Skip to main content
Kumonix - Microsoft Solutions Partner
All articles

Copilot Rollout? Clean Up Your Tenant First

Copilot surfaces whatever a user already has permission to see. Here's what law firms and professional services firms need to check before switching it on

Kumonix Team 5 min read

Copilot rollout is the project on everyone's list this year. What's rarely on that list, until it's too late, is a proper permissions audit beforehand. That gap is where most of the real risk in a Copilot rollout actually sits, and it has nothing to do with the AI itself.

Here's the thing people misunderstand about Copilot. It doesn't grant anyone new access to anything. It works entirely within the permissions that already exist in your tenant. If it can find something, it's because a user already had the technical ability to open it. Copilot just makes that access faster, more visible, and much easier to stumble into by accident.

For a firm handling client files, financial records, or privileged correspondence, that distinction matters enormously.

The problem was already there, Copilot just finds it

In every M365 tenant we review, permission sprawl is the norm rather than the exception. It builds up slowly and nobody notices because, most of the time, it doesn't matter. A SharePoint site set up for a project that ended two years ago, still open to the whole firm because nobody thought to lock it down when the project closed. A shared drive with "everyone" access granted years ago for convenience and never revisited. A folder shared with a client that quietly ended up visible to half the firm.

None of that causes a problem on its own. Nobody's actively looking through old project files. But Copilot changes that. It's designed to search, summarise, and surface content quickly, based on a plain-language question. Ask it something innocuous, and it may return a summary of a document that technically anyone could have opened, but that realistically nobody was ever meant to see.

That's not a Copilot flaw. It's Copilot doing exactly what it's built to do, against a permission structure that was never properly tidied up.

Leavers and inactive accounts make it worse

Offboarding is another place this shows up. When someone leaves a firm, their account access doesn't always get fully removed on day one. Sometimes it lingers for weeks. Sometimes shared mailbox access or old group memberships get missed entirely.

Copilot doesn't distinguish between an active employee and an account that should have been shut down months ago. If the access is technically still there, the content connected to it is fair game. A rollout is a good forcing function to finally close that gap, but only if someone actually checks for it first.

The surface is getting wider, not narrower

This isn't a static problem either. Microsoft has recently expanded what Copilot can connect to beyond your own tenant. Admins can now manage federated connectors that let Copilot pull in data from external sources through the Model Context Protocol, rather than being limited to content already indexed inside Microsoft 365.

That's a genuinely useful capability. It also means the question "what can Copilot see" now has to include external connections your firm has approved, not just internal file shares. If you're planning a rollout, knowing exactly what's been connected, and why, is part of the same conversation as the permissions audit. This isn't a one-off check you do and forget. As Copilot's reach expands, the review needs to keep pace with it.

What to do before you flip the switch

You don't need to halt a Copilot rollout to do this properly, but the order matters. Do the review first, not as a cleanup exercise afterwards.

Start with a proper audit of who has access to what across SharePoint and shared drives, particularly anything set up more than a year ago. Old project sites and dormant shared folders are the highest-risk category, because they're the ones nobody remembers exist.

Check your leaver process. Confirm that access is actually removed promptly when someone leaves, not just their email account disabled while everything else lingers. Know what's connected externally through Copilot connectors, and have a reason for each one. If nobody can explain why a connection exists, that's worth questioning before rollout, not after.

None of this is about slowing Copilot down. It's about making sure that when it does go live, what it surfaces is what you actually intended people to see, rather than three years of accumulated permission mistakes nobody got round to fixing.

If you're planning a Copilot rollout and haven't had a proper look at what it will actually be able to access, that's a conversation worth having before you switch it on rather than after. Happy to talk through your tenant and flag what's worth tidying up first.

Next article

Microsoft MFA Changes: What Law Firms Must Do

Read the next article

Ready to transform your business?

Let's discuss how our Microsoft solutions can drive your business forward. Get a free consultation and discover what's possible.