Fabrikam Inc. has enabled Microsoft 365 Copilot and discovered that Copilot is surfacing confidential HR documents to general employees in its responses. The security administrator suspects data oversharing is occurring through SharePoint. What is the BEST approach to identify and resolve this data readiness issue?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Copilot is like a very diligent employee — it only surfaces what users already have permission to see. If it's showing HR docs to everyone, the permissions are too open. Microsoft Purview DSPM for AI is your flashlight to find that overshared content and lock it down with sensitivity labels.
Full explanation below image
Full Explanation
Microsoft Purview Data Security Posture Management (DSPM) for AI is specifically designed to address data readiness issues that arise with Copilot, including oversharing of sensitive content. DSPM for AI scans your Microsoft 365 environment to identify content that is accessible to broad audiences — such as files shared with 'Everyone' or 'All Users' in SharePoint — and provides recommendations to apply sensitivity labels, restrict permissions, and resolve compliance gaps. Sensitivity labels, once applied, can enforce encryption and restrict who can open documents regardless of where they are stored.
Option A, disabling Copilot for all users, is a disruptive stopgap that does not solve the underlying permission problem. The data remains overshared even with Copilot turned off, meaning users could still access those documents directly.
Option C, Conditional Access policies, control when and how users authenticate to services. They are not designed to remediate SharePoint permission issues or prevent Copilot from surfacing overshared documents.
Option D, Communication compliance policies, monitor Copilot interactions for policy violations such as inappropriate language. While useful for governance, they do not identify or resolve oversharing at the data layer.
Exam tip: When a question involves Copilot surfacing data it should not, the answer usually involves Microsoft Purview — specifically DSPM for AI for oversharing discovery, or sensitivity labels for access control. Copilot respects Microsoft 365 permissions, so fixing permissions is the root-cause fix.