Introduction
You do everything you're supposed to do to keep a Finance site flagged for oversharing out of Copilot's reach. The next morning, a marketing employee with no business reason to see payroll data asks Copilot a question—and gets a detailed answer sourced straight from Finance.
Nothing about the site's permissions changed overnight. Nobody added that employee to a group. So what did "doing everything right" actually accomplish?
Here's what you'd actually done: flipped one switch in the SharePoint admin center, "Restrict content from Microsoft 365 Copilot," for the Finance site—flagged for its "Anyone" sharing links and no clear owner. Within a day, the site dropped out of organization-wide search, and Copilot stopped surfacing it in answers to random prompts. Job done, you assumed.
That gap—between "hidden from search" and "actually inaccessible"—is why governing SharePoint and OneDrive is the single highest-stakes job in Relecloud's Copilot rollout. Get it wrong, and an oversharing remediation can look like it worked while quietly doing nothing at all.
What you'll learn
- Create and manage SharePoint team sites and communication sites with a deliberate owners, members, and visitors permission model.
- Configure the organization-wide SharePoint and OneDrive external sharing settings that set the outer ceiling for what Copilot can ever reach.
- Use data access governance reports—snapshot and activity—to find sites overshared by broad links, unclear ownership, or "Everyone except external users" grants.
- Match a requirement to the right of three lookalike remediation controls: Restricted Content Discovery, Restricted Access Control, and Restricted SharePoint Search.
By the end of this module, you can govern SharePoint and OneDrive content so Copilot grounds only on appropriate data, and you can select the correct control, not just a plausible-sounding one, for a given oversharing or discoverability requirement.