The short version

Copilot uses existing Microsoft 365 permissions to access organisational content, making permission review an important starting point. It also introduces AI-specific considerations such as unreliable output, prompt injection and connected agents. Review both the underlying tenant and the features you enable; completing a checklist does not eliminate every risk.

1. Fix oversharing first

Identify sensitive SharePoint sites, broad sharing links, dormant guest accounts and groups with unnecessary access. Ask data owners to confirm the intended audience, remove access that is no longer justified and test with representative users. Record exceptions and an owner for ongoing review rather than treating permission cleanup as a one-off exercise.

2. Label and protect sensitive content

Sensitivity labels classify content and can apply encryption or other settings. Supported Copilot experiences honour relevant permissions and usage rights, but inheritance and DLP behaviour differ by application and feature. Verify the licences and test whether the configured policy blocks, warns or merely audits the intended action. Microsoft publishes Copilot and Purview feature considerations (opens in new tab); do not assume every summary automatically inherits all source protection.

3. Harden identity and access

Copilot acts as the signed-in user. If that account is weak or compromised, the attacker now has a research assistant. Multi factor authentication everywhere, conditional access that limits risky sign-ins, and a tidy review of privileged accounts all matter more once an AI assistant is in the mix. This is ordinary good email and endpoint security, brought up to a standard you can rely on.

4. Control what Copilot can reach

Review organisational permissions, search visibility, web search and each agent’s data access. Restricted search features can affect discovery, but they are not a substitute for fixing source permissions. Approve agents deliberately, check their terms and test their behaviour using normal user accounts. See Microsoft’s privacy and extensibility documentation (opens in new tab).

5. Put a policy and a record around it

Finally, the human and audit layer. A short AI acceptable use policy tells staff what Copilot may and may not be used for. For regulated and supply-chain work you also want an auditable record of what AI can do and the controls around it, which is a governance and audit question as much as a technical one. An assessor will ask, and "we turned it on and hoped" is not an answer.

None of this is beyond a well-run business, but it is rarely all in place at once. Our Copilot readiness and governance service works through exactly this list before any licence is enabled, and if you want the bigger picture on whether the tool is safe at all, start with is Microsoft Copilot safe for business.

FAQ

Common questions

What is the biggest Copilot security risk?

Oversharing is an important access risk because Copilot can make permitted content easier to discover. Also assess compromised accounts, inaccurate outputs, prompt injection and connected services. Priorities depend on your data, intended use and the features enabled.

Do sensitivity labels work with Copilot?

Yes, supported experiences honour relevant labels, permissions and usage rights, but the exact behaviour depends on the app, policy and licence. Test sensitive files, generated outputs and DLP actions before rollout. Do not assume every generated answer inherits all protections from its source.

Can we limit what Copilot is able to access?

You can manage source permissions, search visibility, connected agents and supported feature settings. Search restrictions do not fix excessive permissions. Review each enabled feature and test the result with users who have different access levels.