Microsoft Purview and Oversharing: Prepare Your Tenant for Copilot
Diesen Beitrag auf Deutsch lesen
Audit SharePoint permissions, apply Purview labels, archive stale content, and enforce Power Automate DLP before deploying Copilot.
TL;DR
Microsoft 365 Copilot uses existing Microsoft Graph permissions, so buried or broadly shared SharePoint, Teams, and OneDrive content can surface in natural language answers. Audit Everyone and guest access, apply Purview sensitivity labels and automated classification, archive inactive sites, and configure environment-level Power Automate DLP to restrict connectors such as Jira.
Original on M365 FM Podcast. Read the original · suggested by Mirko Peters
This is our own summary, not a republication or full translation.
Governance takeaway
- Admins/CoE: Audit Everyone, guest, and Anyone with the link permissions, then review SharePoint oversharing reports before licensing Copilot because AI can surface content users previously overlooked.
- Security/Compliance: Apply Purview sensitivity labels, automated classification, and retention-aware archiving so sensitive or inactive content is restricted or removed from active Copilot discovery.
- Makers: Review Power Automate connectors and follow environment-level DLP policies because workflows connecting internal data to Jira or other SaaS endpoints can create an unintended exposure path.
