Risk · 07
Copilot reads what people can already open
Microsoft Learn's rollout guidance says a secure and governed foundation is recommended, not optional theatre, before you rely on Copilot. If a person can open a file, Copilot can be asked about what that person can open. The new Home screen does not invent a tighter permission model by itself.
What Learn points at
The same Learn page points to SharePoint Advanced Management and Microsoft Purview: remediate oversharing, put guardrails on by default, and label files in SharePoint and OneDrive. The licence comparison adds a plain split. On E3, sensitivity labels are manual and data loss prevention covers SharePoint, Exchange and OneDrive.
September did not retire this work
Office in Copilot, announced with Home on 25 September 2026, produces a real Word, Excel or PowerPoint file. That file lands in the same sharing model as any other file. A tidy draft in a library that is open to thousands of people is a wider leak than a clumsy paragraph in a private chat. The deliverable inherits the library.
Do not borrow a fictional baseline
FrontierOrg, a fictional method, starts from a discovery baseline and an open data issue, not from a claim that controls already work. Use that shape if your own sharing report is empty: an empty report is not evidence the estate is fine.
Monday
Run, or ask for, one SharePoint Advanced Management or oversharing view for a library people actually use. Bring the top finding to the person who owns that library, not to a slide.
Which library would you be unhappy to see quoted in a Copilot answer tomorrow?
Sources: Microsoft Learn, Microsoft Copilot requirements (opens in a new tab). Microsoft Learn, E3, E5 and E7 licence features (opens in a new tab).
Where this note mentions FrontierOrg, that is a fictional method for rehearsing a decision. It is not a company, not a client, and not a case study.