Skip to content
Pro IT NW

Blog · 16 min read ·

Share

Copilot Governance, One Year On: a Tenant-Sprawl Reckoning

CMMC Phase 2's Nov 10, 2026 C3PAO mandate was suspended July 2026 — self-attestation still binds, with no assessor checking it. SOC 2 Type II auditors now ask about AI data access. Copilot prompts leave a queryable audit trail your auditor will pull.

A year ago we wrote about the 12,000-permission problem and warned that mid-market shops needed to clean up SharePoint and OneDrive permissions before turning Copilot on. A meaningful chunk of readers did the work. A larger chunk filed the post under "we'll worry about it later" and shipped Copilot anyway. One year later, in 2026, the consequences for the second group have a recognisable shape.

Correction — September 13, 2026: an earlier version of this post's FAQ and a section heading below asked whether tenants needed to "re-permission 12,000 sites manually." There is no source for a figure of 12,000 sites. The sourced number — Varonis's 2024 study of 717 organizations — is 12,000+ Microsoft 365 sharing links open to every employee, not a site count. The wording below has been corrected to talk about sharing links, which is also the fix the four-control playbook in this post actually targets.

Three exposure patterns recur, and none of them is a Copilot bug. HR compensation content surfacing in a benefits query — an unlabeled salary or performance file sitting in a library that "everyone except external users" can read. Finance forecasts surfacing in a "summarize this folder" prompt issued by someone with no business reading them, because the folder's permissions were never narrowed after the planning cycle ended. M&A or legal working files appearing in a project-team chat because a site nobody remembered restricting inherited its permissions from a parent collection several migrations ago. In every case the access already existed; Copilot only made it legible.

The good news is that Microsoft's governance toolset shipped a generation of capability between mid-2025 and Q1 2026 that didn't exist when the original post ran. Restricted SharePoint Search, Purview Data Security Posture Management (DSPM) for AI, SharePoint Advanced Management oversharing reports, and the Purview AI Hub are now real. The remediation playbook is correspondingly different. This post is the 2026 follow-up: the 90-day sequence, the four controls it rests on, and the order to do them in.

The one-year reckoning

The shops that ignored the 2025 warning fall into three clusters in 2026. The first is the "no incident yet, but the auditor is asking" cluster. Their SOC 2 Type II renewal questionnaire added a section on AI data access controls. Their HIPAA risk assessor wants to know how Copilot prompts are logged. Their cyber insurance renewal added an AI exclusion that doesn't apply if controls are documented. They're not bleeding; they're on the clock.

The second cluster is the "small incident, big quiet" group. A Copilot prompt surfaced something it shouldn't. Someone in HR or legal noticed. There's no breach notification obligation (the data didn't leave the tenant) but there's an internal trust problem and a CIO who's now nervous about the next prompt. The remediation budget is unlocked but the political capital is thin.

The third cluster is the "we shut Copilot off" group. After an incident or a near-miss, the company revoked licenses across the board. The licenses are still being paid. The Copilot rollout is on the executive team's list of failed initiatives. The CIO needs a path back to "on" without re-litigating the original decision.

All three clusters share the same underlying remediation. The difference is how much political surface area is left to operate in.

The mental model update for 2026: Copilot didn't create the oversharing. Copilot made the oversharing legible to users who would never have found it through SharePoint search. The remediation is permission and label hygiene at mid-market scale, not a Copilot configuration change.

Why tenant sprawl was the upstream cause

Permission rot in 2026 mid-market SharePoint estates is overwhelmingly the residue of migrations done between 2017 and 2022. The pattern looks like this. A file server got lifted to SharePoint with inherited NTFS-style permissions translated mechanically into SharePoint groups. An M365 Group was created for every Teams channel spun up during the 2020 to 2021 remote-work surge, with no naming convention and no owner lifecycle. OneDrive "share with anyone in the company" became the default workaround when permissions broke. Ex-employee personal folders accumulated, often containing the only copy of a working document that the team forgot to migrate.

None of that is a Copilot problem. It's a "we did the migration but we didn't do the cleanup" problem. The failure mode in 2025 was that everyone knew the cleanup was overdue and nobody had the budget or political will to do it as a standalone project. The failure mode in 2026 is that the auditor and the AI now both have visibility into it.

What Microsoft actually shipped between mid-2025 and early 2026

Four capabilities matured to the point of being useful in mid-market budgets. They overlap in coverage but each answers a different question.

Restricted SharePoint Search

The most useful immediate control. Restricted SharePoint Search lets a SharePoint admin define an allowed list of up to 100 sites (hub sites count as one and pull their subsites for free) that are visible to organization-wide search and to Copilot grounding. Sites outside the list still exist; users with explicit permissions can still access them directly. They're just excluded from search and Copilot's "what does my organization know about X" pattern. Microsoft positions it as a temporary measure while permissions get rationalized. In practice, "temporary" runs six to nine months for a mid-market shop, which is the right amount of time to do the cleanup properly.

Microsoft Purview DSPM for AI

Data Security Posture Management for AI is the continuous-monitoring layer. It runs an automated weekly data risk assessment on the top 100 SharePoint sites by usage in the tenant, surfaces oversharing patterns, and flags prompt-and-response activity where Copilot touched labeled or sensitive content. Critically, DSPM for AI is bundled into Microsoft 365 E5, which means most mid-market shops with Copilot deployed already have the license entitlement.

SharePoint Advanced Management

SharePoint Advanced Management (SAM) is the admin reporting layer. The data access governance (DAG) reports are the part that matters for Copilot prep: permission state reports across sites and OneDrive, sharing-link reports identifying the sites with the most freshly created Anyone or company-wide links, and the "Shared with Everyone except external users" report that catches the broad-internal-exposure pattern that drives most Copilot incidents. SAM ships included with Microsoft 365 Copilot licenses and is available as a standalone SKU otherwise.

Sensitivity labels with Copilot integration

Purview sensitivity labels aren't new, but the Copilot integration matured significantly. Copilot now displays sensitivity labels for citations in its responses, inherits the highest-priority label from grounding data, and refuses to summarize encrypted content unless the requesting user has EXTRACT and VIEW usage rights. One caveat that bites mid-market shops: labels applied to containers (groups and sites) are not inherited by items inside the container. That means a "Confidential" label on a SharePoint site doesn't propagate to the documents in it. Auto-labeling rules at the content level are still required for actual document-level protection.

The Purview AI Hub

The Purview AI Hub aggregates the auditing surface. Copilot prompts and responses are captured in the unified audit log, accessible through Activity Explorer in DSPM for AI, with role-based access controls that separate "see that a prompt happened" from "read the prompt content." The hub also surfaces ready-to-use DLP policies for the Copilot location, which is the surface where a prompt is treated as a potential exfiltration channel.

The 90-day remediation playbook

This is the version we run for mid-market clients in the 200 to 2,000 seat band. Four controls, not 40. No enterprise overhead. Designed to be done by a 200-seat IT team with senior consulting support, not by a standalone CISO office with 12 analysts.

Weeks 1 to 2: Inventory and triage

  1. Run the SAM data access governance reports across the tenant. Pull the "Shared with Everyone except external users" report, the sharing-links report, and the permission state report.
  2. Inventory M365 groups with external members and active guest accounts. Cross-reference against last sign-in.
  3. Pull the top 100 sites by usage from the SharePoint admin center. This is the cohort DSPM for AI will auto-assess weekly; the cleanup priority follows that list.
  4. Identify the top 20 highest-risk sites by combining usage, permission breadth, and presence of obviously sensitive content categories (HR, finance, legal, M&A, intellectual property).

Weeks 3 to 4: Quarantine

Configure Restricted SharePoint Search with an initial allowed list of sites that have been validated as safe for Copilot grounding. The top 20 high-risk sites identified in weeks 1 to 2 stay off the allowed list during remediation. Communicate the change to site owners and the executive sponsor before activation so that the Copilot user base understands why certain queries are returning narrower results.

Weeks 5 to 8: Label the sensitive five

Deploy Purview sensitivity labels for the top five content categories. The list is consistent across most mid-market clients: HR (compensation, performance, severance), finance (forecasts, board materials), legal (contracts, litigation hold), M&A (working files, term sheets), and intellectual property (product roadmap, customer lists, source assets). Use auto-labeling rules where the content matches durable signals (file names with "salary," presence of compensation numeric patterns, files in known HR libraries) and manual labeling for the rest.

Update — August 2026: the throughput ceiling that shapes this phase is being raised. Microsoft's public roadmap item 567890 states that it is "increasing the maximum auto-labeling capacity for SharePoint and OneDrive from 100,000 up to 500,000 files per tenant per day." Status is In development, with preview in September 2026 and general availability in October 2026, Worldwide (Standard Multi-Tenant).

Why it matters to the sequence above rather than as a headline: on a tenant with millions of documents, the 100,000/day ceiling is what turns an auto-labeling backfill into a multi-week background job you have to plan around. A 5x increase changes the shape of the plan, not the plan itself — you still design the label taxonomy first, and the rules are still only as good as the signals they key on. ⚠️ Treat the dates as roadmap dates: the item is In development, and roadmap targets move.

Weeks 9 to 12: Monitor and retrain

Enable Purview DSPM for AI in full collection mode. Configure DLP policies for the Microsoft 365 Copilot location to flag prompts that touch labeled-sensitive content. Build a query-pattern review cadence (weekly for the first 60 days, monthly thereafter). Retrain Copilot users on what the labels mean and how to respond when Copilot returns a labeled citation. Move quarantined sites off Restricted SharePoint Search's exclusion list as their permissions are rationalized.

The four-control summary table

Control What it does Where it lives License entitlement
Restricted SharePoint Search 100-site allowed list that bounds Copilot grounding while permissions get cleaned up SharePoint admin center Bundled with M365 Copilot
SAM oversharing reports Identifies the 20 to 50 sites that drive most of the oversharing risk SharePoint Advanced Management Bundled with M365 Copilot or standalone SKU
Purview sensitivity labels + auto-labeling Document-level classification on the top five sensitive content categories Microsoft Purview portal Microsoft 365 E5 / E5 Compliance
Purview DSPM for AI Weekly automated risk assessment + Copilot prompt audit trail Microsoft Purview portal (DSPM for AI) Microsoft 365 E5 / E5 Compliance

A worked reference scenario: the CUI/ITAR variant

A worked scenario, not an account of a customer — the shape this takes in a defense-supply-chain tenant running Microsoft 365 GCC High with Copilot enabled for a pilot group rather than the whole seat count. The triggering event is almost always mundane. A compliance officer types a procurement-related question into Copilot during an internal audit and gets back a summary containing unredacted contract values from a supplier negotiation that was supposed to be restricted to the procurement team. The site holding those contracts turns out to be a late-2010s SharePoint library migrated off a file server with inherited "domain users read" permissions, where the inheritance was never broken.

A six-week remediation on that finding sequences like this. Week 1 — run the SAM data access governance reports and expect the offending library to come back with a dozen or more siblings sharing the same inheritance pattern; one bad migration rarely produces one bad site. Weeks 2 to 3 — put that whole cohort outside the Restricted SharePoint Search allowed list, so Copilot stops grounding against them while the permissions are rationalised. Weeks 3 to 5 — apply Purview sensitivity labels to the export-controlled content categories, with auto-labeling rules keyed to ITAR designators in file names and document properties rather than relying on anyone to label by hand. Week 6 — enable DSPM for AI with a weekly review cadence, so the next inheritance surprise surfaces as a signal rather than as an audit finding.

What that sequence is designed to achieve: Copilot stays on for the pilot group instead of being switched off under pressure, and the audit finding closes against a documented remediation plan rather than a promise. The durable win is the last one — a compliance officer who can demonstrate continuous monitoring to a third-party assessor on demand, instead of re-running a manual permission audit every time someone asks. Note what this cannot promise: controls reduce the likelihood of re-exposure and make it detectable when it happens. Nobody should represent, about their own tenant or anyone else's, that re-exposure will not occur.

What not to do

Don't disable Copilot

The political cost of an executive-visible Copilot rollback is worse than the original incident in most mid-market shops. Once licenses are revoked, getting them re-issued requires the same executive sponsor to re-fund a program they just watched fail. The work to bring Copilot back online is the same work that would have prevented the incident, only now it has to be done under a credibility deficit.

Don't try to fix thousands of sharing links by hand

The original 2025 framing pushed people toward a permission audit at the scale of the entire tenant. At mid-market budgets, that's a non-starter. The 2026 approach is to target the 20 to 50 sites that account for most of the risk and let Restricted SharePoint Search hold the line on the rest. The remaining sites get cleaned up opportunistically as part of normal SharePoint admin work, not as a dedicated $200K project.

Don't buy a separate DLP tool when Purview is already in your E5

The third-party data security tools that pitch into Copilot oversharing conversations have legitimate capability, but most mid-market shops with Copilot already have Microsoft 365 E5 or E5 Compliance, which bundles Purview DSPM for AI, sensitivity labels, and DLP for the Copilot location. The marginal value of a third-party tool over the bundled Microsoft capability is usually not worth the integration cost at this size. Re-evaluate at 5,000+ seats.

Don't wait for the auditor to find it

The audit finding pattern in 2026 is consistent. The auditor pulls Copilot prompts from the unified audit log, correlates them against known sensitive document libraries, and asks the IT team to demonstrate the classification and access controls that gated the prompt. If the controls aren't in place, the finding writes itself. The remediation cost is unchanged whether it's done proactively or in response to a finding; the political cost is much higher in the second case.

The 30-second version: Copilot didn't break governance. Copilot made existing tenant sprawl legible to non-technical users. The fix in 2026 is four controls (Restricted SharePoint Search, SAM oversharing reports, Purview sensitivity labels, DSPM for AI) deployed over 90 days, using licensing most mid-market shops already pay for. Copilot stays on. The audit trail becomes continuous. The "we'll worry about it later" position from 2025 is no longer available.

Why this is suddenly urgent in 2026

Four 2026 signals turned Copilot governance from a "should do" into a "must do" for mid-market shops.

  • CMMC Phase 2 was suspended on July 13, 2026 — and that raises the stakes on self-attestation. The November 10, 2026 third-party C3PAO assessment mandate is off, and Phases 3 and 4 are paused pending a reform review. But DFARS 252.204-7012 and NIST 800-171 still bind, so defense contractors handling Controlled Unclassified Information are now attesting to their own SPRS score with no assessor checking the work — which makes an inflated score a larger False Claims Act exposure, not a smaller one. Copilot access to CUI-bearing SharePoint sites without documented controls is exactly the kind of gap a self-attestation is supposed to catch.
  • HHS HIPAA AI-specific guidance is expected in H2 2026. The Office for Civil Rights signaled throughout 2025 that AI-specific guidance under the HIPAA Security Rule was in development. The early indicators point at access controls, audit logging of AI interactions with PHI, and documented risk analysis. Healthcare organizations running Copilot without DSPM for AI logging will be on the wrong side of the guidance the moment it lands.
  • SOC 2 Type II auditors added AI data access controls to standard questionnaires. The Trust Services Criteria didn't change, but the way auditors apply CC6 (Logical and Physical Access) and CC7 (System Operations) now routinely includes AI access patterns. We're seeing this consistently in 2026 Type II renewals.
  • State attorneys general in California, Illinois, and Washington opened AI data-leak inquiries. The questions are exploratory, not enforcement, but the precedent is set. Companies that can demonstrate DSPM for AI logging and sensitivity-label coverage are off the inquiry list quickly. Companies that can't are not.

The NIST AI Risk Management Framework (AI RMF 1.0) and its Generative AI Profile are increasingly cited in audit working papers as the reference for "reasonable AI governance" even where they're not formally adopted. The GOVERN-MAP-MEASURE-MANAGE structure maps cleanly onto the four-control playbook above; auditors are starting to expect that mapping in writing.

Agentic AI raises the stakes: Cowork, Agent 365, and delegated permissions

The June 2026 wave of agentic releases changes the math on everything above. Microsoft 365 Copilot Cowork reached general availability on June 16, 2026. Unlike the chat-style Copilot that returns a draft, Cowork is an agentic system that runs complex, long-running, multi-tool tasks end-to-end and returns a completed result. Microsoft is explicit that it "operates within your Microsoft 365 trust boundary," ships off by default, and inherits sensitivity labels end-to-end. That's the reassuring read. The operational read is the warning: an agent inherits exactly the oversharing the permission graph already allows. A user issuing a one-off "summarize this folder" prompt touches one site; an agent running multi-step work traverses far more of the estate autonomously, on the user's behalf, with the user's delegated permissions. Every broad-internal share and every un-broken inheritance chain that survived the 2025 cleanup is now reachable by something that doesn't get tired, doesn't pause, and doesn't know which folder it wasn't supposed to read.

The licensing signal reinforces the point. With Microsoft Agent 365 generally available, Microsoft introduced Microsoft 365 E5 as a license prerequisite for new Agent 365 purchases, effective June 1, 2026 — enterprise customers must have E5, with the stated reason being "the foundational security, identity, compliance, and management capabilities required to support core Agent 365 functionality." Read that against the four-control table above: Purview DSPM for AI, sensitivity labels, and DLP for the Copilot location all live in E5. Microsoft is, in effect, drawing the line that the governance and identity stack is now the price of admission for running agents at all, not an optional hygiene project to schedule for next fiscal year.

The practical takeaway for a mid-market shop is blunt. The four-control playbook stops being "Copilot prep" and becomes the prerequisite for turning agents loose at all. If you couldn't trust a junior analyst with broad SharePoint access not to surface the finance forecast, you definitely can't trust an autonomous agent traversing the same sites on that analyst's behalf. Restricted SharePoint Search still bounds what an agent can ground against; sensitivity labels still gate what it can summarize; DSPM for AI still logs what it touched. The controls don't change. The cost of not having them does.

What this looks like for the regulated verticals

Healthcare clients in particular need the healthcare-specific framing on top of the general playbook. PHI gets a higher-sensitivity label tier, auto-labeling rules tied to MRN and ICD-10 patterns, and DSPM for AI policy rules that flag Copilot prompts touching PHI for separate review. The sister post on the Microsoft BAA and Copilot covers the contractual layer; this post is the operational layer.

Defense contractors running Copilot in GCC High have a narrower governance surface (GCC High has its own feature lag relative to commercial) but the four-control playbook adapts. The GCC High before CMMC Phase 2 post covers the tenant-level move; this post covers the Copilot governance overlay.

Tying it back to the original migration

Most of the tenant sprawl that drives the 2026 Copilot governance work is residue from M365 migration decisions made in 2017 to 2022. If the original migration didn't include permission rationalization and label deployment as a workstream, the cleanup is happening now whether it's scoped as Copilot prep or not. The Microsoft 365 migration practice at Pro IT NW now includes Purview data governance as a default workstream for exactly this reason; the cost of inserting governance into a migration is a fraction of the cost of retrofitting it three years later under audit pressure.

Related reading

Sources and further reading


Pro IT NW does senior-led Microsoft project work. Vendor-neutral. Labor-only. The Copilot governance 90-day engagement is a fixed-scope follow-on to the 2-week readiness assessment.

Questions we get asked

What's actually different about Copilot governance in 2026 vs. 2025?
Three things shipped or matured in the past 12 months. Restricted SharePoint Search gives admins a 100-site allowed list that limits Copilot's reach while permissions get cleaned up. Microsoft Purview Data Security Posture Management (DSPM) for AI runs weekly automated risk assessments on the top 100 SharePoint sites and surfaces oversharing as a continuous signal rather than a one-time audit. SharePoint Advanced Management (SAM) added data access governance reports, including a 'Shared with Everyone except external users' report and per-site sharing-link reports. The combined effect is that the manual permission audit is no longer the only option, and audit-driven remediation is now realistic at mid-market budgets.
Should we disable Copilot if oversharing is found?
Almost never. Disabling Copilot after a finding creates three problems: paid licenses go unused, executive sponsors lose confidence in the IT team, and the underlying oversharing is still there for anyone using SharePoint search to find. The better move is to put the affected sites behind Restricted SharePoint Search (which excludes them from Copilot grounding) while remediation runs, deploy Purview sensitivity labels on the top five sensitive content categories, and enable DSPM for AI so the audit trail is continuous. Copilot stays on, the leakage path is closed, and the auditor gets a defensible remediation plan.
Do we need to fix thousands of sharing links by hand?
No. That's the mistake the original 'permission problem' framing pushed people toward, and at mid-market scale (200 to 2,000 seats) it's not feasible. The 2026 approach is targeted: use SAM data access governance reports to identify the 20 to 50 sites that account for most of the oversharing risk, quarantine them with Restricted SharePoint Search, label the top five content categories with Purview sensitivity labels, and let DSPM for AI flag new oversharing as it appears. Four controls, not 40. The remaining sites stay accessible to Copilot under the existing permission graph, with the high-risk surface area pulled out.
What does the 90-day remediation actually cost a 500-seat mid-market shop?
Most of the licensing is already in place if the tenant has Microsoft 365 E5 (Purview DSPM for AI, sensitivity labels, DLP are bundled). SharePoint Advanced Management is the add-on layer; it ships with Microsoft 365 Copilot licenses or as a standalone SKU. Professional services for a 500-seat 90-day rollout typically run $35K to $75K depending on how much label taxonomy work and end-user training is in scope. The compare-against number is the cost of one Copilot-related data incident, which lands six figures once legal and audit time are counted.
What's the auditor going to ask about Copilot data access in a 2026 SOC 2 or HIPAA review?
Four questions, in our experience. (1) Show me the inventory of sites Copilot can read. (2) Show me how sensitive content is identified and labeled. (3) Show me the audit trail of Copilot prompts that touched sensitive data in the last 90 days. (4) Show me the policy that determines who can invoke Copilot from which device. Purview DSPM for AI plus the unified audit log answers (1) and (3). Sensitivity labels plus auto-labeling rules answer (2). Conditional Access policies for Copilot answer (4). If any of those four are missing, expect a finding.
Do agentic AI features like Copilot Cowork and Agent 365 make the oversharing problem worse?
Yes, and that's the most important 2026 development. Microsoft 365 Copilot Cowork reached general availability on June 16, 2026 as an agentic system that runs long-running, multi-tool work end-to-end rather than returning a draft. Microsoft confirms it operates within the existing Microsoft 365 trust boundary and inherits sensitivity labels, which means it also inherits whatever oversharing the permission graph already allows. A user issues one prompt against one folder; an agent traverses far more of the estate autonomously on that user's delegated permissions. The licensing signal points the same way: with Microsoft Agent 365 generally available, Microsoft made Microsoft 365 E5 a license prerequisite for new Agent 365 purchases effective June 1, 2026, citing the foundational security, identity, compliance, and management capabilities needed to support it. E5 is where Purview DSPM for AI, sensitivity labels, and DLP live. The four-control playbook is no longer Copilot prep; it's the prerequisite for running agents safely.
Is this only a problem for healthcare and defense contractors, or does every mid-market shop need to care?
Every shop with a SharePoint estate older than three years has the same underlying tenant sprawl. The regulated verticals (healthcare under HIPAA, defense under CMMC, financial under SOC 2 and GLBA) are the first to feel audit pressure, but state attorneys general in California, Illinois, and Washington have opened AI data-access inquiries that are not industry-specific. Practically, if the company is large enough to license Copilot, it's large enough to need the governance work. The 'we'll worry about it later' position from 2025 has aged into 'the auditor is going to find this' in 2026.

Written by the team at · Senior-led Microsoft project consultancy · Seattle and the Pacific Northwest, delivered USA-wide.

Have a project on the runway?

Tell us the workload, the seat count, and the deadline. We'll come back with scope and a fixed-fee range.