Skip to content

M365 Permissions: The Oversharing Problem Before Copilot

By Donovan Brown
September 7, 2026
8 sections
Microsoft 365 productivity suite on screen
Photo: Microsoft 365 imagery

Old SharePoint sites and stale sharing links create silent oversharing risk long before Copilot arrives. Here's how Texas businesses should audit and fix permissions now.

01

The SharePoint site nobody remembers building

A logistics company we worked with out near Katy had a SharePoint site called "HR-Shared" that had been sitting there since 2019. Someone in HR had set it up to pass a benefits enrollment packet around during open enrollment one year, granted "Everyone except external users" access to make it easy, and then moved on with life. Nobody ever locked it back down. By the time we looked at it, that folder held terminated-employee files, a spreadsheet with partial SSNs for a 401k reconciliation, and salary bands for three departments. Every employee in the company, including a summer intern, technically had access to all of it.

Nobody did anything malicious. Nobody hacked in. The access was just sitting there, granted years earlier by a well-meaning person trying to solve a small, immediate problem. That's how oversharing actually happens in Microsoft 365 tenants. It's rarely a single bad decision. It's a slow accumulation of small conveniences that nobody ever goes back and cleans up.

02

Copilot doesn't create this mess, it finds it

A lot of the anxiety we hear from clients about rolling out Microsoft 365 Copilot centers on the idea that the AI will "leak" sensitive data. That's not quite how it works, and it's worth being precise about it because the precision matters for what you do next. Copilot only surfaces content a user already has at least view permission to access, according to Microsoft's own documentation on the topic. It doesn't grant new access and it doesn't bypass permissions. What it does is make existing access far more visible and far more usable.

Before Copilot, that stale HR-Shared site was a needle in a haystack. An employee would have had to know it existed, know how to search SharePoint effectively, and be curious enough to dig through folders. Most people never bothered. With Copilot summarizing content across a tenant on request, someone can ask a completely innocent question like "what's our current org chart and pay structure" and get an answer pulled straight from a file they were never supposed to see, because technically they always had permission to see it. Copilot exposes oversharing. It doesn't cause it. But the practical effect on your risk is the same either way, and it shows up faster once Copilot is turned on.

03

Why loose permissions matter more than most owners think

Credential abuse shows up in some form in 39% of breaches, per the Verizon 2026 Data Breach Investigations Report, and it's the single most common thread across incident types. An attacker who compromises one set of credentials, whether through phishing, a reused password, or an infostealer infection, doesn't just get that one person's mailbox. They get whatever that person's account can reach. If your permissions structure is tight, a compromised marketing coordinator's account gets an attacker into marketing files. If your permissions structure is loose, that same compromised account might get them into HR records, finance folders, and customer data because nobody ever scoped access down to what people actually need.

This is the real argument for permissions hygiene, and it has nothing to do with whether you ever turn on Copilot. Tight permissions shrink the blast radius of a single compromised account. Loose permissions turn every phishing click into a potential tenant-wide event.

04

The Texas angle: SB 2610 and access controls

Texas businesses with 20 to 99 employees got a meaningful incentive to get this right last year. Texas SB 2610, effective September 1, 2025, shields qualifying businesses from exemplary damages in a data breach lawsuit if they've implemented CIS Controls Implementation Group 1, which is a defined set of 56 safeguards. It doesn't create a new right to sue and it doesn't cap actual damages, but it does take exemplary damages off the table if you can show you had reasonable access controls in place. Account and credential management, along with access control management, are core parts of IG1. A documented permissions review process is exactly the kind of thing that helps you make that case if you're ever in a position to need to.

If your business falls in that employee range and you haven't looked at how IG1 maps to what you're already doing, it's worth a conversation. Our FTC Safeguards Rule compliance work and broader cybersecurity services overlap heavily with IG1 requirements, so a lot of clients find they're closer to compliant than they thought once someone actually maps it out.

05

A permissions audit you can actually run this quarter

You don't need a six-month project to make real progress here. Start with these steps, in this order:

  • Pull a sharing report. Microsoft's SharePoint admin center and the Microsoft Purview compliance portal both let you export a list of every site and file shared externally or via "Anyone" links. Sort by last-modified date and start with the oldest ones.
  • Kill "Everyone except external users" links. These are the tenant-wide sharing links that let anyone inside your company open a file with no further check. Replace them with links scoped to specific people or security groups.
  • Check your Global Admin count. If more than two or three people hold Global Admin, that's a problem on its own, independent of file sharing. Move day-to-day admin work to scoped roles.
  • Review Teams guest access. Every Teams site created for a client project or vendor relationship potentially outlives that relationship by years. Set an expiration policy and actually enforce it.
  • Turn on sensitivity labels. Label HR, finance, and legal content so it's classified regardless of where it ends up getting copied or shared later.
  • Schedule quarterly access reviews. Access that made sense when someone was hired rarely stays right-sized as they change roles. A recurring review catches the drift before it becomes an incident.

None of this requires exotic tooling. It requires someone with the time and the M365 admin knowledge to actually do it, which is exactly where a lot of internal IT teams get stuck, not from lack of skill but from lack of bandwidth. If that's your situation, our Microsoft 365 managed services team runs exactly this kind of audit as a standing engagement rather than a one-time favor squeezed between tickets.

06

Rolling out Copilot the right way

If you're planning a Copilot rollout, do the permissions audit first, not alongside it and definitely not after. Treat it like you would any privileged access project: figure out who needs what, scope it down, and then turn on the tool that makes access more discoverable. Pairing this with a broader look at privileged access management catches related problems, like service accounts with standing admin rights or shared logins that nobody can trace back to a person. This is also a good moment to loop in whoever manages your network and identity infrastructure, since permissions sprawl often mirrors network access sprawl in the same tenant.

07

Frequently Asked Questions

Sometimes, briefly. The fix is to run a report first, identify which links are actually in active use versus dormant, and communicate with the handful of people using live links before you cut them. Most stale links have had zero access in months, which the sharing report will show you.

Do we need to fix this before we can safely use Copilot at all?

You can technically turn Copilot on without cleaning up permissions first, but you're choosing to make existing oversharing more visible and more actionable to more people. A short cleanup window before rollout, even just addressing the highest-risk sites, meaningfully reduces exposure.

How often should we review permissions after the initial cleanup?

Quarterly is a reasonable cadence for most small and midsize businesses. Companies with higher turnover, frequent contractor use, or regulated data like healthcare or financial records should consider monthly spot checks on top of the quarterly full review.

08

Next step

If you're not sure how exposed your tenant actually is, don't guess. Request a free IT assessment and we'll run the sharing and permissions audit for you, flag what needs attention first, and give you a straight answer about where you stand before you flip the switch on Copilot. Or if you'd rather just talk it through first, contact us and we'll set up a time.

Related Services

Need Help With Cloud Services?

LayerLogix provides expert cloud services solutions for businesses across Houston and nationwide.

Serving Houston, The Woodlands, and nationwideGet a Free Consultation
Back to Blog
Keep Reading

Related Articles

Need Expert IT Support?

Let our team help your Houston business with enterprise-grade IT services and cybersecurity solutions.

Call NowBook a Call