Before you switch on Copilot: getting your Microsoft 365 data ready

AI assistants can find anything a user has access to — including files overshared years ago. Here's how to clean up permissions and data before rolling out Copilot.

Microsoft 365 Copilot and similar AI assistants are genuinely useful. Ask a question in plain English and they’ll search your emails, chats, meetings and documents to give you an answer, a summary or a first draft.

That’s also exactly why you need to prepare before switching them on.

The “oversharing” problem

Copilot works within your existing permissions. It only surfaces content that the individual user already has access to. That sounds reassuring — and it is, as far as it goes — but in most organisations, people have access to far more than anyone realises.

Over the years, files and sites pick up broad permissions:

  • A salary spreadsheet shared with “Anyone with the link” to send to an accountant.
  • A Teams site for a project where the whole company was added “just in case”.
  • SharePoint sites created years ago with access for “Everyone except external users”.
  • Folders that inherited permissions nobody has reviewed since they were set up.

Before AI, these were technically accessible but practically hidden — you had to know where to look. With an AI assistant, someone can simply ask “what are the salaries in the finance team?” and, if the permissions allow it, get an answer.

AI doesn’t create the oversharing. It makes it visible.

Step 1: Find out what’s overshared

Start by getting a clear picture of how your data is shared today:

  • Review sharing links. Look for files and folders shared with “Anyone” links or organisation-wide links, particularly in finance, HR and leadership areas.
  • Audit broad groups. Check which SharePoint sites and Teams include large groups such as “Everyone except external users”.
  • Identify site owners. Every SharePoint site and Team should have a named, current owner who is responsible for who has access.
  • Use the reporting you already have. The SharePoint admin centre and Microsoft Purview include reports on sharing and access. What’s available depends on your licences, but even the basic reports reveal a lot.

Step 2: Fix the biggest risks first

You don’t need a perfect tenant to start — you need the sensitive areas locked down:

  1. Restrict HR, finance, legal and board content to the people who genuinely need it.
  2. Remove “Anyone” links on sensitive files and consider disabling anonymous links by default.
  3. Tighten default sharing settings so new links are limited to specific people unless there’s a reason otherwise.
  4. Remove leavers and stale guest accounts that still have access.

Step 3: Label what’s sensitive

Microsoft Purview sensitivity labels let you classify documents and emails — for example Public, Internal, Confidential and Highly Confidential. Labels can apply protection such as encryption and access restrictions that travel with the file.

Start simply. A handful of clear labels that staff understand is far more effective than a complex scheme nobody uses. Where your licences allow, automatic labelling can help classify obviously sensitive content such as documents containing financial or personal data.

Step 4: Clear out old and duplicate data

AI assistants are only as good as the information they draw on. If your SharePoint is full of outdated policies, old drafts and five copies of the same price list, answers will reflect that confusion.

  • Archive or delete content that’s no longer needed.
  • Apply retention policies so data is kept for as long as required — and no longer.
  • Make sure the current, authoritative version of key documents is clearly identified.

Step 5: Secure the accounts

An AI assistant makes a compromised account more valuable to an attacker, because it can summarise information quickly. Before rollout, make sure:

  • Multi-factor authentication is enforced for every user — ideally phishing-resistant methods.
  • Conditional access policies block risky sign-ins and unmanaged devices where appropriate.
  • Admin accounts are separate, limited and closely protected.

Step 6: Pilot, train and measure

Roll out to a small pilot group first — ideally a mix of roles. Give them a short briefing on:

  • What the assistant can and can’t do.
  • Checking outputs before relying on or sending them.
  • What to do if it surfaces something they shouldn’t be able to see — which tells you there’s a permission to fix.

Collect feedback on real time saved and the tasks it helps with most. That evidence makes the case for a wider rollout — and the right licensing decisions.

A quick readiness checklist

  • Sensitive sites and folders reviewed and restricted
  • “Anyone” links removed from confidential content
  • Default sharing settings tightened
  • Every site and Team has a named owner
  • Sensitivity labels defined and communicated
  • Old and duplicate content cleaned up
  • MFA and conditional access enforced
  • Pilot group briefed, with a way to report issues

How NXAPP can help

Our NX Cloud team runs Copilot readiness reviews: we identify oversharing, tighten permissions, set up labelling and retention, and secure your accounts — so when you switch AI on, it helps your team rather than exposing your data. Talk to us about getting ready.

Let’s talk

Ready to build a smarter,
more secure future?

Book a call with our team and discover how NXAPP can help your business grow, innovate and stay protected.