On July 1, 2026, Microsoft made Copilot a standard part of its small business plans. Business Standard with Copilot runs $23.50 per user per month, Business Premium with Copilot is $32, and the standalone Copilot for Business license moved from the promotional $18 up to $21. The add-on you used to buy separately is now folded into the plan itself.
Which means a lot of businesses around the valley now have Copilot sitting in their Microsoft 365 tenant without ever having planned a rollout, written a policy, or thought about it for more than about five minutes. It arrived with the renewal.
That's mostly fine. But there's one specific thing worth checking before your team starts leaning on it, and it has nothing to do with AI being dangerous.
That sentence is the whole issue, so it's worth sitting with for a second.
Copilot can only see what the person using it can already see. It respects every permission in SharePoint, OneDrive, Teams, and Exchange exactly as they're configured. Nothing gets bypassed, and no data leaves your tenant to train anything.
The problem is that "what the person can already see" is usually a much bigger set than anyone realizes. Years of sharing links, inherited folder permissions, and sites set to "Everyone except external users" have piled up quietly. Nobody noticed, because finding a file you weren't supposed to have access to used to require knowing it existed and going looking for it.
Now somebody types "what are the salary bands for the sales team" into a chat box and gets a clean answer, sourced from a spreadsheet in a folder that got shared a little too broadly back in 2019.
The permissions were always wrong. Copilot just made them convenient.
Large enterprises turn up hundreds of overshared sites when they go looking. Smaller tenants tend to have a handful of specific problems, and it's almost always these:
The theme is that none of these were mistakes at the time. They were reasonable shortcuts that never got cleaned up, which is a different problem and a more forgivable one.
You don't need to buy anything to get started here, and you don't need PowerShell.
The SharePoint admin center includes Data Access Governance reports. They'll show you which sites are shared with everyone, which ones have live anyone links, and which have the widest sharing overall, ranked so you can work down the list. That's the right first stop for any Copilot readiness check, and it's already included in what you pay for.
From there:
One timing note worth knowing: Restricted SharePoint Search, which a number of organizations used as a temporary fence around Copilot while they cleaned things up, is being retired. New enablement was blocked as of July 31, 2026. If that was your plan, it isn't available anymore, and the permissions cleanup was always the real answer regardless.
Clean up the permissions first. Then pilot with a small group, maybe ten or fifteen people spread across different departments, and pay close attention to what surprises them. Then expand.
Somewhere in there, give people ground rules. Not a fifty page document, just clarity on what belongs in a prompt, what doesn't, and what they need to verify before they send something a customer will read. We've written separately about acceptable use policies and won't repeat all of it here, but if you don't have one, this is the moment to write it.
Some people's first instinct is to disable Copilot until the cleanup is done. That's a legitimate move, and if you're in a regulated business with a known permissions mess, it's the responsible one for a few weeks.
It's a poor long term answer, though, for two reasons. The first is that you're paying for it now whether it's on or off, and your competitors aren't leaving it off. The second is that turning Copilot off doesn't fix anything. The overshared folder is still overshared. Regular SharePoint search will still find it, a curious employee will still stumble into it, and if someone's account gets compromised the attacker inherits that same wide access. Copilot didn't create the exposure, it just made it easier to notice, which is arguably a favor.
The better framing is that Copilot gave you a deadline for a cleanup you should have done years ago.
The other thing worth knowing is that this isn't only about people typing into a chat window anymore. Microsoft has been pushing agents, which are essentially Copilot configured to do a specific job and often shared with a group. An agent built by someone with broad access, then shared with a department, can pass that reach along in ways that are genuinely hard to reason about.
If anyone in your organization starts building agents, that should be a deliberate decision with someone reviewing what data each one can reach, not something that happens because a manager found the button.
This lands harder on regulated businesses. The FTC Safeguards Rule and GLBA both care specifically about access controls and limiting who can reach customer information. An overshared folder full of loan files or credit applications was already a problem. Copilot turns it into a demonstrable one, and "we didn't know it was shared that way" has never been a defense that works well in an examination.
The same logic applies to dealerships sitting on credit apps and driver's license scans, and to anyone whose customers send them security questionnaires once a year.
Copilot is a good tool and you're paying for it either way now. The question was never whether to use it. It's whether your file permissions are in good enough shape that letting people search everything they technically have access to won't surface something it shouldn't.
If you don't know the answer to that, we can find out. We're based in Murray and we do Copilot readiness reviews for businesses across Salt Lake County and the Wasatch Front, starting with your Data Access Governance reports and a clear picture of where the real exposure is.
We run Copilot readiness reviews starting with your Data Access Governance reports, then help you close the real exposure before you turn it loose. Start with a free, no-pressure assessment.
Get a Free IT Assessment