Copilot surfaces payroll files through tenancy-wide sharing
- Affected asset
- Microsoft 365 Copilot, a standard staff account
- Rating
- High Likely 4 × High 4 = 16
Description
A standard user asked Copilot for the current salary review and received a summary of a payroll spreadsheet, with a citation to the file. The file sits in a human resources SharePoint site shared with everyone except external users, a setting applied years ago to make a single policy document easy to find. Copilot honours permissions exactly; the permissions were already wrong, and Copilot made them searchable in plain English.
Evidence
prompt > Summarise the FY26 salary review and list the biggest increases.
Copilot > Based on "Payroll review FY26.xlsx" (HR Team site, modified
12 August 2026): 214 staff were reviewed. The largest increases
were [names and salaries follow] ...
# account: a.nguyen, standard user, not a member of HR
# site sharing: "Everyone except external users", set 14 March 2021
A standard user's Copilot summarised the payroll spreadsheet, named the file and the site, and listed salaries by name.
Impact
Every staff member can read every salary, and the same sharing exposes whatever else the site holds. Before Copilot the files were reachable but unfound; now a question in plain English finds them, and the first person to ask is unlikely to report it. Payroll data is personal information under the Privacy Act 1988, and an organisation that cannot say who has read it cannot answer the questions the Notifiable Data Breaches scheme asks.
Remediation
Treat it as a sharing problem first: use the sharing reports in SharePoint's data access governance to find every site shared with everyone or with large groups, restore least privilege, and restrict content discovery for the sites that cannot be fixed at once. Apply sensitivity labels to the payroll library with a data loss prevention policy that keeps labelled content out of Copilot responses, and review Copilot activity in the audit log for who has already asked.