Solution · M365 Governance

Copilot governance.Review sharing first,then roll out.

Microsoft 365 Copilot works with the user's permissions. Conbool M365 Governance shows which content is shared too widely before an assistant finds it.

Why Copilot puts old shares on the agenda

Copilot bypasses no permission. It uses the existing ones, more thoroughly than any person.

Whatever is shared can be found

What a user may open can show up in their answers. A grant to “Everyone” went unnoticed so far because nobody searched for it.

Organisation-wide links

A link for everyone in the company in an HR folder is created quickly. It stays until someone removes it.

Public teams

Anyone in the company can join a public team. Its files are within everyone's reach.

Data protection asks for evidence

Anyone introducing Copilot has to show who can access which content. Without an overview that remains an assumption.

How to prepare the tenant

Three steps before the first Copilot licence.

1. Record the inventory

A scan reads sites, libraries, OneDrives, groups, teams, guests and every permission. File contents are never read.

2. Identify oversharing

Fixed rules report grants to Everyone, organisation-wide links in confidential areas, public teams and links for anyone without sign-in.

3. Clean up and keep watch

Findings are fixed with a dry run and approval by a second person. The scheduled scan reports what appears afterwards.

What matters before Copilot

Six points that decide how visible content is.

Grants to Everyone

Every permission for “Everyone” and “Everyone except external users” appears as a finding with object and item.

Organisation-wide links

Links for the whole organisation in objects using the Confidential template are reported separately.

Public teams

Teams with public visibility are listed as a separate finding.

Confidential template

A stricter template applies to single sites, teams or name patterns, for example HR, finance and management.

Score as a release criterion

The score from 0 to 100 and its trend show whether the tenant is ready and stays ready.

Report for data protection and works council

Score, open findings and exceptions with justification as PDF, as of the time of retrieval.

Rolling out Copilot with and without reviewing sharing

The same rollout, two outcomes.

 
With Conbool M365 Governance
Without a review
Knowledge of the inventory
Every permission recorded and assessed
Assumption that everything is fine
Grants to Everyone
Visible as findings, cleaned up before the rollout
Noticed only through an assistant's answer
Confidential areas
Separate, stricter template per site or team
Same treatment for all content
Evidence
PDF report with exceptions and reasons
No verifiable statement
After the rollout
Scheduled scan reports new findings
The inventory grows back unnoticed
Remediation
Dry run and four-eyes approval
One by one, by hand

As of October 2026. The right-hand column describes the usual approach without Conbool, not a specific vendor.

FAQ on Copilot and oversharing

What does oversharing mean for Microsoft 365 Copilot?
Content is shared with more people than necessary. Copilot respects the user's permissions but can draw on everything that user may open. Overly broad shares become visible as a result.
Does Conbool intervene in Copilot?
No. M365 Governance reviews and cleans up permissions and sharing in SharePoint, OneDrive and Teams. Copilot itself is neither configured nor monitored.
Does the product read file contents or classify data?
No. Names, types and counts are assessed: who has access, through which link, with which role. Content classification and data loss prevention are out of scope.
How does the product recognise confidential areas?
By the Confidential template that you assign to a site, team, library or name pattern. Stricter rules apply to those objects.
Does this make Copilot GDPR compliant?
That cannot be promised across the board. Reviewing permissions is a technical measure that limits access to what is necessary and can be evidenced. The legal assessment of the rollout remains your task.
Is the review worthwhile without Copilot?
Yes. The same shares can already be found through search in Microsoft 365, and a compromised account reaches everything open to that user.

Review first, then Copilot.

We show on your own tenant which shares need clarifying before the rollout.