// RESOURCE GUIDE · AI & AUTOMATION · UPDATED 2026-09-13

Microsoft 365 Permissions to Review Before You Enable Copilot or an AI Assistant

An access review worth doing on its own merits — and one that becomes urgent the moment an assistant can search your tenant on a user's behalf.

By GlobalTSS · Educational information only. Product behavior, feature names, and licensing change; verify against Microsoft's current documentation for your tenant.

03 // Microsoft 365 Permissions Before an AI Assistant

An AI assistant that works inside your Microsoft 365 environment is, from an access standpoint, a very fast colleague. Microsoft's published documentation describes Microsoft 365 Copilot as returning only content that the signed-in user already has permission to access, and as inheriting the tenant's existing identity, access, and compliance controls. That is Microsoft's own description of its product; confirm the current wording, the behavior, and the terms that apply to your licence in Microsoft's documentation and your agreement before relying on any summary, including this one.

Taken at face value, that design has an uncomfortable implication for most organizations. Permissions that were technically open but practically obscure — a finance folder shared with the whole company in 2019, a site nobody remembers owning — stop being obscure. Anything a user could have found by searching hard, an assistant can surface by being asked a plain question. The access review below is worth doing regardless. If an assistant is coming, it should happen first.

1. Sharing Links and Their Defaults

Sharing links are the most common source of unintended access, because they are created one at a time by people trying to be helpful.

  • Check the tenant's default link type — whether a new link defaults to anyone with the link, everyone in the organization, or only specific people
  • Review whether anonymous links are permitted at all, and whether they expire
  • Look for links created for a one-off share that have been live for years
  • Decide whether link expiration and permission defaults should differ for sensitive sites

2. SharePoint Site Membership and Sprawl

Sites accumulate. Each one created for a project, a committee, or a customer keeps its membership after the reason for it ends.

  • Produce a list of sites with an identified owner; anything without one needs an owner or an archive decision
  • Review membership on sites holding finance, HR, legal, or customer-confidential material
  • Look specifically for broad grants such as an everyone-in-the-organization group applied to a site that should be restricted
  • Check permission inheritance that has been broken at folder or item level — those exceptions are where surprises live

3. OneDrive Used as a Shared Drive

Personal storage frequently becomes the real home of a business process. That is a resilience problem before it is an AI problem.

  • Identify business-critical content sitting in individual OneDrive accounts and move it to a site with an owner
  • Review the OneDrive content of departed employees, and the retention decision attached to it
  • Look for personal drives shared broadly across the organization

4. Teams, Channels, and Guests

Teams membership carries file access, because the files live in an underlying SharePoint site.

  • Review membership of teams that handle sensitive work, including standard channels visible to every team member
  • Check private and shared channel membership separately — they do not always match the parent team
  • Enumerate guest accounts: who invited them, for what, and whether that work has ended
  • Confirm what guests can see beyond the single channel they were invited to

5. Mailboxes, Calendars, and Delegation

  • Review shared mailbox membership and full-access delegation, including permissions granted temporarily years ago
  • Check calendar sharing defaults, particularly where calendar detail reveals client names or matters
  • Confirm that mailboxes of departed staff are handled deliberately — converted, delegated, or retained under policy, not left licensed and reachable

6. Identity Hygiene and Administrative Roles

Access review is wasted effort if the accounts themselves are not in order.

  • Enforce multi-factor authentication, and confirm there are no standing exclusions nobody remembers creating
  • Review who holds global administrator and other privileged roles, and reduce to the minimum
  • Separate administrative accounts from the accounts used for daily email and documents
  • Disable accounts for departed staff promptly, and check for licensed-but-unused accounts
  • Inventory service accounts and application permissions granted to third-party apps — consent granted by users is easy to miss

7. Information Architecture and Retention

An assistant is only as accurate as the content it draws on, and it does not know which document was superseded.

  • Archive superseded policies, price lists, and procedures out of locations that are actively searched
  • Establish one identifiable current version of the documents people ask about most
  • Review retention settings so that content no longer needed is not sitting indefinitely in a searchable location
  • Where sensitivity labelling is in use, check what remains unlabelled rather than assuming coverage

8. Sequence the Work

A full tenant remediation before anyone sees a benefit is a project that stalls. A workable order:

  • Inventory sites, guests, and privileged accounts, and fix the worst sharing exposure first
  • Pilot with a small group whose content lives in sites you have already reviewed
  • Watch what the assistant surfaces during the pilot — it is an unusually effective way to find remaining permission problems
  • Expand only into areas that have had the same review

Licensing, Claims, and What This Guide Is Not

Microsoft's AI features, their names, their prerequisites, and their licensing terms change regularly, and what applies to one subscription may not apply to another. Treat the specifics as something to verify in Microsoft's current documentation and your own agreement at the time you make the decision.

This guide describes general administrative practice from an independent IT provider's perspective. We are not restating Microsoft's product terms, and we are not making any claim of partner status, certification, or authorization with Microsoft. Nor is a permissions review a compliance certification — it is a control that supports whatever obligations your organization already carries.

If you are earlier in the process, the AI readiness checklist covers the surrounding work, and the guide to business data and public AI tools covers what staff should keep out of services running outside your tenant.

// RELATED READING

Keep Going

// READINESS
A Practical AI Readiness Checklist
Ten things to work through before an AI tool touches company information — most of which have nothing to do with AI.
READ GUIDE >
// DATA GOVERNANCE
What Business Data Should Not Go Into a Public AI Tool
The categories to keep out, why editing the details out is unreliable, and what to do if something has already been shared.
READ GUIDE >
// CLOUD
Cloud Services & Microsoft 365
Day-to-day management of identity, access, and Microsoft 365 workloads for Upper Peninsula businesses.
EXPLORE SERVICE >

Want This Reviewed Before You Switch It On?

We can walk your tenant's sharing, membership, and identity settings and tell you what to fix first.

☎ (906) 662-4481FREE ASSESSMENT
// BEFORE YOU GO
Free Cybersecurity Checklist
A practical 19-point self-audit covering access, backups, endpoint security, staff training, and compliance — built specifically for UP businesses.
Check Your Email
Or download it directly here.
We use your email only to send the checklist and occasional GlobalTSS updates. Unsubscribe anytime. We never sell your information. See our Privacy Policy.
// quick_callback_request
Just your name and number — we will call you back during business hours (Mon–Fri 8am–5:30pm ET), normally within one business day.
// REQUEST_RECEIVED
We will call you back shortly.
Or call now: (906) 662-4481  ·  Privacy