Microsoft shifts focus from permission trust to content governance in Copilot deployment

Microsoft’s latest guidance on Copilot highlights a strategic move away from permission-based trust towards robust content governance and discovery controls, reflecting a nuanced approach to data privacy and security.

Microsoft’s latest guidance on Copilot deployment amounts to a warning to administrators: do not confuse permission-respecting behaviour with safe information handling. In its current SharePoint Advanced Management guidance, Microsoft says Copilot and agents use Microsoft Graph and honour existing permissions, sharing settings and policies, while also acknowledging that SharePoint’s default sharing posture is the most permissive option. At the same time, one of Microsoft’s earlier containment measures, Restricted SharePoint Search, has moved into retirement: as of 31 July 2026, new enablement has been blocked in favour of broader controls such as Restricted Content Discovery. The message from Redmond is now less about trusting the assistant and more about repairing the estate it is allowed to search. (learn.microsoft.com)

The underlying model is straightforward and, for many tenants, unforgiving. Microsoft’s architecture and privacy documentation says Copilot works within the signed-in user’s scope, not with tenant-wide visibility, and only surfaces organisational data for which that person has at least view permission. The Semantic Index, Microsoft says, follows that identity boundary during grounding. In practice, that means Copilot is not inventing a new route to confidential material; it is turning every loose read permission, inherited folder exception and forgotten sharing link into something that can be queried in natural language across mail, chat and documents. That is why Petri’s recent assessment argues that the product is exposing a permissions problem rather than creating one. (learn.microsoft.com)

Microsoft’s own checklist for preparing a tenant is broader than a simple review of site ACLs. The company tells administrators to look for “Anyone”, “Everyone” and organisation-wide links, overly large audiences, broken inheritance, sensitive content with weak protection, unlabeled or public sites, and governance failures such as ownerless, inactive or unreviewed sites. Petri adds familiar operational causes: the Everyone except external users group applied too widely, folders that inherit broader access than the libraries above them, and anonymous links that were never set to expire. Framed that way, Copilot readiness becomes a content-governance exercise, not a feature toggle. (learn.microsoft.com)

The toolset Microsoft now puts in front of admins reflects that shift. The SharePoint Advanced Management guide points to Content Management Assessment, data access governance reports, AI insights and the SharePoint Admin Agent as the main ways to identify oversharing and prioritise remediation. Those reports are useful, but they are still snapshots. Microsoft’s Everyone except external users report covers the top 100 sites shared with the whole organisation in the past 28 days, while sharing-link activity reports also look back 28 days. Petri’s recommendation is therefore practical rather than theoretical: run the assessments repeatedly, because permission drift restarts the moment staff create a new Team, site, folder or link. (learn.microsoft.com)

The most important distinction in the current documentation is between controlling access and controlling discovery. Restricted Access Control changes who can open a SharePoint site at all; Microsoft says users outside the specified group cannot access the site or its contents even if they previously had access through a permission assignment or a link. Restricted Content Discovery does something different: it leaves site access unchanged but stops the site’s material appearing in Copilot, agents and organisation-wide search. A separate Microsoft page on SharePoint agents makes the operational effect clearer still. Once a site is flagged for restricted content discovery, the Agent icon disappears from that site, users cannot use the ready-made agent, cannot create new agents there, and cannot add content from that site to other agents. (learn.microsoft.com)

That helps explain why Restricted SharePoint Search now looks like transitional scaffolding rather than a lasting answer. When Microsoft introduced it in March 2024, Petri reported that the feature would roll out from April 2024, remain off by default and be enabled through PowerShell, allowing IT to curate up to 100 SharePoint Online sites for Copilot use. Microsoft’s current documentation is much blunter. It calls the feature temporary, says it is “not a security boundary”, caps it at 100 sites, and warns that users may still get results from content they own, have previously accessed, or received directly in Teams or Outlook. Microsoft also notes that site-scoped searches are unaffected, which limits the control further. With new enablement blocked since 31 July 2026, the company’s own direction of travel is away from allow-listing and towards permission repair plus discovery controls. (petri.com)

Sensitivity labels, encryption and related controls offer help, but not the absolute shield many organisations would like. Microsoft’s current privacy documentation says encrypted content can exclude programmatic access for agents, thereby limiting their ability to read it. Tony Redmond’s testing for Practical 365 showed the nuance behind that wording. Copilot may be unable to extract and summarise the contents of a protected file, yet still reveal that the file exists because Microsoft Search continues to index clear metadata such as titles and subjects. Redmond also found similar “protected but discoverable” behaviour where a SharePoint block-download policy was in force. In other words, content protection can stop grounding without fully removing discoverability. (learn.microsoft.com)

There is, however, a useful audit trail. Microsoft’s privacy page says Copilot stores prompts and responses, including the citations used to ground an answer, and that administrators can view or manage that data through Content search or Microsoft Purview. For Teams interactions with Copilot, Microsoft also points to Teams Export APIs, while users can delete their own Copilot activity history through the My Account portal. Petri argues that the more sustainable response is to combine those records with Microsoft Purview DSPM for AI and DLP so that organisations keep scoring exposure risk and can prevent sensitive content from grounding future responses. The broader conclusion is awkward but clear: Copilot is usually doing what Microsoft said it would do; the real surprise is how much permissive sharing many tenants have been living with. (learn.microsoft.com)

Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.