Deep dive Copilot in the enterprise / 3 of 6

Rolling out enterprise Copilot without breaking your DLP posture

Sensitivity labels, Graph permissions and the three settings that decide the outcome.

Rolling out enterprise Copilot without breaking your DLP posture — Deep dive article banner on grbadhon.com

A Copilot licence does not grant access to anything. It surfaces access that was already there, which is why a rollout that looks like a licensing exercise turns into a discovery exercise about ten days in.

What oversharing actually means here

Copilot grounds its answers in whatever the signed-in user can already open. If a finance workbook sits in a site with a company-wide sharing link on it, that workbook was always reachable. The difference is that finding it used to require knowing it existed, and now it requires asking a question in plain English.

That distinction matters because it changes who is accountable. The permission was granted years ago by someone who has since left. The prompt was typed this morning.

Worth knowing

Run the baseline before you assign a single licence. Once people are using it, every number you collect is contaminated by the rollout itself.

Baseline before you touch a setting

Pick twenty users across four departments and measure how many files each one can technically open. Not how many they do open, how many they could. In the tenants I have worked in, the number is consistently between eight and forty times what anyone estimates.

SharePoint Advanced Management reports this directly. Without it, a Graph query against each user’s accessible sites will get you close enough to make the argument.

The three settings, in order

Order matters more than the settings themselves. Restricted SharePoint Search first, because it buys you time without breaking anything. Sensitivity labels second, applied in simulation mode until the false positive rate is under about two percent. Copilot grounding scope last, once the first two have settled.

Doing this in the other order produces a fortnight of help desk tickets and a stalled programme.

What the labels have to cover

Three categories account for almost every genuine incident: HR records, anything with unreleased financials, and the shared drive that predates the current intranet. Label those three well and the long tail stops mattering much.

Tenant impact

Restricted SharePoint Search caps you at one hundred sites in the allow list. On a large estate that is a real constraint, and it shapes which sites you migrate first.

How to know it worked

Re-run the baseline ninety days later with the same twenty users. If the reachable-file count has not fallen by at least half, the labels are not doing what you think they are doing. That measurement is the whole programme, and it is the one most teams skip.

Common questions

No. Copilot reads only what the signed-in user could already open. It surfaces existing access rather than granting new access, which is why an oversharing problem discovered during a Copilot rollout predates the rollout.

Not strictly, but you need them before a wide rollout. Restricted SharePoint Search will hold the line for a pilot group. Labels are what make the position sustainable past a few hundred users.

In an estate of a few thousand seats, budget six to ten weeks from baseline to wide rollout. Most of that is deciding what should be restricted, not configuring anything.

Assigning licences before baselining. Once people are using Copilot, every access measurement you take is contaminated by the rollout, and you lose the ability to prove the programme worked.