What happened
Info-Tech Research Group has published a sobering assessment of how most organizations manage Microsoft 365—and the news isn’t good for anyone relying on default settings. The new “Govern Microsoft 365” blueprint warns that the typical tenant is configured more as a loose collection of technical switches than as a governed, business-aligned platform. That gap, Info-Tech says, creates hidden data oversharing that AI tools like Microsoft 365 Copilot are about to make painfully visible.
The core message: configuration is not governance. Simply checking boxes in admin centers doesn’t equal a defensible strategy for who can see what, and Copilot—which respects existing user permissions to surface information—will dramatically amplify the consequences of years of ad-hoc access decisions.
What actually changed
Info-Tech’s blueprint doesn’t announce a new Microsoft feature or breaking vulnerability. Instead, it articulates a structural problem that has been building for years: Microsoft 365 tenants are sprawling mixes of Teams chats, SharePoint sites, OneDrive folders, group mailboxes, Loop workspaces, and Power Platform artifacts, all governed by inconsistent and often undocumented rules. The rapid expansion of collaboration tools, combined with the ease of creating groups and sharing links, has left a trail of ownerless sites, stale guest accounts, and permissions that no longer reflect anyone’s real-world responsibilities.
According to the research group, too many organizations rely on Microsoft’s default settings without revisiting them. Those defaults are designed for broad usability and low deployment friction, not for the specific risk posture of a regulated enterprise, healthcare provider, or financial institution. Defaults often permit anonymous sharing links, unrestricted group creation, and open guest access—decisions that might have made sense during pilot phases but persist because no one has clear ownership of the governance function.
The new piece is the explicit connection to AI readiness. Info-Tech argues that Copilot doesn’t invent broken permissions; it just makes already-broken permissions vastly more exploitable. When an employee can ask natural-language questions and instantly receive summaries, files, or messages that they technically had access to all along, oversharing moves from a theoretical risk to a practical business threat.
What this means for you
For everyday users, the immediate impact is likely to be a wave of tightened controls and, in some organizations, a confusing flurry of new sharing restrictions. If you suddenly find yourself unable to create a Team or share a file externally, this blueprint—and the governance policies it inspires—may be the reason. On the positive side, a well-governed environment ultimately means fewer “why can’t I find that file?” moments and less worry about accidentally leaking sensitive data.
For IT administrators and security teams, the report is a call to shift from reactive firefighting to intentional design. The blueprint provides a practical framework: define business outcomes first, then translate them into enforceable controls. No more playing whack-a-mole with sharing settings after every audit finding. Instead, admins should map out who is responsible for each collaboration space, what classification it needs, how external access should work, and how long content must live. The report’s emphasis on a RACI model (Responsible, Accountable, Consulted, Informed) is especially useful for breaking the deadlock where multiple departments all assume someone else owns Microsoft 365 governance.
Power users and business decision-makers should pay attention to the “permission debt” concept. Over years of frantic collaboration, you and your colleagues have likely been added to Teams, shared folders, and distribution lists that have nothing to do with your current role. That access might seem harmless, but Copilot can now surface that information in answers you didn’t even know you could get. Cleaning up permission debt—removing yourself from irrelevant groups, auditing who has access to your sensitive files—is suddenly urgent.
How we got here
Microsoft 365’s governance gap isn’t a bug; it’s a side effect of success. When the platform was younger, organizations adopted one service at a time: Exchange Online for email, SharePoint for intranets, and maybe Skype for Business. Governance could be siloed because the services were siloed. Then came Teams, which knitted everything together: every team brings a SharePoint site, a group mailbox, a OneNote notebook, a Planner plan, and a web of interlinked permissions. The more integrated the platform became, the more a misconfiguration in one place rippled across the entire tenant.
At the same time, Microsoft’s default posture favored fast adoption. You could spin up a Team in seconds, share a file with an anonymous “anyone with the link” setting, and invite external guests with no approval workflow. That speed helped M365 win the collaboration war, but it also meant that governance became an afterthought for many organizations—something you scheduled for “after we get this project done,” which never happened.
Copilot changed the equation because it lowers the effort required to find information. In the past, a user with overly broad permissions might never stumble upon a sensitive file buried in a forgotten SharePoint library. But Copilot actively searches across all the data you can access and serves it up in response to a vague question. The AI doesn’t care about the original context; it just finds matches. So a document shared with “Everyone except external users” during a 2019 marketing campaign suddenly pops up in a 2025 query about “company trade secrets,” even though the audience was never intended to be that broad.
Regulatory pressure has also intensified. Laws like GDPR, HIPAA, and various state privacy acts require organizations to know what data they hold, where it lives, and who can access it. A governance-free M365 tenant can make that impossible to prove, leading to fines, litigation risks, and reputational damage.
What to do now
Info-Tech’s blueprint outlines five key actions, but you can start with high-impact, manageable steps that don’t require a complete overhaul.
1. Inventory your current sharing posture
Before you can tighten controls, you need to know what’s exposed. Use the Microsoft 365 admin center and Purview portal to run reports on:
- External sharing links and guest users
- Ownerless Teams and SharePoint sites
- Sites with broad “everyone” permissions
- Sensitivity label coverage
Microsoft’s SharePoint Advanced Management reports can surface overshared files specifically. The goal isn’t to fix everything overnight; it’s to identify the most egregious problems—for example, sites containing financial data that are set to “Anyone with the link.”
2. Designate governance owners and a RACI model
Decide who is responsible for what. At a minimum, assign:
- A person or small committee to approve external sharing policies
- Business owners for each Team/SharePoint site (IT cannot be the default owner for content it doesn’t understand)
- A lifecycle manager for inactive workspaces
- A data classification lead from legal/compliance
If a RACI chart feels too formal, even a simple list of named owners for each governance domain will reduce chaos.
3. Apply tiered sharing and access controls
Not all content is equal. Implement a tiered model:
- General collaboration: managed external sharing with approved guests only
- Internal-only: prohibit guest access and anonymous links
- Confidential/restricted: enforce sensitivity labels, encryption, and prevent downloads
For most organizations, starting with 3–4 tiers prevents analysis paralysis. Then create SharePoint site templates that enforce these tiers automatically when someone provisions a new Team, so governance becomes part of the creation workflow rather than a post-hoc clean-up.
4. Clean up permission debt aggressively
Schedule quarterly access reviews for high-value or broadly shared resources. Use Entra ID access reviews to make owners periodically recertify membership in groups and Teams. For SharePoint, run “Check Permissions” on sensitive libraries to see if anyone has access who shouldn’t. Encourage employees to leave Teams and groups they no longer need—and make it easy through self-service tools.
5. Prepare for AI with data readiness
Even if you haven’t deployed Copilot yet, your governance decisions today will determine how dangerous (or useful) it becomes. Action items:
- Apply sensitivity labels to all existing documents, not just new ones. Use auto-labeling policies if you have Purview Information Protection.
- Define acceptable-use policies for AI: what kind of data can employees query? What’s off-limits?
- Enable Copilot activity monitoring so you can see which documents are being surfaced and by whom, spotting oversharing in action.
- Implement data loss prevention (DLP) policies that specifically address AI usage scenarios, such as preventing users from copying sensitive content into external AI tools.
6. Communicate changes in user language
Governance that arrives as a surprise restriction breeds resentment and shadow IT. Before you lock down sharing, explain why: “We’re tightening external sharing to protect client data and prepare for AI tools that can automatically surface files. Here’s the new process for sharing with partners, and here’s how it keeps you—and our customers—safe.” Provide users with easy, approved alternatives so they don’t resort to personal Dropbox accounts.
Outlook
Governance will only become more central as Microsoft weaves AI deeper into the platform. Copilot is just the beginning; AI agents, automated workflows, and third-party plugins will all rely on the existing permission model. Organizations that invest in structured governance now will not only reduce risk but will also unlock more value from AI, because their high-quality, well-classified data will produce more accurate and useful results. Those that ignore the blueprint will find the whispers of their overshared data turning into a roar.
The next 12 months will likely bring more tools from Microsoft to automate governance—better default policies, more sensitive-by-default settings, and deeper integration between Purview, Entra, and Copilot controls. But as Info-Tech emphasizes, technology alone cannot replace the human decisions that define what is acceptable, who is accountable, and how data should be treated. The time to make those decisions is now, before the AI gets better at finding what you never meant to expose.