First page of Microsoft's 100,000-partner directory, sorted by responsiveness Microsoft Solutions Partner — Security, Modern Work, Infrastructure, App Innovation Microsoft partner since 2006 1,100+ organizations under management
Home/Services/Microsoft 365 Copilot Oversharing Assessment and Remediation
AssessmentSecurity and ProtectionCompliance

Microsoft 365 Copilot Oversharing Assessment and Remediation

Microsoft 365 Copilot does not bypass your permissions — it removes the friction that used to hide them. This is a fixed-price, three-week engagement that finds what Copilot, Copilot Chat, agents and Copilot Cowork could surface to the wrong person, then fixes it. IT Partner runs Microsoft Purview Data Security Posture Management data risk assessments and SharePoint Advanced Management's Data Access Governance and Content Management Assessment reports across SharePoint, OneDrive and Teams, ranks every exposed site by sensitivity and reach — 'Everyone except external users' grants, broken inheritance, Anyone and organization-wide sharing links, oversized groups, guest drift, unlabeled sensitive content — and remediates the agreed set: sharing links removed or replaced, inheritance restored, groups and owners right-sized, sensitivity labels applied or corrected from your existing label set, Restricted Content Discovery or site access restriction switched on for high-risk sites, dead sites archived. The assessment is re-run as before-and-after evidence, and you keep a repeatable monthly check. $4,950 fixed for the tenant-wide assessment plus remediation of up to 25 flagged sites or teams; larger estates are quoted per estate in writing before we start. Microsoft licensing — Copilot seats, SharePoint Advanced Management, the Purview tier that sets how deep the assessments go — is yours and is not part of this fee.

Timeline 3 weeksService owner Roman SotnikMicrosoft 365 CopilotMicrosoft PurviewSharePoint Advanced Management

What this engagement is

Ask a room of IT and security leads who have bought Microsoft 365 Copilot what worries them and the answer is the same: 'What will Copilot show the wrong person?' The honest reply is 'whatever they can already reach' — and in most tenants that is far more than anyone would defend if they reviewed it today. Copilot honors SharePoint permissions, sharing links and sensitivity labels exactly as they stand; what it removes is the friction of knowing which site to search or which link to follow. A sales manager asking for 'the concessions we have discussed internally' can get a cited answer assembled from a pricing workbook opened to the whole company during a CRM migration, a 'People in your organization' link pasted into a chat two years ago, and an executive deck in a team whose membership was widened for a week and never corrected. We wrote up the mechanics in our analysis of Copilot oversharing. Since mid-2026 the surface is wider still: Copilot in SharePoint reached Copilot-licensed users as an opt-out preview, SharePoint and Copilot Studio agents ground on the same content, and Microsoft's Purview controls now extend to Copilot Cowork — every one of them reading the same access model underneath. Microsoft moved the workflow for finding this into the product in 2026, and this service is built on those tools rather than on a third-party scanner. Microsoft Purview Data Security Posture Management runs a default data risk assessment weekly on your hundred most active SharePoint sites and lets us run custom assessments on the sites that actually matter — HR, finance, legal, executive, M&A — with item-level investigation and remediation for SharePoint that became generally available in March 2026: resolve the item, apply a sensitivity label, notify the owner, or remove the sharing link. SharePoint Advanced Management, which Microsoft entitles to your SharePoint administrators once a single Microsoft 365 Copilot license is assigned in the tenant, adds the Data Access Governance reports (activity on 'Everyone except external users', new Anyone, organization-wide and specific-people sharing links over the last 28 days, sensitivity-label and site-permission snapshots), the Content Management Assessment (inactive sites, sites with no owner or a single owner, broken inheritance, unrestricted internal sharing), site access reviews that email each owner about the specific problem on their site, Restricted Content Discovery to keep a high-risk site out of Copilot, agents and organization-wide search without changing a single permission, and site access restriction to fence a site to a named group. Restricted SharePoint Search, the older tenant-wide allow-list, is being retired — Microsoft blocked new enablement from 31 July 2026 — so we do not build on it. Which Purview tier you hold sets how deep the assessments go: Microsoft 365 E5 or E5 Compliance for the full experience, a narrower version with E3 plus Microsoft 365 Copilot, and a Purview Suite add-on route for Business Premium. We confirm what your licenses unlock at kickoff and say plainly which findings would need more. The three weeks split into find, fix and prove. Week one is the tenant-wide assessment: the DSPM assessments, the SharePoint Advanced Management reports, a Teams and Microsoft 365 Groups pass for ownerless, oversized and guest-heavy workspaces, OneDrive sharing-link exposure, and role-based prompt tests with three to five of your own people, whose citations tell us exactly which sites, links and memberships are leaking. Everything lands in one exposure register ranked by sensitivity multiplied by reach, and we agree the remediation set with you — up to 25 sites or teams inside the fixed fee, the rest in a costed backlog. Week two is the remediation, done with the owners rather than to them: 'Everyone except external users' grants replaced with role-based groups, Anyone and organization-wide links removed or replaced with specific-people links, inheritance restored where the break was never a decision, groups right-sized and second owners added, sensitivity labels applied or corrected from your existing label set, Restricted Content Discovery or site access restriction switched on for the sites that must never surface in a chat, guests removed where the relationship has ended, and dead sites archived. The posture is archive-first and reversible: nothing is bulk-deleted, an owner confirms before anything moves, and every action is logged with how to undo it. Week three re-runs the assessments and reports, re-tests the prompts and packages the before-and-after evidence — then we hand over a monthly check your administrator can run in well under a morning, and run the first cycle together. Boundaries, stated because they matter. This is the hands-on remediation that the Microsoft 365 Copilot Readiness Assessment, AI Security for Microsoft 365 Copilot and Agents and Microsoft Purview Data Governance for Copilot each hand off — it does not repeat their verdicts, redesign your labels or DLP, or restructure your information architecture. Restricted Content Discovery is a containment control, not a permission fix; we use it to take the highest-risk sites off the table while the permissions underneath are corrected, and the register says which sites still carry it and why. We read permissions, sharing metadata and Purview's classification results, not your documents. And the fee is fixed and quoted in writing before work begins — you pay after you approve delivery — so the register reports what the evidence shows, not what a remediation quota needs.

Success criteria

01Scope agreed in writing at kickoff: the tenant, the workloads in scope (SharePoint, OneDrive, Teams), which Purview and SharePoint Advanced Management capabilities your licensing unlocks, and the named high-sensitivity domains — HR, finance, legal, executive, M&A, customer data — that lead the ranking.
02A tenant-wide exposure register exists, ranked by sensitivity and reach, with every flagged site or team carrying its exposure type, evidence source (DSPM assessment, Data Access Governance report, Content Management Assessment, Groups inventory, prompt test) and a named owner.
03The agreed remediation set — up to 25 sites or teams — is remediated, each with an owner attestation on record and every change logged with its rollback.
04High-risk sites that must not surface in Copilot carry Restricted Content Discovery or site access restriction, verified after reindexing by role-based prompt tests that no longer cite them.
05Re-run assessments and reports show the flagged exposures on remediated sites resolved, and the before-and-after evidence pack is dated and re-checkable by a third party.
06Nothing was bulk-deleted; every archive, link removal and permission change happened after owner confirmation and inside Microsoft's documented recovery windows.
07Your administrator has run the monthly oversharing check once with us and can run it alone, and the backlog beyond the 25 is costed and prioritized.

What you receive

Exposure register: every SharePoint site, OneDrive and team flagged by the assessment, ranked by sensitivity and reach, with exposure type, evidence source, owner and recommended action.
Licensing and capability map: which DSPM assessment features, SharePoint Advanced Management reports and controls your current licenses unlock, and exactly what a higher tier would add — no upgrade recommended where a setting change covers it.
Agreed remediation plan for up to 25 sites or teams: per-site actions, owner, sequence and the confirmation each one waits for.
Owner notification and attestation record: the tailored notices sent (SharePoint Advanced Management site access reviews and DSPM owner notifications where licensed, our own where not), the owners' responses and their decisions.
Remediation change log: every sharing link removed or replaced, inheritance restored, group membership or ownership change, label applied or corrected, and site archived — with timestamp, who confirmed it and how to reverse it.
Restricted Content Discovery and site access restriction register: which sites carry which control, why, the reindex confirmation, and the date to revisit lifting it.
Prompt-test results: the role-based prompts run before and after, the citations they returned, and the sites those citations traced to.
Before-and-after evidence pack: dated exports of the DSPM assessments, Data Access Governance and Content Management Assessment reports, and the Groups inventory, organized so an auditor, insurer or your board can re-check any claim.
Monthly oversharing check runbook: the reports to open, the PowerShell and admin-center steps, the thresholds that trigger an owner notice, and who owns each step — written for your administrator, not for us.
Costed backlog for everything beyond the 25, and a live readout with your IT, security and data owners.

How the work unfolds

Days 1–2 — Kickoff, licensing and access

Agree scope and the high-sensitivity domains; confirm the Copilot license count (SharePoint Advanced Management entitlement), the Purview tier and the existing sensitivity labels; set up time-bound, least-privilege access to SharePoint, Purview and Groups administration through GDAP you approve; switch on the DSPM assessments and SharePoint Advanced Management reports that are not yet running.

Days 3–6 — Tenant-wide assessment

Run the default and custom DSPM data risk assessments on the sites that matter, the Data Access Governance reports, the Content Management Assessment and a Teams and Groups inventory (ownerless, oversized, guest-heavy); pull OneDrive sharing-link exposure; run role-based prompt tests with your testers and trace every sensitive citation to its source.

Days 7–8 — Rank and agree

Build the exposure register ranked by sensitivity and reach; walk it with you; agree the remediation set of up to 25 sites or teams and the containment list; send owner notifications and initiate site access reviews.

Days 9–13 — Remediate

Execute the per-site plan with owner confirmation at each step — links, inheritance, groups and owners, labels, guests, archives; apply Restricted Content Discovery or site access restriction to the containment list and wait out the reindex; log every change with its rollback.

Day 14 — Re-run and evidence

Re-run the assessments and reports, re-test the prompts, and assemble the dated before-and-after evidence pack.

Day 15 — Handover

Run the first monthly check together with your administrator, walk through the runbook and the containment register, and deliver the readout and the costed backlog.

Prerequisites

A Microsoft 365 tenant with SharePoint Online, OneDrive and Microsoft Teams in use, and a rough count of sites and teams so we can confirm the fixed fee holds.
At least one Microsoft 365 Copilot license assigned — it entitles SharePoint Advanced Management to your administrators and is what Microsoft requires for Restricted Content Discovery. Without it the assessment still runs on SharePoint admin reporting and PowerShell/Graph inventory, and we tell you which controls are off the table.
Purview licensing for data risk assessments: Microsoft 365 E5 or E5 Compliance unlocks the full experience; a narrower version ships with E3 plus Microsoft 365 Copilot; the Business Premium route is the Purview Suite add-on. Which assessment features your tenant actually unlocks is confirmed at kickoff, not assumed.
An existing sensitivity-label set if labels are to be applied or corrected — we work with your taxonomy, not design one; without labels the labeling steps are skipped and noted in the register.
Named data owners for the high-sensitivity domains, with the authority to confirm or decline each remediation, and an escalation path for owners who do not respond.
Three to five people in real roles — sales, HR, finance, project, support — available for two short prompt-test sessions, before and after remediation.
Time-bound administrative access — SharePoint Administrator, the Purview roles for DSPM, Groups administration — granted through GDAP for the three-week window.

Who does what

IT Partner

  • Run the assessments, reports and prompt tests, and build the ranked exposure register.
  • Propose the remediation set and the containment list, and explain the risk of every item we recommend leaving alone.
  • Execute the agreed remediation with owner confirmation, log every change with its rollback, and apply and verify the containment controls.
  • Re-run the assessments and assemble the before-and-after evidence pack.
  • Write the monthly runbook for your administrator and run the first cycle together.
  • State scope limits in the readout — what was assessed, what was remediated, what remains in the backlog.

Your team

  • Grant time-bound access, provide the site and team counts and the existing label set, and name the data owners.
  • Decide the remediation set and the containment list; owners confirm or decline each action within the agreed window.
  • Provide the prompt testers and a decision-maker for owner escalations.
  • Own the residual risk for exposures deliberately left open and for the backlog beyond the 25.
  • Run the monthly check after handover, or contract it separately.
  • Own Microsoft licensing decisions and costs — Copilot seats, SharePoint Advanced Management, Purview tiers.

What's not included

The readiness verdict itself — licensing, adoption ownership and the go/no-go for a rollout are the Microsoft 365 Copilot Readiness Assessment; this service is the remediation that assessment explicitly leaves out.
A Purview governance program — the DSPM operating model, label and auto-labeling design, retention and audit configuration at tenant scale — is Microsoft Purview Data Governance for Microsoft 365 Copilot.
Platform-level AI security controls — Copilot and agent inventories, Defender and Entra hardening, agent governance policies — are AI Security for Microsoft 365 Copilot and Agents.
Building DLP policies, including DLP for Microsoft 365 Copilot — that is Configure and Enable DLP Policies.
Designing a sensitivity-label taxonomy or rolling labels out tenant-wide — Azure Information Protection Implementation; here we apply and correct the labels you already have.
Information-architecture redesign, hub topology and governance policy packs — SharePoint Governance and Information Architecture Review.
Teams lifecycle policy and sprawl cleanup beyond the flagged teams in the remediation set — Microsoft Teams Governance and Sprawl Cleanup.
Remediation beyond 25 sites or teams, content migration between sites, or restructuring of libraries — quoted from the backlog, in writing, before any of it starts.
Copilot deployment, pilots, training and adoption — Microsoft 365 Copilot Deployment and Adoption and the Copilot training and prompt workshops.
Microsoft licensing costs — Microsoft 365 Copilot seats, SharePoint Advanced Management, Microsoft 365 E5, E5 Compliance or the Purview Suite add-on. They are yours; if you buy them through IT Partner they are at Microsoft's published list price, and the licensing decision is made before work begins.
Ongoing execution of the monthly check after handover, Exchange mailbox content, third-party repositories, or any guarantee that every exposure in the tenant has been found — we report what the evidence shows and what remains.

Limitations & technical notes

!Point in time. Sharing links, group memberships and new sites change daily; the evidence pack is dated and says so, and the monthly check exists because a clean tenant does not stay clean by itself.
!Depth follows licensing. The full Purview DSPM assessment experience needs Microsoft 365 E5 or E5 Compliance; a narrower version ships with E3 plus Microsoft 365 Copilot; Microsoft's guidance on what the Purview Suite add-on unlocks for Business Premium has been inconsistent, so we verify it in your tenant. Restricted Content Discovery requires at least one Microsoft 365 Copilot license in the tenant, and site access restriction may need SharePoint Advanced Management licensing for the users who keep access — we confirm before switching it on. The capability map says which findings would need more.
!Microsoft's item-level assessment limits apply at the time of writing — a custom item-level data risk assessment covers up to 10 SharePoint sites, OneDrive is not yet covered at item level, and there is a per-location item cap — so for larger remediation sets we combine DSPM findings with the SharePoint Advanced Management reports and PowerShell/Graph inventory rather than pretending one console sees everything.
!Restricted Content Discovery is containment, not a fix. It keeps a site out of Copilot, agents and organization-wide search without changing who can open the files; reindexing can take up to 72 hours, and Microsoft's enhancement that also hides recently accessed files from those sites was still completing its worldwide rollout in September 2026. Every site carrying it is in the register with a date to revisit.
!We read permissions, sharing metadata, group membership and Purview's classification results — not the contents of your documents. Whether a file belongs on a site at all is the owner's call; where content-level questions dominate, that is Purview territory and we say so.
!Remediation moves at the speed of owner decisions. Sites whose owners do not respond inside the agreed window are contained with Restricted Content Discovery and escalated, not silently changed — and they count toward the 25.
!The fixed fee covers one tenant and up to 25 flagged sites or teams. Every site is assessed regardless of estate size; a 3,000-site estate gets its riskiest corners remediated first and the rest costed in the backlog. If your estate is genuinely larger than the fee assumes, we say so at the scoping call, not in week two.
!Feature names, limits and licensing rules in this area change quarterly. Every dated Microsoft statement on this page is checked at each review of this service; if Microsoft's current documentation disagrees with it, Microsoft is right.

Frequently asked questions

How do you actually find what Copilot would show the wrong person?

Three ways that cross-check each other. Purview DSPM data risk assessments report sensitive items per site and whether they are labeled and how they are shared; SharePoint Advanced Management's Data Access Governance reports and Content Management Assessment show which sites are open to 'Everyone except external users', where sharing links pile up, where inheritance is broken and which sites have no owner; and role-based prompt tests — a real HR generalist, sales manager or finance analyst asking ordinary questions — show us the citations Copilot returns, and each citation traces to a site, a link or a membership. The register ranks all of it by how sensitive the content is and how many people can reach it.

Is Copilot bypassing our permissions?

No. Copilot, Copilot Chat, agents and Cowork ground only on content the user can already open, and they honor sensitivity-label protection. What they remove is friction: before Copilot, someone had to know which site to search or which link to follow. That is why the fix is the permissions and sharing model, not a Copilot setting — and why Restricted Content Discovery is only a bridge while the permissions are corrected.

What counts as one of the 25 sites or teams, and what if we have more?

One SharePoint site (a team's connected site counts as one, with its private- and shared-channel sites counted separately only if they are flagged in their own right) or one OneDrive with flagged exposure. The tenant-wide assessment covers every site regardless of count; the 25 is the remediation cap inside the fixed fee. Larger flagged sets are costed in the backlog and quoted per estate in writing before we start — we tell you at the scoping call if your estate looks like it will exceed the cap.

What licensing do we need before you start?

At least one Microsoft 365 Copilot license assigned, which entitles SharePoint Advanced Management to your administrators and is what Microsoft requires for Restricted Content Discovery. For the Purview assessments, Microsoft 365 E5 or E5 Compliance gives the full DSPM experience; E3 plus Microsoft 365 Copilot gives a narrower version; Business Premium tenants take the Purview Suite add-on route, and we confirm in your tenant which assessment features that unlocks. Without any of it the assessment still runs on SharePoint reporting and PowerShell/Graph inventory — the capability map in the deliverables says exactly what you get at each tier, and we never recommend a license where a setting change does the job.

We have already had the Copilot Readiness Assessment — is this the next step?

Yes, by design. The readiness assessment gives the verdict and a risk-ranked roadmap but explicitly excludes permission cleanup, sharing changes and label deployment. This service takes that roadmap and executes the SharePoint, OneDrive and Teams part of it, with the assessment re-run as proof. If you have not had the readiness assessment, you can start here when the exposure question is the one you need answered; the readiness assessment remains the right first step when licensing and adoption ownership are still open.

How is this different from Purview Data Governance for Copilot?

Scope and shape. Purview Data Governance for Copilot is a four-to-eight-week program that designs and implements your labeling, auto-labeling, DLP and DSPM operating model. This is a three-week, fixed-fee engagement that measures the exposure with the tools you already have and fixes a defined set of sites. Run this first when you need the worst exposures closed before a rollout; run the Purview program when the finding is that your label and policy model is the problem — the register will say which.

Will remediation break collaboration?

It is built not to. Every change waits for the owner's confirmation; broad grants are replaced with role-based groups rather than simply deleted; links are replaced with specific-people links where people genuinely need access; sites are archived, not deleted, and stay recoverable inside Microsoft's documented windows; and every action is logged with its rollback. The point is an access model that matches how the business works — not a lockdown that pushes people into shadow copies.

What is Restricted Content Discovery, and does it fix the problem?

It is a per-site SharePoint Advanced Management control that keeps a site's content out of Microsoft 365 Copilot, agents and organization-wide search without changing who can open the files. It is the right tool for an HR or M&A site that must never surface in a chat while its permissions are being corrected, and Microsoft tightened it in 2026 so that recently accessed files and Copilot entry points on those sites disappear too. It is not a fix: anyone with access can still open the files directly, so every site carrying it is in the register with a date to revisit. Restricted SharePoint Search, the older tenant-wide allow-list, is being retired and we do not build on it.

Do you read our documents?

No. We read permissions, sharing metadata, group membership and the classification results Purview already produces — sensitive-information types and labels. Whether a specific file belongs on a site is the owner's decision, which is why owners confirm each action. Access is time-bound and least-privilege through GDAP that you approve, and the audit log shows exactly what we touched.

Does this cover Copilot Chat, agents and Copilot Cowork?

Yes, because they all read the same permissions. Restricted Content Discovery applies wherever Microsoft 365 Copilot can use SharePoint files, agents included, and Microsoft's Purview controls — label inheritance, audit, DSPM activity — now extend to Cowork. What this service does not do is govern the agents themselves, their connectors or their publishing; that is the AI Security for Microsoft 365 Copilot and Agents engagement.

What about OneDrive and Teams — or is this only SharePoint?

All three. Every team is a SharePoint site with a Microsoft 365 group behind it, so ownerless, oversized and guest-heavy teams are in the Groups inventory and in the register. OneDrive shows up through the sharing-link reports and the DSPM assessments at site level; Microsoft's item-level assessment does not yet cover OneDrive, so OneDrive remediation leans on the sharing-link reports and PowerShell rather than the DSPM console. Exchange mailbox content is out of scope.

Can we do this ourselves with Microsoft's tools?

Yes — the reports, assessments and controls are Microsoft's and this page names them. What you are buying is three weeks of an engineer who has run them before: knowing which of the many findings matter, what to do about each without breaking a team, how to get owners to decide, how to prove it afterward, and a runbook so you can keep doing it yourself. If your team has the time and the SharePoint depth, the runbook alone is worth reading; many organizations find they want the first pass done for them.

Why three weeks and $4,950?

Because the scope is fixed: one tenant, a tenant-wide assessment, remediation of up to 25 flagged sites or teams, a re-run, a runbook and 15 working days. The price is quoted in writing before work begins and you pay after you approve delivery. If your estate is genuinely bigger — thousands of sites, multiple tenants, hundreds of flagged sites — we say so at the scoping call and quote the difference before anything starts.

What happens after the three weeks?

Your administrator runs the monthly check from the runbook: open the DSPM assessment and the Data Access Governance reports, act on the thresholds, send the owner notices, review the containment register. We run the first cycle with you on day 15. If you would rather we ran it every month, that is a separate recurring scope quoted on request. Nothing about this engagement ties you to us afterward.

Do we have to buy licenses or anything else from you?

No. The licensing is yours to decide and to buy wherever you like; if you buy Microsoft subscriptions through IT Partner they are at Microsoft's published list price, and organizations that do get business-hours break-fix support included. The engagement has no minimum term beyond the three weeks and no lock-in — the runbook, the register and the evidence pack are yours whoever runs the next cycle.

Didn’t find your question?

Ask it here. A real engineer answers by email within one business day — and if it’s a good one, it becomes part of this page so the next person finds it.

Answered by a person, one time, to your inbox. Nothing you type here is published without a human reviewing and anonymizing it first.

Often combined with

$4,950 per project
3 weeks
Book the oversharing assessment