Messy permissions in Microsoft 365 let Copilot reach files and data it should never touch. Bellwether IT keeps tenant controls tight so your office stays protected.

Files the Bookkeeper Uses Daily

Good IT already sets folder permissions so only the right staff reach the bookkeeper’s spreadsheets and ledgers. When those rules drift, Copilot can surface old invoices or client lists to anyone who asks the right question in chat.

The tell is simple. An employee mentions a vendor detail they should not know, or a file appears in search results that was meant to stay quiet. That gap shows the controls were not reviewed after the last staff change.

We review every shared library and OneDrive folder tied to Microsoft 365 accounts. We lock down access so Copilot only sees what the user is already allowed to open.

Data from Laptops That Walked Out the Door

Good IT removes accounts and revokes device access the same day an employee leaves. A laptop that left with an employee still carries cached files and tokens if that step is skipped.

The sign shows up when Copilot pulls up a project folder that was closed months ago. The former staff member’s permissions were never cleaned out of the tenant.

We run regular account audits and device wipes. We make sure no old tokens or cached data stay active after someone is gone.

Vendor Invoices and Shared Folders

Good IT keeps vendor invoice folders restricted to the people who process payments. Loose links or inherited permissions let Copilot reach those documents from unrelated chats.

You notice it when a sales question brings up a cost sheet or when a team member sees pricing they were never meant to view. The folder structure was not cleaned after the last project ended.

  • Review every shared mailbox and library for old links
  • Confirm inheritance is turned off on sensitive folders
  • Test Copilot prompts against actual user roles

We handle those checks on a set schedule and fix the gaps before they reach the tenant.

What we do Bellwether IT audits Microsoft 365 permissions and cleans up access so Copilot only works with the data each user is allowed to see.

The Real Job of Your IT Company

Your IT company is supposed to own the tenant rules that stop Copilot from pulling the wrong records. When that work is skipped, the office ends up with data showing up in places it does not belong.

We keep those rules current and test them against the tools your team actually uses. reach out.