Skip to main content
10 July, 2025
# Topics
Follow Us

Is Your San Antonio M365 Tenant Ready for AI Copilot? What to Check Before You Deploy

28 August, 2024

Microsoft 365 Copilot adoption is accelerating in San Antonio. The city's combination of military contracting, healthcare systems, financial services, and a growing technology corridor has created strong demand for AI productivity tools — along with significant risk from enabling them without proper preparation.

Managed IT services clients in San Antonio consistently encounter the same problem: Copilot is being trialed before anyone has audited what Microsoft 365 permissions actually exist in the tenant. In most tenants, those permissions are broader than any IT administrator has mapped — accumulated through years of projects, shared folders, and staff changes without systematic review.

How Copilot Uses Your Microsoft 365 Permissions

Copilot retrieves content through Microsoft Graph, using the permissions of the signed-in user. When someone asks Copilot a question, it pulls from everything that user can access — emails, calendar items, SharePoint files, Teams messages, meeting transcripts. The risk is not in Copilot itself. It is in the fact that what users are authorized to access has typically expanded far beyond what anyone intended.

Microsoft's own deployment guidance is direct: before enabling Copilot, audit and remediate permission exposure. For managed IT services clients in San Antonio, this is the starting point — not the pilot.

Where Oversharing Hides in San Antonio Tenants

Military and Government Contractors

San Antonio's large JBSA-anchored contracting community stores sensitive procurement and operational data in Microsoft 365 alongside general business files. A Copilot deployment without a permissions audit means users can surface contract data from projects they have no active role on — through Copilot responses pulling from accessible SharePoint libraries they were never removed from after project completion.

Healthcare Networks

San Antonio has significant healthcare infrastructure. Patient-adjacent documents, clinical communications, and billing records stored in shared Teams channels or OneDrive folders can appear in Copilot responses for users who were added to those channels for unrelated reasons and never removed. Healthcare organizations running managed IT services in San Antonio face heightened exposure given HIPAA obligations around information access controls.

Growing Technology and Professional Services Firms

San Antonio's growing tech and professional services sector provisions access quickly and rarely cleans up old permissions. Copilot will surface everything a user can access — including folders from former teams, SharePoint sites set to broad access, and files shared during client projects that were never restricted afterward.

The Four-Step Audit Required Before Copilot

1. SharePoint Sharing Defaults

Check the tenant-level SharePoint sharing setting. In many San Antonio business tenants configured before 2022, the default is "Anyone with the link" — meaning any recipient can open a shared file without authentication and can forward the link indefinitely with no expiration. Switching to "Specific people" takes 15 minutes and eliminates permanently accessible open links from new shares going forward.

2. Site and Library Membership

Review SharePoint sites where former employees or cross-department members still have access from past projects. Managed IT services providers in San Antonio with active Microsoft 365 governance practices maintain access registers; providers managing tenants reactively typically find significant exposure in this review.

3. Teams Channel Membership

Teams channels accumulate membership over time. A channel built around a client engagement or major project will have had appropriate membership at launch. Months later, the project is complete but the channel membership remains. Files in that channel — and Copilot's access to them — extend to everyone who was ever added.

4. Sensitivity Labels for Confidential Content

Microsoft Purview sensitivity labels restrict Copilot from reading or summarizing labeled content even when the user has file-level access. For San Antonio businesses in healthcare, military contracting, and financial services, implementing sensitivity labels on confidential content before Copilot deployment is the containment layer that permissions alone cannot provide.

The Question to Ask Your San Antonio IT Provider

Before making any Copilot decision, send this to whoever manages your Microsoft 365 environment: "Can you show me a report of every SharePoint site accessible to more than ten people, and flag any that contain client data, financial records, or employee information?" If they can produce something useful within a few days, your tenant has been managed actively. If the answer is that they need to enable some tools first, the SharePoint sharing reports have never been run.

What Elevate Technology Does for San Antonio Businesses

Elevate Technology provides managed IT services for San Antonio and Austin businesses, including Microsoft 365 tenant administration, SharePoint governance, sensitivity label implementation, and Copilot readiness assessments. If your tenant has not had a permissions audit in the past 12 months, that is the right starting point — before any Copilot license is enabled.

Frequently Asked Questions

Does Microsoft 365 Copilot access all business files?

Copilot accesses whatever the signed-in user is authorized to access — scoped by SharePoint, OneDrive, Exchange, and Teams permissions. The risk is that in most tenants, those permissions have accumulated significantly beyond current role requirements, making Copilot's reach broader than intended.

Is a small Copilot pilot safe before a full rollout?

Only if pilot users have limited, well-understood permissions. The common mistake is piloting with senior staff, who tend to have the broadest access. A safer approach reviews and restricts pilot user permissions before enabling any Copilot license.

→ Contact Elevate Technology for managed IT services in San Antonio. Visit Managed IT Services — Elevate Technology