An organization enables Microsoft Copilot for Microsoft 365 and receives reports that Copilot is surfacing confidential HR documents to non-HR employees in Teams. After investigation, the security team determines the HR documents are stored in SharePoint without proper access controls. What is the ROOT CAUSE of the oversharing issue?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — b is correct because Microsoft 365 Copilot strictly respects existing SharePoint permissions. If HR documents are accessible to all authenticated users due to overly permissive sharing settings, Copilot will surface those documents to any user who queries relevant topics.
Full explanation below image
Full Explanation
B is correct because Microsoft 365 Copilot strictly respects existing SharePoint permissions. If HR documents are accessible to all authenticated users due to overly permissive sharing settings, Copilot will surface those documents to any user who queries relevant topics. The root cause is the overly permissive SharePoint access control configuration, not a Copilot bypass. A is incorrect because Copilot respects all SharePoint permissions and only shows users content they already have permission to access. C is incorrect because Copilot does not bypass sensitivity label encryption; encrypted files that cannot be decrypted by the user are not returned. D is incorrect because license tier does not determine whether Copilot respects SharePoint permissions.