Microsoft Copilot security
Copilot reads what your users can already reach. Usually 200,000 files.
Copilot does not break permissions - it uses them, at machine speed, in the answer of anyone who asks. In a typical tenant an ordinary account can reach hundreds of thousands of files, dozens of sites hold card numbers or ID numbers behind anyone links, and 30-50 AI agents already exist that nobody has listed. 1Security shows you all of that before the licenses go out - and, once you turn write access on, revokes, blocks or grants that access behind a review window.
- 100k+files an ordinary account can typically reach - and therefore Copilot can quote to it
- 30-50AI agents already present in a typical mid-size tenant, across Copilot, Copilot Studio and Entra
- 1 dayfrom read-only consent to your first Copilot exposure numbers
The problem
Copilot is a search engine over every permission mistake you ever made.
Copilot inherits what each user is allowed to open. Copilot security starts with permissions.
For years oversharing was harmless in practice: the payroll folder was open to Everyone except external users, but nobody knew the URL. Copilot removes that last protection. A user asks "what is our salary band for senior engineers" and gets the answer, correctly cited, from a file they were technically allowed to read all along. In a typical tenant more than half of all files sit in sites nobody has opened in a year - Copilot indexes those too.
The second half of the problem is agents. A Copilot Studio maker points an agent at a SharePoint site. A developer registers an agent in Entra. A vendor ships a wrapper with its own service principal. Each is configured in its own place - a knowledge source is a pointer, a permission is a scope string. What configuration alone does not tell you is how many files, mailboxes or people that adds up to.
1Security produces that single number - how much sensitive data this user, or this agent, can pull into an answer - from the permission graph it already holds, on standard licenses, read-only. It works alongside SharePoint Advanced Management and Purview if you run them.
What you get
What Copilot can read, per user, per site, per agent.
Six numbers a Copilot rollout needs, each a filter or a column in 1Security.
Files reachable per user
Open any account in Users and read one number: how many files it can open through direct grants, sharing links, nested groups and inheritance - and how many of those carry sensitive data. Sort the whole company by it.
- sites x sensitive info
Copilot-enabled sites with sensitive data
Sites carries a Copilot-enabled flag next to detected sensitive-info counts and anyone links. Filter Copilot enabled + with sensitive info, sort by detections: that list is your rollout blocker.
One agent inventory
Copilot and Copilot Studio declarative agents, Entra Agent ID agents, Azure AI Foundry and vendor wrappers in one list, with publisher, verification status, the admin who consented, and last activity.
- files · sites · users · emails
Agent reach in numbers
Every agent's knowledge sources are resolved to the content behind them. A knowledge source is a pointer; 1Security shows "this agent can read 41,000 files across 12 sites, 3,100 of them with personal data".
- 300+ detectors
Sensitive data inside the reach
1Security's own scanner - 300+ sensitive information types plus OCR for scans and screenshots - finds card numbers, IDs, credentials and health data in the files Copilot and each agent can read. No E5 required - Purview labels are shown alongside.
Grant, revoke, block - behind a review window
Revoke the grant or nested membership an agent inherits its reach through, block Copilot org-wide search on an exposed site, close its external sharing, expire anyone links - or grant the scoped access somebody actually needs. Write access is a separate consent; every action is staged as a proposal with a 72-hour review by default, owner review optional, all of it logged.
In practice
The pre-rollout check, in four steps.
What a Copilot readiness pass looks like in 1Security - most tenants finish it the day they connect.
- 01
Connect read-only, get the numbers
The first scan resolves effective access for every user and site. The first surprise is usually the median: how many files a normal employee can open. It is common to see six figures.
- 02
List the sites Copilot should not be quoting yet
Sites: filter Copilot enabled + with sensitive info + anyone links or Everyone access, sort by detections. In a mid-size tenant this is typically 30-80 sites - short enough to fix, long enough to justify the pause.
- 03
Review the agents nobody mentioned
Agents: sort by files in reach, then filter to unverified publisher, or to agents that can both read email and act. Orphaned agents unused for months but still holding reach show up here too.
- 04
Stage the fixes, then measure
Enable the suggested automations - block org-wide search, expire the links, restrict the agents. Proposals wait 72 hours for review. Afterwards the "Sensitive Data Exposure to Copilot" trend keeps the number on a chart so it stays down.
What 1Security adds
From configuration to files.
Configuration says what is set. 1Security turns it into files, sites, users and emails.
- How many files each user can actually reach, and how many of them hold sensitive data - one number per account
- Copilot-enabled sites crossed with detected sensitive info and anyone links, in one list
- Every agent - Copilot Studio, Entra Agent ID, Azure AI Foundry, vendor - as one record with its reach in files, sites, users and emails
- Knowledge sources resolved to the content behind them, with the sensitive types inside
- Blueprints as a governed object: an unverified blueprint and its fifty child agents are one filter
- An activity baseline per agent, so a deviation raises an alert
- 300+ detectors and OCR on standard licenses, next to imported Purview labels
- Grant, revoke and block run through the same engine that measured the reach - opt-in, staged behind a review window, every action logged
Deployment
Live before the pilot ends.
One read-only consent covers the whole tenant. Nothing is installed on endpoints, no appliance, no log forwarder. File content is streamed into analysis and discarded - your documents never become a second copy anywhere.
- 0write permissions needed to see every number on this page - the write module is a separate, optional consent
- Day 1Entra Agent ID, Azure AI Foundry and app-layer agents on the licenses you already own - Copilot Studio agents follow your Agent 365 licensing
- 72 hdefault review window before any staged fix executes; instant, 24 h and 7 days are the other presets
Use cases
Before rollout, in production, at audit time.
Before rollout: run the four-step check and decide what Copilot reads instead of finding out from a generated answer. Most tenants cut the exposed-sensitive-sites list to zero within a week of connecting.
In production: watch per-agent baselines. When a vendor's wrapper starts reading ten times its usual volume, or a new agent appears with tenant-wide read, you get an email the same day with the exact activity listed.
At audit time: every agent, its publisher verification, who admitted it and what it can reach - the AI section of your NIS2 or ISO 27001 evidence, exportable as it stands today.
Keep exploring
Where the Copilot story continues.
Microsoft 365 alerts
Per-agent anomaly episodes and instant alerts the moment an agent or a user crosses a line you drew.
See the alerts tool →Microsoft 365 inventory
Agents next to apps, users, sites, devices and files - the whole tenant in one model.
See the inventory tool →SharePoint governance
The Copilot-enabled flag per site, crossed with where sensitive data concentrates and who can reach it from outside.
See SharePoint governance →Agents beyond Copilot
Copilot Studio, Azure AI Foundry, Entra Agent ID and third-party agents on one graph - and how that sits next to Microsoft Agent 365.
See it next to Agent 365 →
FAQ
Copilot security, asked directly.
Do we need E5, Purview or Copilot licenses for this?
No. Reach, sensitive-data detection and the Copilot-enabled site view run on standard Microsoft 365 licenses over a read-only connection, and Entra Agent ID, Azure AI Foundry and app-layer agents appear from day one on the licenses you already own. Copilot Studio and declarative Copilot agents sit under Microsoft Agent 365 licensing, and 1Security follows that model: license what you decide to license, and those agents light up in the same inventory. Without it they still appear as enterprise apps with their app-level permissions - you lose detail, never the inventory.
Does 1Security read our documents?
Content is streamed into analysis to detect sensitive information types and then discarded. Only the detection type, match count and confidence persist - matched values are never written to the database.
Can 1Security actually stop Copilot reading a site?
Yes, under the separately consented write module: block Copilot org-wide search on selected sites, close their external sharing, expire or remove sharing links, revoke the grant or nested membership an agent inherits its reach through, or disable the account it runs under - each staged as a proposal with a 72-hour review window by default, routable to the resource owner, and recorded in one audit trail.
How is this different from SharePoint Advanced Management?
SharePoint Advanced Management adds site-level reports inside SharePoint. 1Security resolves effective access per user and per agent, detects sensitive data with its own engine and stages fixes - across SharePoint, OneDrive, Teams, Exchange and agents, on standard licenses. The two work side by side.
What about agents we did not build - vendor wrappers?
They appear in the same inventory with publisher and verification status, the admin who consented to them, their activity, and their reach. The supply-chain check - unverified publisher plus real data reach - is a single filter.
See what Copilot would read. Then decide.
Connect read-only in the morning and by the evening you have the files-per-user number, the list of Copilot-enabled sites with sensitive data, and every agent with its reach.
Or find out what Copilot could reach from a generated answer.








