The mechanism, stated plainly
Copilot retrieves under the asker's permissions (foundations FLOW). Years of "share with everyone to make the deadline", org-wide links, public-by-default sites and "Everyone except external users" ACLs mean most users can technically open thousands of documents nobody remembers sharing. Search made this hard to exploit (you had to know what to look for); Copilot removed the friction — "summarise anything sensitive about layoffs" is now a competent query. The data didn't move. The discovery cost collapsed.
The remediation toolkit (mostly unlocked by one Copilot seat)
| Tool | What it does | Use it for |
|---|---|---|
| SAM Data access governance reports | Finds oversharing: org-wide links, 'Everyone…' ACLs, sites with broad access | The map of the problem — run FIRST |
| Restricted SharePoint Search | Allowlist mode: Copilot/search grounded only on curated sites | The emergency brake during cleanup (blunt: also hides legitimate content) |
| Restricted Access Control (RAC) | Per-site: restrict access to a group even if wider ACLs exist | Surgical containment of the worst sites |
| Restricted Content Discovery | Keeps named sites OUT of Copilot grounding while normal access continues | The scalpel: usable site, not groundable |
| Sensitivity labels + DLP for Copilot | Labeled content excluded from grounding/summarisation per policy | The durable, content-level control |
| Site access reviews / sharing reports | Owner attestation loops on flagged sites | Making cleanup someone's job |
The runbook (staged, like Microsoft's own guidance)
- Assess before seats: SAM oversharing reports + Purview's DSPM-for-AI assessments on day one of the pilot — the pilot licence itself unlocks them.
- Contain: RAC/Restricted Content Discovery on the red-list sites (M&A, HR, board); Restricted Search only if the red list is unmanageably long.
- Remediate: kill org-wide links (expire + re-share), fix 'Everyone…' ACLs, label the crown jewels — DLP-for-Copilot then enforces at grounding time.
- Institutionalise: access reviews on sensitive sites, sharing-link policies
tightened at the SPO tenant level (your serv365 scan holds
sharingCapability— drift there is exactly this control regressing), quarterly SAM re-runs.
What to watch (proofs)
- The before/after: SAM oversharing report counts at pilot start vs 90 days — the metric the steering committee actually understands.
- The live test: a pilot user asks Copilot for known-sensitive topics — findable before, not-findable after containment; screenshots into the runbook.
- Regression guard: SPO tenant sharing settings in the nightly serv365 scan —
sharingCapabilityor link defaults drifting back = the alert that matters. - Label coverage on crown jewels: % of red-list sites' content labeled — the durable-control adoption curve.