# Copilot Didn't Leak Your Files — It Made the Ones You Overshared Easy to Find

> Copilot creates no new access. It just makes everything a user can already reach instantly searchable. The oversharing was there for years — Copilot is the flashlight.

- Canonical: https://www.rnits.com/blog/copilot-oversharing-sharepoint-permissions-smb
- Provider: RNITS — cybersecurity-first managed IT for small businesses
- Phone: (978) 226-8931
- Talk to RNITS: https://www.rnits.com/contact · Free cyber security audit: https://www.rnits.com/free-cyber-security-audit
- Published: 2026-09-16
- Category: AI Security
- Tags: Microsoft Copilot, AI Governance, Microsoft 365, Data Loss Prevention

The office manager at a 30-person accounting firm in Nashua asked Copilot a reasonable question during their rollout: "Summarize our staff compensation structure."

It did. In a tidy paragraph, with names and numbers, pulled from a spreadsheet a bookkeeper had saved to a SharePoint site back in 2021 and shared with "Everyone" so a colleague could open it once. Nobody had looked at that file in years. Nobody remembered it existed. It took Copilot about four seconds to find it and read it back.

Here is the part that matters: Copilot did nothing wrong. The office manager already had permission to open that file. She could have found it herself by browsing SharePoint — if she had known it was there, which she did not, because nobody browses SharePoint. Copilot did not break a rule, bypass a control, or leak anything. It simply answered a question using files the user was already allowed to see.

That is the whole Copilot oversharing problem in one sentence. It is not a security hole in Copilot. It is a spotlight on the permissions mess you have been quietly accumulating for a decade.

## What Copilot actually does with your files

Microsoft 365 Copilot works by reading the data a user already has access to. When you ask it something, it searches across your SharePoint sites, OneDrive, Teams chats, and Exchange mailbox, finds relevant content, and uses it to build an answer. That access is scoped to the individual — Copilot cannot see anything the person asking could not already open on their own.

This is a good security design, and worth saying plainly before we criticize anything: Copilot respects existing permissions. It does not create a shared pool of company data that everyone can query. If a user has no rights to the finance site, Copilot will not surface finance files for them.

The trouble is the phrase "already has access to." In most small businesses, that set is enormous, and nobody has ever measured it.

For fifteen years, the way people shared a file in Microsoft 365 was to make it easy. A partner needed a document, so someone clicked Share and picked "Anyone" or "Everyone in the organization" because it was faster than typing an email address. A department stood up a Teams channel and dumped every file it touched into the connected SharePoint site with default-open permissions. An intern got added to a security group in 2019 and never got removed. A folder got shared to a client's personal Gmail for one project that ended two years ago.

None of that caused a problem, because finding a file required knowing it existed and where it lived. Discovery was hard, so oversharing was invisible. The access was always there — the friction of navigating to it was the only thing keeping it quiet.

Copilot removes the friction. A natural-language question against your entire tenant surfaces the one payroll file, the one board deck, the one HR investigation, that a user technically could reach but never would have found. The exposure did not increase. Its discoverability went from near-zero to instant.

## Why small businesses are more exposed than enterprises here

Large companies have been fighting oversharing for years with governance tooling, records management, and staff whose job is data classification. They still get it wrong — Microsoft published an entire "oversharing blueprint" because their biggest customers kept turning on Copilot and immediately surfacing HR files. But at least someone owns the problem.

Small businesses have the same mess with none of the controls, and a few conditions that make it worse:

- **The tenant grew organically with no plan.** Nobody designed the SharePoint structure. It accreted, one Team and one "quick share" at a time, across multiple IT providers who each did things their own way. There is no map of who can see what because there was never an architect.
- **"Everyone" and "Anyone" links are everywhere.** The default sharing behavior in older tenants was permissive, and the people clicking Share were not thinking about a future AI reading everything. Every one of those links is a standing grant.
- **Guests never leave.** External users — clients, contractors, the accountant's outside bookkeeper, a former vendor — get added to a site or a file and stay there indefinitely. Copilot honors those grants too, though the guest sees results through their own access, not the employee's.
- **Old files never die.** The 2021 comp spreadsheet, the 2019 layoff plan, the merger discussion that fell through. Small businesses almost never retire old data. It sits in SharePoint at whatever permission it was born with, waiting for a question that matches it.
- **There is no data classification.** Nothing is labeled "confidential." Copilot cannot treat sensitive files differently because nothing tells it which files are sensitive.

The result is that the average 20-to-50-person business we assess has thousands of files reachable by people who have no business reason to see them — and until Copilot arrives, everyone assumes those files are effectively private because nobody ever stumbles into them.

## The failure modes we actually see

When a small business turns on Copilot without doing the prep, the same handful of things surface in the first week. These are not hypotheticals — they are what shows up.

**Compensation and HR data.** The single most common one. Payroll spreadsheets, offer letters, performance reviews, and disciplinary records that were shared too broadly years ago. Someone asks Copilot a payroll or headcount question and it cheerfully assembles an answer from files that HR believed were locked down.

**Mergers, sales, and financials.** Board decks, cap tables, buyer discussions, tax returns. A business owner's most sensitive documents, often stored in a personal OneDrive and shared to an accountant or attorney with a link that later got forwarded internally.

**Client and patient data crossing internal walls.** In a professional-services firm, matter files or client records shared to the wrong internal group. For a healthcare or legal practice, that is not just embarrassing — it is a potential HIPAA or confidentiality problem, because internal access controls are part of what those regulations require you to maintain.

**Old projects with external guests still attached.** Copilot surfaces content from a site where a former contractor's account is still a member. The employee did not know the guest was there; the guest may not even remember they still have access.

**One documented Copilot bug, for completeness.** In May 2026, Microsoft patched CVE-2026-26129, an information-disclosure flaw in Copilot Business Chat. It is worth knowing it existed, and it is worth keeping Copilot patched like anything else. But it is a footnote. The oversharing problem is not a bug that gets patched — it is your own permissions, and no update from Microsoft will fix those for you.

## The honest part: this is not a reason to avoid Copilot

Plenty of vendors are using Copilot oversharing to sell fear, and a certain kind of MSP will happily quote you a stack of new monitoring tools to "make Copilot safe." That is the wrong frame.

Copilot is a legitimately useful tool, and the oversharing it exposes is a problem you already had. The files were overshared yesterday, before Copilot. A curious or disgruntled employee could have found them with enough browsing. A departing staffer could have already walked out with them. Copilot did not create the risk — it made it measurable, which is actually a gift, because now you can see it and fix it.

The right response is not to cancel the rollout. It is to run a cleanup first, then turn Copilot on with confidence. The cleanup is worth doing even if you never deploy Copilot, because everything it fixes is a real exposure regardless of whether an AI is the thing that finds it.

## The pre-Copilot cleanup, in order of leverage

This is a few hours of focused work for a typical small tenant, not a six-month governance project. Do it in this order — each step removes the most risk for the least effort at that stage.

### 1. Find and kill the broad sharing links

The "Everyone," "Everyone except external users," and "Anyone with the link" grants are where the worst surprises live. The Microsoft 365 admin center and SharePoint admin center can report on sites and files shared organization-wide. Pull that list, and for each one ask a simple question: does this genuinely need to be open to the whole company? Almost none of them do. Replace broad grants with access scoped to the specific people or group that actually needs the file.

This one step removes the majority of the "Copilot found the payroll file" scenarios, because those files were almost always reachable through a broad link, not a deliberate share.

### 2. Review your guest and external access

List every external guest in the tenant and every externally shared site or file. For each guest, confirm there is a current reason they should still have access. The former contractor, the vendor from a finished project, the client whose engagement ended — remove them. Set an expiration policy on new external sharing links so this stops accumulating again on its own.

### 3. Clean up the security groups behind your SharePoint sites

Oversharing often hides one layer down, in the groups that grant site access. A "Finance" group with a former marketing hire still in it. A catch-all "All Staff" group used to grant access to a site that should have been department-only. Walk the membership of the groups that gate your most sensitive sites and remove anyone who does not belong. This is also where you catch the intern from 2019.

### 4. Deal with the genuinely sensitive stuff directly

Some data should never be in a broadly reachable location at all — active HR investigations, compensation planning, M&A discussions, anything under legal hold. Move it to a properly restricted site with a named, minimal access list, or apply a sensitivity label that restricts it. Do not rely on obscurity. Once Copilot is on, obscurity is gone.

### 5. Turn on the controls you are already paying for

Most of what you need to keep the tenant clean going forward is already in your Microsoft 365 licensing, unused. Sensitivity labels let you classify and automatically restrict confidential content. Data loss prevention policies can flag or block sensitive data patterns. Copilot itself can be told to exclude labeled content from its responses. The tooling exists; in nearly every tenant we assess, it has never been switched on. Our [Microsoft 365 managed services](https://www.rnits.com/services/microsoft-365-managed-services) work is frequently where these controls finally get configured, because someone has to own the setup and nobody ever had.

### 6. Roll Copilot out to a small group first

Do not flip it on for all 40 people at once. Enable it for a handful of trusted users, ask them to run the kinds of questions that would surface trouble — payroll, headcount, anything about a specific person or a sensitive project — and watch what comes back. If something appears that should not, you have found another overshared file to fix before it reaches the whole company. Expand once the pilot group stops finding surprises.

## The governance layer that keeps it clean

The cleanup fixes today's mess. Keeping it clean is a governance question, and it is the same answer as every other AI problem: a policy and an owner, not a pile of tools.

An AI governance framework for Copilot answers the questions that determine whether the tenant stays clean six months from now. Who is allowed to share files organization-wide, and how? What gets labeled confidential, and by whom? How often does someone review external guests and broad grants? What is Copilot allowed to touch, and what is walled off from it? These are decisions, not products, and they belong in a short written policy your staff can actually follow. We build these as part of our [AI governance service](https://www.rnits.com/services/ai-governance) — the deliverable is a workable policy and a clear owner, not a binder designed to impress an auditor.

The deployment side matters too. Turning Copilot on properly means configuring the sensitivity labels and exclusions, setting up the DLP rules, running the pilot, and training staff on what Copilot can and cannot see — so the office manager in Nashua understands that "Copilot can read it" means "I already could read it," and knows to report anything that looks like it should not be there. That technical rollout is what our [AI enterprise deployment service](https://www.rnits.com/services/ai-enterprise-deployment) handles, and it is the difference between a Copilot launch that surfaces your HR files and one that does not.

## Five questions to ask whoever manages your Microsoft 365

If you outsource IT and you are considering Copilot — or worse, if someone already turned it on — these questions will tell you where you stand. Ask them by email so you have the answers in writing.

1. **Before we enable Copilot, will you run an oversharing report on our tenant?** A provider who has never heard of this is not ready to deploy Copilot for you.
2. **How many files and sites in our tenant are shared with "Everyone" or "Anyone with the link"?** If the answer is "we'd have to check," that number has never been managed.
3. **Who are all the external guests in our tenant, and why does each one still have access?** A stale guest list is a standing exposure with or without Copilot.
4. **Are sensitivity labels and DLP configured, and will Copilot respect them?** These are included in most business licensing. "Not turned on" is the common — and fixable — answer.
5. **What is the rollout plan — everyone at once, or a monitored pilot first?** "Everyone at once" is how the HR files get found.

If the answers are vague, that is not a reason to panic. It is a reason to do the cleanup before the launch rather than after.

## The short version

Copilot oversharing is not a flaw in Copilot. It is your own permissions, built up over years of clicking Share to make life easier, suddenly made searchable by a tool that is very good at finding things. The files were exposed the whole time. Copilot is just the first thing to go looking.

That reframing should be reassuring, not alarming. A problem you can see is a problem you can fix, and the fix is a few hours of permissions cleanup plus a policy to keep it clean — not a canceled rollout and not six new line items on your IT bill. Do the cleanup, turn Copilot on to a pilot group, expand when the surprises stop. That is the entire playbook.

If you want an honest read on what your tenant would surface the moment Copilot goes live — how many broad shares, how many stale guests, what is sitting in SharePoint at the wrong permission — that is included in our [free cyber security audit](https://www.rnits.com/free-cyber-security-audit). You keep the findings whether or not you ever hire us, and if your setup is already clean, we will tell you that too. Serving small businesses across New Hampshire and Massachusetts, we would rather you turn Copilot on the right way than learn what it can see the hard way. Or just [get in touch](https://www.rnits.com/contact) and ask.

---

**RNITS** — New Hampshire & Massachusetts (onsite within 150 miles of Tyngsboro, MA); Virginia and the rest of the US served remotely

RNITS (The Rnits Company) · 404 Middlesex Road, Suite 9, Tyngsboro, MA 01879 · (978) 226-8931 · info@rnits.com

Contact: https://www.rnits.com/contact · Free cyber security audit: https://www.rnits.com/free-cyber-security-audit
