Securing Your Law Firm logoSecuring Your Law Firm
Back to resources
Blog post2026-08-14By Securing Your Law Firm

Your Firm Turned On Copilot. Did Anyone Check Who Can See What?

Microsoft Copilot surfaces whatever a user can technically access. Here's why that's a professional responsibility risk for law firms, and how to audit it.

Microsoft 365 Copilot doesn't grant anyone new access to your firm's files. It respects every permission already in place. That sentence sounds reassuring right up until you remember how those permissions actually got set.

What Microsoft Itself Had to Fix

In early 2026, Microsoft confirmed an issue – internally tracked as CW1226324 – where Copilot in Teams meetings was summarizing content from channels a user had never joined, because the user had inherited access through a broad group membership. The result: employees receiving AI-generated summaries of HR disciplinary discussions, M&A planning threads, and litigation hold conversations they were never meant to see. Microsoft patched the specific bug in February 2026. The underlying cause – years of accumulated, unaudited group memberships and sharing links – was still sitting in place at every organization that hadn't gone back and checked.

Why This Is a Different Problem for a Law Firm

For most businesses, oversharing is an embarrassment. For a law firm, it's a professional responsibility problem. Conflict walls and information barriers exist precisely so an associate working one matter can't see files from a matter they're screened off from. Litigation holds exist to preserve sensitive communications, not distribute them. Copilot doesn't know any of that. It knows what SharePoint, Teams, OneDrive, and Exchange say a user can technically open, and it will summarize, quote, and surface that content the moment someone asks a plain-language question. A permission that was harmless when it required someone to know a specific site existed and dig through folders becomes a real exposure the moment it can be reached by typing "summarize everything about [matter name]."

How Common Is This, Really

Firms that assume this is an edge case should look at the audit data. One firm's review across more than 700 enterprise Microsoft 365 tenants found an average of 150 to 300 overshared SharePoint sites per organization, with 40 to 60 percent of sites carrying at least one oversharing pattern – a public link, a broken permission inheritance, or an "everyone except external users" group grant. Oversharing isn't the exception in a typical Microsoft 365 environment. It's closer to the default state.

Microsoft Is Building a Fix. That's Not a Reason to Wait.

Microsoft has announced that oversharing-risk visibility and Copilot data loss prevention controls will be built directly into the Microsoft 365 admin center by October 2026, making it easier for IT teams to spot and remediate exposure without leaving their normal workflow. That's a genuinely useful development. It's also not a substitute for knowing, today, what Copilot can already surface inside your firm.

What a Small or Mid-Sized Firm Can Do Now

  • Run a permissions audit before – or immediately after – turning Copilot on. Find overshared sites and broken inheritance patterns before an associate does, by accident, in front of a client.
  • Remove "everyone except external users" access from anything sensitive. This single group setting is behind a large share of oversharing incidents.
  • Apply sensitivity labels to privileged and conflict-screened matters. Copilot respects labels correctly applied; it can't respect what was never labeled.
  • Scope any Copilot agents to specific sites or libraries rather than granting tenant-wide search by default.

The Bottom Line

Copilot isn't the vulnerability. It's a very fast, very literal reader of a permissions structure most firms built over a decade without ever intending anyone – human or AI – to see all of it at once. The firms getting ahead of this are auditing their access today, not waiting for Microsoft's October dashboard to tell them what they should have already found.

This article is informational and does not constitute legal or compliance advice.