What is oversharing in Microsoft 365?
Also known as: data oversharing, permission sprawl
Oversharing in Microsoft 365 is the condition where content is accessible to more people than the business intends, usually through broad sharing links, permission inheritance, or 'Everyone except external users' grants. It turns routine collaboration into exposure, because a single 'Anyone with the link' setting can make a document readable across the tenant. Oversharing is the main reason Microsoft 365 Copilot can surface data a user should never have seen.
Oversharing rarely comes from a single bad decision. It accumulates through broad sharing links, inherited permissions, and legacy “Everyone except external users” grants that no one revisits. A document set up for one team quietly becomes readable across the tenant.
This is why oversharing is the first thing to fix before a Microsoft 365 Copilot rollout. Copilot inherits the permissions of the user who prompts it, so anything a user can technically reach, Copilot can surface in a summary. Finding and closing broad access is the difference between a safe rollout and an exposure incident.