Microsoft 365 · Last updated

Microsoft 365 Copilot Security and Governance: UK Guide

Copilot shows each user everything their permissions allow. The checks UK firms should run first: oversharing, labels, DLP, audit and data residency.

Nerdster Team

You are about to give every employee a search engine that has already been granted their permissions. That is Microsoft 365 Copilot, and it is why Copilot governance matters more than the licence decision.

Copilot drafts your documents, summarises your meetings, reads your spreadsheets, and answers questions from anywhere in your tenant. To do that, it reads everything the person asking is allowed to read. Not what you intended them to read. What your permissions currently say.

In most tenants those two things stopped matching years ago. A SharePoint site shared with “Everyone except external users”. A Teams channel anyone can join. A OneDrive folder opened up for a project that finished in 2022. None of it caused a visible problem, because nobody went looking. Copilot goes looking every time somebody types a question.

This guide is the governance framework we work through before we let a client switch Copilot on.

Fixing permissions before Copilot finds them for you

Copilot does not break your security model. It obeys it, exactly and instantly. If a junior analyst has read access to the board’s SharePoint site because someone shared it broadly three years ago, Copilot will quote board papers back to them the moment a question makes those documents relevant.

Before Copilot, that risk was theoretical. Your analyst had to know the site existed, find it, and read through it. Now “summarise our company strategy” does the work for them in four seconds.

Microsoft calls this oversharing, and its own documentation tells you to review permissions before deployment. Plenty of organisations skip it, because the review is dull and slow. That is the step you cannot skip.

What goes wrong without Copilot data governance

Copilot pulling salary and revenue data into a budget draft

Someone in marketing asks Copilot for help with a budget proposal. Copilot obligingly reaches into a finance site that was opened to all staff for a reason nobody remembers. The draft comes back containing salaries, margins, or an acquisition model.

Client A’s files turning up in Client B’s answers

In legal and financial services, the wall between client matters is the whole business. If your analyst works on Client A, asks Copilot a general question, and gets an answer drawn from Client B’s folder that they technically had access to, you have a confidentiality breach to report.

Performance reviews surfacing in everyday prompts

HR keeps performance reviews, disciplinary notes, and pay data in SharePoint. Where the access group is broader than HR believes, Copilot will surface that material whenever the context fits.

Board papers surfacing in “what is our growth strategy?”

Board packs, deal documents, and strategic reviews sitting behind loose permissions become available in plain English. Nobody has to hack anything. They just have to ask.

A Copilot governance checklist to work through before you deploy

1. Audit SharePoint Permissions

This is the single most important pre-deployment task. For every SharePoint site and document library:

  • Review who has access (members, visitors, owners)
  • Check for “Everyone” or “Everyone except external users” sharing
  • Review sharing links (anyone links, organisation-wide links)
  • Remove access that is no longer needed
  • Implement the principle of least privilege

Microsoft gives you tools to work with. SharePoint Advanced Management adds data access governance reports that find overshared sites, site access reviews that hand the question to site owners, and restricted content discovery, which keeps high-risk sites out of Copilot’s answers. Microsoft turns these on for tenants on enterprise plans such as E3 and E5 once at least one user has a Copilot licence; Business plan tenants are not on Microsoft’s list of eligible base subscriptions, so smaller firms usually work from the standard SharePoint admin reports instead. Either way, the tools tell you where the problems are. They will not tell you who should have access to what — that judgement is yours, and it is the slow part.

2. Clean Up OneDrive Sharing

Your people share OneDrive files freely, because sharing is the point. Review:

  • Files shared with “anyone with the link”
  • Folders shared with broad groups
  • External sharing that has outlived its project

Then change the default, so the next three years do not repeat the last three. Tighten your OneDrive sharing policies to stop broad sharing happening by accident.

3. Review Teams and Groups Membership

Every Team and Microsoft 365 group carries a SharePoint site behind it, and its membership sets your Copilot data access controls. Review:

  • Public Teams that should be private
  • Teams with open membership that should require approval
  • Guest accounts that have outlived their purpose
  • Groups with broad membership that reach sensitive content

4. Implement Sensitivity Labels

Microsoft Purview sensitivity labels classify and protect documents by content, and Copilot respects them. Before you deploy:

  • Define a label taxonomy (Public, Internal, Confidential, Highly Confidential)
  • Apply labels to existing sensitive content, using auto-labelling to cover volume
  • Encrypt Confidential and Highly Confidential documents through label policies. Copilot honours the usage rights: where a label’s encryption withholds the copy (EXTRACT) right, Copilot will not summarise that content
  • Restrict what Copilot can use from your most sensitive material with a Purview data loss prevention policy for the Microsoft 365 Copilot and Copilot Chat location, which stops Copilot processing files and emails with the labels you choose. The same policy type can also block prompts containing sensitive data such as card or passport numbers (a feature Microsoft still lists as in preview)

5. Configure Information Barriers (Where Required)

For FCA-regulated firms and legal practices, information barriers are how the ethical walls between client matters or deal teams are enforced inside Microsoft 365. They restrict who can communicate and share content across segments, and because Copilot only works with what the user can reach, a barrier that holds for the user holds for Copilot. This requires:

  • Defining barrier segments based on department, team, or function
  • Configuring barrier policies in Microsoft Purview
  • Testing that barriers hold before Copilot goes anywhere near production

One exception Microsoft documents: Channel Agent in Teams does not support information barriers and can return information that crosses them, so decide whether to turn it off in segmented tenants.

6. Deploy to a Pilot Group First

Never switch Copilot on for everyone at once. Start with 10 to 15 people:

  • Pick users from different departments and seniority levels
  • Watch what Copilot surfaces in their answers
  • Ask them about productivity and about anything they saw that surprised them
  • Fix permissions and policies before you widen the group
  • Expand in phases, not in one move

7. Establish Copilot Usage Policies

Write down what good use looks like:

  • Which questions are appropriate to ask Copilot
  • What to do when Copilot surfaces something the user should not have seen
  • How Copilot-generated content gets checked before it leaves the firm
  • Where Copilot must not be used at all, such as regulated advice

Make the second point easy to follow. If reporting an accidental disclosure feels like confessing, nobody will do it.

8. Enable Audit Logging

Microsoft Purview audits Copilot interactions automatically as part of Audit (Standard), which is how you prove your controls work. Each CopilotInteraction record shows who asked, when, in which app, and which files, sites and emails Copilot drew on — including their sensitivity labels. Make sure:

  • Auditing is on in your tenant (it is by default, but check)
  • Retention is long enough. Audit (Standard) keeps records for 180 days; Audit (Premium) lets you set retention policies of up to a year, or ten years with an add-on licence, which regulated firms usually need
  • You know where the words live. The audit log records the interaction, not the prompt and response text; for that you use eDiscovery or Purview’s AI activity tools
  • Somebody reads them, especially in the first weeks of rollout

Copilot security and compliance for UK organisations

Most of the controls above are the same wherever you are. Three points are specific to a UK firm’s compliance position.

Training and contractual terms. Microsoft states that prompts, responses and data accessed through Microsoft Graph are not used to train the foundation models behind Copilot, and that Copilot interactions are processed and stored in line with the commitments that already cover your other Microsoft 365 content. Its data, privacy and security documentation is the page to hand your data protection lead.

Where the processing happens. The UK is outside the EU Data Boundary, and Microsoft says customers outside the EU may have Copilot queries processed in the US, the EU or other regions. Microsoft announced in-country processing of Copilot interactions for UK customers in November 2025; an April 2026 update to that announcement now says it expects this to be available by the end of 2026. If data location matters to your clients or your regulator, record the current position in your risk assessment and revisit it when the option arrives.

Your own obligations. UK GDPR still applies to what Copilot touches. A data protection impact assessment is the natural place to record what personal data Copilot can reach, which controls limit it, and how long interaction data is retained. Microsoft publishes a Copilot risk assessment quickstart on its Service Trust Portal that can shorten that work.

Clear the permissions debt Copilot exposes

Your permissions problem was not one bad decision. It was thousands of small, reasonable ones: a folder shared here, a person added there, a temporary link that nobody ever revoked.

Copilot did not create that debt. It made it searchable.

Cleaning up before deployment is the urgent job. Keeping it clean is the real one. That means scheduled access reviews, sharing links that expire on their own, and a default of deny where broad access has to be asked for and justified.

Weigh the cost of Copilot against the cost of getting it wrong

On Microsoft’s UK site, Microsoft 365 Copilot for enterprise plans is £23.10 per user per month, and Copilot Business, for organisations of up to 300 users on Business plans, is £16.10 (£13.80 on Microsoft’s own introductory offer, bought direct, running to 31 December 2026). Copilot Chat is included in every plan at no extra cost, but the full product is not — our breakdown of what the July 2026 Microsoft 365 price change actually included sets out the difference before you buy seats.

Now weigh that against one client confidentiality failure, one data breach notification, or one regulatory finding. The subscription is not where your money is at risk.

Deploy it properly and the gains are real. Your people spend less of the day hunting for information, drafting from scratch, and catching up on meetings they missed. Those hours only count as a win if the deployment did not quietly create a new problem behind them.

A tenant audit before Copilot goes live

We take London businesses through the whole Microsoft Copilot deployment: permissions audit, data governance, pilot, training, and the ongoing reviews that keep it safe. We do the tedious part — reading through your SharePoint permissions, setting up sensitivity labels, and building the governance framework — so your rollout rests on controls you can point to. It sits alongside our Microsoft 365 management, so the tenant stays tidy after launch.

If you are weighing up Copilot, or you have already switched it on without a governance framework, book a free IT assessment with Nerdster. We will tell you what your tenant would expose today, and what to fix first.

CopilotMicrosoft 365AI governancesecurity

FAQ

Microsoft 365 Copilot Security and Governance: your questions answered

Does Microsoft 365 Copilot use our data to train its AI models?

No. Microsoft states that prompts, responses and data accessed through Microsoft Graph are not used to train the foundation models behind Copilot. Copilot interactions are processed and stored in line with the contractual commitments that already cover your other Microsoft 365 content.

Where is Microsoft 365 Copilot data processed for UK organisations?

The UK is outside the EU Data Boundary, and Microsoft says customers outside the EU may have Copilot queries processed in the US, the EU or other regions. Microsoft has announced in-country processing of Copilot interactions for UK customers and, in an April 2026 update, said it expects this to be available by the end of 2026.

Can we stop Copilot reading specific documents?

Yes. A Microsoft Purview data loss prevention policy for the Microsoft 365 Copilot and Copilot Chat location can stop Copilot processing files and emails that carry chosen sensitivity labels, and encryption that withholds the copy (EXTRACT) right stops Copilot summarising that content. The first control, though, is tightening who can open the document in the first place.

Related insights

Talk to our team about your IT

Tell us what you need. Our London team replies within 2 hours during business hours.

We respond within 2 hours during business days. Your data is handled per our privacy policy.

Contact details

IT assessment

A review of your IT, your security posture and your compliance readiness, free of charge.

  • 30-minute consultation call
  • Infrastructure & security review
  • Compliance gap analysis
  • Custom recommendations report