Microsoft 365 · Security & Governance · 9 min read

Your Microsoft 365 Environment Isn't Ready for AI — And Copilot Will Expose It
AI isn't creating your Microsoft 365 security problem. It's revealing the one you already had.
Most organisations approach Microsoft 365 Copilot as a licensing decision. Buy the seats, enable the service, run a pilot, measure productivity. What actually happens in the first weeks is different: Copilot starts answering questions with content people technically had access to but never realised they could find.
The core point
"AI doesn't necessarily create new access. It makes existing access dramatically more useful."
Copilot inherits your permissions — all of them
Microsoft 365 Copilot respects the permission model. That sentence is usually offered as reassurance, and it is technically correct. The uncomfortable part is what it implies: if your permission model is ten years of accumulated exceptions, inherited grants and "just share it with everyone for now" decisions, Copilot respects that too.
Before Copilot, bad permissions were protected by friction. Nobody browsed 400 SharePoint sites looking for a salary spreadsheet. With natural language search across the tenant, that friction disappears. The data was always reachable. It simply wasn't discoverable.
Where the real risk lives: SharePoint and OneDrive
In practice, the majority of Copilot surprises come from SharePoint permissions and OneDrive sharing rather than from the AI service itself. The usual suspects:
- Sites where inheritance was broken once, years ago, and never reviewed.
- "Everyone except external users" applied to a site that later became the home of HR or finance content.
- Anonymous sharing links with no expiry date, created for a single meeting in 2022.
- Team sites left behind after a reorganisation, still full of drafts nobody wants surfaced.
None of this is exotic. It's the normal residue of a busy organisation. It just becomes visible the moment someone asks Copilot a direct question.
The security model: Identity → Device → Access → Data → AI
When I plan Microsoft 365 AI readiness, I work through five layers in order. AI is the last one for a reason: it consumes the output of everything below it.
Identity
Who the user really is. MFA, Conditional Access, guests and dormant accounts in Microsoft Entra ID.
Device
What they work from. Intune enrolment, compliance policies and a known, healthy endpoint.
Access
What they are allowed to reach. SharePoint permissions, OneDrive sharing, Teams membership.
Data
What the content actually is. Sensitivity labels, retention and Microsoft Purview governance.
AI
Copilot sits on top of all of it — and inherits every decision made in the four layers below.
Identity: Entra ID is the first control, not the last
Every Copilot response is delivered to an identity. If that identity can sign in without MFA, from any device, anywhere, then the strength of your data governance is irrelevant — you've already lost the argument at the front door.
The baseline in Microsoft Entra ID is unglamorous and well understood: MFA for everyone, legacy authentication blocked, admin roles separated from daily accounts, and Conditional Access policies that actually reflect how people work. I've written a full walkthrough in this practical guide to Entra Conditional Access, and a smaller-organisation version in Entra ID for small and medium businesses.
Then there are the identities nobody talks about: guests from finished projects, shared mailboxes with interactive sign-in, service accounts with permanent elevated rights, and dormant accounts of people who left. Access reviews exist precisely for this, and AI readiness is a good excuse to finally run them.
Device: compliance is part of data security
Microsoft Intune device compliance determines whether the endpoint reading your AI-generated summaries is encrypted, patched and managed. Tying Conditional Access to compliant devices is the single highest-value control most organisations still haven't fully enforced. If you're planning that work, my notes from migrating 500 users to Intune cover the pitfalls honestly.
Worth repeating
"Good AI governance often starts with boring IT housekeeping."
Data: Purview, labels and the content nobody owns
Microsoft Purview is where AI readiness becomes a data governance exercise. Sensitivity labels let you express what content is, retention policies decide how long it survives, and classification tells you what you're actually holding. Copilot is far easier to govern when labelled, classified content exists — and nearly impossible to govern when it doesn't.
Start small. A label taxonomy with four clear options that people use beats a twelve-level scheme that everyone ignores. Apply it where the risk is real: personal data, finance, legal, HR, customer contracts.
Then deal with the archaeology. Old Teams and SharePoint sites are where the genuinely awkward documents live. Archiving or deleting them is unglamorous work with an immediate payoff: content that doesn't exist can't be surfaced.
How to run a Copilot pilot that tells you something
A pilot that only measures "did people like it" is a wasted opportunity. Pick a mixed group — HR, finance, sales, IT — precisely because their content sensitivity differs. Ask participants to report not just useful answers, but anything that surfaced which felt wrong. Treat each of those reports as a permissions finding, not as a Copilot bug.
Pilot mindset
"The objective of an AI pilot shouldn't simply be proving that AI works. It should be discovering where your organisation doesn't."
The Microsoft 365 AI Readiness Checklist
Ten checks. None of them require Copilot licences, and all of them improve your Microsoft 365 security posture whether or not you ever deploy AI.
Map SharePoint permissions
Run a permissions report across your top sites. Find broken inheritance, site-wide 'Everyone except external users' grants and sites nobody owns any more.
Audit OneDrive and link sharing
Check default sharing link types, anonymous links and links with no expiry. Tighten the tenant default before Copilot makes that content easy to surface.
Enforce MFA everywhere
No exceptions for service accounts used interactively, admins or executives. Copilot is only as trustworthy as the sign-in behind it.
Review Conditional Access
Require compliant or hybrid-joined devices for access to Microsoft 365 data, block legacy authentication, and keep break-glass accounts documented and tested.
Clean up guests and dormant identities
Guests from a project that ended in 2023 still count as people who can be surfaced content. Use access reviews and remove what nobody can justify.
Confirm Intune device compliance
Encryption, patch level, defender status, enrolment coverage. An unmanaged laptop reading AI-summarised company data is a governance gap, not a productivity win.
Deploy sensitivity labels
Start narrow: a small, understandable label set applied to the content that genuinely matters. Labels are the language your AI governance will speak later.
Turn on the Purview basics
Data classification, retention policies and DLP for the obvious categories — personal data, finance, contracts, HR. You cannot govern what you have never classified.
Archive dead Teams and SharePoint sites
Old team sites are where outdated salary sheets, draft reorganisation plans and abandoned customer data live. Archive or delete before you index them.
Define your pilot and its success criteria
A small, mixed group. Clear rules on what to report. And an explicit expectation that surfacing a permissions problem counts as a successful outcome.
If you can tick all ten honestly, you're ready for Copilot. If you can't, you've just built your Microsoft 365 security roadmap for the next two quarters.
The question to ask before you buy a single licence
Strip away the vendor material, the productivity statistics and the pilot enthusiasm, and AI readiness comes down to one uncomfortable question in a leadership meeting:
"If AI suddenly made everything our employees are already allowed to access easier to discover tomorrow, would we be comfortable with what they find?"
If the answer isn't an immediate yes, you have just discovered where your AI strategy should begin.
Not with AI.
With your Microsoft 365 environment.
For the productivity side of the story, I've covered the practical use cases in the Microsoft 365 Copilot business guide and ten practical ways to save time with Copilot. For the operational angle, see how AI is transforming IT support and hybrid cloud migration strategy.
Working on this?
I help organisations get Microsoft 365, Intune, Entra ID, Conditional Access, identity, endpoint management and data governance into a state where AI is a sensible next step. See my Microsoft 365 work, my Intune and Entra ID focus areas, or get in touch to talk it through.
About the author — Davor Smajilovic, 15+ years of professional IT experience and 17 professional certifications including Microsoft, Cisco, ITIL and Skillsoft. Previously Technology Specialist at Lenovo (2022–2026), now open to new IT opportunities in Copenhagen. More on my skills or working together.
More about my Copenhagen IT profile
I work with businesses in Copenhagen, across Denmark and the Øresund region on Microsoft 365, Intune, Entra ID and day-to-day IT support.