. Anyone with access can still open the file. The exposure moves from Copilot back to search-by-browsing, which is where it was before.

Ignoring Teams and OneDrive

Teams channels store files in SharePoint, private and shared channels have their own sites, and Microsoft notes Copilot honours permissions granted to people outside your organisation through shared channels. RCD does not apply to OneDrive, so personal drives shared broadly need sharing-link clean-up instead.

Waiting while shadow AI spreads

Delay has a cost too. While the business waits, staff paste content into public chatbots, which the OAIC recommends against. Our post on staff leaking business data into public AI tools covers that risk. A well-governed Copilot often reduces it.

Once Copilot is live, the reports, labels and reviews need an owner. Our managed AI services cover that ongoing operating work, and where Copilot needs to draw on line-of-business systems through connectors, system integration is the place to start.


Getting Started

The first useful step costs nothing but an admin's afternoon:

  1. Run the Site permissions across your organization report and the EEEU report in the SharePoint admin center.
  2. Sort by audience size and mark every site holding personal, financial or legal information.
  3. Check the Data location card in the Microsoft 365 admin center and confirm your tenant's default geography.

If the results are longer than you expected, that is normal, and it is the right moment to talk. Book a scoping conversation with Solve8 or contact our team to plan the audit, the containment and the pilot before the licences arrive.


Common Questions

Does Microsoft 365 Copilot give staff access to files they could not open before?

No. Microsoft states that Copilot only surfaces organisational data to which each user has at least view permission. The risk is that many users already have permission to far more than they realise, through "Everyone except external users" grants, organisation-wide sharing links and broken inheritance, and Copilot makes that content easy to find.

What is Restricted Content Discovery and is it enough on its own?

Restricted Content Discovery is a SharePoint Advanced Management setting that stops a site's content appearing in organisation-wide search and Copilot responses without changing permissions. It is designed as a temporary control while owners review access. Users who already have access can still open the files, so the permanent fix is a site access review.

Is Restricted SharePoint Search still an option for Copilot rollouts?

Microsoft has announced that Restricted SharePoint Search is retiring, with new enablement blocked from 31 July 2026, and recommends Restricted Content Discovery and SharePoint Advanced Management instead. It was always limited to an allow list of 100 sites and was never a security boundary.

Is Copilot data stored in Australia?

For tenants with an Australian default geography, Microsoft's Product Terms data residency commitments cover Copilot along with Exchange, SharePoint, OneDrive and Teams, with data at rest in Sydney and Melbourne. Language model processing can occur in other regions during high demand, so confirm with Microsoft if your obligations require in-country processing.

How does the Privacy Act apply to a Copilot rollout?

APP 11 requires reasonable steps to protect personal information from unauthorised access, including access by staff who have no need to see it. The OAIC's October 2024 guidance on commercially available AI products asks organisations to do due diligence before adoption, and a documented permissions audit is direct evidence of that.

How long does Copilot readiness take before a pilot?

A typical shape is about eight weeks of discovery, containment and remediation before a pilot cohort is licensed, then a pilot of about six weeks. The deciding factor is how quickly site owners complete access reviews, which is why ownership is assigned in the first fortnight.


Related Reading:

Sources: Microsoft Learn: Data, Privacy, and Security for Microsoft Copilot (updated Sep 2026), Configure a secure and governed foundation for Microsoft Copilot (updated Sep 2026), Restrict discovery of SharePoint sites and content (Sep 2026), Restricted SharePoint Search (Aug 2026), Data access governance reports (Jul 2026), Data residency overview (Sep 2026), License options for Microsoft Copilot (Sep 2026). OAIC, Guidance on privacy and the use of commercially available AI products (Oct 2024). Digital Transformation Agency, Evaluation of the whole-of-government trial of Microsoft 365 Copilot, summary of findings (Oct 2024).