Microsoft Copilot security review for Australian organisations.
A review of the Entra ID and Microsoft 365 tenant behind a Copilot rollout: conditional access, privileged roles, app consent, SharePoint and OneDrive sharing, and a re-check once fixes land.
Black Shard is an Australian software engineering and cybersecurity firm headquartered in Brisbane. Microsoft 365 Copilot answers a prompt by retrieving material from Microsoft Graph and the semantic index built over your own tenant, and that retrieval runs in the security context of the person who asked. Access is trimmed to what that account could already open, and Copilot does not extend it. A rollout still inherits every permission mistake already sitting in the tenant, because Copilot makes each one much easier to find. A Copilot security review checks whether that inherited access is safe before or after rollout.
A Copilot security review extends Black Shard's Entra ID and Microsoft 365 identity security review to the parts of the tenant a rollout puts in front of users every day: conditional access and MFA coverage, privileged roles, app consent, and SharePoint and OneDrive permission and sharing-link hygiene, with a re-check once remediation lands.
Why a Copilot rollout is a permissions problem
Before a rollout, an over-permissioned site or a stale sharing link was protected mostly by obscurity. Staff went to the folders they already knew about, tenant-wide search saw little use, and a question with no obvious document to click on had no easy way to be asked. Copilot does not add obscurity back. The access that existed before licences were assigned can now be reached through a single prompt.
An oversharing default left on a SharePoint site, an app consent grant nobody revisited, and a privileged role left standing after a project ended all become things Copilot can find and answer from with confidence, whether or not they should still be reachable. The exposure already existed, and Copilot is what surfaces it.
What the review covers
Conditional access policies and multi-factor authentication coverage are checked across every account that matters, including break-glass accounts. Privileged roles are audited in full: who holds Global Administrator and the other high-impact roles, and whether each assignment is still justified. App consent is reviewed for third-party and internal applications carrying access broad enough that a single compromised account reaches content well beyond what that user normally opens.
SharePoint and OneDrive carry the second half of the review, because that is where the bulk of organisational content sits and where broad grants accumulate fastest. Sites and libraries are checked for the Everyone except external users group sitting in their membership, for Anyone and organisation-wide sharing links, and for permission inheritance broken somewhere under a large audience.
- Conditional access and MFA coverage across every account that matters, including break-glass accounts
- Privileged-role audit: who holds high-impact roles, and whether each assignment still stands up
- App-consent audit across the tenant, including over-broad third-party grants
- SharePoint and OneDrive permission and sharing-link hygiene, including Anyone links and broken inheritance
Copilot readiness, before and after rollout
The review is most useful before Copilot licences are assigned. Run ahead of rollout, it is a readiness assessment: oversharing and permission defects get found and fixed while Copilot has not yet had the chance to surface them to anyone.
Organisations that have already turned Copilot on still get the same review. The scope stays the same, and the questions asked of it extend to what may already have been surfaced, and which still-standing access or broad sharing link made that possible. Once remediation lands, the tenant is checked again against the same signals. A permission change made in SharePoint or Entra ID takes time to propagate through the search index, so the re-check confirms the fix is live in the tenant before the engagement closes.
Remediation
Black Shard is a software engineering firm as well as a cybersecurity firm, so the findings do not stop at a report. Remediation can run as advisory support, with the plan written so your own IT team can execute it, or as hands-on configuration change: reconfiguring conditional access policies, tightening privileged role assignments, revoking over-broad app consent grants, and fixing SharePoint and OneDrive permissions and sharing links.
What does a Copilot security review cost?
No figure is published. Effort is driven by the size of the identity and content estate: how many users, guest accounts and privileged roles the tenant carries, how many SharePoint sites and OneDrive libraries are in scope, and how many third-party applications have accumulated access over time.
The engagement runs with a defined target, timeframe and deliverable agreed before work starts. Send a brief to [email protected] with the rough shape of the tenant and where Copilot sits in the rollout.
Delivered Australia-wide from Brisbane
The review needs read access to the tenant, a brief on what the organisation runs on Microsoft 365, and time with the people who can answer the questions a configuration export cannot. Scoping and the debrief run by video call, the same way in every state, and Brisbane organisations can choose an in-person debrief at our Eagle Street head office.
Access is reader-level and scoped to the engagement, typically Global Reader in Entra ID with read access to Conditional Access policies, Enterprise Applications and the SharePoint admin centre, agreed at scoping and removed when the review ends. Black Shard's own position, including SMB1001:2026 Gold verifiable on CyberCert's registry, is on the trust page.
Questions, answered
- Does Copilot get access to anything a user could not already reach?
- No. Copilot's retrieval runs in the security context of the person asking and is trimmed to what that account could already open. The risk sits in permission mistakes already present in the tenant, such as an oversharing default, a stale sharing link, or an app consent grant nobody revisited. Copilot makes each of those easier to find and answers from them with confidence.
- What access do you need to review our tenant?
- Reader-level roles scoped to the review, typically Global Reader in Entra ID with read access to Conditional Access policies, Enterprise Applications and the SharePoint admin centre, agreed at scoping and removed when the engagement ends.
- Should we run this before or after switching Copilot on?
- Before, where that is still possible. Run ahead of rollout, the review contains oversharing before anyone can ask Copilot about it. Organisations that have already turned Copilot on still get the full review, with more urgency attached to what may already have been surfaced.
- Can you fix what you find?
- Yes. Black Shard is a software engineering firm as well as a cybersecurity firm, so remediation can run as advisory support or hands-on configuration change after the review. The plan is written so your own team can execute it.
- Is this the same as your Entra ID security review?
- It builds on it. The Entra ID security review covers conditional access, privileged roles, app consent and offboarding across the identity tenant. This review carries the same checks and adds the SharePoint and OneDrive permission and sharing-link hygiene that a Copilot rollout puts in front of users directly.
- Do you work with organisations outside Brisbane?
- Yes. Black Shard is an Australian firm headquartered in Brisbane and delivers Australia-wide. Scoping and the debrief run remotely as standard, and Brisbane organisations can choose an in-person debrief.
Scope a Copilot security review with Black Shard.
Brisbane head office. Work delivered across Australia.