Nobody shared the Desktop with Copilot. Somebody moved it into the tenant, and Copilot reads what the tenant holds.

Why Copilot Data Security Matters Now

Most Copilot risk reviews start with the prompt: what the user can ask, what the model can say back. That is the wrong end of the pipe. Microsoft 365 Copilot works over the content a user is already permitted to reach in the tenant, so the real question is how much content got into the tenant, and how it got there.

Two mechanisms are worth marking to market. First, OneDrive Known Folder Move can redirect Desktop, Documents and Pictures into OneDrive, and it can be deployed through Intune or Group Policy without a user prompt. Second, Microsoft’s message center item MC1311968 describes Copilot in SharePoint turning on by default from June 2026, with the notice stating that no administrator action is required. Put together, files that sat on a laptop and were never meant to be shared can end up inside the retrieval surface of an assistant that nobody scoped.

Signal Figure Source
Enterprises with agents in use that IT did not sanction 88% Ospiri published research
Added breach cost attributed to shadow AI +$670K Ospiri published research, directionally consistent with IBM Cost of a Data Breach
Typical time to put agent governance in place 12-18 months Ospiri published research

Two Different Questions: Sharing vs Reach

Security teams tend to audit sharing: who has been granted access to this site, this folder, this file. Copilot is governed by reach: what can this user’s identity touch, across everything the tenant now contains. Those are different ledgers, and the gap between them is where the exposure lives.

Dimension Sharing audit Reach audit
Unit of analysis A file and its ACL A user and everything their identity can retrieve
Typical owner Content owner Security and IT jointly
Catches a Desktop folder moved by policy Rarely Yes
Catches over-broad inherited permissions Partly Yes
What Copilot respects Permissions as they stand Permissions as they stand

Copilot honors existing permissions. That is a feature, and it is also the problem: it faithfully surfaces whatever an over-permissioned estate already allows. The assistant does not create the exposure. It removes the friction that used to hide it.

Anatomy of the Silent Redirect

Here is how the pattern plays out in an ordinary rollout:

  1. Known Folder Move is enabled by policy. Desktop, Documents and Pictures are redirected into OneDrive through Intune or GPO. No user clicks anything.
  2. Local clutter becomes tenant content. Draft contracts, exported spreadsheets, screenshots, a CSV pulled from a production system for a one-off analysis. Files that were never filed anywhere now sync.
  3. Retrieval surfaces widen. Copilot features that default to on, such as Copilot in SharePoint after the June 2026 change, add reach without an admin decision attached.
  4. Labels lag the content. Sensitivity labels in Purview only protect what has been classified. Unlabeled files that arrived by redirect are, by construction, unclassified.
  5. A routine prompt returns something nobody expected. An employee asks for last quarter’s pricing and gets a snippet from a colleague’s exported draft.

No attacker is required. This is a drift problem: the estate changed, the control assumptions did not.

The Copilot Reach Score

Frequency times severity, adjusted for how much of the estate is classified:

Copilot Exposure = (Unclassified Share × Reachable Data Sensitivity) + (Default-On Features × Redirected Content Volume)

Factor What you measure Where it comes from
Unclassified Share Share of tenant content with no sensitivity label Purview label coverage report
Reachable Data Sensitivity Sensitivity of what a typical user identity can retrieve Access reviews, sample queries
Default-On Features Copilot capabilities enabled without an explicit admin decision Message center review, tenant settings
Redirected Content Volume Files that entered OneDrive through Known Folder Move OneDrive adoption and sync reports

The decimals are not the point. The point is that two of the four factors sit upstream of Copilot entirely, in endpoint policy and in message center defaults.

What Control Looks Like at the Source

Tenant-side controls matter and you should use them: restricted search scopes, label coverage, access reviews. They all act after the content has landed. The complementary control acts where the files and the agents actually live, on the endpoint, before and during the movement.

Control point What it enforces Tenant controls alone?
Endpoint filesystem Which local paths may be redirected or read by an agent No
Process Which agents and embedded clients may touch local data No
Network Which destinations local content may be pushed to Partly
Labeling at the source Classification applied before sync, not after Partly
Tenant permissions and labels What Copilot may retrieve once content is in the tenant Yes, and worth tightening

We have written about why per-tenant policy leaves a gap for Copilot, and about where Purview labels stop at the SaaS border. Our Copilot firewall and agent governance pages cover the endpoint side of the argument.

What CISOs Should Do This Quarter

Step Action Output Effort
1 Check whether Known Folder Move is deployed by Intune or GPO, and for which folders List of redirected folders and affected user groups 1 week
2 Review Copilot message center items and tenant settings for features that turned on by default Default-On Features inventory with an owner per item 1 week
3 Measure sensitivity label coverage on content that arrived through redirect Unclassified Share, as a number 2 weeks
4 Run reach tests: sample users, sample prompts, log what comes back Reachable Data Sensitivity evidence 2 weeks
5 Put endpoint controls on the highest-exposure groups Reversible default with an audit trail 2-4 weeks

The Bottom Line

Copilot does not expand access; it removes the friction that was quietly protecting an over-broad estate, and silent redirects keep widening that estate. Let’s step back: if your Copilot review ended at the prompt, you priced the interface and ignored the inventory. If your team is sizing this for the next budget cycle, request a working session. We will walk through your environment, compute your Copilot Exposure against your current Known Folder Move and label coverage, and scope a deployment. Expect a first readout within two weeks.