Microsoft's own playbook for turning on Copilot starts with a step almost everyone skips: fix who can see what, first.
Here's why that matters. Copilot doesn't break into anything. It only surfaces data the person asking already has permission to view — that's straight out of Microsoft's documentation. Which sounds reassuring until you look at how permissions actually pile up in a real office.
Every practice I walk into has the same three things: folders shared with "everyone in the company" years ago, a link somebody emailed in 2019 that still works, and a SharePoint site whose owner left in 2023. Nobody noticed, because nobody was digging.
Copilot digs. Ask it a casual question and it will happily summarize the provider compensation spreadsheet your front desk was never meant to find. No breach, no attacker — just a tool doing exactly what it was told.
The fix isn't avoiding Copilot. Microsoft gives you controls to fence off sensitive sites before rollout and to see what Copilot is actually surfacing. It's a few weeks of unglamorous permissions cleanup, and it's the difference between a productivity win and a very awkward Monday morning.
One thing worth knowing, since it's the first question I always get: your prompts, responses and files aren't used to train Microsoft's models.
If Copilot is on the list this year, do the cleanup first.
Want the next one in your inbox?
One practical Microsoft 365, Copilot, Azure, or security move per week — plain English, no pitch.
Subscribe via email