Guide AI Governance Microsoft 365

Microsoft Copilot: How to deploy without exposing confidential data

Copilot sees everything your users can see. If your Microsoft 365 permissions have never been audited, that's a larger problem than it sounds. Here's what to put in order before you switch it on.

RD
Ryland Deakin
Lead Consultant, Cyvra
17 July 2026
9 min read

The problem nobody mentions in the sales demo

When Microsoft demonstrates Copilot, the demo is impressive: ask for a summary of every meeting this week, Copilot delivers. Ask for a proposal draft based on previous contracts, it delivers that too. What the demo doesn't show is what happens when your Microsoft 365 environment has never had a permissions review.

Copilot has no access of its own. It uses the signed-in user's permissions. If Sarah in finance still has access to an HR folder that should have been removed in 2021, Sarah's Copilot will include HR data in responses about project costs. If a SharePoint site from a finished project is still open to the whole company, any employee can ask Copilot to summarise those files.

That's the central risk with Copilot: it isn't a bug, it's a mirror. It reflects the exact state of your permissions.

Why this matters now

Microsoft is progressively rolling Copilot into Microsoft 365 Business and Enterprise plans. Many organisations will gain access without having actively requested it. If you haven't prepared your environment, Copilot may already be available to your users today.

The four real risks

Copilot governance isn't bureaucracy. It's the difference between a productivity tool and an internal data leak vector. These are the four risks we see most often before implementations.

Risk 1
Oversharing through excessive permissions
Copilot returns data the user can access but shouldn't see in context. Years of accumulated permissions without review make this almost certain.
Risk 2
Personal data in prompts
Users enter customer, patient, or employee data into prompts without realising the implications. Under GDPR, the organisation remains responsible for how that data is processed.
Risk 3
Responses shared without context
Copilot responses can be copied and forwarded by email or Teams with no indication they contain data pulled from other sources. Sensitive information leaves the controlled environment.
Risk 4
Shadow AI and prompt injection
Staff who haven't been trained copy data from external systems into Copilot prompts, creating exposure in both directions: internal data out, external data in. See our guide to shadow AI risks for the broader picture.

Excessive permissions: the problem you almost certainly already have

Microsoft has a name for the most common situation it encounters before Copilot deployments: structural oversharing. It happens when an environment accumulates years of permission decisions made for convenience. Someone needed access to a folder for a week, access was granted, never revoked. A project ended, the SharePoint site stayed open. An employee left, but the Teams channel they were in still exists with its original documents intact.

In organisations with more than three years of Microsoft 365 use, finding an environment without this problem is rare. And Copilot doesn't skip those files: it treats them as legitimate context for whoever is asking.

A permissions review doesn't need to be a six-month project. Start with your most critical data: contracts, financial records, HR information, intellectual property. Apply least-privilege: each user should only have access to what their current role requires.

GDPR and Copilot: what your organisation needs to check

Microsoft 365, including Copilot, operates under Microsoft's Data Processing Addendum, which is aligned with GDPR. But several points need specific attention for organisations operating under EU data protection law.

  • Purpose limitation: verify that your privacy notice covers the use of AI tools in processing personal data of your data subjects
  • Data residency: confirm in the Microsoft 365 Admin Center where Copilot prompt and response data is stored and for how long
  • International transfers: if personal data of EU data subjects is processed outside the EEA, ensure there is an adequate transfer mechanism in place
  • User training: document that employees have been instructed not to enter personal data about clients or individuals into Copilot prompts

Organisations that already have structured data protection policies under GDPR generally need targeted adjustments rather than a full overhaul to cover Copilot. Where Copilot processes personal data in automated ways, Article 35 requires a Data Protection Impact Assessment; our guide to AI DPIA requirements covers the criteria and assessment process.

What to implement before enabling Copilot

This list covers the minimum needed for a responsible deployment. The goal isn't to slow adoption: make sure the productivity Copilot delivers doesn't come with data exposure you can't trace afterwards.

Audit permissions in SharePoint and Teams. Use the Microsoft 365 Admin Center or SharePoint Access Reviews to identify excessive permissions. Prioritise sites holding financial data, HR records, and contracts.
Deploy sensitivity labels. Microsoft Purview lets you classify documents as Confidential, Internal, or Public. Copilot respects these labels and can be configured to exclude confidential documents from responses for users without the appropriate clearance.
Create an AI acceptable use policy. Document what employees can and cannot do with Copilot: which types of data must not be entered in prompts, how to use generated responses responsibly, and how to report a data incident involving AI.
Review the DPA with Microsoft. Confirm that your data processing agreement covers Copilot usage, especially if you are on older Microsoft 365 plans that may not include updated terms.
Train users before rollout. A 45-minute session on what Copilot does, what it doesn't do, and what not to enter in prompts significantly reduces the risk of incidents caused by oversight.
Enable Copilot audit logs. Microsoft Purview Audit records Copilot interactions. These logs are essential for investigating incidents and demonstrating compliance in a regulatory audit.
Run a pilot before the full rollout. Enable Copilot for 10 to 20 users for four weeks. Collect feedback on unexpected responses or surprising data access. Fix permissions before scaling.

What a well-run implementation looks like

A professional services firm with 120 staff that we supported through Copilot adoption found, during its permissions audit, that 34% of SharePoint sites had at least one user with access they should no longer have had. Three of those sites contained contracts with confidentiality clauses and client fee information.

Fixing the problem took three weeks. Without the audit, that data would have become part of the available context for any employee asking Copilot about client work.

After the governance project, the Copilot rollout was straightforward. Users understood what to expect, sensitive documents were labelled, and permissions reflected the reality of current roles rather than six years of unreviewed growth.

Copilot doesn't create new risks from nothing. It amplifies the risks you already had but couldn't measure.

Where to start

If you don't have a Copilot activation date yet, use that time well. A four-week readiness assessment is enough to cover permissions, data classification, and an acceptable use policy, putting you in a position to enable Copilot with confidence.

If Copilot is already active in your environment, the first step is to run an access report in the SharePoint Admin Center and see how many sites have permissions open to "Everyone" or broad groups. That number will tell you whether you have an urgent problem or a maintenance project.

Cyvra helps organisations structure AI governance before and during Microsoft Copilot adoption, covering permissions, GDPR, and acceptable use policy. Our Copilot implementation guide covers the configuration steps and rollout sequence for new deployments. If you want to talk through the current state of your environment, get in touch with our team.

Frequently asked questions

Can Microsoft Copilot expose confidential company data?

Yes, if access permissions are not configured correctly. Copilot accesses everything the user can access in Microsoft 365, including SharePoint, Teams, email, and OneDrive. If an employee has access to files they shouldn't, Copilot will include that data in responses. The issue isn't Copilot itself. It's the excessive permissions most organisations have built up without realising.

What is oversharing in the context of Microsoft Copilot?

Oversharing is when Copilot returns information a user can technically access but shouldn't see in context. A sales manager asks about client reports and receives HR salary data because those folders had open permissions. Copilot doesn't judge what's contextually appropriate: it returns what's accessible. That's why a permissions review is the first step before enabling Copilot.

How does Microsoft Copilot affect GDPR compliance?

When Copilot processes personal data, your organisation remains the data controller under GDPR. You need to verify that processing is covered by the purposes in your privacy notice, that your Microsoft contract includes an adequate DPA, where prompt and response data is stored, and that users are trained not to enter personal data into prompts. Microsoft provides GDPR-aligned data processing terms for Microsoft 365.

Does my organisation need a governance project before enabling Copilot?

Yes, especially if you hold sensitive data in Microsoft 365. The minimum recommended: review and correct excessive permissions in SharePoint and Teams, apply sensitivity labels to critical documents, create an AI acceptable use policy, and train users on what not to enter into prompts. Without these steps, Copilot can distribute confidential information without leaving a clear audit trail.

What is the difference between Microsoft Copilot and ChatGPT for business use?

Microsoft Copilot is integrated into Microsoft 365 and uses your organisation's internal data as context. Personal ChatGPT does not access company data. Copilot is more powerful for productivity precisely because it reads emails, documents, and Teams meetings, but internal data exposure risks are correspondingly higher. Both require usage policies, but Copilot additionally requires permissions governance and data classification.

How does Cyvra help with a safe Microsoft Copilot deployment?

Cyvra runs a structured pre-deployment audit that maps excessive permissions in SharePoint, Teams, and OneDrive, then configures sensitivity labels in Microsoft Purview to protect confidential documents. We establish an AI acceptable use policy, review the Microsoft data processing agreement for GDPR alignment, and train your team to use Copilot productively and securely. The result is a Copilot rollout with full governance, audit trail, and minimum data exposure risk.

Ryland Deakin
About the author
Lead Consultant, Cyvra · CISM · CompTIA Security+ · MCP

Ryland has delivered cybersecurity, compliance, and IT management programmes for regulated organisations across the UK and the Netherlands for over 20 years, including senior roles at Microsoft, ING, IPsoft, PPHE and more. View full profile

Work with Cyvra

Ready to adopt Copilot safely?

We structure AI governance before and during Microsoft Copilot adoption: permissions, GDPR, and acceptable use policy.

Disclaimer: This article is for informational purposes only and does not constitute legal, regulatory, or professional advice. Cyvra makes no warranty as to the accuracy or completeness of this content. Readers should seek independent professional advice appropriate to their specific circumstances.