← Resources

Copilot doesn’t leak data — your permissions do

Turn on Copilot and it surfaces the salary file half the company could already open. Copilot doesn’t leak data — it exposes the permissions you already had. For MSPs, that’s a revenue line.

There's a quiet panic happening in Microsoft 365 right now, and it's worth talking about plainly because it's both a real risk and a genuine opportunity for MSPs.

The panic goes like this: a customer turns on Microsoft 365 Copilot, an excited employee asks it something innocent like "summarise our latest plans for the leadership offsite," and Copilot cheerfully surfaces a salary spreadsheet, an unannounced redundancy list, or a confidential acquisition memo that the employee was never supposed to see. The customer calls you, alarmed, asking what your AI tool just did.

Here's the thing you can tell them, and it's important: Copilot didn't leak anything. It just held up a mirror to permissions that were already broken.

Copilot doesn't create access — it amplifies it

This is the single most important point to understand, and Microsoft says it themselves. As the Microsoft 365 Copilot blog on mitigating oversharing explains, Copilot doesn't introduce new data access paths on its own. It operates strictly within each user's existing Microsoft 365 permissions. If a user can already open a document, Copilot can summarise, quote and reason over it. If they can't, Copilot can't either.

What changes is discoverability. Before Copilot, your oversharing was latent. That salary file was technically accessible to half the company, but nobody stumbled across it because nobody was going to manually browse to it. Copilot removes the friction. Suddenly every over-permissioned file in the tenant is one natural-language question away from being surfaced, summarised and shared.

Copilot, helpfully, applies no judgement about whether access is appropriate. It doesn't ask "should this person really see this?" It just answers the question using everything it's allowed to touch.

This is a configuration problem, not a user problem

The reassuring part — and the part that makes this a fixable problem rather than an existential one — is that the vast majority of oversharing isn't malicious. It's misconfiguration. The common patterns are depressingly familiar to anyone who's audited a SharePoint estate:

  • Site privacy set so everyone in the organisation has access by default.
  • Default sharing options left on "everyone" or "everyone except external users."
  • Broken permission inheritance, where a subfolder quietly grants access nobody intended.
  • Expired guests who still have standing access months after a project ended.

Nobody sat down and decided to expose the HR folder to the whole company. It happened one reasonable-seeming sharing click at a time, over years, across every tenant you manage.

The numbers explain why deployments are stalling

This isn't a fringe worry. It's actively holding back the biggest product launch Microsoft has had in years. According to figures gathered in reporting on Copilot governance in 2026:

  • Security researchers estimate more than 15% of business-critical files are at risk due to oversharing or misconfigured access.
  • Nearly 70% of security teams worry that AI tools like Copilot could expose sensitive data.
  • A striking 73% of organisations in regulated industries have paused enterprise-wide Copilot rollouts specifically because of data exposure concerns.

Read that last one again. Almost three quarters of regulated organisations have hit pause on a product they're often already paying for, because they don't trust their own permission hygiene. That's not a Copilot problem. That's a permissions problem wearing a Copilot-shaped warning label.

The opportunity hiding inside the panic

Here's where it gets interesting for MSPs. Every one of those paused rollouts is a customer who wants to move forward and can't — because the prerequisite work feels overwhelming. That prerequisite work is a permission audit and remediation across the tenant. And that is squarely, profitably, in your wheelhouse.

Microsoft's own guidance points organisations toward Microsoft Purview and SharePoint Advanced Management to assess permissions, generate reports and remediate oversharing before deploying Copilot. The capability exists. The problem, if you're an MSP, is doing it across every customer tenant — which is exactly where the manual, portal-by-portal approach falls apart.

How DendronAI makes this practical

This is the centrepiece of what DendronAI was built to do. Its SharePoint app exists to answer one deceptively hard question: who can see what, across every tenant you manage?

Instead of logging into each customer's SharePoint admin centre and manually tracing permissions, you get external sharing, broken inheritance, anonymous links and expired guests surfaced against all tenants in one console. The view follows the chain that actually matters — tenant → site → folder → user → file — all in one place, so you can see not just that something is overshared, but exactly who it's exposed to and why.

A few things make this genuinely useful for the Copilot-readiness conversation:

  • You can fix at the source. Revoke risky links, tighten over-permissive folders and clear expired guests directly in the app — reducing risk and rebuilding trust without leaving the console.
  • AI gives you plain-English summaries and suggested actions. Rather than handing your team a 4,000-row permissions export to interpret, the platform tells you what's risky and what to do about it. (A nice irony: using AI to clean up the mess that's blocking AI.)
  • It works across your whole book at once. Because everything is cross-tenant by design, "are my customers Copilot-ready?" becomes a question you can actually answer this week, not a per-tenant slog you keep postponing.

That turns a scary customer conversation into a clean, sellable engagement: we'll audit your permissions across the tenant, remediate the oversharing, and get you to a defensible position before you switch Copilot on.

A fair word of caution

To keep this balanced: tightening permissions is not risk-free, and you shouldn't go in swinging. Aggressively revoking access can break legitimate workflows people quietly depend on, so remediation needs review and, ideally, a preview of impact before you act. Permission hygiene is also never "done" — it drifts the moment people start sharing again, so this is an ongoing service, not a one-off cleanup. And no tool substitutes for sensible data governance design with your customer in the first place.

But those are reasons to approach it carefully, not reasons to avoid it. The alternative — letting customers turn on Copilot over a tangle of broken inheritance and "everyone" links — is far worse.

The bottom line

Copilot is the most honest auditor your customers have ever had. It doesn't break in; it simply uses the access you've already granted, without the human discretion that used to keep latent oversharing hidden. The organisations pausing their rollouts understand this instinctively, even if they can't quite name it.

For MSPs, that's a rare thing: a security problem that's also a revenue line. If you'd like to see how DendronAI surfaces oversharing across every tenant — and turns Copilot readiness into a clean engagement — take a look at the platform.

Before you sell your customers Copilot, sell them the permission audit. They'll thank you for it, and so will their auditors.

DendronAI

Stop being the integration layer.

Book a 30-minute call. We'll talk through your client estate, how many tenants, where it hurts, and what to turn on first. No deck.

Book a demo