NXT

Assessments

Microsoft 365 Copilot oversharing assessment

Copilot answers from everything a user is permitted to reach. We find out what that is before an employee, or an attacker with one account, does.

01

The problem in Microsoft's words

Microsoft's security documentation puts it plainly: Copilot “only accesses data that users are authorized to access,” and “overshared or poorly governed content can affect Copilot results and increase risk.” (Microsoft Learn, updated September 2026)

That is the whole issue. Copilot does not break permissions. It makes every permission in the tenant usable in one sentence, including the ones nobody remembers granting. The question an assessment answers is not whether Copilot is secure. It is what your tenant will tell it.

In September 2026 Microsoft renamed the product from Microsoft 365 Copilot to Microsoft Copilot. This page uses both names because people still search for the old one. Microsoft Copilot is named here as a system we assess in our clients' tenants. NXT has no commercial relationship with Microsoft.

02

What Copilot reaches in a tenant

Mail and calendar

Copilot reads and summarizes the user's mailbox and meetings, including threads the user never opened.

Teams

Chats, channel messages, and meeting transcripts the user is a member of, searchable in one question.

SharePoint and OneDrive

Every file the user's account can open, whether or not it was ever shared with them on purpose.

Agents and connectors

Copilot Studio agents extend the reach to connected systems and can take actions, not just answer.

03

Four ways it goes wrong

Permission sprawl

Years of sites shared to "Everyone except external users", stale project libraries, and broad links. Search rarely surfaced them. Copilot does, in a sentence, on request.

Unlabeled sensitive files

Salary sheets, board decks, and customer exports with no sensitivity label are indistinguishable from the rest of the tenant. Label and policy coverage decides what Copilot will and will not summarize.

Instructions hidden in content

An email or document Copilot reads can carry instructions aimed at Copilot rather than the reader. A zero-click exfiltration flaw of this kind was publicly disclosed in 2025 and fixed by Microsoft. Your own content and connectors are the surface that remains.

Agents that act

A Copilot Studio agent with an email action and a SharePoint connector is a workflow, not a chat. Public disclosures in 2026 showed form submissions steering such agents into sending data out.

04

What the assessment covers

01

What Copilot surfaces, by role

Working as ordinary users in your tenant, we ask the questions an employee or an intruder with one compromised account would ask, and record what comes back and from where.

02

Where labels and policies hold

We check whether sensitivity labels and data loss prevention actually change Copilot's answers for the content that matters, rather than assuming the policy does what the admin center says.

03

Agents, connectors, and content

For Copilot Studio agents and anything with an action, we test the inputs they read, including documents, forms, and messages, for instructions aimed at the agent.

04

Findings, fixes, and a re-test

Every finding ships with the prompt, the response, and the location of the exposed content. Remediation is mapped to Microsoft's own controls. We run it again after your team acts.

05

What you receive

A findings register where each entry has the question asked, the answer Copilot gave, the file or message it drew on, and a severity. A remediation plan that names the Microsoft control that closes each finding, prioritized by exposure. A compliance mapping to the EU AI Act, NIST AI RMF, and OWASP LLM Top 10. And, once your team has acted, a re-test with an attestation you can hand to a customer, an auditor, or a regulator.

Remediation is written against the controls your admins already have:

  • SharePoint Advanced Management and site access reviews
  • Restricted SharePoint Search and Restricted Content Discovery
  • Sensitivity labels and auto-labeling coverage
  • Data loss prevention policies for Copilot
  • Copilot Studio agent permissions and connector scope
06

Questions we get

Does Copilot bypass permissions?

No. Microsoft states that Copilot only accesses data the user is authorized to access. The problem is that most tenants have far more authorized access than anyone intended, and Copilot makes it instantly usable.

Is this a penetration test of Microsoft?

No. We test your deployment, under your authorization and within Microsoft's rules of engagement. Microsoft's service is the platform; the configuration, permissions, labels, and agents are yours.

We have not rolled Copilot out yet. Is it too early?

It is the best time. Finding the exposed content before Copilot is switched on means the rollout starts clean, and the findings become the data-readiness plan.

What about the oversharing reports in the admin center?

They are useful and we use them. They show what is broadly shared; they do not show what Copilot will say when asked, or how a connected agent behaves with hostile content. That is what the assessment adds.

Find out what your tenant will tell Copilot.

A short call to scope the tenant, the roles, and any agents. Testing runs under your authorization, with no production customer data required.

Written by the NXT AI research team. Product statements are Microsoft's own and linked to source. Last updated October 6, 2026.