Protecting sensitive information when adopting Microsoft Copilot

Microsoft Copilot rarely creates new information risks - it reveals the ones already there. A practical guide for SMB leaders on data governance, access controls and sensitivity labels before you widen Copilot adoption.

Most conversations about Microsoft Copilot start with productivity and end with a question the leadership team can't quite answer: if we give people an assistant that can read across everything they have access to, what exactly is that?

It's a fair question, and the honest answer for a lot of organisations is "we're not sure". Client contracts sit in a shared folder that was set up years ago. Commercial proposals are in a Teams channel that half the business joined during a busy period and never left. Pricing models, tender responses and product designs are scattered across SharePoint, OneDrive and email. Historic permissions have accumulated quietly, and nobody has reviewed them since the day they were granted.

None of that is caused by Microsoft Copilot. But Copilot does make it visible.

Copilot usually exposes existing problems rather than creating new ones

Before Copilot, poor information governance was survivable because finding things was hard. If a salesperson technically had access to the finance folder, they'd probably never stumble across it. Search was clumsy, folder structures were opaque, and obscurity did a lot of quiet work.

An assistant that can summarise, search and pull together information across Microsoft 365 removes that obscurity. What people can reach, they can now find easily.

So the risk isn't really "AI reading your data". It's that access rights in most businesses drifted a long way from what anyone would design today, and nobody had a reason to look until now.

That reframing matters, because it changes who owns the problem. This isn't purely an IT or security exercise. It's an operational discipline: knowing where your information lives, who is responsible for it, and who should reasonably be able to see it.

How access actually works (and why nuance matters)

You'll often hear the shorthand that Copilot can see whatever the user can see. That's a useful rule of thumb, but it's not the whole picture and it's worth being precise.

What Copilot can surface depends on how your Microsoft 365 environment is configured - permissions on sites and files, sharing settings, sensitivity labels applied through Microsoft Purview, data loss prevention rules, retention policies, and which Copilot experiences and connectors you've enabled. Behaviour also varies between Copilot in Microsoft 365 apps, Copilot Chat and any agents you build.

Equally, no technology configuration removes risk entirely. Controls reduce exposure and make problems detectable. People still share files, download documents and paste content into places they shouldn't. Good governance is a combination of sensible configuration, clear expectations and ongoing review - not a switch you flip once.

Common governance gaps organisations find

When we work with businesses preparing their Microsoft 365 environment for Copilot, a familiar set of issues comes up:

  • Over-permissioned SharePoint sites - a site created for one project that gradually became the default dumping ground for the whole department.
  • "Anyone with the link" sharing - links created for a supplier or client three years ago that still work today.
  • Departed staff and stale groups - access granted to individuals rather than roles, so leavers and movers are missed.
  • No classification - nothing distinguishes a lunch menu from a signed contract or an unreleased product design.
  • Duplicate and abandoned content - old versions of pricing sheets and proposals that are wrong but still discoverable.
  • Unclear ownership - nobody can say who is accountable for a given site, library or dataset.
  • No retention or disposal - information that should have been deleted years ago is still live.
  • Personal storage sprawl - commercially important documents sitting in individual OneDrive accounts rather than shared, governed locations.

Every one of these is a business problem before it's a security problem. Wrong pricing being reused, tender responses built on outdated content, or a client seeing information about another client - those cost money and credibility regardless of whether Copilot is involved.

Information governance is an operational discipline

The businesses that adopt Microsoft Copilot well tend to treat information governance the same way they treat health and safety or finance controls: something owned by the business, supported by technology, reviewed regularly.

In practice that means five things:

Ownership. Every significant site, library or information set has a named owner in the business who understands what it contains and who should have access. IT can administer it; the business decides.

Classification. A simple, workable scheme - typically three or four levels such as public, internal, confidential and highly confidential. Anything more elaborate tends to be ignored.

Access management over time. Permissions reviewed on a schedule, tied to joiners, movers and leavers, and granted to groups rather than individuals so changes actually stick.

Records management. Clear rules on how long things are kept and what happens when they're not needed. Less content means less exposure and better answers.

Accountability. Someone chairs the review, someone reports on it, and exceptions get discussed rather than quietly accepted.

Microsoft Purview provides the tooling for much of this - sensitivity labels, data loss prevention, retention policies and reporting on where sensitive information sits. But the tooling only reflects decisions the business has made. Buying the licence doesn't make the decisions for you.

A practical example

A 90-person engineering consultancy wanted to widen Microsoft Copilot beyond a small pilot group. Their concern was specific rather than theoretical: their design methodology and rate cards were genuinely valuable intellectual property, and they had no confidence about who could reach them.

The work took a few weeks and looked like this.

First, they identified what actually mattered. Not everything - three categories: client contracts and commercial terms, rate cards and pricing models, and their design methodology documentation. Everything else was treated as internal by default.

Second, they found it. A review of SharePoint and OneDrive showed the rate cards existed in eleven places, four of which were in personal storage and one of which was in a site shared externally with a former joint venture partner.

Third, they consolidated and assigned ownership. Each category moved to a governed location with a named business owner - the commercial director for pricing, the technical director for methodology.

Fourth, they applied sensitivity labels through Microsoft Purview, with data loss prevention rules preventing the highly confidential material leaving the organisation by email or download.

Fifth, they cleaned up sharing. Legacy "anyone with the link" shares were expired, external guests were reviewed, and permissions were re-granted to groups rather than named individuals.

Then they widened Copilot adoption - and the review runs quarterly, taking about half a day.

The interesting part is what else came out of it. Removing ten stale copies of the rate card didn't just reduce risk; it stopped people quoting from outdated pricing. The governance work paid for itself before Copilot did.

Protecting information versus restricting productivity

There's a real tension here and it's worth naming, because the instinct in many organisations is to lock everything down and call it safe.

Over-restriction has costs. People can't find what they need, so they work around the controls - emailing files, using personal accounts, keeping local copies. Copilot gives poor answers because it can't see the information that would make the answer good. Adoption stalls, and the investment doesn't return anything.

The aim isn't minimum access. It's appropriate access - deliberate, understood and reviewed. Most information in most businesses should be broadly available to staff; a small proportion genuinely needs tight control. Good data governance is about knowing which is which, not about defaulting to "no".

Done properly, governance is what allows you to say yes. It's the reason you can widen Copilot adoption with confidence rather than holding it back indefinitely because nobody can vouch for the environment.

Where to start

  1. Decide what's genuinely sensitive. Get the leadership team to name the three to five categories of information that would cause real commercial harm if they were seen by the wrong people.
  2. Find out where it lives. Run a discovery exercise across SharePoint, Teams and OneDrive. Expect surprises.
  3. Fix the obvious sharing problems first. Expired links, external guests, open-to-everyone sites. This is usually the highest-value work in the shortest time.
  4. Assign owners. Names, not departments, for each significant information set.
  5. Apply a simple classification scheme, supported by sensitivity labels in Microsoft Purview where it adds value.
  6. Set a review rhythm. Quarterly access reviews, with joiners, movers and leavers handled properly in between.
  7. Set expectations with people. A short, plain-English guide on what Copilot does, what to check before trusting an answer, and what not to paste into it.
  8. Then widen adoption, and monitor what's actually happening.

A readiness checklist

Before expanding Microsoft Copilot beyond a pilot, can you answer yes to these?

  • We know which categories of information are commercially sensitive.
  • We know where that information is stored.
  • Each significant site or library has a named business owner.
  • Sharing links and external guest access have been reviewed in the last six months.
  • Access is granted through groups, not individual assignments.
  • Leavers and internal movers have their access changed promptly.
  • We have a simple classification scheme people understand.
  • Sensitivity labels and data loss prevention rules are applied to our most sensitive material.
  • Old and duplicate content has been cleared out of key locations.
  • We have a scheduled review, with someone accountable for running it.
  • Staff have practical guidance on using Microsoft Copilot sensibly.
  • We can see how Copilot is being used and report on it.

If you're answering no to several of these, that's normal - and it's a much better place to be than not knowing.

How Axon approaches this

As a Managed Intelligence Provider, our starting point isn't security tooling. It's understanding how your business actually works: where information lives, who needs it, who owns it, and how your Microsoft 365 environment should support the outcomes you're trying to achieve.

Information protection matters, and we'll help you get sensitivity labels, Microsoft Purview policies and access controls right. But we treat that as part of a broader piece of work - making your information trustworthy, well-owned and properly managed - rather than as a security project bolted on before an AI rollout.

Successful Microsoft Copilot adoption rests on trusted information, clear ownership, sensible access controls and ongoing review. Get those right and the productivity benefits follow. Skip them and you'll either get disappointing answers or an uncomfortable surprise.

If you'd like help preparing your data, governance and Microsoft 365 environment before widening Copilot adoption, get in touch. We'll start by showing you what's actually in your environment today - and what's worth fixing first.

Let's talk

Ready to talk to a real human?

Whether you have a quick question or a bigger project, the Axon team is here to help.