Imagine a company activates Copilot on a Monday. By Friday, an employee discovers through a natural language prompt that they can see their colleagues' salaries. Not because Copilot has a security flaw. But because that file has been accessible to everyone in the company for four years, and nobody remembered it existed.
Copilot doesn't create new vulnerabilities. It removes the friction that made existing vulnerabilities invisible. And that changes everything.
The Year the 3% Decided to Go First
Microsoft reported 15 million paid Copilot users in January 2026, against 450 million commercial Microsoft 365 subscribers. That's an adoption rate of just 3.33%. Even among the world's largest companies, most are running limited pilots. Not real deployments.
The barrier isn't price. The barrier is readiness. And readiness, in this context, has an unglamorous name: data governance. That is, knowing what information exists inside the organization, where it lives, and who can see it.
The Folder Nobody Remembered
Every organization using Microsoft 365 accumulates the same type of problem over time. Decisions that seemed harmless:
- A document shared with "anyone with the link"
- A workgroup from three years ago that still has access to active folders
- A financial report distributed broadly in 2021 for a meeting, and never revoked
- Sites from completed projects still open with no active owner
A 2025 analysis found that organizations have an average of 802,000 files at risk from oversharing, with 16% of business-critical data exposed to people who shouldn't have access.
That number isn't alarming because it's new. It's alarming because it already existed and nobody had quantified it.
| Situation | Before Copilot | With Copilot Active |
|---|---|---|
| Salary file shared too broadly | Hard to find among thousands of files | Anyone can request it in natural language |
| Completed project with open folders | Access ignored, unused | Content available to everyone with access |
| "Anyone with the link" active | Theoretical risk | Immediate and exploitable risk |
| Unclassified information | Goes unnoticed | Copilot includes it in responses without restriction |
Copilot doesn't create the problem. It makes the problem impossible to ignore.
See Before You Act
The first action before activating Copilot isn't configuring the tool. It's understanding who can see what inside your environment.
Microsoft includes with any Copilot license a management tool that identifies which content is overexposed, verifies that every workspace has an active owner, and allows continuous access review.
Visibility reports show, file by file, who has permission to see what across the entire environment, allowing those responsible to identify and correct excessive access systematically.
You don't need to clean everything before activating Copilot. The right strategy is to prioritize by sensitivity and reach: the most critical and most exposed content goes first.
Naming What Should Be Secret
Identifying the problem isn't enough. Information needs to be classified so that policies can be applied automatically.
Think of it like the categories in a physical filing system. The recommendation is to keep that classification simple: three to five categories, with names clear enough that anyone on the team can apply them correctly on the first try.
| Category | What it includes | Who can see it |
|---|---|---|
| Public | Press releases, marketing content | Anyone, including external |
| Internal | Procedures, general policies | The whole organization |
| Confidential | Financial data, contracts, HR | Only the relevant teams |
| Restricted | Strategy, M&A, regulated information | Explicit per-person access |
When a document has an assigned category, Copilot respects it. If the document is marked confidential, it won't appear in a response to someone who shouldn't see it. But if it was never classified, there's no rule to apply.
Automatic classification resolves the historical backlog at a scale that manual review could never achieve, and documents that Copilot generates automatically inherit the highest category of the content that grounded them.
The Sequence That Changes the Outcome
The right sequence isn't "activate Copilot and see what happens." It's:
- Audit access. Understand what content is overexposed and to whom. The tools included with any Copilot license cover this step.
- Classify sensitive information. Start with the most critical content, not everything. A four-category system is enough to begin.
- Configure automatic policies tied to those classifications, so the system acts without manual intervention when sensitive content is detected.
- Run a scoped pilot with a small group of users, monitor how they interact with Copilot, and what kind of responses it generates.
- Expand gradually from that pilot to the rest of the organization, with visibility into what Copilot is doing at each stage.
Compressing this process creates gaps that are far more expensive to fix after deployment is done.
The Point
The question worth asking isn't "are we ready for Copilot?" It's "do we have clarity on what Copilot will be able to see?" If the answer is no, the problem isn't the tool. It's the order of operations.
The average cost of a data breach reached $4.44 million in IBM's 2025 research. The cost of a pre-deployment assessment is considerably lower. The difference between the two scenarios is exactly the work that was avoided when there was still time.
Copilot is an extraordinary tool when the environment is prepared for it. And it amplifies ignored risks when it isn't.
If this kind of analysis is useful to you, there's more every week in the macareno.net newsletter. No spam, no generic content, just Microsoft technology that matters.
Sources
- Microsoft 365 Copilot Readiness and Resiliency with SharePoint — Microsoft Tech Community
- Security and governance innovations for Microsoft 365 Copilot from Ignite 2025 — Microsoft Tech Community
- Microsoft 365 Copilot Security: Get the Tenant Ready First — BDEmerson
- Is Your Microsoft 365 Tenant Ready for Copilot? — ABT
- Microsoft Purview: Proven Copilot Data Security Guide — Progressive Robot
