Why does Microsoft Copilot show people files they should not see?
Because they already had access to those files. Microsoft 365 Copilot runs every prompt as the person asking, using only content that person could already open, so it cannot show anyone anything new. What it changes is how easily people find things. Blue Arc IT Solutions finds the same three causes in almost every tenancy: permissive sharing defaults, content shared with the whole organisation, and permissions that stopped following the folder they sit in.
Copilot is not the leak
This is worth being precise about, because the instinct after a bad Copilot demo is to blame the tool.
Copilot reads your content through Microsoft Graph, the same interface the Microsoft 365 apps use, and it honours the permissions already on each item. Microsoft's data loss prevention documentation states that all Microsoft 365 Copilot prompts "run in the security context of the user who initiates the prompt", and that a user must have permission to the content before it can appear in a response.
So when a payroll spreadsheet turns up in someone's Copilot answer, the permission that allowed it was already there. The person could have found the file through SharePoint search, or by opening the site, at any point in the preceding years. They simply never tried.
The useful way to think about a Copilot rollout is that it is an audit of your tenancy, run by your own staff, at speed, on day one. That is uncomfortable, and it is also the most valuable thing it does.
Where the oversharing came from
Four causes, in rough order of how much damage they do.
SharePoint ships permissive. Microsoft says so directly in its own Copilot readiness guidance: "By default, SharePoint sets sharing settings to the most permissive option." Unless someone deliberately tightened them when the tenancy was built, the defaults are still in place.
Sharing with everyone in the organisation. This is usually the worst single category. It happens through organisation-wide sharing links, and through a permission called Everyone except external users, which gets added to a site to save the effort of working out who actually needs it. Microsoft's report for this looks at the top 100 sites where content was shared with your entire organisation in the past 28 days, which tells you how routine the practice is.
Broken permission inheritance. Normally a folder or file inherits permissions from the site around it. Once someone grants access to a single folder directly, that inheritance breaks, and from then on the folder no longer tracks changes made at the site level. Remove someone from the site and they can keep the folder. Multiply that by a decade and nobody can say who can open what.
Sites nobody owns. A site whose owner has left the business has no one reviewing its membership, so its permissions freeze in place while the organisation moves on around it. Microsoft lists ownerless, inactive and unreviewed sites among the risk signals worth hunting for, and flags sites where several signals overlap, such as a site holding sensitive data that also has open sharing links.
The reports that find it
This section is for whoever administers your Microsoft 365 tenancy. The short version for everyone else: the tooling to find this exists, it is included with a Copilot licence, and it does not need an expensive enterprise plan.
The reports live in SharePoint Advanced Management, and the licensing is better than most people expect. From Microsoft's documentation: "If your organization assigns at least one Microsoft Copilot license to a user, SharePoint administrators get access to the SharePoint Advanced Management (SAM) features that support your Copilot deployment." One licence, on a Business Premium base, and the whole toolkit appears in the SharePoint admin centre.
Four things to run first.
The Content Management Assessment is the guided starting point. It runs a suite of reports, categorises sites needing attention and produces recommendations. Microsoft suggests rerunning it every 30 days to track progress.
The site permissions baseline report gives a tenancy-wide snapshot of current permission structure across SharePoint and OneDrive, which is the fastest way to see overall exposure rather than one site at a time.
The Everyone except external users report finds organisation-wide sharing, as described above. Start remediation here.
The sharing links activity reports show which sites generated the most links in the last 28 days, split by link type: Anyone links, links for people in the organisation, and links for specific people. Anyone links are the ones that work without signing in.
There is also a site permissions for users report, which lists every site a named individual can reach. That one is worth running before a senior hire starts, and again when someone leaves.
Buying time on the worst sites
Some sites will need more review than you can do before Copilot goes live. There is a control for exactly that situation, and one that has recently been withdrawn.
Restricted Content Discovery is the current answer. Applied per site, it removes that site's content from organisation-wide search and from Copilot responses, and it also strips the AI features out of the site itself: "Users don't see entry points such as the Copilot button, AI actions menus (including creating agents), or Create pages with AI." That last part matters, because it stops someone building a Copilot agent over a site you have not finished reviewing.
Two things it does not do. It does not change access: "Restricted Content Discovery doesn't change existing permissions." Anyone who could open the content still can, directly. And it does not remove content from the search index, so Purview functions such as eDiscovery and automatic labelling keep working.
It is also slow on large sites and should be used sparingly. Microsoft cautions that "Excessive use can reduce the amount of content available to organization-wide search and Microsoft Copilot experiences, which can affect the completeness and relevance of search results and AI-generated responses." On propagation time: "For sites with more than 500,000 items, an update to Restricted Content Discovery could take more than a week to fully process and reflect in search and Copilot experiences." Plan it in, rather than switching it on the afternoon before a launch.
Most importantly, Microsoft frames it as a stopgap, "designed as a temporary governance control that gives organizations time to review and right-size access". Anyone presenting it as the fix is selling you a holding pattern. The fix is permissions.
Restricted SharePoint Search is closed to new tenancies
A large amount of published Copilot advice, including much of what AI assistants will tell you, still recommends Restricted SharePoint Search as step one. That advice is now out of date, and it is worth checking the date on anything that offers it.
Microsoft's notice is unambiguous: "Restricted SharePoint Search is retiring. Starting July 31, 2026, new enablement is blocked." If your tenancy has not already turned it on, you cannot.
It was never as protective as it sounded, either. Microsoft's own page notes that it "isn't a security boundary and doesn't change any permissions on SharePoint sites", that its allow list was capped at 100 sites, and that sites a user recently visited or had shared with them still appeared regardless. If you do still have it enabled, the documented path is to use the reports to fix permissions, apply Restricted Content Discovery where you need breathing room, and then turn it off.
When you need to actually remove access
Restricting discovery hides a site from search and Copilot. Sometimes that is not enough and you need the access itself gone.
Restricted Access Control does that. You nominate a Microsoft Entra security group or a Microsoft 365 group, and access to the site is limited to its members. Microsoft's description is the important part: "Users who aren't part of the specified group can't access the site or its contents, even if they had prior access through permissions or a link."
That overrides the accumulated mess rather than untangling it, which makes it the right tool for a genuinely sensitive site: a board site, an HR site, a Defence-related project site where the access list is contractual. It is a blunt instrument and that is the point.
The order of work
Tighten the tenancy sharing settings first, because everything else is undone by permissive defaults. Run the assessment and the permissions baseline report next, so you are working from evidence rather than instinct. Fix organisation-wide sharing first, then broken inheritance, then ownerless sites. Apply Restricted Content Discovery to the handful of sites that need more time. Use Restricted Access Control where the access list is genuinely fixed. Only then turn to labelling, which is covered in whether sensitivity labels control what Copilot can see.
Copilot agents built over a SharePoint site deserve a note of their own, because they inherit exactly the access that site grants and they can be created by ordinary users. Reviewing which sites can host an agent is part of this work, not a separate project.
How Blue Arc IT Solutions helps
We run the assessment and the access reports, present what they found in terms your leadership team can act on, and remediate in priority order. The reporting is fast. The time goes into deciding who should keep access to what, which is a business decision rather than a technical one, and one we will not make on your behalf without asking.
Blue Arc IT Solutions has supported Australian businesses since 2004, delivering nationally from Canberra. Our latest client survey recorded 96 per cent satisfaction with response time, 94 per cent with resolution and 97 per cent overall. We are experienced supporting DISP member organisations, where who can open which document is a contractual question rather than a preference.
Back to getting a Microsoft 365 Business Premium tenancy ready for Copilot, or see how we approach managed IT services more broadly.
Last reviewed: 11 September 2026, against Microsoft Learn's SharePoint Advanced Management Copilot readiness guidance (updated 16 July 2026), the Restricted Content Discovery page (updated 18 August 2026) and the Restricted SharePoint Search page (updated 6 July 2026), which confirms new enablement has been blocked since 31 July 2026. The SharePoint Advanced Management licensing position was confirmed against Microsoft's Copilot licence feature page on the same date.
Frequently asked questions
Does Microsoft Copilot bypass SharePoint permissions?
No. Copilot runs each prompt in the security context of the person asking and can only use content that person already has permission to open. When Copilot returns something unexpected, the permission that allowed it was already there.
Can you still use Restricted SharePoint Search to limit what Copilot sees?
Not if you have not already enabled it. Microsoft states that Restricted SharePoint Search is retiring and that new enablement has been blocked since 31 July 2026. The replacement is Restricted Content Discovery, which is applied per site and is available to tenancies licensed for Copilot with SharePoint Advanced Management.
Do you need Microsoft 365 E5 to find SharePoint oversharing?
No. Microsoft states that assigning at least one Microsoft Copilot licence gives SharePoint administrators the SharePoint Advanced Management features that support a Copilot deployment. That includes the data access governance reports, Restricted Access Control and Restricted Content Discovery, on a Business Premium base licence.
What is the single biggest cause of Copilot surfacing the wrong files?
Content shared with everyone in the organisation, usually through an organisation-wide sharing link or an Everyone except external users permission added years earlier to save time. Blue Arc IT Solutions starts every remediation with those sites because they carry the most exposure for the least deliberate intent.