1Security + Microsoft 365 Copilot

Copilot answers from what your users can already open. Check that first.

Copilot returns only content the asking user is allowed to see. That is the right design, and it means Copilot inherits every permission your tenant collected over the years - in a typical tenant, around 200,000 files per ordinary account. 1Security shows that list per user before you assign the first license, ranks it by sensitivity, and cleans it up behind a review window.

  • 200,000
    files an ordinary account can open in a typical tenant
  • 3 years
    of activity history, Copilot and agent usage included
  • Same day
    from read-only consent to the first per-user exposure list

What Copilot does

Copilot is grounded in your tenant and respects your permissions.

Three design decisions that make Copilot safe to build on - and the reason the work before rollout is about permissions, not about Copilot.

  • Grounded in your data, with citations

    Copilot reasons over your own files, mail, chats and meetings through the Microsoft Graph and cites the source item. Answers come from work that actually happened in your organisation, not from a plausible generalisation.

  • Security trimming by design

    Copilot surfaces only content the user has at least view permission to, and the semantic index respects the same access boundary. Where a Purview label applies encryption, protected content comes back only to users allowed to extract it. Prompts, responses and Graph data are not used to train the foundation models.

  • A platform for agents

    Copilot Studio and declarative agents let a business team build a purpose-built assistant over a chosen set of sites, files and connectors in an afternoon. It is why the number of agents in a tenant grows faster than anyone planned for - and why they need an inventory.

The question before rollout

What would Copilot return for each of your users today?

The permissions Copilot inherits were never meant to be searched in plain language. They accumulated one exception at a time: a folder shared with "Everyone except external users" for one deadline, a site nobody has opened since 2019, an anyone link on a spreadsheet, a guest who stayed after the project ended. None of it felt urgent, because nobody could find those files anyway.

Semantic search changes that. What used to take a site name, a folder path and a file title now takes a good question. Week one of a rollout is when someone asks "what is our redundancy plan?" and gets a correct, correctly-permissioned answer nobody intended them to have.

The deployment guidance is clear: reduce oversharing before you switch Copilot on, and keep monitoring afterwards. Doing that needs a tenant-wide list of who - and which app, and which agent - can reach what right now. That list is what 1Security produces on the first day.

What 1Security adds

The per-user exposure list, the cleanup, and the agent inventory.

1Security connects read-only to the same tenant and resolves every identity - people, guests, apps, AI agents, devices - to what it can open and what it actually did.

  1. 01

    See what each pilot user could get back

    Before a single license is assigned: open Users, pick the pilot group, and get every file each of them can reach, ranked by sensitivity instead of alphabetically. Payroll, board packs, legal, credentials - a list to fix, not a risk to accept.

  2. 02

    Fix the oversharing behind a review window

    Sites with sensitive info and Copilot enabled, anyone links on sensitive files, tenant-wide grants, guests still sitting in project sites. Block org-wide search on a site, expire the links, remove the grants - staged as proposals with a 72-hour review window, so nothing changes without a person deciding.

  3. 03

    Count the agents next to the people

    Copilot Studio agents, declarative agents and third-party AI apps are identities with their own scopes and knowledge sources. Agents lists all of them: what each can reach, how many users, files and sites, which are active and which were built once and forgotten.

  4. 04

    Watch adoption and drift after go-live

    Who is using Copilot versus who holds a license, and whether the amount of reachable sensitive data is shrinking or growing week over week - as a trend with an alert line. Three years of activity history on standard licenses.

How the two fit together

Copilot answers. 1Security shows what it can answer from.

Copilot stays the assistant, grounded in the Graph and trimmed by your tenant's own permissions. 1Security connects to that same tenant with read-only consent, no agents to install and standard Microsoft licenses, and resolves the level underneath: every identity, every effective permission, three years of activity. Fix the permissions with 1Security and Copilot's security trimming becomes a boundary you have measured. First findings land the same day, usually well before the licenses do.

The three weeks before go-live

The rollout that does not pause in week two.

The pattern repeats in almost every deployment. A pilot group is chosen, the licenses are assigned, and within days someone in that group retrieves something they should never have been able to find. The permission was always there; Copilot made it reachable. The rollout pauses, and the security team is asked for a number nobody has: how much more of this is there?

Run in the other order, the same three weeks look different. 1Security resolves what each pilot user can reach and ranks it by sensitivity. The dangerous grants - the tenant-wide shares, the live anyone links, the finance site with an inherited "Everyone" entry - get trimmed through reviewed, reversible automations with a grace period. Then the licenses go out.

Same deployment, same licenses. The difference is whether the exposure list is produced by your security team in week one or by an executive in week four.

Roll out Copilot on a tenant you have checked.

Connect read-only in the morning. By the end of the day you have the ranked list of sensitive data Copilot could return for each pilot user, and the cleanup queued behind a review window.

Or find out what Copilot can reach in week two.