Nobody shared the Desktop with Copilot. Somebody moved it into the tenant, and Copilot reads what the tenant holds.
Why Copilot Data Security Matters Now
Most Copilot risk reviews start with the prompt: what the user can ask, what the model can say back. That is the wrong end of the pipe. Microsoft 365 Copilot works over the content a user is already permitted to reach in the tenant, so the real question is how much content got into the tenant, and how it got there.
Two mechanisms are worth marking to market. First, OneDrive Known Folder Move can redirect Desktop, Documents and Pictures into OneDrive, and it can be deployed through Intune or Group Policy without a user prompt. Second, Microsoft’s message center item MC1311968 describes Copilot in SharePoint turning on by default from June 2026, with the notice stating that no administrator action is required. Put together, files that sat on a laptop and were never meant to be shared can end up inside the retrieval surface of an assistant that nobody scoped.
| Signal | Figure | Source |
|---|---|---|
| Enterprises with agents in use that IT did not sanction | 88% | Ospiri published research |
| Added breach cost attributed to shadow AI | +$670K | Ospiri published research, directionally consistent with IBM Cost of a Data Breach |
| Typical time to put agent governance in place | 12-18 months | Ospiri published research |
Two Different Questions: Sharing vs Reach
Security teams tend to audit sharing: who has been granted access to this site, this folder, this file. Copilot is governed by reach: what can this user’s identity touch, across everything the tenant now contains. Those are different ledgers, and the gap between them is where the exposure lives.
| Dimension | Sharing audit | Reach audit |
|---|---|---|
| Unit of analysis | A file and its ACL | A user and everything their identity can retrieve |
| Typical owner | Content owner | Security and IT jointly |
| Catches a Desktop folder moved by policy | Rarely | Yes |
| Catches over-broad inherited permissions | Partly | Yes |
| What Copilot respects | Permissions as they stand | Permissions as they stand |
Copilot honors existing permissions. That is a feature, and it is also the problem: it faithfully surfaces whatever an over-permissioned estate already allows. The assistant does not create the exposure. It removes the friction that used to hide it.
Anatomy of the Silent Redirect
Here is how the pattern plays out in an ordinary rollout:
- Known Folder Move is enabled by policy. Desktop, Documents and Pictures are redirected into OneDrive through Intune or GPO. No user clicks anything.
- Local clutter becomes tenant content. Draft contracts, exported spreadsheets, screenshots, a CSV pulled from a production system for a one-off analysis. Files that were never filed anywhere now sync.
- Retrieval surfaces widen. Copilot features that default to on, such as Copilot in SharePoint after the June 2026 change, add reach without an admin decision attached.
- Labels lag the content. Sensitivity labels in Purview only protect what has been classified. Unlabeled files that arrived by redirect are, by construction, unclassified.
- A routine prompt returns something nobody expected. An employee asks for last quarter’s pricing and gets a snippet from a colleague’s exported draft.
No attacker is required. This is a drift problem: the estate changed, the control assumptions did not.
The Copilot Reach Score
Frequency times severity, adjusted for how much of the estate is classified:
Copilot Exposure = (Unclassified Share × Reachable Data Sensitivity) + (Default-On Features × Redirected Content Volume)
| Factor | What you measure | Where it comes from |
|---|---|---|
| Unclassified Share | Share of tenant content with no sensitivity label | Purview label coverage report |
| Reachable Data Sensitivity | Sensitivity of what a typical user identity can retrieve | Access reviews, sample queries |
| Default-On Features | Copilot capabilities enabled without an explicit admin decision | Message center review, tenant settings |
| Redirected Content Volume | Files that entered OneDrive through Known Folder Move | OneDrive adoption and sync reports |
The decimals are not the point. The point is that two of the four factors sit upstream of Copilot entirely, in endpoint policy and in message center defaults.
What Control Looks Like at the Source
Tenant-side controls matter and you should use them: restricted search scopes, label coverage, access reviews. They all act after the content has landed. The complementary control acts where the files and the agents actually live, on the endpoint, before and during the movement.
| Control point | What it enforces | Tenant controls alone? |
|---|---|---|
| Endpoint filesystem | Which local paths may be redirected or read by an agent | No |
| Process | Which agents and embedded clients may touch local data | No |
| Network | Which destinations local content may be pushed to | Partly |
| Labeling at the source | Classification applied before sync, not after | Partly |
| Tenant permissions and labels | What Copilot may retrieve once content is in the tenant | Yes, and worth tightening |
We have written about why per-tenant policy leaves a gap for Copilot, and about where Purview labels stop at the SaaS border. Our Copilot firewall and agent governance pages cover the endpoint side of the argument.
What CISOs Should Do This Quarter
| Step | Action | Output | Effort |
|---|---|---|---|
| 1 | Check whether Known Folder Move is deployed by Intune or GPO, and for which folders | List of redirected folders and affected user groups | 1 week |
| 2 | Review Copilot message center items and tenant settings for features that turned on by default | Default-On Features inventory with an owner per item | 1 week |
| 3 | Measure sensitivity label coverage on content that arrived through redirect | Unclassified Share, as a number | 2 weeks |
| 4 | Run reach tests: sample users, sample prompts, log what comes back | Reachable Data Sensitivity evidence | 2 weeks |
| 5 | Put endpoint controls on the highest-exposure groups | Reversible default with an audit trail | 2-4 weeks |
The Bottom Line
Copilot does not expand access; it removes the friction that was quietly protecting an over-broad estate, and silent redirects keep widening that estate. Let’s step back: if your Copilot review ended at the prompt, you priced the interface and ignored the inventory. If your team is sizing this for the next budget cycle, request a working session. We will walk through your environment, compute your Copilot Exposure against your current Known Folder Move and label coverage, and scope a deployment. Expect a first readout within two weeks.