Skip to main content
Valto — Keep ahead of tomorrow

Video

How to secure SharePoint data before deploying Microsoft Copilot

Duration
10:36
Overview

Concerned about Microsoft Copilot accessing sensitive SharePoint data?

Microsoft Copilot only surfaces information that users already have permission to access, but that can expose hidden risks within overshared SharePoint sites. In this video, Will Jones (Valto M365 Consultant) explores how SharePoint Advanced Management helps organisations identify overshared content, review permissions, and strengthen governance before rolling out Copilot across Microsoft 365. You'll see a live demonstration showing how a confidential file can be surfaced through Copilot when SharePoint permissions are configured incorrectly. We then walk through the reporting, governance, and access control features available within SharePoint Advanced Management, including Data Access Governance and Site-Level Access Restrictions, to help reduce the risk of sensitive information being exposed.

What we cover

Chapters

  1. 1

    Introduction to Microsoft Copilot and data security concerns

    Understand why Copilot often highlights existing permission and sharing issues within Microsoft 365, and why data governance should be part of every Copilot rollout.

  2. 2

    Exploring SharePoint Advanced Management for overshared content

    Learn how SharePoint Advanced Management can identify overshared content, review permissions, detect governance issues, and provide visibility into data access across your organisation.

  3. 3

    Demonstration of Copilot accessing sensitive information

    Watch a practical example of how a user can retrieve confidential information through Copilot when SharePoint permissions have not been correctly managed.

  4. 4

    Securing SharePoint Access with Advanced Management Controls

    Discover how site-level access restrictions and governance tools can help lock down sensitive content and prevent Copilot from surfacing information to unauthorised users.

Man at a desk on a computer

Explore our solutions

Explore Valto's Microsoft solutions, from Copilot to SharePoint

Successful Copilot adoption starts with the right foundations. At Valto, we help organisations assess Microsoft 365 permissions, improve governance, secure SharePoint environments, and prepare for Microsoft Copilot deployments. From readiness assessments and governance reviews to implementation, training, and adoption support, our team can help you deploy Copilot securely and confidently.

What we do

Questions, plainly answered

If you enjoyed this video, these follow-up questions might help.

SharePoint Advanced Management is a Microsoft governance and security solution that provides enhanced visibility, reporting, and access controls to help organisations manage content and permissions across SharePoint.
Copilot only accesses content that a user already has permission to view. If SharePoint permissions are overly broad or content has been overshared, Copilot may surface that information in response to user prompts.
SharePoint Advanced Management includes reporting tools that help identify files, sites, and permissions that could expose sensitive information to a wider audience than intended.
Site-Level Access Restrictions allow organisations to limit access to specific SharePoint sites to approved users or groups, regardless of historical sharing activity or inherited permissions.
No. Microsoft Copilot respects the same permissions model as Microsoft 365. Users can only retrieve content that they are already authorised to access.
Yes. Reviewing permissions, sharing practices, and governance controls before deployment can help reduce the risk of sensitive information being surfaced through Copilot.
Valto can help assess your Microsoft 365 environment, review SharePoint permissions, implement governance controls, and support a secure and successful Microsoft Copilot rollout.

Ready to deploy Microsoft Copilot securely?

Before rolling out Microsoft Copilot, make sure your SharePoint permissions and governance controls are ready. Our specialists can help you identify overshared content, reduce security risks, and build a secure foundation for Copilot adoption across your organisation. Get in touch with Valto to start your Copilot readiness journey.

Video transcript

Will (00:00)

Hi everyone, and welcome to today’s video.

One of the biggest concerns we hear when speaking to organisations that are starting to explore Microsoft Copilot is data security.

It’s not because Copilot is insecure. Instead, Copilot often shines a light on the permissions and sharing practices that already exist across Microsoft 365.

In today’s video, I’m going to show you how SharePoint Advanced Management can help you identify overshared content, clean up inactive or abandoned sites, review access, and ultimately put the right guardrails in place before rolling Copilot out at scale.

If you’re worried that Copilot might expose information that it shouldn’t, this is probably where the conversation should start.

On the screen, I’m going to walk through a quick demonstration.

If we open our demo site and go into Documents, we’ll see a folder called Pay Slips – Confidential.

Inside this folder is a payslip for Bobby. This is sample data that has been created purely for demonstration purposes.

If we check the site permissions, we’ll notice that Everyone Except External Users has been added to the site.

Even if you haven’t been granted access through a specific group or department, adding this permission means you’ll be able to access all of the data within the site.

If another user can access the site, then Copilot can access that information on their behalf as well.

This permission may have been added by mistake, or by someone who wasn’t fully familiar with SharePoint permissions.

We see this quite often. Sites are configured with Everyone Except External Users, which may not seem like a problem until Copilot is introduced.

With Copilot, users can find information through natural language prompts without needing to know the site URL or where the file is stored.

What we’re going to do now is log in as Carl.

This is a standard user account.

We can see that Carl has now signed in to Copilot.

I’m going to ask Copilot to retrieve Bobby’s payslip.

Let’s give it a moment and see what it returns.

There we go.

Straight away, Copilot has returned a PDF and a direct link to Bobby’s payslip.

If I open the file, you’ll be able to see the payslip. Remember, this is demonstration data only.

I’ve managed to retrieve the information and access the file directly.


Will (03:01)

So, what can we do to prevent this type of data exposure across confidential documents?

Let’s log back in as an administrator.

If we open the SharePoint Admin Center, once SharePoint Advanced Management has been enabled, you’ll notice a new section appears with a Pro icon next to it.

From here, we can generate various reports showing site activity, sites that may be missing owners, broken permission inheritance, unusual site permissions across the organisation, and sharing activity.

It’s important to understand that site permissions and sharing permissions aren’t always the same thing.

A site may have appropriate permissions configured, but if sharing is enabled broadly, users may still be able to send files internally or externally.

As a result, sensitive information could still be exposed.

You’ll also find resources explaining how to improve governance, detect inactive sites, and prepare your environment for Microsoft Copilot.

These are all useful resources to review.

On the left-hand side, if we select Data Access Governance, we can generate additional reports using SharePoint Advanced Management.

We can review permissions across the organisation, see which sensitivity labels have been applied to files, analyse sharing links, and generate reports showing files that have been shared with Everyone Except External Users.

That’s exactly the situation we’ve created in this demonstration.

If we select Access Control under Policies, you’ll see another feature that becomes available after enabling SharePoint Advanced Management.

It also has a Pro icon, indicating that it’s an advanced feature rather than standard SharePoint functionality.

The feature is called Site-Level Access Restrictions.

I’ve already enabled it as part of this demonstration.

Although it’s disabled by default, enabling it provides additional controls that help secure older sites that may have inherited permissions, sharing links, or access settings over time.

Without regular governance, these sites can become difficult to manage.

If you’re unaware of what’s happening inside them, Copilot could potentially surface confidential information stored there.

Let’s enable the feature and navigate to Active Sites.

We’ll locate our demo site and open it.

If we go to Settings, we’ll see some additional options marked with the Pro icon.

We’re going to look at Restrict Site Access.

If we select Edit, we can choose to restrict SharePoint site access to specific users or groups.

For this example, I’ll add the Engineering group.

Carl is not a member of that group.

Once applied, anyone who isn’t a member of Engineering will lose access to the site.

It doesn’t matter whether files were previously shared, whether historic permissions existed, or whether the user had access in the past.

If they are not a member of the specified group, they can no longer access the content within that SharePoint site.

I’ll save the setting.

The site has now been configured so that only Engineering users can access the information stored within it.

We’re now going to log back in as Carl and perform the same search to see what Copilot can find.


Will (07:34)

We’ve logged back into Copilot as Carl.

Now we’re going to see whether Copilot can retrieve Bobby’s payslip again.

Let’s give it a moment.

There we go.

Copilot has searched accessible SharePoint files and returned no results.

If a document exists within a SharePoint library that is protected using SharePoint Advanced Management or restricted permissions, it may no longer appear in search results.

That means Copilot can no longer retrieve the information.

If you’re familiar with SharePoint, you might think this isn’t new because SharePoint permissions can already be managed through groups.

The difference is that this feature overrides permissions that may already exist on individual files or folders within the site.

If files have been shared internally or externally over time, it can be difficult to know exactly who has access to what.

Unless you inspect every document individually, it’s often impossible to identify all of those permissions.

This approach provides an additional layer of security on top of traditional SharePoint permissions.

Even if someone had access previously, enabling these advanced management controls can remove that access.

As a result, Copilot will no longer be able to return content from that site.

I’m not suggesting this approach should be used for every SharePoint site.

However, I do think there’s a strong case for using it on finance sites and other locations that contain sensitive or confidential information.

I would definitely recommend exploring SharePoint Advanced Management further.

You can start by enabling a trial and reviewing the reports available within SharePoint.

You can also experiment with some of the security controls and access restriction features that become available once the trial is enabled.

If you have any questions, or would like to learn more about how SharePoint Advanced Management can help protect your data and reduce the risk of exposing confidential information through Microsoft Copilot, please get in touch with Valto.

We’d be happy to arrange a consultation to discuss your requirements.

Thank you for watching. I hope you found this useful, and I’ll see you in the next video.

Share this

More like this