The helper can find anything you're allowed to open. If too many people can open a secret file, the helper might show it to them. So check who can open what first.
Copilot respects permissions, so it only shows people content they can already access. The trouble is that many files are shared more widely than anyone intended. Purview checks the busiest SharePoint sites every week for oversharing, and SharePoint has tools to hide sites from Copilot while you fix them.
DSPM runs a weekly default data risk assessment on the top 100 SharePoint sites by usage (custom assessments in preview), with Protect actions (DLP for Copilot by label, Restricted Content Discovery, auto-labelling, retention). Interim controls: RCD and DLP; remediation: site access reviews, labels, ownership. Validate with audit.
Why oversharing matters more with Copilot
Microsoft 365 Copilot answers from content the user has permission to open. That's the right design, and it has a side effect. Content that was technically open to everyone but practically hidden, because nobody knew where to look, becomes easy to find when someone simply asks.
Copilot doesn't get around permissions. The risk comes from permissions that were looser than anyone realised. Checking that before rollout is one of the most useful steps an organisation can take.
What Purview gives you
Microsoft Purview's Data Security Posture Management (DSPM) includes data risk assessments designed, in Microsoft's words, "to help you identify, remediate, and monitor potential oversharing of data". Microsoft says a default assessment runs automatically every week for the top 100 SharePoint sites by usage, with no activation needed. You can add custom assessments for particular sites or users, which Microsoft lists as a preview feature. The first default assessment takes four days to show results.
For each site, the assessment shows how much sensitive data was found and how items are shared: with anyone, with everyone in the organisation, with specific people, or externally. The Protect tab offers remediation options, which Microsoft lists as:
| Option | What it does |
|---|---|
| Restrict access by label | A data loss prevention policy that stops Copilot and agents summarising content with chosen sensitivity labels |
| Restrict all items | SharePoint Restricted Content Discovery, so a site's content isn't surfaced by Copilot |
| Auto-labelling | Applies sensitivity labels automatically to unlabelled sensitive files |
| Retention | Deletes content that hasn't been accessed for at least three years |
A sequence that makes sense
Microsoft's guidance on configuring a secure foundation for Copilot follows a sequence I find easy to explain. First identify high-risk sites using DSPM and SharePoint Advanced Management's assessments. Then apply interim protections, such as Restricted Content Discovery or DLP for Copilot, so sensitive sites stay out of Copilot while you work. Then fix access properly: remove excess permissions, correct broken inheritance and make sure every site has an accountable owner. Finally, check with Purview auditing that Copilot no longer surfaces the restricted content.
The interim step is the one I'd stress. It means rollout doesn't have to wait for every site to be fixed.
A worked example
This example is illustrative. Before a Copilot pilot for 300 people, an organisation's first default assessment covers its 100 busiest sites.
| Finding | Sites | Interim step | Lasting fix |
|---|---|---|---|
| Sensitive HR data shared with everyone in the organisation | 3 | Restricted Content Discovery | Site access review; site sensitivity label |
| "Anyone" links to finance files | 7 | DLP for Copilot on the Confidential label | Remove anyone links; auto-label |
| No owner | 15 | None needed if not sensitive | Assign owners |
| Old project sites unused for years | 20 | None | Retention policy |
The pilot goes ahead on schedule, with three HR sites hidden from Copilot until their access reviews finish.
Fitting it to the register
Oversharing belongs in the data column of the risk map for every activity that uses Copilot or a SharePoint agent. The weekly assessment is also a ready-made nudge: if a new site enters the top 100 with sensitive data shared widely, that's a trigger for review.
What I'm still checking
Microsoft now has two versions of DSPM: a classic DSPM for AI and a newer DSPM that it says replaces it. The oversharing assessments appear in both. I haven't confirmed which licences each requires, so I'd check the Purview service description before planning around them.
Sources
- Microsoft Learn, Prevent oversharing with data risk assessments from Data Security Posture Management, accessed 11 October 2026.
- Microsoft Learn, Learn about Data Security Posture Management for AI (classic), accessed 11 October 2026.
- Microsoft Learn, Configure a secure and governed foundation for Microsoft Copilot, accessed 11 October 2026.
- Microsoft Learn, Use Microsoft Purview to manage data security and compliance for Microsoft Copilot and Copilot Chat, accessed 11 October 2026.