M365 Permissions: The Oversharing Problem Before Copilot
Copilot doesn't create oversharing in Microsoft 365 — it just finds it. Here's how Texas businesses can find and fix permission sprawl first.
The HR Folder Everyone Could See
A manufacturing client in Katy called us last spring because their finance director had stumbled into a SharePoint site called "HR - Confidential" while looking for a vendor contract. She wasn't supposed to have access. Neither were forty-one other employees, as it turned out, including two contractors who'd left the company eight months earlier. Nobody had done anything malicious. The folder had just been shared "with everyone in the organization" back in 2021 by someone trying to solve a five-minute access problem, and it never got locked back down.
That's oversharing. It's not a hack, not a breach, not even usually intentional. It's the accumulated residue of years of "just give them access" decisions, and almost every Microsoft 365 tenant we've audited in Texas has some version of it sitting quietly in SharePoint, OneDrive, and Teams.
How the Sprawl Actually Happens
Permission creep doesn't arrive all at once. It builds up in small, reasonable-sounding steps:
- Someone shares a document via "Anyone with the link" instead of picking specific people, because it's faster.
- A Teams channel gets created for a project, then the project ends, but the channel — and everyone's access to it — stays.
- An employee leaves, their manager reassigns their laptop, but nobody audits what folders and sites that account could still touch.
- A SharePoint site inherits permissions from a parent site that was set to "Everyone except external users" back when the company had twelve employees.
- Guest accounts from a vendor relationship that ended two years ago never got removed.
None of this shows up on a dashboard unless you go looking for it. It's invisible in daily use because everyone with access is using it for legitimate reasons — until someone without a legitimate reason finds it too.
Copilot Didn't Cause This — It Exposes It
There's a common misconception going around that Microsoft 365 Copilot is somehow responsible for oversharing incidents. That's backwards. Copilot only surfaces content a user already has at least view permission to access; it doesn't grant new access or bypass existing controls (Microsoft Learn, as of 2026-08-20). What it does is make existing access dramatically more useful — and more visible.
Before Copilot, that finance director in Katy would've had to actually browse into the HR folder to find anything. She had access, but access without a search engine sitting on top of it is mostly theoretical. Ask Copilot a question like "summarize recent salary changes" and it will happily pull from any file the asking user can technically open, HR folder included. The permission problem was already there. Copilot just turned it into a working query.
This is exactly why rolling out Copilot without a permissions audit first is asking for trouble. You're not adding a new risk — you're putting a flashlight on an old one and handing it to every employee in the building.
What It Actually Costs When This Goes Wrong
Oversharing incidents rarely make headlines the way ransomware does, but they feed the same pipeline. Credential abuse — stolen or misused logins — shows up at some point in 39% of breaches, making it the single most common thread across incident types (Verizon 2026 DBIR, as of 2026-08-20). An overshared HR site or finance folder is a gift to anyone who does get a foothold in your tenant, because it means one compromised account can see far more than it should.
And ransomware recovery isn't cheap even when nothing was overshared. The median cost to recover, excluding any ransom paid, sits at $375,000 (Sophos, State of Ransomware 2026, as of 2026-08-20). The good news buried in that same report: 69% of victims didn't pay the ransom at all, up from 65% the year before — which tells you recovery increasingly depends on how well you'd already segmented and backed things up, not on negotiating with criminals.
The Texas Angle: SB 2610 and Compliance Exposure
Texas businesses with 20 to 99 employees got a real incentive to clean this up last year. SB 2610, effective September 1, 2025, shields a business from exemplary damages in a breach lawsuit if it has implemented the CIS Controls IG1 safeguard set — 56 specific controls, several of which are directly about access management and least privilege. It doesn't create a new right to sue and it doesn't cap actual damages, but it does mean the difference between a bad day and a catastrophic judgment can hinge on whether you documented your access controls before the incident, not after.
If your business handles patient records or financial data, the stakes are higher still. HIPAA and the FTC Safeguards Rule both expect documented access controls and periodic access reviews — not just firewalls and antivirus. An overshared SharePoint site full of client financial documents is exactly the kind of gap an auditor or a plaintiff's attorney will find fast. If you're not sure where you stand, our HIPAA compliance and FTC Safeguards Rule pages walk through what documentation actually needs to look like.
A Practical Cleanup Plan Before You Flip the Copilot Switch
You don't need an enterprise security team to fix this. You need a methodical pass through your tenant and a habit of repeating it.
- Run a sharing report first. Microsoft's compliance center and third-party tools can list every site, folder, and file shared broadly — "Anyone with the link" and "Everyone in organization" links especially. Start there, not with individual files.
- Kill stale guest accounts and orphaned permissions. Anyone who left the company or ended a vendor engagement should lose access the same week, not the same year.
- Move from broad groups to least privilege. "Everyone" and "All Employees" groups are convenient and dangerous. Scope access to the people who actually need a given site or folder.
- Set a review cadence. Quarterly is realistic for most small and mid-sized businesses; monthly if you're in a regulated industry.
- Test with Copilot's own audit tools before full rollout. Run a pilot with a small group, watch what surfaces, and fix what shouldn't be there before expanding access tenant-wide.
This is the kind of work that's easy to postpone because nothing is on fire — until it is. Our Microsoft 365 managed services team handles exactly this kind of permissions audit as a standard part of onboarding, alongside broader cybersecurity work and, where it makes sense, privileged access management for the accounts that matter most.
Frequently Asked Questions
Does Copilot actually create new security risks in Microsoft 365?
No — it doesn't grant new access. Copilot only shows content a user can already open based on existing permissions. The risk it creates is one of visibility: it makes forgotten or overly broad access easy to find and use, which is why an audit before rollout matters so much.
How do I know if my company has an oversharing problem?
Run a sharing report through the Microsoft Purview compliance portal and look specifically for links set to "Anyone" or "Everyone in the organization," plus guest accounts with no recent activity. Most tenants that have never done this audit find at least a handful of surprises.
Does SB 2610 mean I don't need cyber insurance or other protections?
No. SB 2610 only limits exemplary damages in a lawsuit if you've implemented CIS Controls IG1 — it doesn't cap actual damages, doesn't create a lawsuit where none existed, and doesn't replace insurance, backups, or monitoring.
How often should we review Microsoft 365 permissions?
Quarterly works for most small and mid-sized businesses. Companies in regulated industries — healthcare, finance, legal — should review monthly, especially around employee departures and vendor contract changes.
If you're planning a Copilot rollout, or just haven't looked at your SharePoint sharing settings in a while, get a permissions audit done before you turn anything on. Request a free IT assessment or contact us to talk through what a cleanup would actually take for your tenant.
Need Help With Cloud Services?
LayerLogix provides expert cloud services solutions for businesses across Houston and nationwide.
Related Articles
Need Expert IT Support?
Let our team help your Houston business with enterprise-grade IT services and cybersecurity solutions.