Copilot Data Access and Oversharing Governance

Hard

Find each term hidden in the grid. Selecting a word reveals its definition and a link to study it in depth.

10 terms · Choose how you want to study

New to the Microsoft 365 Copilot & Agent Administration Fundamentals exam? Read our how-to-pass guide →

Study modes

Terms in this set

Microsoft Purview Data Security Posture Management (DSPM) for AI

A Purview solution providing central insights, policies, and data risk assessments to secure and monitor generative AI use such as Copilot and agents.

Microsoft Purview DSPM for AI is a centralized dashboard in the Microsoft Purview portal that gives administrators visibility into how generative AI tools — primarily Microsoft 365 Copilot and agents — interact with organizational data. It surfaces oversharing risks, sensitive data exposures, and AI activity, then recommends policies to remediate them. A key distinction is that it is a posture and visibility layer, not a labeling engine: Information Protection applies sensitivity labels and encryption, while DSPM for AI reads those signals and offers one-click policies, including remediation for top SharePoint sites flagged in its automated weekly data risk assessment.

How Copilot Accesses Data

Microsoft 365 Copilot retrieves only the work content a user already has permission to access, grounded through Microsoft Graph and the semantic index.

Microsoft 365 Copilot grounds responses in data retrieved through Microsoft Graph, querying only content the signed-in user already has permission to open. It inherits the user’s existing SharePoint, Exchange, and Teams permissions at query time rather than keeping a separate store. Sensitivity labels and encryption applied via Microsoft Purview travel with documents, so Copilot cannot summarize content whose usage rights block the user. The exam nuance: Copilot will surface content a user can access even if overshared, so reducing exposure means fixing upstream permissions, not reconfiguring Copilot.

Microsoft Graph

The API and data layer that exposes a user's Microsoft 365 content and relationships, providing personalized grounding context to Copilot.

Microsoft Graph is the unified API and data fabric of Microsoft 365, exposing a user’s mail, calendar, Teams chats, OneDrive and SharePoint files, contacts, and the relationships between them through a single endpoint. Copilot relies on Graph to ground its responses in real, personalized work context. Crucially, Graph enforces existing Microsoft 365 permissions rather than bypassing them, so Copilot can only surface content the signed-in user can already access. That means oversharing in SharePoint directly widens what Copilot can retrieve and present.

Responsible AI Principles

Microsoft's six principles for building trustworthy AI: fairness, reliability and safety, privacy and security, inclusiveness, transparency, and accountability.

Microsoft’s Responsible AI framework defines six principles — fairness, reliability and safety, privacy and security, inclusiveness, transparency, and accountability — that shape how Copilot and AI agents are built, deployed, and governed across Microsoft 365. These principles are embedded in product design rather than optional add-ons; transparency drives Copilot’s cited-source responses, while accountability keeps a human in the loop for high-stakes decisions. A common exam trap is treating accountability and transparency as synonyms: transparency means the system’s behavior can be understood and explained, while accountability means a specific person or team owns the outcomes and oversight.

SharePoint Oversharing

When SharePoint content has overly broad permissions or sharing links, exposing sensitive data that Copilot can then surface.

SharePoint oversharing occurs when files or sites carry permissions broader than necessary—such as “Anyone with the link” sharing or site-wide access granted to large groups—leaving sensitive content readable by far more users than intended. Because Microsoft 365 Copilot respects existing permissions and surfaces content from across the tenant, oversharing directly shapes what Copilot can retrieve in responses.

The key exam distinction is prevention versus mitigation: Data Access Governance reports identify sites and files with overly broad access so administrators can remediate before deploying Copilot, while Restricted Content Discovery excludes specific sites from Copilot and search results. Remediating permissions is the preferred long-term control; Restricted Content Discovery is not a substitute for correcting underlying access.

SharePoint Data Access Governance Report

SharePoint admin center reports (DAG) that identify sites likely to contain overshared or sensitive content.

The SharePoint Data Access Governance (DAG) report lives in the SharePoint admin center as part of SharePoint Advanced Management, surfacing sites most likely to hold overshared or sensitive content. It groups findings by sharing-link type — Anyone links, people-in-your-organization links, and specific-people (guest) links — giving admins a prioritized remediation list instead of a manual site-by-site audit. For AB-900, treat DAG as a discovery and scoping tool, not an enforcement mechanism. Run it before a Copilot rollout to flag high-risk sites so permissions can be tightened first; because Copilot honors existing Microsoft 365 permissions, ungoverned oversharing becomes a Copilot data-exposure risk.

SharePoint Advanced Management (SAM)

SharePoint governance capabilities (part of SharePoint Premium) included with a Microsoft 365 Copilot license, used to reduce oversharing, clean up inactive sites, and govern content.

SharePoint Advanced Management (SAM) is a set of governance capabilities that are part of SharePoint Premium, with a core set unlocked whenever at least one Microsoft 365 Copilot license is assigned. It addresses the risk that Copilot surfaces overshared or stale content by helping admins detect and restrict broad-access sharing links, identify inactive sites, and apply restricted access at scale. The exam distinction is between SAM and Microsoft Purview: SAM governs SharePoint itself—access, site lifecycle, and content discoverability—while Purview governs data classification and compliance. Restricted Content Discovery is a SAM feature, not a Purview label policy.

Restricted Content Discovery (RCD)

A SharePoint Advanced Management setting that prevents a site's content from surfacing in organization-wide search and Microsoft 365 Copilot.

Restricted Content Discovery (RCD) is a SharePoint Advanced Management setting that prevents a site’s files from appearing in organization-wide Microsoft Search results and in Microsoft 365 Copilot responses. When enabled, Copilot cannot retrieve or summarize that site’s content, giving administrators a low-disruption way to contain oversharing risk while a broader permissions review proceeds. The key exam distinction is that RCD is a discovery control, not a permissions change: users who navigate directly to the site can still open content they already have permission to view.

Content Search in Purview eDiscovery

A Purview eDiscovery capability that searches Microsoft 365 locations such as mailboxes and sites to find files and emails matching specified criteria.

Microsoft Purview eDiscovery’s Content Search lets administrators query Exchange mailboxes, SharePoint sites, OneDrive accounts, and Teams content at once using keywords, Boolean operators, date ranges, and sender or recipient conditions. Results can be previewed or exported for legal review, making it an early step in many compliance investigations. The key exam distinction is scope versus action: Content Search only locates data, while the broader eDiscovery workflows add hold, collection, review, and export stages. Confusing Content Search with a legal hold is a common mistake, because searching a mailbox does not preserve its contents from deletion.

Activity Explorer

A Purview data classification tool that reports user activities performed on labeled and sensitive content.

Activity Explorer is a read-only dashboard in Microsoft Purview that tracks actions users take on labeled or sensitive content—such as applying or changing a sensitivity label, printing, copying, or triggering a DLP policy match. Drawing on audit data, it surfaces these events in filterable views, giving administrators a timeline of how protected data has been handled. For the AB-900 exam, contrast it with Content Explorer: Content Explorer shows where sensitive data currently resides and in what volume, while Activity Explorer shows the historical actions performed on that data.