Over the past year, Ontario businesses have been asking if they should be using AI services in their business. Now, they're asking us to turn on Microsoft 365 Copilot, or link ChatGPT to SharePoint, or give Claude access to Outlook and Teams so staff can ask questions about their own files, email, and data.
All three are legitimate, legal tools that can increase efficiency greatly across the board. However, connecting an AI assistant to your Microsoft 365 environment isn't like installing another app or plugin. Instead, it gives your team a very fast, very thorough search engine with the same access your employees already have. For most businesses, the access provider is broader than you may realize.
Most Microsoft 365 tenants have years of accumulated sharing permissions. It could be simple, like a single folder shared with "Everyone" during a project. Or maybe you have a SharePoint site created for a team that no longer exists, or an "anyone with the link" share on a salary spreadsheet that was meant to be temporary.
Historically, these permission issues were a quiet problem that were very hard to exploit, unless an internal user knew what they were looking for. AI completely changes that.
Copilot, ChatGPT and Claude all work on delegated permissions, meaning they can see exactly what the signed-in user can see and nothing more. That sounds reassuring, and it is. But, only as long as your permissions are assigned correctly.
Let's say an employee asks ChatGPT "what are we paying the new operations manager?" and a compensation file is open to the whole organization, the AI client will find it and answer. This is simply because AI follows its assigned rules and security as instructed, and if your organization delegates access carelessly, it can carelessly provide data as well.
So How Do We Fix This?
Step 1: Lock Down App Consent.
This is the gap that we find most often in organizations. By default, many Microsoft 365 tenants still allow regular users to approve third-party apps that request access to their data (think of grammar-checking plugins, or a calendar tool). While seemingly innocent, the users' permission-set could let them connect a personal AI like ChatGPT or Claude to your company's data (SharePoint, OneDrive) without IT ever being involved or their boss knowing.
Before anything else, it's vital to confirm user consent to third-party apps is restricted, and that an admin consent workflow is in place. This forces any user requests to go to IT for review, rather than being silently approved by the user. Then, an extensive audit the Enterprise Applications list in Entra ID should happen. If AI tools are already there, they were likely approved by individual users, and you'll want to know what access they have.
Step 2: Clean Up Oversharing
This is the core of any AI rollout, and it's what makes AI safe to use. We need to reduce, or remove organization-wide access. This means sites and files shared with "Everyone" or "Everyone except external users" a big source of accidental exposure, and access permissions should be updated to allow a specific security group only, rather than individual users (or everyone).
Furthermore, anonymous and org-wide sharing links were probably meant to be temporary, but we often see them outlive the project by years, especially if no 'expiration' policy was assigned to the link. These links should be closed down and removed once they've run their course.
Ownerless and inactive sites can also cause issues, where team members still have access to an old SharePoint site, and nobody is responsible for access control anymore.
Microsoft provides tools to clean up a lot of the above issues. SharePoint Advanced Management is a new license from Microsoft, which can report on oversharing, run site access reviews and restrict which sites Copilot can search. This license is a exceptional 'jumping off point' for most businesses to begin the permission cleanup.
Step 3: Set a Security Baseline for your Tenant
An AI assistant with access to a compromised account is the fastest data exfiltration tool an attacker could ask for. Instead of browsing folders one at a time, they can simply ask it to summarize everything sensitive.
Multi-factor authentication on every account, conditional access policies, and blocking legacy authentication shouldn't be optional pushing out an AI rollout. For most SMBs, Microsoft 365 Business Premium provides this baseline through Entra ID P1, Intune and Defender for Business. These licenses can also be ordered and setup separately, and we urge all M365 businesses to look into the features and benefits of the above licenses.
Step 4: Decide What AI Is Allowed to Do and See
Read access and write access are separate decisions. An AI tool that can summarize a thread is very different from one that can reply to it, send a Teams message, or update a file in SharePoint on someone's behalf. Where connectors offer write actions, they can usually be enabled or disabled individually. You should always start with read-only access, test-drive with a small group, and expand once you understand how your team actually uses it, what they can see, and what you want them to be able to accomplish.
Step 5: Put a Policy In Place
Create a security policy that covers what AI tools can reach. An acceptable policy covers:
- How staff should use AI
- Which tools are approved
- Whether personal AI accounts can be used for work (spoiler, they probably shouldn't)
- What type of business information is allowed to go into prompts
- Who to ask when something is unclear.
Without a policy in place to answer the above questions, your staff will likely make those decisions individually.
Getting AI Into Microsoft 365 the Right Way
AI in Microsoft 365 can seriously change how your team works, but only if your environment, policies and security measures set you up for success. Keystone Technologies helps Ontario businesses assess their Microsoft 365 environment, lock down app consent, clean up oversharing and roll out AI tools with the right controls from day one.
If your team is asking to connect AI, or you suspect someone already has, contact us at keystonetech.ca, call 519-451-1793, or email info@keystonetech.ca to book an AI readiness assessment.
