1Security + Microsoft 365 Copilot

Copilot honours your permissions perfectly. That is exactly the problem.

Every answer is grounded in the Microsoft Graph and trimmed to the asking user’s own access - Copilot will never surface a file that person could not already open. It is the right design. It also means Copilot inherits, in one afternoon, every permission your tenant accumulated over a decade. 1Security is the map of what it inherited.

  • 98%
    of granted permissions are never needed
  • 3 years
    of activity history, Copilot usage included
  • Same day
    from read-only consent to the first exposure list

Credit where due

What Copilot does brilliantly.

Three things Microsoft got right, and none of them are the reason rollouts stall.

  • Grounded in your tenant, not the open web

    Copilot reasons over your own files, mail, chats and meetings through the Microsoft Graph, with citations back to the source item. Answers come from work that actually happened in your organisation instead of a plausible-sounding generalisation.

  • Security trimming by design

    Microsoft’s own wording: Copilot only surfaces organizational data the user has at least view permissions to, and the semantic index honours the same identity-based access boundary when it grounds an answer. Where a Purview label applies encryption, content comes back only if the user holds the EXTRACT usage right. Prompts, responses and Graph data are not used to train the foundation models.

  • A platform, not a chat box

    Copilot Studio and declarative agents let a business team stand up a purpose-built assistant over a chosen set of sites, files and connectors - which is why the agent count in a tenant grows far faster than anyone planned for.

The mirror problem

Copilot does not create the exposure. It finds it.

The permission model Copilot inherits was never built to be queried in natural language. It accumulated one exception at a time: a folder shared with “Everyone except external users” for a single deadline, a site nobody has opened since 2019, an anonymous link on a spreadsheet, a guest who stayed after the project ended. None of it was ever wrong enough to fix, because nobody could find those files anyway.

Semantic search removes obscurity as a control. What used to require knowing a site name, a folder path and a file title now requires knowing what to ask. Week one of a rollout is when someone types “what is our redundancy plan?” and gets a genuinely correct, correctly-permissioned answer that nobody intended them to have.

Microsoft says as much: the deployment guidance leads with reducing oversharing before you turn Copilot on, and monitoring it afterwards. What it does not hand you is the tenant-wide map of who - and which app, and which agent - can currently reach what. That part you have to bring.

The complement

What 1Security adds around the rollout.

1Security is a permission-centric decision engine for Microsoft 365: it maps every identity - human, app, AI agent, device - what it can reach, and what it actually did.

  1. 01

    The pre-flight exposure list

    Before a single licence is assigned: every file each pilot user can reach, ranked by sensitivity rather than alphabetically. Payroll, board packs, legal, credentials - surfaced as a list to fix, not a risk to accept.

  2. 02

    The oversharing that survives go-live

    Dormant anonymous links, tenant-wide grants, guests still sitting in sites, folders inheriting from a permission set nobody remembers approving. The exact patterns that turn into instant retrieval the moment semantic search is switched on.

  3. 03

    Agents counted alongside the humans

    Copilot Studio agents and third-party AI apps are identities with consented scopes and knowledge sources of their own. One inventory for all of them - what each can reach, which are active, which were built once and abandoned.

  4. 04

    Adoption and drift, measured

    Who is actually using Copilot versus who is holding a licence, and whether reachable-sensitive-data is shrinking or growing week over week. Three years of activity history, no SIEM contract required.

Joint architecture

Copilot answers. 1Security decides what it is allowed to answer from.

Copilot stays the assistant, grounded in the Graph and trimmed by the tenant’s own access controls. 1Security connects to that same tenant with read-only consent, no agents and standard Microsoft licences, and resolves the layer underneath - every identity, every effective permission, three years of activity. Fix the permission model with 1Security, and Copilot’s security trimming stops being a promise you hope holds and becomes a boundary you have measured. First findings land the same day, which is usually well before the licences do.

The three weeks before go-live

A rollout that survives contact with the executive floor.

The pattern repeats in almost every deployment. A pilot group is chosen, the licences are assigned, and within days someone in that group retrieves something they should never have been able to find. The permission was always there; Copilot just made it reachable. The rollout pauses, and the security team is asked for a number nobody has: how much more of this is there?

Run in the other order, the same three weeks look different. 1Security resolves what each pilot identity can reach and ranks it by sensitivity. The genuinely dangerous grants - the tenant-wide shares, the live anonymous links, the finance site with an inherited “Everyone” entry - get trimmed through reviewed, reversible automations with a grace period, so nothing irreversible happens without a human decision. Then the licences go out.

Same deployment, same licences. The difference is whether the exposure list is produced by your security team in week one or by an executive in week four.

Deploy Copilot on a tenant you can vouch for.

Read-only consent in the morning - by the end of the day, the ranked list of sensitive data Copilot would be able to reach.

Or find out what Copilot can reach the way everyone else does.