Areza
Copilot readiness

Before you switch on Copilot, find out who can see what

Microsoft 365 Copilot only shows what a user is already allowed to see, so before you switch it on it is worth finding out which SharePoint and OneDrive files are shared too widely: our check shows you, using read permissions only.

Access report · illustrative example

Read-only

Who can see what

LocationOpen toStatus
Management / ContractsThe whole organisationReview
Projects / ClientsThe project teamOK
People / FilesOpen sharing linkReview

Before Copilot is switched on

  • Widely shared foldersReview
  • Sharing linksReview
  • Guest accessOK

Report → your decision → changes as a separate step

01

Why Copilot makes access matter

Microsoft's documentation says Copilot only shows organisational data that the user has at least view permission for. Copilot opens no new access, but it can surface whatever is already open.

Over a few years, organisations collect links anyone can open, files shared with everyone in the company and access left behind by people who have left. While a file has to be found by hand, few people trip over it. Once anyone can ask Copilot, such a file can turn up in an answer to someone it was never meant for.

Files shared in Microsoft Teams are stored in SharePoint sites too, so the same permissions apply.

02

What the check finds

We planted each of these in our test environment, and the check found all 12.

Links anyone can open

Files and folders that anyone with the link can open, without signing in. The check also finds a single file buried deep in a folder tree.

Links for the whole organisation

Files that anyone in your organisation can open with the link.

Access for specific people

Links for specific people and direct permissions, so you can see exactly who has access to a folder.

Access held by disabled or deleted accounts

Permissions left with disabled or deleted users, and OneDrives whose owner's account is disabled or deleted.

Company files in personal OneDrives

Shared company documents kept in an employee's personal OneDrive rather than in a shared library.

Items with their own permissions

The check marks only the files and folders whose sharing differs from the folder they sit in, so the report is not buried in thousands of inherited permissions.

03

How the check runs in your tenant

The app is registered in your Microsoft 365 tenant and uses read permissions only, approved by your administrator. It does not read file contents: names, paths, dates and sharing permissions are enough. There are two permission options.

Copilot readiness
PermissionWhy it is neededAccessOption
Files.Read.AllRead the list of files and folders and their sharing permissions in libraries and OneDrivesReadA
Sites.Read.AllFind SharePoint sites and their document librariesReadA
User.Read.AllTell active, disabled and deleted accounts apartReadA and B
Sites.SelectedRead only the one site you name; your administrator grants read on that site aloneReadB

Option A sees every library and personal OneDrive. Option B sees only the named site; personal OneDrives stay invisible. Sites.FullControl.All is not needed: in our test it produced exactly the same results as the read permissions.

04

Test results

Measured on 2026-10-08 in our own Microsoft 365 test environment with invented data and read permissions only. We planted the risky access on purpose. The results do not show how the check will perform in your tenant.

12 of 12
planted risky access found
0
false findings
84
Microsoft Graph calls to check 940 files and folders
about 31 s
for the whole check (one library and three OneDrives)

05

What you get

  • A report and CSV files listing every access found
  • For each finding: where the file or folder is, who can see it and what kind of access it is
  • No link addresses in the report: the app learns that a link exists and who it is for, but does not receive its address
  • A list of proposed changes to review with your IT team
  • A call to go through the results with your IT team

06

Changes only after you approve

The check only reads and changes nothing. Once you have reviewed the results, we agree which links to close and which permissions to remove.

Changes are a separate step, made only from the list you approved: by your IT team, or by us together with your IT team under separately granted rights. Then we run the check again so you can see the result.

07

What we need from your IT team

How we work and how we price
  • An administrator who can approve Microsoft Graph application permissions: a Global Administrator or Privileged Role Administrator
  • A decision on the permission option: A (whole organisation) or B (one site)
  • An Azure subscription and a resource group in an EU region for the app
  • A person to review the results with us
  • An agreed time for the first run, ideally outside working hours

08

What the test did not cover yet

You can also check which required documents are missing

In our test environment we checked direct permissions and links. Guest accounts, access through groups and Teams-connected sites were not part of that test. New Microsoft 365 tenants do not allow guest invitations, so we have not yet checked guest access on live data.

That is why, at the start of a pilot, we check these cases on your tenant's data and tell you the result before going further. In a large tenant Microsoft may throttle requests; the app then pauses and waits, which is why the first run happens outside working hours.

Common questions.

Something else on your mind?

Book a call
How do we prepare Microsoft 365 for Copilot?

Start by finding out who can see what: look for links anyone can open, files shared with the whole organisation and access left behind by people who have left. Then decide what to close, and only then switch Copilot on for a first group of users. Our check does the first step with read permissions only.

What can Copilot see?

Microsoft's documentation says Copilot only shows organisational data that the individual user has at least view permission for. So Copilot sees as much as the user does: if a file is shared with the whole organisation, it can turn up in any employee's Copilot answer.

What is Microsoft 365 Copilot?

It is Microsoft's AI assistant inside the Microsoft 365 apps. It answers questions and drafts text using organisational data the user has access to, such as documents, emails and chats. We do not sell licences: you buy them from Microsoft or a reseller.

Will the check change our files or permissions?

No. We ask for read permissions only, so the app cannot change, delete or move files. Your administrator sees the list of permissions before approving them.

Does the check see employees' personal OneDrives?

Yes, if your administrator grants read access across the organisation (option A). If read access is granted to one site only (option B), personal OneDrives stay invisible. We discuss which option suits you on the call.

Are Microsoft's own tools enough?

Microsoft has its own tools for getting data ready for Copilot, some of them with a SharePoint Advanced Management licence. On the call we look at what your licences already include. Our check is a separate app in your tenant that gives you one list of findings and the changes we propose.

How long does the check take?

In our test environment, checking 940 files and folders took about 31 seconds. In your tenant the time depends on the number of files, which is why the first run happens outside working hours.

Let's agree where to start

In a 30-minute call we find out where your documents are kept, which permissions would be needed and whether to start with a read-only check or a pilot. You are welcome to bring your IT administrator.

Book a free call

30 min · free · price in writing, excluding VAT

A free 30-minute call

After the call we send a fixed price for the check or the pilot in writing, excluding VAT.

  • Where your documents are kept and which permissions would be needed
  • Where to start: a read-only check or a pilot
  • What your IT team would need to do

1 of 2 · How can we reach you?

It takes less than a minute.