TL;DR: Microsoft 365 Copilot can surface salaries, contracts, and customer records from anything a user can reach through Microsoft Graph, so one overshared folder or stale permission becomes an answer exposure problem, according to Orion. Traditional DLP misses that risk because it inspects files and transfers, not the answer itself, which makes context-aware control essential.
NHIMG editorial — based on content published by Orion: DLP for Microsoft 365 Copilot and the oversharing risk
By the numbers:
- 72% of organisations have experienced or suspect they have experienced a breach of non-human identities , 46% confirmed, 26% suspected.
Questions worth separating out
Q: How should security teams control Copilot oversharing in Microsoft 365?
A: Start with the permissions that feed Copilot, not the prompt itself.
Q: Why does Microsoft 365 Copilot complicate data loss prevention?
A: Because the leak now happens inside the answer, not at a transfer point.
Q: What do teams get wrong about Copilot and access control?
A: They often assume that if a user can reach the source data, Copilot can safely summarise it.
Practitioner guidance
- Audit Microsoft Graph reachability first Inventory the SharePoint sites, Teams resources, mailboxes, and inherited folders Copilot can reach for high-risk populations, then remove broad sharing and stale permissions before expanding use.
- Move DLP policy to the answer layer Extend DLP decisions to the response Copilot is about to surface, not only to files and transport paths, so business-specific disclosures can be blocked even when they do not match a known sensitive information type.
- Prioritise business-sensitive data labelling Label HR, finance, legal, and customer records that are sensitive to your organisation but may not match generic pattern-based detectors, because those files are the most likely to leak through contextual AI answers.
What's in the full article
Orion's full article covers the operational detail this post intentionally leaves for the source:
- How its answer-level DLP logic classifies Copilot responses before disclosure instead of relying on file or mail inspection.
- How it distinguishes business-specific sensitive content from generic patterns that traditional DLP can miss.
- How it integrates alongside Microsoft Purview in Microsoft 365 without replacing existing policy foundations.
- How the 30-minute deployment and low-admin operating model are positioned for teams running multiple AI tools.
👉 Read Orion's analysis of Microsoft 365 Copilot oversharing and DLP →
Microsoft 365 Copilot oversharing: what IAM and data teams must fix?
Explore further
Oversharing has become the primary data governance failure mode for Microsoft 365 Copilot. The issue is not that Copilot invents secrets, but that it operationalises permission debt already sitting in Microsoft 365. When a single over-shared folder can become a natural-language answer, access governance and disclosure governance must be treated as the same control domain. Practitioners should now measure risk by reachability plus response exposure, not storage location alone.
A question worth separating out:
Q: Who is accountable when Copilot exposes internally shared data?
A: Accountability sits with the organisation’s data and identity governance, not with the AI feature itself. The shared responsibility model means Microsoft provides the service, but the business owns classification, permissions, and internal sharing discipline. That is why audit evidence must show control ownership and remediation, not just tool deployment.
👉 Read our full editorial: Microsoft 365 Copilot oversharing exposes a new DLP control gap