Here is the awkward truth about rolling out Copilot, or any AI assistant, across a Microsoft 365 tenant: the AI is fine. Your permissions probably aren’t.
Copilot does not bypass security. It strictly respects the permissions you already have — it can only read what the signed-in user can read. The problem is what that actually means in a tenant that has accumulated ten years of “Everyone except external users” groups, organisation-wide sharing links, inherited folder permissions, and Teams sites created for projects that ended in 2021. Before AI, an overshared salary spreadsheet sat three clicks deep in a site nobody visited. Nobody found it because nobody looked. With Copilot deployed, “what do people earn here?” can surface it in seconds — politely, with a citation.
The scale of the problem is consistently underestimated. Concentric AI’s Data Risk Report found 16% of business-critical files are overshared — exposed to internal or external users who should not have access — and that’s a vendor with an interest in the number, so treat it as an indicator rather than gospel. But every independent practitioner working in this space reports the same pattern: the overwhelming majority of tenants that run their first data access report find material exposure they did not know about. This is the same visibility problem we wrote about from the tool side in our shadow AI discovery guide — this time it’s your data, not your apps.
So before the pilot, before the licence order, before the lunch-and-learn: fix the sharing. Here’s how, and why the timeline just got less optional.
For the past two years, the standard advice for nervous IT teams was a stopgap called Restricted SharePoint Search (RSS): flip one switch and Copilot plus organisation-wide search could only see an allowed list of up to 100 curated sites. Imperfect — it capped the value of Copilot along with the risk — but it bought time.
That time is now expiring. In message centre notice MC1395311 (June 2026), Microsoft announced RSS is being retired: new enablement was blocked from 31 July 2026, the feature retires fully by 31 January 2027, and its PowerShell cmdlets stop working after 28 February 2027. Crucially, Microsoft will not migrate your settings. If your tenant is one of the many hiding behind RSS and you do nothing, content you thought was fenced off becomes discoverable again when the fence is removed.
The replacement is Restricted Content Discovery (RCD) — a per-site control that keeps a specific site’s content out of tenant-wide search and Copilot grounding while leaving direct access untouched. It’s a better tool: instead of allow-listing 100 sites and hoping, you deny-list the handful of genuinely high-risk ones. But it assumes you know which sites those are — which brings us back to doing the actual work.
If your tenant has even one Microsoft 365 Copilot licence, you already own SharePoint Advanced Management (SAM) — it’s included, and most SMEs that qualify have never opened it. Its Data Access Governance reports show you exactly where the everyone-group permissions, org-wide links, and oversharing hotspots are, ranked by site. No Copilot licence yet? The standard SharePoint admin centre sharing reports plus a PowerShell pass over site permissions gets you a usable first picture for nothing.
Change the tenant default sharing link from “People in your organisation” to “Specific people”, set link expiry, and require new Teams to be private unless someone argues otherwise. This is thirty minutes of configuration that stops adding to the backlog while you work through it.
Perfection is the enemy here. Sort the Data Access Governance report by exposure, take the top ten sites, and for each one either fix the permissions, run a SAM site access review (which delegates the “who should actually be here?” question to the site owner, who unlike IT actually knows), or make the site private. A tenant where the ten worst sites are fixed is dramatically safer than one where a hundred sites are 10% reviewed.
Some sites are correctly permissioned but still shouldn’t feed an AI assistant — the M&A data room, the HR casework site, the board library. Apply RCD to those specific sites so their content stays out of Copilot grounding and tenant-wide search even for people with legitimate access. This is the targeted successor to the retiring RSS switch, and it’s the right long-term home for your “never in an AI answer” category.
Sensitivity labels on genuinely confidential material give every downstream control something reliable to key off — encryption that travels with the file, and DLP rules that can act on the label. Microsoft’s Purview DLP for Microsoft 365 Copilot, which reached general availability earlier this year, can exclude labelled content from Copilot processing altogether, and Microsoft has said oversharing visibility and Copilot DLP controls are coming directly into the Microsoft 365 admin centre later in 2026. Exactly what you get depends on your Purview tier — Business Premium covers a workable core, the fuller AI-specific controls sit higher up. Sequence it honestly: permissions first (free), defaults second (free), labels third (maybe a licensing conversation). This is the layer where the policy you wrote — if you’ve used our free UK AI usage policy template, the data classification section — becomes something a tenant can actually enforce, and it slots into the wider structure in our AI governance framework for SMEs.
The two-week version, if you do nothing else:
1. Run the Data Access Governance reports (or the standard sharing reports) and identify your ten most exposed sites.
2. Change default sharing links to “Specific people” and make new Teams private by default.
3. Fix or lock down the top ten — and apply Restricted Content Discovery to your two or three genuinely sensitive sites.
4. If you’re currently relying on Restricted SharePoint Search, diarise its 31 January 2027 retirement and plan the migration now, not in December.
A caution in the other direction, because we see this too: some organisations discover the oversharing problem and conclude they can’t touch AI for eighteen months. That’s the wrong lesson. Microsoft’s own deployment blueprint recommends exactly the opposite — start a small, well-scoped pilot group while remediation runs in parallel, then broaden deployment as the guardrails firm up. A pilot of fifteen people with sensible site restrictions teaches you more about where AI pays off than a year of data hygiene with nothing to show the board. And the readiness work is not wasted whichever way you go on tooling — whether you land on Copilot, a custom build, or the mix we usually recommend in Copilot vs custom AI tools, every option grounds itself in the same tenant and inherits the same permissions.
The tenants that get this right treat data readiness as a four-week project with a deadline, not a standing objection. Reports, defaults, worst-ten remediation, RCD on the crown jewels, pilot. Then the AI conversation gets to be about value instead of fear.
We run Microsoft 365 data readiness assessments for UK SMEs — the oversharing reports run and translated, the worst sites fixed, Restricted Content Discovery applied where it matters, and a pilot plan you can defend. It’s the same ground our Microsoft 365 AI consultancy covers every week. Get in touch or book a 30-minute call — no sales theatre.
Book a Free Discovery Call