A new advisory from Info-Tech Research Group is sounding the alarm for any organization that flipped on Microsoft 365 Copilot without a thorough housecleaning. The firm’s Govern Microsoft 365 blueprint, published July 22, warns that years of accumulated permissions, unchecked collaboration workspaces, and muddled ownership make it dangerously easy for AI to surface sensitive data to the wrong people. This isn’t a software vulnerability—it’s an operational crisis waiting to happen.

What Info-Tech’s Blueprint Actually Found

The research group analyzed how most Microsoft 365 tenants are actually managed. The picture is grim: default settings, one-off configurations, and no clear ownership for who creates, shares, or retires content. The result is a sprawling mess of open sharing links, stale Teams channels, and SharePoint sites with inherited permissions that no one reviews. Info-Tech calls this a governance vacuum, and it’s far more common than you’d think.

The blueprint stresses that the problem is not technical—Microsoft provides an enormous array of controls—but organizational. Without a policy-first approach, administrators treat individual settings as security fixes, missing the forest for the trees. Limiting external sharing or restricting Teams creation won’t help if you can’t answer the basic question: who should have access to what, and why?

Why Copilot Changes the Game

For years, oversharing was a latent risk. An employee could theoretically stumble across a confidential document in a shared library, but it required manual effort. Copilot removes that friction. It reads everything a user has access to—files, emails, Teams chats—and summarizes, answers questions, and generates content using that data. If your permissions are too broad, Copilot will happily serve up salary spreadsheets to an intern or display merger discussions to a frontline worker.

Info-Tech’s report notes that AI makes already-accessible information dramatically easier to find and use. So the urgency isn’t just about data hygiene; it’s about having an AI that weaponizes your lax governance. Organizations that rushed to deploy Copilot without auditing permissions are essentially handing employees a powerful search engine over improperly secured data.

Who’s at Risk and What’s at Stake

If you’re an individual using OneDrive for personal files, the risk is more limited. But the moment you share links with “anyone with the link” or invite guests, you’ve created a potential leak. For businesses, the exposure scales exponentially. A 500-person company that never defined who can create Teams sites might have 300 unmanaged groups, each with its own file repository, guest access, and no owner. A large enterprise could have thousands.

The consequences range from embarrassing leaks to regulatory fines. Info-Tech points to weak classification and messy permissions as a direct path to data spillage, especially when Copilot is allowed to crawl everything. If you’re in a regulated industry—healthcare, finance, law—the compliance implications are severe. Even without regulators, a single incident where Copilot reveals a sensitive strategy document can damage trust and investor confidence.

How Did We Get Here? The Evolution of M365 Sprawl

The pandemic supercharged Microsoft 365 adoption. Organizations frantically enabled Teams, SharePoint, and OneDrive to keep employees collaborating. Speed was the priority, not governance. Microsoft’s default settings are deliberately permissive to encourage adoption—anyone can create a Team, share files externally, and spin up a SharePoint site. Over time, this creates a jungle of content with no map.

Info-Tech’s advice isn’t new, but the AI twist makes it urgent. For years, we’ve had best practices around lifecycle management, access reviews, and data classification. Yet most IT departments are understaffed and overwhelmed, so governance takes a back seat. The emergence of Copilot finally gives a concrete, business-critical reason to clean house: because the cost of not doing so just skyrocketed.

Five Steps to Rein In the Chaos

The blueprint distills its guidance into five actionable governance pillars. These aren’t vague suggestions; they’re a roadmap for bridging the gap between policy and technical controls.

  1. Define governance objectives before touching settings. Decide the business purpose: Are you enabling secure external collaboration? Locking down regulated data? Eliminating orphaned workspaces? Your configuration must serve those goals.
  2. Assess where you stand today. You can’t fix what you can’t see. Audit sharing practices, permission structures, and ownership across Teams, SharePoint, and OneDrive. Look for inconsistencies—they’re the cracks where data slips through.
  3. Connect policies to enforceable controls. A PDF stating “don’t overshare” is useless if anyone can still create anonymous sharing links. Every rule needs a corresponding technical enforcement, whether a configuration setting, an approval workflow, or an automation.
  4. Assign clear ownership. IT, security, legal, and business units all have a role. Decide who approves new workspaces, who reviews access quarterly, and who retires stale content. Without accountable owners, nothing gets maintained.
  5. Communicate expectations to users. Even the best technical controls have gaps. Train employees on what’s acceptable: when to share externally, how to label sensitive data, and why you’re locking things down. Governance fails if users see it as an obstacle rather than protection.

The High-Risk Paths to Tackle First

If a full governance overhaul seems daunting, Info-Tech recommends starting with the collaboration paths that pose the greatest danger. These six areas account for most accidental exposures:

  • Locate and classify sensitive data. Use built-in tools like Microsoft Purview Information Protection to automatically label and protect confidential files.
  • Control who can create new workspaces. Limit Team and Group creation to a managed process. Rogue sites are the #1 source of uncontrolled sharing.
  • Harden external sharing. Review your tenant’s sharing defaults: disable “Anyone” links unless absolutely necessary, enforce guest expiration, and require approval for external invites.
  • Establish lifecycle management. Set expiration policies for inactive Teams and sites, and automate ownership reviews.
  • Align acceptable-use policies with real controls. If your employee handbook says “don’t share financials externally,” but your SharePoint allows it with a click, you have a disconnect that Copilot will exploit.
  • Reassess permissions before deploying AI. Before you expand Copilot to a new department, run a permission audit on their core data stores. It’s far easier to fix issues beforehand than to mop up after a leak.

What to Do This Week

For administrators reading this, the clock is ticking. Even if you’re not using Copilot yet, the same permission mess affects Teams and SharePoint searches. But the arrival of AI makes cleanup an urgent priority. Here’s a practical starting list:

  • Run Microsoft 365’s Permissions Management tool (if licensed) to spot overexposed resources.
  • Use the SharePoint “Sharing” reports to see all active sharing links and their type.
  • Check the Microsoft 365 Groups activity report for teams with no recent activity—they’re prime candidates for archival.
  • Review guest users in Azure AD and remove any that are no longer needed.
  • Create a small tiger team to draft a governance policy if none exists. Don’t aim for perfection; start with high-risk areas.
  • Communicate the why to your users before tightening controls, so you don’t trigger a rebellion.

If your organization is small and you wear all the IT hats, focus on the basics: restrict who can create Microsoft 365 Groups, disable anonymous links, and label your most sensitive folders. Every step you take reduces the blast radius when someone eventually asks, “Hey Copilot, what’s our Q3 strategy?”

The Bigger Picture: AI Governance on the Horizon

Info-Tech’s blueprint is a wake-up call, but it’s also a sign of things to come. Microsoft is pouring AI into every product—Windows, Office, Dynamics, Power Platform. Each new AI surface will again test your permissions and governance. The report’s central message is timeless: technology amplifies what you already are. If your data is a mess, AI will just make that mess more visible, more quickly, and more damaging.

The good news is that the tools to fix this exist today, built right into Microsoft 365. You don’t need a third-party suite or a consultant army; you need a commitment to treat governance as a continuous practice, not a one-time project. For organizations that take this seriously, Copilot can be a transformative productivity booster rather than a corporate liability. The choice is yours, but the window to avoid a headline-making data spill is closing.