AI assistants built into Microsoft 365 are attractive to law firms: summarize a long email thread, draft a first pass, find a document you half remember. But these tools work by searching the content a user is already allowed to see. If your permissions are loose, the assistant will happily surface things that should have stayed private. Preparing your environment first is the difference between a useful pilot and an embarrassing one.
This post describes the preparation work. Features and licensing change often, so check Microsoft's current documentation for the details of your plan.
How the risk arises
An AI assistant does not break access controls, but it makes existing access much more discoverable. In a firm where a former file share was opened to "everyone," or a SharePoint site was shared broadly years ago, nobody noticed because nobody searched there. An assistant that can answer a natural-language question across all accessible content changes that.
Consider a hypothetical firm where HR spreadsheets sit in a folder every employee can technically open. An attorney asks the assistant about compensation trends, and it retrieves a document that was never meant to be seen. The assistant did not hack anything. The firm's permissions simply were never tightened.
For a law firm, the stakes include client confidentiality, ethical walls and protective orders, so the clean-up matters even more.
Step 1: Inventory where content lives
List the repositories the assistant could reach: SharePoint sites, OneDrive accounts, Teams channels, shared mailboxes and any connected sources. Identify which hold client matter files, HR or financial data, and which are legacy.
Step 2: Review and reduce sharing
- Find sites and folders shared with large groups such as "all staff" or "everyone except external users."
- Review sharing links, especially anonymous or organization-wide links.
- Remove access for former employees, expired projects and unused guests.
- Apply least privilege: access should follow the matter team or job function.
- Check that ethical walls and restricted matters are enforced in the document system and not just by custom.
Microsoft provides reports and tools to help find overshared content, and your IT provider can run them.
Step 3: Apply sensitivity labels and data protection
Sensitivity labels can mark and protect content, for example "Client Confidential" or "Internal HR only," with encryption and access rules that travel with the file. Decide on a small, simple set of labels people can actually understand. Consider data loss prevention rules for highly sensitive categories.
Step 4: Check your document management platform
If your matter documents are in a system such as NetDocuments or iManage, find out how the AI feature interacts with it. Ask the vendor what the assistant can index, how permissions are honored and what data leaves the environment. Several document-management vendors have their own AI features, with their own settings and terms.
Step 5: Understand data handling
Ask Microsoft's documentation and your reseller: where prompts and responses are processed and stored, whether customer content is used to train underlying models, and what auditing is available. Align the answers with your confidentiality obligations. ABA Formal Opinion 512 discusses the confidentiality and supervision implications of generative AI tools for lawyers.
Step 6: Pilot with a small group
- Choose a handful of users who are willing and who handle lower-risk work.
- Set expectations: output must be reviewed, citations checked, and nothing treated as final.
- Collect feedback on where it saves time and where it produces errors.
- Review audit logs and any unexpected content that surfaced.
- Fix new permission problems before expanding.
Step 7: Write the rules and train staff
Update your AI use policy to name the approved assistant, what it can be used for, and what verification is required. Short training should include examples of good prompts, how to spot errors, and what to do if the assistant shows content the user should not see. Report it so the permissions can be fixed.
Step 8: Keep monitoring
Permissions drift as people join, leave and share files. Schedule periodic access reviews and watch usage and audit data. Revisit the pilot's lessons before each wider rollout.
Costs and expectations
Licensing is an extra per-user cost for most plans, so measure value honestly. Some tasks will see real time savings, others little. The preparation work is useful regardless, because tighter permissions reduce risk even without AI.
Where we fit
Counsel Cyber helps law firms assess Microsoft 365 permissions, set up sensitivity labels and prepare policy and training before deploying AI features. If you are considering a pilot, we can start with a permissions review and show you what an assistant would currently be able to see.