Skip to main content

By Errin O'Connor, Founder & Chief AI Architect, EPC Group

Last updated: 2026 · Read time: ~8 min

Key Facts

  • Copilot grounds on Microsoft Graph — it returns content from every site, folder, and mailbox a user has access to, including sites they never knowingly visited.
  • Microsoft incident CW1226324 demonstrated that Teams Copilot could pull context from HR investigation channels, legal hold discussions, and executive compensation threads when users had overly broad access.
  • EPC Group finding: most enterprise tenants have 15+ years of accumulated oversharing — stale permissions, broken inheritance, and "Everyone except external users" links on sensitive document libraries.
  • EPC Group Copilot Safety Blueprint: full permission audit, sensitivity label deployment, Purview DLP for Copilot, Restricted SharePoint Search, phased rollout, and ongoing Power BI monitoring dashboards.
  • Executive compensation spreadsheets, M&A documents, and HR investigation files have appeared in Copilot responses within the first week of ungoverned deployments.

Microsoft Copilot Data Exposure Risks for Enterprise

By Errin O'Connor, Chief AI Architect at EPC Group  |  Published April 2026  |  Updated April 15, 2026

Microsoft 365 Copilot is the most powerful productivity tool Microsoft has ever shipped — and the most dangerous if your permissions model is broken. Here is what enterprises need to know before and after deployment.

Why Copilot Turns Oversharing into a Data Breach

Microsoft 365 Copilot does not bypass your security model. It respects every permission, conditional access policy, and sensitivity label already in place. That sounds reassuring until you realize that most enterprises have spent 15 years accumulating SharePoint sites, Teams channels, OneDrive folders, and Exchange distribution lists with permissions that were never audited and never revoked.

Before Copilot, oversharing was a potential risk. An employee could navigate to a SharePoint site with board meeting minutes, but they needed to know the URL, find the right library, and open the document. This friction provided control.

Copilot removes that friction completely. Now, a user can simply type “summarize the latest board discussion about layoffs.” Copilot will:

  • Fetch the document
  • Read it
  • Return a summary — all within seconds

All of this happens within the permissions the user technically had but never used.

This is not a bug; it is the intended design. Copilot shows information that users are allowed to access. However, the issue is that authorization was never meant to be this simple to use.

EPC Group has audited tenants and found that:

  • 40% of SharePoint sites were shared with “Everyone except external users.”
  • This setting is a default option that Microsoft made too easy to select during site creation.

The CW1226324 Incident: What Happened and What It Revealed

In January 2026, Microsoft acknowledged incident CW1226324 — a behavior where Copilot in Teams meetings was generating summaries from Teams channels the meeting participant had not explicitly joined. The root cause was inherited access through broad Microsoft 365 group memberships. When a user was a member of an M365 group, they technically had access to every Teams channel owned by that group, even channels they had never visited.

In practice, this meant that when Copilot summarized a meeting, it would pull context from all channels accessible to the user — including HR investigation channels, legal hold discussions, and executive compensation threads. Employees began receiving AI summaries that contained information they were never supposed to see.

Microsoft deployed a fix in February 2026 that scoped Copilot's context window to explicitly joined channels, but the damage was already done for early adopters. The incident exposed a fundamental truth: Copilot makes your permission model honest. If your permissions are sloppy, Copilot will expose that sloppiness at machine speed.

Organizations regulated under HIPAA, SOC 2, or GDPR face particular exposure. A Copilot summary that surfaces PHI to an unauthorized employee is a reportable breach under HIPAA, regardless of whether the user “technically” had SharePoint access. The Copilot deployment model must account for regulatory exposure, not just technical access.

The Five Attack Surfaces Copilot Exposes

1. SharePoint Sites with Inherited Permissions

SharePoint permission inheritance means a site shared with “Everyone except external users” propagates that access to every library, folder, and file within it. Copilot indexes all of it. The most common offenders are project sites created years ago, departmental sites with stale memberships, and migration artifacts from on-premises SharePoint that carried overshared permissions into SharePoint Online. EPC Group's SharePoint consulting practice regularly finds 200-400 overshared sites in a typical 5,000-seat tenant.

2. OneDrive Shared Folders

Users can share OneDrive folders using options like “Anyone with the link” or “People in your organization.” These sharing links remain active indefinitely unless an expiration policy is set. Copilot can access documents from these shared folders when responding to queries. A single shared folder that holds salary benchmarking spreadsheets, offer letters, or termination documents can become a liability once Copilot is in use.

3. Teams Channels with Broad Group Membership

Every Teams team is backed by a Microsoft 365 group. When that group has broad membership — common in “All Company” or “Department-Wide” teams — every member has access to every standard channel and its files. Private channels mitigate this, but most organizations have a mix of standard and private channels with no consistent policy on which topics belong where.

4. Exchange Shared Mailboxes and Distribution Lists

Copilot in Outlook can access shared mailboxes the user has “Full Access” permissions to. If your finance team's shared mailbox is accessible to a broad group, Copilot can summarize vendor invoices, wire transfer confirmations, and confidential correspondence from that mailbox.

5. Microsoft Graph API Connections

Copilot uses Microsoft Graph to aggregate context. Any Graph-connected application — Power Automate flows, Logic Apps, third-party connectors — that writes data into SharePoint or Teams makes that data accessible to Copilot. This creates indirect exposure paths that do not show up in a simple SharePoint permission audit.

How to Audit Permissions Before Copilot Deployment

A Copilot readiness audit is not optional — it is a prerequisite. Here is the framework EPC Group uses across our Microsoft 365 consulting engagements:

Phase 1: Discovery (Week 1-2)

  • Export all SharePoint site collections with sharing settings via SharePoint Admin Center and Graph API
  • Identify every site shared with “Everyone except external users” or “All Users”
  • Enumerate Teams channels and their backing M365 group memberships
  • Scan OneDrive for organization-wide sharing links older than 90 days
  • Map Exchange shared mailbox permissions across all departments

Phase 2: Classification (Week 3-4)

  • Deploy Microsoft Purview sensitivity labels: Public, Internal, Confidential, Highly Confidential
  • Use Purview auto-labeling policies to classify documents containing PII, PHI, financial data, and legal privilege markers
  • Identify high-risk sites: HR, Legal, Finance, Executive, M&A
  • Build a risk heat map showing exposure by department and data classification

Phase 3: Remediation (Week 4-6)

  • Replace “Everyone except external users” with scoped security groups on all identified sites
  • Enable SharePoint Access Reviews for site owners to validate membership quarterly
  • Configure Restricted SharePoint Search to limit Copilot indexing to approved sites during the rollout period
  • Deploy Purview DLP policies that prevent Copilot from surfacing “Highly Confidential” labeled content
  • Set OneDrive sharing link expiration to 30 days organization-wide

Purview DLP for AI: The Last Line of Defense

Microsoft Purview Data Loss Prevention now supports Copilot interactions as a monitored location. This means you can create DLP policies that specifically govern what Copilot can and cannot include in its responses. Here is how it works:

  • Sensitivity label-based blocking: Prevent Copilot from referencing any document labeled “Highly Confidential” or “Legal — Privileged”
  • Content-based detection: Block Copilot responses that contain Social Security numbers, credit card numbers, or medical record numbers regardless of labeling
  • User-scoped policies: Apply different DLP rules to different user groups — executives might have broader Copilot access than interns
  • Audit logging: Every Copilot interaction that triggers a DLP policy is logged in Purview Audit with the user, query, matched content, and action taken

The critical limitation: DLP only works on labeled content. If your documents are not classified with sensitivity labels, DLP has nothing to enforce. This is why Phase 2 of the audit — classification — is non-negotiable. Organizations using Power BI with Copilot should also apply sensitivity labels to Power BI semantic models and reports, as Copilot in Power BI can surface data from underlying datasets.

Restricted SharePoint Search: Controlling Copilot's Index

Restricted SharePoint Search (RSS) is a relatively new feature that lets administrators limit which SharePoint sites Copilot can index and search. Instead of Copilot searching all sites the user has access to, RSS creates an allowlist of approved sites. This is a powerful control during phased rollouts:

  • Start with only IT, Marketing, and Sales sites on the allowlist
  • Add departments to the allowlist only after their permissions have been audited and remediated
  • Keep HR, Legal, Finance, and Executive sites off the allowlist until sensitivity labels and DLP policies are fully deployed
  • Monitor Copilot usage logs to identify access pattern anomalies before expanding the allowlist

RSS is not a permanent solution — it is a phased deployment control that buys time while you fix the underlying permission model. The goal is to eventually remove RSS restrictions once all sites have proper permissions and labeling.

EPC Group's Copilot Safety Blueprint

The Copilot Safety Blueprint is a 6-week fixed-scope engagement designed for enterprises deploying Microsoft 365 Copilot. It is built on of since 1997 SharePoint governance and Microsoft 365 security experience across Fortune 500 and regulated industries.

What the Blueprint Delivers

  • Permission audit report: Every overshared site, team, and mailbox documented with risk rating
  • Sensitivity label taxonomy: Custom label hierarchy aligned to your data classification policy
  • DLP policy set: Pre-configured Purview DLP policies for Copilot interactions
  • Restricted Search configuration: Allowlist-based Copilot deployment with department-by-department expansion plan
  • Phased rollout plan: 90-day deployment schedule starting with low-risk groups
  • Power BI monitoring dashboard: Real-time visibility into Copilot usage, DLP triggers, and access pattern anomalies
  • Quarterly review cadence: Ongoing governance model with access review automation

Organizations in healthcare, financial services, and government face additional requirements — HIPAA Business Associate Agreements, SOC 2 audit trail requirements, and FedRAMP boundary considerations. EPC Group's Azure and compliance consulting team customizes the Blueprint for each regulatory context.

What to Do If You Already Deployed Copilot Without Auditing

If Copilot is already live in your tenant and you skipped the permission audit — you are not alone. Microsoft's aggressive Go licensing and Sales push has led many organizations to deploy Copilot on top of a permission model that was never designed for AI-powered search. Here is the emergency remediation path:

  1. Enable Restricted SharePoint Search immediately. Set the allowlist to only your most well-governed sites. This limits Copilot's scope while you fix everything else.
  2. Pull Copilot audit logs from Purview. Review what Copilot has accessed in the last 30 days. Look for access to HR, Legal, Finance, and Executive sites by users outside those departments.
  3. Run a SharePoint oversharing scan. Use the SharePoint Admin Center “Site sharing” report to identify all sites with organization-wide sharing.
  4. Deploy sensitivity labels on high-risk libraries first. Do not try to label everything — start with the top 20 sites by risk rating and expand from there.
  5. Brief your CISO and legal team. If Copilot surfaced regulated data (PHI, PII, financial records) to unauthorized users, you may have notification obligations.

Frequently Asked Questions

What is the biggest data exposure risk with Microsoft Copilot?

The biggest risk is overshared SharePoint sites and OneDrive folders. Copilot respects existing Microsoft 365 permissions, so if a SharePoint site containing executive compensation data is shared with 'Everyone except external users,' Copilot will surface that data to any employee who asks. Most organizations have hundreds of overshared sites they have never audited. Copilot does not create new access — it makes existing oversharing visible and exploitable at scale.

What was the CW1226324 Copilot incident in January 2026?

CW1226324 was a Microsoft-acknowledged issue where Copilot in Teams meetings was summarizing content from channels the user had not joined but had inherited access to through broad Microsoft 365 group memberships. This meant employees received AI-generated summaries of HR disciplinary discussions, M&A planning threads, and legal hold conversations they were never intended to see. Microsoft patched the behavior in February 2026, but organizations that had not scoped group memberships were already exposed.

How do you audit permissions before deploying Copilot?

EPC Group runs a 3-phase Copilot Readiness Audit: Phase 1 scans all SharePoint sites, Teams, and Microsoft 365 groups for oversharing using Microsoft Graph API and SharePoint Access Reviews. Phase 2 classifies sensitive content with Microsoft Purview sensitivity labels — financial data, PII, PHI, legal privilege. Phase 3 remediates by breaking inheritance on overshared sites, replacing 'Everyone except external users' with scoped security groups, and enabling Restricted SharePoint Search to limit Copilot's indexing scope. This typically takes 4-6 weeks for a 5,000-seat tenant.

Can Microsoft Purview DLP protect against Copilot data exposure?

Yes, but only if properly configured. Purview DLP policies can block Copilot from surfacing content with specific sensitivity labels — for example, preventing Copilot from including 'Highly Confidential' labeled documents in its responses. You need Purview Information Protection to apply sensitivity labels, Purview DLP to enforce policies on Copilot interactions, and Purview Audit to log what Copilot accesses. Most organizations we assess have Purview licensed but fewer than 20% of sensitive documents actually labeled, which means DLP policies have no effect on unlabeled content.

What is the Copilot Safety Blueprint from EPC Group?

The Copilot Safety Blueprint is EPC Group's 6-week engagement that prepares an enterprise for safe Copilot deployment. It includes a full SharePoint and OneDrive permission audit, sensitivity label deployment across all document libraries, Purview DLP policy configuration for Copilot, Restricted SharePoint Search setup, a phased rollout plan starting with low-risk departments, and ongoing monitoring dashboards in Power BI that track what Copilot accesses. The deliverable is a documented, auditable state where every Copilot interaction respects least-privilege access.

Get the Copilot Safety Blueprint

EPC Group's 6-week Copilot Safety Blueprint ensures your enterprise deploys Microsoft 365 Copilot without exposing sensitive data. Permission audit, sensitivity labels, DLP policies, and phased rollout — all documented and auditable.

Call (888) 381-9725 or schedule a consultation below.

Schedule a Copilot Safety Assessment

Ready to get started?

EPC Group has completed over 10,000 implementations across Power BI, Microsoft Fabric, SharePoint, Azure, Microsoft 365, and Copilot. Let's talk about your project.

contact@epcgroup.net(888) 381-9725www.epcgroup.net
Schedule a Free Consultation

Microsoft Copilot Data Exposure Risks for Enterprise

Last updated: 2026 · Read time: ~8 min

Microsoft Copilot surfaces all content a user can access via Microsoft Graph — including content they forgot they had access to. After 15+ years of ungoverned SharePoint and OneDrive permissions, most enterprise tenants have significant oversharing exposure. This guide explains the data exposure vectors, the CW1226324 incident, and EPC Group's Copilot Safety Blueprint for remediation.

Key facts

  • Copilot grounds on Microsoft Graph — it returns content from every site, folder, and mailbox a user has access to, including sites they never knowingly visited.
  • Microsoft incident CW1226324 demonstrated that Teams Copilot could pull context from HR investigation channels, legal hold discussions, and executive compensation threads when users had overly broad access.
  • EPC Group finding: most enterprise tenants have 15+ years of accumulated oversharing — stale permissions, broken inheritance, and "Everyone except external users" links on sensitive document libraries.
  • EPC Group Copilot Safety Blueprint: full permission audit, sensitivity label deployment, Purview DLP for Copilot, Restricted SharePoint Search, phased rollout, and ongoing Power BI monitoring dashboards.
  • Executive compensation spreadsheets, M&A documents, and HR investigation files have appeared in Copilot responses within the first week of ungoverned deployments.

How Copilot exposes data

Copilot does not invent data. It retrieves it from Microsoft Graph. If a user has permission to access a document, Copilot can return that document's content in a response — even if the user never knew the document existed.

This is not a Copilot bug. It is a permissions problem. Copilot simply makes existing permission misconfigurations visible at AI speed and scale.

The three most common exposure vectors:

  • "Everyone except external users" sharing links on sensitive libraries — gives every employee Copilot-surfaceable access to confidential content. Common on SharePoint sites created 5–10 years ago before governance controls existed.
  • Stale project site memberships — former team members retain access years after a project ended. Copilot can surface project M&A files, HR data, or board materials to users who should no longer have access.
  • Broken permission inheritance on subsites — permissions were customized at subsite level and never audited. Copilot returns content from the subsite to users who have subsite access but not parent-site access awareness.

The CW1226324 incident

Microsoft incident CW1226324 is the documented example of Copilot data exposure at scale. When Copilot summarized a meeting in Teams, it pulled context from all channels accessible to the user. This included:

  • HR investigation channels.
  • Legal hold discussion threads.
  • Executive compensation threads.

Users with broad Teams membership received meeting summaries containing information they were technically permitted to access — but had no legitimate need to see.

The incident highlighted the core risk: Copilot does not distinguish between "access the user should have" and "access the user technically has." Every stale group membership and broken permission chain becomes a Copilot exposure vector.

Why 15 years of permissions is the real problem

Most enterprises have spent 15 years accumulating SharePoint sites, Teams channels, OneDrive folders, and Exchange distribution lists. Permissions were set when content was created. They were rarely audited or revoked.

A user types "summarize the latest board discussion about layoffs." Copilot fetches the document, reads it, and returns a summary — all within seconds. All within permissions the user technically had but never exercised.

This scenario repeats across thousands of sensitive documents in an unaudited enterprise tenant.

EPC Group Copilot Safety Blueprint

EPC Group's Copilot Safety Blueprint prepares your tenant for Copilot deployment without data exposure events. It covers six components:

  • Full SharePoint and OneDrive permission audit — per-user oversharing exposure quantification. Identifies every "Everyone except external users" link, stale member, and broken inheritance chain.
  • Sensitivity label deployment — across all document libraries. Labels control what Copilot can surface. Without labels, all content is treated as unclassified and accessible.
  • Purview DLP policy configuration for Copilot — DLP policies scoped to Copilot interactions prevent Copilot from surfacing content that violates DLP rules.
  • Restricted SharePoint Search setup — limits Copilot's indexing to a curated list of governed sites. All other sites are excluded from Copilot queries.
  • Phased rollout plan — starts with low-risk departments with clean governance. Expands as governance improves.
  • Ongoing Power BI monitoring dashboards — tracks what Copilot accesses, sensitivity label coverage trends, and oversharing exposure score over time.

Consequences of ungoverned Copilot deployment

  1. Data exposure events — executive compensation spreadsheets, M&A documents, and HR investigation files appear in Copilot responses within the first week. This has happened at EPC Group client sites during initial assessment phases.
  2. Compliance violations — regulated industries (HIPAA, SOC 2, GDPR) face audit findings when AI tools access and surface data without proper controls.
  3. Trust collapse — when leadership discovers the exposure risk, they pull Copilot entirely. License investment is lost. Organizational AI skepticism takes years to overcome.

Retroactive governance is expensive

Remediating governance after Copilot is live costs 2–3× more than doing it before deployment:

  • Immediate permissions audit and remediation on an urgent timeline (2–3× cost vs. planned remediation).
  • Sensitivity label rollout while Copilot is live — risk of users encountering label changes mid-workflow.
  • DLP policy rollout that may interrupt ongoing business processes.
  • User trust re-establishment after a publicized data exposure event.

The cost of proactive governance: scoped after discovery. The cost of retroactive governance: $150,000–$450,000 plus regulatory and reputational exposure.

Frequently asked questions

How does Copilot expose sensitive data?

Copilot retrieves content from Microsoft Graph based on user permissions. If permissions are too broad, such as stale memberships, "Everyone" sharing links, or broken inheritance, Copilot can return confidential content in its responses. It does not bypass permissions; rather, it reveals permissions that were already too broad.

What is the CW1226324 incident?

A documented Microsoft incident where Teams Copilot pulled context from HR investigation channels, legal hold discussions, and executive compensation threads during meeting summarization — because the user had broad Teams channel membership and therefore broad Graph access. It demonstrated the scale of Copilot's data retrieval capability when permissions are ungoverned.

How do I prevent Copilot data exposure?

Four controls: enable Restricted SharePoint Search to limit Copilot's indexable sites, deploy sensitivity labels with 80%+ coverage, run a full permissions audit and remediate "Everyone" links and stale memberships, and configure Purview DLP policies scoped to Copilot interactions.

Is this a Copilot bug or a permissions problem?

It is a permissions problem. Copilot works as intended by returning content that the user can access. However, most enterprise tenants have built up 10–15 years of unmanaged permissions. Copilot highlights these permission gaps instantly and at AI scale.

What is Restricted SharePoint Search?

Restricted SharePoint Search (RSS) limits the SharePoint sites Copilot can index for each user. With RSS enabled, Copilot only queries sites on an admin-curated allowed list. All other sites are excluded from Copilot results — even if the user technically has access to them.

Get a Copilot Safety Assessment

EPC Group delivers a 2-week Copilot Safety Assessment covering all six Blueprint components. Call (888) 381-9725 or request a discovery call.

AI assistant — not human