Skip to content

SharePoint · Microsoft Purview

Make information ready for wider use.

Address oversharing and information handling before expanding AI access.

Who should be involved: IT, information security, data owners and collaboration teams

What makes information ready for Microsoft 365 Copilot?

Information readiness for Microsoft 365 Copilot means that relevant content has accountable owners, appropriate access and understandable handling rules. Permissions determine who can reach information; sensitivity labels and discovery controls address different parts of its protection and use. Amplified Pi reviews these controls together and checks whether intended users can work while excluded users remain excluded. Labelling alone does not establish readiness.

When this is a good fit
Copilot or an agent will use shared business information, and the organisation cannot yet explain who can reach which content or who owns its quality.
Before you invest
Choose a business area with available information owners. Treat excessive access as an existing information risk, not only as a concern for a future AI deployment.

Clarify permissions. Add protection rules. Verify the result.

Example: internal project documents

Who should have access?

Clarify owners, groups, sharing links and exceptions.

How should information be handled?

Define labels and appropriate protection rules.

Does protection work in the intended use?

Test access and the agreed controls in practice.

Authorised person: required access works
Unauthorised person: access is denied
Verified controls and documented exceptions

Labels alone do not resolve excessive permissions. Actual behaviour is verified for the agreed use.

What we work on

  • Inventory a bounded set of sites, sharing links, memberships and accountable information owners.
  • Remediate excessive permissions and agree classification, retention and sharing practices.
  • Configure and test the agreed Purview controls with permitted and denied access scenarios.

What you take away

  • An exposure register with owners, priorities and remediation decisions.
  • A tested permissions and labelling baseline for the pilot scope.
  • An information ownership and review routine, with open exceptions recorded.

How we approach the work

We start with the information people will actually use in the pilot. The aim is a dependable working boundary: relevant content, accountable owners and access that behaves as intended. This is more useful than trying to label the entire tenant before learning where the real exposure sits.

  1. Identify exposure in a bounded content estate

    We select the sites, libraries and user groups involved in the use case. Owners review broad groups, external guests, old project memberships and sharing links. We distinguish active information from stale or duplicated material and record who can approve a change.

    What you receive

    A prioritised register of exposure, content quality issues and owners.

  2. Repair access without breaking the work

    We agree intended access with the business owner before changing membership or sharing. Changes are sequenced so teams can continue working. Emergency needs and unresolved exceptions receive an owner and a review date rather than becoming undocumented permanent access.

    What you receive

    A reviewed access model and a controlled remediation backlog.

  3. Define understandable information handling

    We turn the organisation’s classification rules into a small set of examples users can recognise. We assess where file labels, encryption, site settings and data-loss controls are appropriate and supported. Retention and deletion are considered separately from confidentiality.

    What you receive

    A scoped configuration plan and guidance for content owners.

  4. Prove the boundary with different users

    The same sample is tested as an authorised colleague, an excluded colleague and, where relevant, a guest. We inspect direct access and the intended AI experience, record false blocks and retest after changes. Site owners receive a repeatable review routine.

    What you receive

    Access-test evidence, documented exceptions and a handover to named owners.

The guidance behind the approach

Permissions, labels and discovery solve different problems

Microsoft’s deployment guidance separates oversharing remediation from protective controls. A site label does not automatically label its documents. We therefore review site settings, file protection and access rights separately rather than treating a label as proof that content is safe.

Reference: Microsoft: secure and governed Copilot foundations; Microsoft: sensitivity labels for groups and sites

Turn Zero Trust into testable controls

Explicit verification checks identity and access conditions; Conditional Access can bring identity and device signals into policy decisions. Least privilege limits access to the work that is needed. Assuming breach means planning for compromise rather than trusting the tenant boundary. In our scope, identity owners review authentication and device requirements, data owners confirm permissions, and the support team agrees how to detect, contain and investigate an exposure.

Reference: Microsoft: Zero Trust security principles; Microsoft: Entra Conditional Access

Illustrative example

Example: project information beside commercial terms

A project site contains delivery guidance and a restricted pricing file. A team member should find the guidance but not retrieve the pricing content. We check memberships, links and file protections, then test both outcomes. Adding a site label without verifying the restricted file would not close the issue.

What we need to get started

  • Site and information owners for the pilot area
  • Existing classification, sharing and retention rules
  • Representative test accounts and approved sample documents

Questions before you begin

Do we need to clean the whole tenant before starting?

We propose starting with a risk-based, agreed scope and expanding from the findings. That does not make unresolved exposure elsewhere acceptable; it gives owners a practical order for remediation and a clear pilot boundary.

Does hiding content from AI search fix excessive access?

Discovery settings and permissions are different controls. A content item that is less discoverable may still be reachable through another route. The access decision must be checked independently of the AI search experience.

Related modules

The decision at the end

Data owners accept remaining exceptions; representative users can access what they need and are denied what they should not see.

How progress is judged

Track unresolved exposure, owner coverage and success of access-control tests.

Scope boundary

Labels alone do not fix permissions. Purview features, licences and control coverage must be confirmed for the actual workload.

Choose the next step from the evidence.

The next module depends on the constraint revealed by the work. You do not need to complete every module.

Explore the other modules

Product and policy references

  • Copilot architecture and data protection
  • Purview for Microsoft 365 Copilot
  • Microsoft: secure and governed Copilot foundations
  • Microsoft: sensitivity labels for groups and sites
  • Microsoft: Zero Trust security principles
  • Microsoft: Entra Conditional Access

Next step