Copilot Doesn't Break Your Law Firm's Permissions. It Reads Them Out Loud.
Microsoft Copilot inherits your existing SharePoint permissions — including the broken ones. What law firms need to check before turning it on, and how ethical walls fail.
Copilot Doesn't Break Your Law Firm's Permissions. It Reads Them Out Loud.
A paralegal at a 30-attorney firm opens Copilot and types a reasonable question: "What's our position on the indemnification dispute with the manufacturer?"
Copilot returns a clean, well-organized summary. It pulls from four documents. One of them is a strategy memo from a matter the paralegal was formally screened off of six weeks ago.
Nobody hacked anything. No permission was bypassed. No policy was violated by the person asking. The firm's ethical wall was implemented as a SharePoint permission, that permission had a hole in it, and for three years the hole didn't matter because nobody could find the document.
Then the firm turned on Copilot.
---
The sentence that misleads everyone
Microsoft's position on Copilot and permissions is accurate: Copilot only surfaces content the user already has permission to access. It does not grant new access. It does not bypass your security model.
Every word of that is true. It is also the most misunderstood sentence in enterprise AI, because it quietly assumes something that is almost never true in practice — that your existing permissions are correct.
They are not. Not at your firm, not at anyone's.
The relevant industry number: roughly 16% of business-critical data is overshared, averaging around 802,000 exposed files per organization. Scale that down to a 30-person firm and you're still looking at thousands of documents reachable by people who were never meant to reach them.
Before Copilot, that didn't produce incidents. SharePoint search was mediocre, nobody browsed document libraries recreationally, and finding an overshared file required knowing it existed and roughly where it lived.
Obscurity was doing the work your permissions weren't.
Copilot removes obscurity as a control. It reads everything the user can technically access, understands natural language, and volunteers what it finds. It doesn't need the user to know the document exists. That's the entire product.
---
Where the holes come from
None of these require anyone to have done anything wrong. Every one of them is a normal artifact of a firm using Microsoft 365 for a few years.
"Everyone Except External Users." A legacy default that granted access to every internal account. Microsoft changed the defaults years ago, but tenants that predate the change still carry the old grants, and nobody audits them because nothing visibly broke.
Broken permission inheritance. Someone needed to share one folder with one person, so they broke inheritance on a library. That library now has permissions nobody has reviewed since, and the person who set it up left in 2023.
"Anyone with the link" sharing. The fastest way to get a document to a co-counsel, an expert, or a client. Those links usually don't expire by default. They accumulate.
Teams sprawl. Every Team creates a SharePoint site, and by default members can edit. A Team spun up for a single matter three years ago still exists, still has its original membership, and still contains everything anyone dropped into it.
File share migrations. The firm moved off the on-prem file server. The migration preserved the files. It rarely preserved a coherent permission model, and "we'll clean it up later" became the permanent state.
OneDrive matter work. An attorney shared a working folder with two colleagues for one matter. Neither the folder nor the sharing was ever revisited.
Lateral hires and departures. People arrive and get added to groups. People leave and their content stays where it was, with whatever access it had.
Every one of these was survivable when documents were hard to find. Copilot is a tool whose sole purpose is making documents easy to find.
---
Why this lands harder on a law firm
Most organizations facing Copilot oversharing risk a compensation spreadsheet or an unannounced reorg deck. Uncomfortable, recoverable.
A law firm's exposure is structurally different.
Ethical walls are usually just permissions. When a firm screens an attorney off a matter, that screen is typically implemented as a SharePoint or Teams permission, often set up under time pressure at the moment the conflict was identified. If it has a gap — a document in a shared library, a copy in someone's OneDrive, an email attachment in a Team the screened attorney belongs to — Copilot will find it and summarize it, on request, with no indication that anything unusual happened. And a screen that fails isn't an inconvenience. It's a disqualification risk for the firm and a problem for the client.
Confidentiality is broader than privilege. The duty covers all information relating to the representation, regardless of source, including client identity and the fact of the engagement. A Copilot answer that reveals which clients the firm represents in a given industry is a confidentiality problem even if no privileged content surfaces.
Conflicts data is unusually sensitive. Prospective client information, declined matters, and conflicts analysis are exactly the kind of content that ends up in ad-hoc SharePoint locations with permissions nobody thought hard about.
Client agreements may already prohibit this. Outside counsel guidelines increasingly contain AI restrictions and data-handling terms. A firm that enables Copilot tenant-wide without checking its client obligations may be in breach of an agreement it signed, on day one, without anyone noticing.
Nobody is watching for it. The person who receives an overshared answer sees a helpful summary. There is no alert, no access-denied log, no anomaly. The firm's first indication that a wall failed is likely to be someone mentioning something they shouldn't know.
And the governance obligation sits with firm leadership regardless. ABA Formal Opinion 512, issued July 29, 2024, addresses competence, confidentiality, and supervision in the context of generative AI, and the Model Rules place responsibility on managerial and supervisory lawyers to establish policies that ensure compliance. "The vendor said it respects permissions" is not a supervision program.
---
The good news: Microsoft built the tools, and you may already own them
This is the part most firms don't know.
If anyone in your tenant holds a Microsoft 365 Copilot license, SharePoint Advanced Management (SAM) is unlocked for your SharePoint administrators automatically. You don't buy it separately. Microsoft began including it with Copilot licensing in early 2025. It's also sold standalone as SharePoint Advanced Management Plan 1 for tenants without Copilot.
A small number of features — restricted site creation by apps, for one — still require the Plan 1 add-on. But the tools you need for a pre-deployment audit are in the box.
There are four distinct controls, and they are not interchangeable. Firms get into trouble by reaching for the wrong one.
1. Data Access Governance reports — find it
Your starting point. DAG reports surface which sites carry the highest oversharing risk: broad sharing through "Anyone," "Everyone," and organization-wide links, and sites where multiple risk signals overlap. A site that holds sensitive content and has "Anyone" links is where you start.
Run these before you make a single change. You cannot prioritize what you haven't measured, and the report almost always contradicts what leadership expects.
2. Restricted Content Discovery — hide it
RCD removes a site from Copilot results and organization-wide search without changing permissions. People who should have access still have it and can still work normally; the content simply stops being passively discoverable.
This is the right tool for content that must stay accessible to its team but should never surface in a general query — which describes a great deal of what a law firm stores. It's also the correct holding action while you remediate underlying permissions, since permission cleanup is a months-long project and RCD takes effect immediately.
3. Restricted Access Control — lock it
RAC restricts access to a site to a defined group, full stop. Heavier than RCD, and appropriate for genuinely walled content: an active screened matter, a firm-management site, an acquisition workspace.
4. Restricted SharePoint Search — the temporary net
RSS limits Copilot and organization-wide search to an allowlist of sites. It's a blunt instrument and Microsoft positions it as temporary — a safety net for a phased rollout, not a governance model. Useful if you need Copilot live next week and haven't finished the audit. Not something to still be relying on next year.
And the sensitivity label gotcha
Firms often assume applying a sensitivity label protects content from Copilot. That's only true under specific conditions: the label has to actually enforce something. If the label applies encryption and removes the EXTRACT usage right (shown in Purview as "Copy"), Copilot can cite that the file exists but cannot summarize its contents. A label that only tags and classifies without enforcing those rights does not stop Copilot from reading the document.
If your firm has labels configured, verify what they actually enforce before treating them as a control.
---
The pre-deployment checklist
Work through this before the first Copilot license activates. If Copilot is already live, work through it now.
Measure
- [ ] Run Data Access Governance reports across the tenant
- [ ] List every site with "Anyone" links, "Everyone Except External Users" grants, or org-wide sharing links
- [ ] Identify sites where sensitive content and broad sharing overlap — these are the fires
- [ ] Inventory sites with broken permission inheritance
- [ ] Audit OneDrive sharing for attorneys handling sensitive matters
Verify the walls
- [ ] List every active ethical screen at the firm
- [ ] For each, identify how it is technically implemented
- [ ] Test each one: can a screened user reach any screened content through any path — SharePoint, Teams, OneDrive, a shared link, an email attachment?
- [ ] Confirm no copies of screened material exist outside the walled location
Contain
- [ ] Apply Restricted Content Discovery to sensitive-but-accessible sites
- [ ] Apply Restricted Access Control to genuinely walled sites
- [ ] Consider Restricted SharePoint Search if going live before remediation completes
- [ ] Verify what your sensitivity labels actually enforce, not just what they're named
Check your obligations
- [ ] Review outside counsel guidelines and client security agreements for AI restrictions
- [ ] Confirm no client has instructed the firm not to use AI on their matters
- [ ] Confirm your firm's cyber insurance application answers remain accurate after enabling Copilot
Govern
- [ ] Disable or expire default "Anyone" sharing links; set expiration on the rest
- [ ] Turn on site access reviews and delegate to site owners
- [ ] Establish a written AI acceptable use policy naming approved tools and required verification
- [ ] Name a specific person accountable for the program — not "IT"
- [ ] Set a review cadence, because permissions drift and guidance is changing quickly
---
What SAM doesn't cover
Worth knowing before you declare victory.
SAM's reports address SharePoint and OneDrive. They do not surface exposure in Teams chat content, Copilot conversation history, or Power Platform connectors. Its inactive site policy allowances are limited — the cap is five policies per tenant — which is generous for a small firm and constraining for a large one. On big tenants, snapshot reports can take days rather than hours.
And SAM tells you nothing about the AI tools your people are using outside the Microsoft ecosystem, which for most firms is where the larger confidentiality exposure actually sits.
---
The honest summary
Copilot is a good product and there is no reason a law firm can't use it. This is not an argument against adoption.
It is an argument against adoption as a licensing decision. Turning on Copilot is a change to your firm's effective confidentiality posture, because it converts a permission model nobody has audited into a natural-language interface anyone can query. The permissions were always wrong. Copilot is just the first tool that reads them out loud.
The firms that handle this well do the same three things: they measure before they deploy, they verify their ethical walls hold under a tool designed to find things, and they write down who is accountable.
The firms that handle it badly find out when someone mentions something they shouldn't know.
---
Frequently asked questions
Is Microsoft Copilot safe for law firms? It can be, but safety depends on your tenant's permission hygiene rather than on Copilot itself. Copilot surfaces content the requesting user can already access. If your SharePoint and OneDrive permissions are accurate, exposure is limited. If they carry years of accumulated oversharing — which is the norm — Copilot will surface that content on request.
Does Copilot bypass SharePoint permissions? No. It respects existing permissions and grants no new access. The risk is that existing permissions are frequently broader than intended, and Copilot makes overshared content easy to find where it was previously buried.
Can Copilot break an ethical wall? Copilot cannot defeat a correctly implemented screen. It can expose an incorrectly implemented one. Because screens are usually enforced as SharePoint or Teams permissions and are often set up quickly, gaps are common — a stray copy in a shared library, an attachment in a Team, a file in someone's OneDrive. Test every active screen before deploying.
Do sensitivity labels stop Copilot from reading a document? Only when the label enforces encryption and removes the EXTRACT usage right. Under those conditions Copilot can cite the file's existence but cannot summarize its contents. Labels that only classify without enforcing those rights do not prevent Copilot from reading the file.
Do we need to buy SharePoint Advanced Management? Probably not. If any user in your tenant has a Microsoft 365 Copilot license, SAM is included automatically for SharePoint administrators. It's also available standalone as Plan 1 for tenants without Copilot. A small number of features still require the add-on.
What's the difference between Restricted Content Discovery and Restricted Access Control? RCD removes a site from Copilot and search results without changing permissions - authorized users keep working normally, the content just stops being discoverable. RAC restricts access to the site to a defined group entirely. RCD is for sensitive-but-accessible content; RAC is for genuinely walled content.
How long does permission cleanup take? For most firms, months. That's why Microsoft built controls that let you contain exposure immediately while remediation proceeds. You don't have to finish the cleanup before deploying — you do have to know what you're containing.
---
Before you turn it on
We run Copilot Readiness Assessments for law firms nationwide: permission blast-radius analysis, oversharing and broken-inheritance reporting, ethical wall verification, sensitivity label review, and a go/no-go recommendation with a prioritized remediation list.
If you'd rather start with something free, our Proprietary Exposure Review shows what your firm already reveals publicly — email impersonation risk, lookalike domains, and exposed infrastructure — using public records only, with no access to your systems.
---
Securing Your Law Firm is a service of Cyber Bulwark, LLC. This article is informational and does not constitute legal or compliance advice. Microsoft product capabilities and licensing change frequently; verify current details against Microsoft's documentation.
