Copilot governance.Review sharing first,then roll out.
Microsoft 365 Copilot works with the user's permissions. Conbool M365 Governance shows which content is shared too widely before an assistant finds it.
Why Copilot puts old shares on the agenda
Copilot bypasses no permission. It uses the existing ones, more thoroughly than any person.
Whatever is shared can be found
What a user may open can show up in their answers. A grant to “Everyone” went unnoticed so far because nobody searched for it.
Organisation-wide links
A link for everyone in the company in an HR folder is created quickly. It stays until someone removes it.
Public teams
Anyone in the company can join a public team. Its files are within everyone's reach.
Data protection asks for evidence
Anyone introducing Copilot has to show who can access which content. Without an overview that remains an assumption.
How to prepare the tenant
Three steps before the first Copilot licence.
1. Record the inventory
A scan reads sites, libraries, OneDrives, groups, teams, guests and every permission. File contents are never read.
2. Identify oversharing
Fixed rules report grants to Everyone, organisation-wide links in confidential areas, public teams and links for anyone without sign-in.
3. Clean up and keep watch
Findings are fixed with a dry run and approval by a second person. The scheduled scan reports what appears afterwards.
What matters before Copilot
Six points that decide how visible content is.
Grants to Everyone
Every permission for “Everyone” and “Everyone except external users” appears as a finding with object and item.
Organisation-wide links
Links for the whole organisation in objects using the Confidential template are reported separately.
Public teams
Teams with public visibility are listed as a separate finding.
Confidential template
A stricter template applies to single sites, teams or name patterns, for example HR, finance and management.
Score as a release criterion
The score from 0 to 100 and its trend show whether the tenant is ready and stays ready.
Report for data protection and works council
Score, open findings and exceptions with justification as PDF, as of the time of retrieval.
Rolling out Copilot with and without reviewing sharing
The same rollout, two outcomes.
With Conbool M365 Governance | Without a review | |
|---|---|---|
| Knowledge of the inventory | Every permission recorded and assessed | Assumption that everything is fine |
| Grants to Everyone | Visible as findings, cleaned up before the rollout | Noticed only through an assistant's answer |
| Confidential areas | Separate, stricter template per site or team | Same treatment for all content |
| Evidence | PDF report with exceptions and reasons | No verifiable statement |
| After the rollout | Scheduled scan reports new findings | The inventory grows back unnoticed |
| Remediation | Dry run and four-eyes approval | One by one, by hand |
As of October 2026. The right-hand column describes the usual approach without Conbool, not a specific vendor.
FAQ on Copilot and oversharing
What does oversharing mean for Microsoft 365 Copilot?
Does Conbool intervene in Copilot?
Does the product read file contents or classify data?
How does the product recognise confidential areas?
Does this make Copilot GDPR compliant?
Is the review worthwhile without Copilot?
Related solutions
M365 Governance
Berechtigungen und Freigaben in Microsoft 365 erfassen, bewerten, bereinigen.
SharePoint-Berechtigungen verwalten
Alle Berechtigungen aus SharePoint und OneDrive in einer Liste.
Microsoft-365-Sicherheitscheck
Mandanteneinstellungen gegen eine Vorlage, dazu der Bestand an Freigaben.
Microsoft 365 Backup
Acht Quellen in einem Zeitplan, Rückholung einzelner Elemente.
Microsoft 365 E-Mail-Sicherheit
Schutz des Mailwegs vor Exchange Online.
Vergleich mit Hornetsecurity
Conbool und Hornetsecurity im Überblick.
Review first, then Copilot.
We show on your own tenant which shares need clarifying before the rollout.