A Microsoft 365 audit before switching Copilot on in a central government office
A central government office made Microsoft Copilot available to its staff. The order of the work mattered more than the rollout itself: an audit of the Microsoft 365 environment first, then the assistant, then training for staff, and finally DLP controls covering AI tools. ZeroLayer ran all four stages.
Challenge: Copilot sees whatever the user can see
Copilot holds no permissions of its own. It answers from content the signed-in user already has at least view rights to — Microsoft states this plainly in the product documentation. The assistant therefore creates no new access risk; it makes the existing one visible. Shares granted once and never withdrawn, links open to everyone in the organisation, SharePoint libraries and OneDrive locations with broken permission inheritance: as long as nobody asked for that content, nobody saw it. Once the assistant is on, one question in plain language is enough. That is why the Microsoft 365 audit came before the Copilot rollout in this project, not after it.
- Copilot answers within the asking user's permissions — oversharing surfaces only when somebody puts the right question to it.
- Permissions in SharePoint and OneDrive accumulate over years and are rarely revisited once granted; moving to the cloud does not tidy them up.
- Staff paste content into AI assistants that should not go there, whether or not the institution has formally allowed the tool.
- The office had to be able to demonstrate oversight of what reaches the model and what the model draws on in its answers — under GDPR and its own information security policy.
Solution: audit first, then rollout, training and DLP
The project ran in four stages, in a fixed order. The Microsoft 365 audit came before the Copilot rollout so that the permissions picture was known before the assistant started drawing on it. With the assistant live, the work moved to the human side — training — and only then closed the technical layer: control over what data reaches AI tools.
- Microsoft 365 environment audit: a review of permissions, sharing and tenant configuration before the assistant was switched on. The scope covered an environment of up to 500 user accounts, together with the SharePoint libraries and OneDrive locations Copilot draws on when it builds an answer.
- Microsoft Copilot was switched on for a pilot group first and rolled out to the whole organisation once the pilot closed. The pilot let permission settings be verified against real usage before the assistant reached everyone.
- Training for 50 staff, delivered remotely over Microsoft Teams: how to work with the assistant and what must never be typed into it.
- DLP for AI tools built on the controls native to Microsoft 365: rules limiting what can reach the assistant and excluding content marked sensitive from its answers. The rules covered citizens' personal data, HR and payroll records, bank account numbers and other financial data, and documents carrying a sensitivity label.
What ZeroLayer delivered
All four stages ran as one project under a single point of accountability — audit, rollout, training, then the DLP policies. The whole engagement took three months, from the start of the audit to the DLP policies going live. It is worth being clear about how that last stage differs from classic endpoint DLP. Instead of watching a file leave over USB or email — the job of classic endpoint DLP, which we deploy separately — DLP for AI tools governs the text typed into a prompt and the material the model grounds its answer in: it can stop a prompt containing given sensitive information types from being processed, exclude documents carrying a particular sensitivity label from the response, or cut off web search when a query contains data that should not leave the organisation. This layer closes the project but does not substitute for it — without the permissions work done first, it limits only what the assistant says, not what it reaches for.
Related services
Secure your
future today
Cyber threats don't sleep, and neither do we. Whether you need an immediate response to a breach or a long-term strategic security partner, ZeroLayer is ready.
Book a 30-minute call
Pick a time that works for you and talk directly to our security team. A conversation about your situation, not a sales pitch.