An AI assistant that works inside your Microsoft 365 environment is, from an access standpoint, a very fast colleague. Microsoft's published documentation describes Microsoft 365 Copilot as returning only content that the signed-in user already has permission to access, and as inheriting the tenant's existing identity, access, and compliance controls. That is Microsoft's own description of its product; confirm the current wording, the behavior, and the terms that apply to your licence in Microsoft's documentation and your agreement before relying on any summary, including this one.
Taken at face value, that design has an uncomfortable implication for most organizations. Permissions that were technically open but practically obscure — a finance folder shared with the whole company in 2019, a site nobody remembers owning — stop being obscure. Anything a user could have found by searching hard, an assistant can surface by being asked a plain question. The access review below is worth doing regardless. If an assistant is coming, it should happen first.
1. Sharing Links and Their Defaults
Sharing links are the most common source of unintended access, because they are created one at a time by people trying to be helpful.
- Check the tenant's default link type — whether a new link defaults to anyone with the link, everyone in the organization, or only specific people
- Review whether anonymous links are permitted at all, and whether they expire
- Look for links created for a one-off share that have been live for years
- Decide whether link expiration and permission defaults should differ for sensitive sites
2. SharePoint Site Membership and Sprawl
Sites accumulate. Each one created for a project, a committee, or a customer keeps its membership after the reason for it ends.
- Produce a list of sites with an identified owner; anything without one needs an owner or an archive decision
- Review membership on sites holding finance, HR, legal, or customer-confidential material
- Look specifically for broad grants such as an everyone-in-the-organization group applied to a site that should be restricted
- Check permission inheritance that has been broken at folder or item level — those exceptions are where surprises live
3. OneDrive Used as a Shared Drive
Personal storage frequently becomes the real home of a business process. That is a resilience problem before it is an AI problem.
- Identify business-critical content sitting in individual OneDrive accounts and move it to a site with an owner
- Review the OneDrive content of departed employees, and the retention decision attached to it
- Look for personal drives shared broadly across the organization
4. Teams, Channels, and Guests
Teams membership carries file access, because the files live in an underlying SharePoint site.
- Review membership of teams that handle sensitive work, including standard channels visible to every team member
- Check private and shared channel membership separately — they do not always match the parent team
- Enumerate guest accounts: who invited them, for what, and whether that work has ended
- Confirm what guests can see beyond the single channel they were invited to
5. Mailboxes, Calendars, and Delegation
- Review shared mailbox membership and full-access delegation, including permissions granted temporarily years ago
- Check calendar sharing defaults, particularly where calendar detail reveals client names or matters
- Confirm that mailboxes of departed staff are handled deliberately — converted, delegated, or retained under policy, not left licensed and reachable
6. Identity Hygiene and Administrative Roles
Access review is wasted effort if the accounts themselves are not in order.
- Enforce multi-factor authentication, and confirm there are no standing exclusions nobody remembers creating
- Review who holds global administrator and other privileged roles, and reduce to the minimum
- Separate administrative accounts from the accounts used for daily email and documents
- Disable accounts for departed staff promptly, and check for licensed-but-unused accounts
- Inventory service accounts and application permissions granted to third-party apps — consent granted by users is easy to miss
7. Information Architecture and Retention
An assistant is only as accurate as the content it draws on, and it does not know which document was superseded.
- Archive superseded policies, price lists, and procedures out of locations that are actively searched
- Establish one identifiable current version of the documents people ask about most
- Review retention settings so that content no longer needed is not sitting indefinitely in a searchable location
- Where sensitivity labelling is in use, check what remains unlabelled rather than assuming coverage
8. Sequence the Work
A full tenant remediation before anyone sees a benefit is a project that stalls. A workable order:
- Inventory sites, guests, and privileged accounts, and fix the worst sharing exposure first
- Pilot with a small group whose content lives in sites you have already reviewed
- Watch what the assistant surfaces during the pilot — it is an unusually effective way to find remaining permission problems
- Expand only into areas that have had the same review
Licensing, Claims, and What This Guide Is Not
Microsoft's AI features, their names, their prerequisites, and their licensing terms change regularly, and what applies to one subscription may not apply to another. Treat the specifics as something to verify in Microsoft's current documentation and your own agreement at the time you make the decision.
This guide describes general administrative practice from an independent IT provider's perspective. We are not restating Microsoft's product terms, and we are not making any claim of partner status, certification, or authorization with Microsoft. Nor is a permissions review a compliance certification — it is a control that supports whatever obligations your organization already carries.
If you are earlier in the process, the AI readiness checklist covers the surrounding work, and the guide to business data and public AI tools covers what staff should keep out of services running outside your tenant.