ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX · Serving TX, AR, LA, OK & KS
(737) 325-2520

Using Microsoft Copilot in a Law Firm: Fix Permissions First

Why law firms should audit Microsoft 365 permissions, sensitivity labels and sharing before turning on Copilot or similar assistants, with a step-by-step plan.

3 min readBy Counsel Cyber Team

AI assistants built into Microsoft 365 promise to summarize email threads, draft documents and answer questions using the firm's own files. For law firms, that is attractive. It is also where an old, quiet problem becomes visible: these tools work with whatever the user already has permission to see.

If a paralegal's account can technically open a folder of partner compensation documents or a sensitive client's files because nobody tightened the permissions years ago, an assistant that searches everything that user can access may surface content they never knew existed. The assistant does not break permissions. It exposes how loose they were.

This is why permission cleanup comes first.

How these assistants generally work

Product details change, so confirm current behavior with your vendor. In general terms, Microsoft states that its Copilot features operate within the user's existing Microsoft 365 permissions and the tenant's security and compliance settings. That is reassuring, but it means the quality of your protection depends on the quality of your configuration.

The ABA's Formal Opinion 512 on generative AI emphasizes confidentiality, competence, and supervision. Controlling who can reach what data is how a firm applies those principles in practice.

Step 1: Map where data lives

Inventory the places Microsoft 365 can search:

  • SharePoint sites and Teams channels.
  • OneDrive folders.
  • Shared mailboxes and calendars.
  • Any connected third-party sources.

If your document management system sits outside Microsoft 365, find out what the assistant can and cannot see, and how it respects that system's permissions.

Step 2: Find overshared content

Look for the usual suspects:

  1. Sites open to "everyone" or "everyone except external users."
  2. Broad groups. Teams or groups with many members that were created for convenience.
  3. Anyone links. Sharing links that grant access to anyone who has the URL.
  4. Stale access. Former project members, departed employees' OneDrive folders and old external guests.
  5. Sensitive folders in general areas. HR, finance, partner materials and conflict-sensitive files stored in sites with wide access.

Microsoft 365 administrative reports and third-party tools can help identify these. Your IT provider should run them and share results in a form partners can review.

Step 3: Tighten access

Work through the findings systematically.

  • Replace "everyone" access with named groups.
  • Remove stale members and external guests.
  • Move sensitive content into restricted locations.
  • Turn off or limit anyone-links and add expiration to guest access.
  • Set up site ownership so a responsible person reviews membership.

For client matters requiring ethical walls, verify the restriction by testing: log in as a restricted user and attempt to find the content through search.

Step 4: Apply sensitivity labels and policies

Sensitivity labels let you classify content, such as "Public," "Internal," "Confidential" and "Highly Confidential," and attach protections like encryption or access limits. Data loss prevention rules can block certain sharing. Labels take effort to design, so start small: label the top few categories that matter, such as HR and financial files or particularly sensitive client matters.

Step 5: Pilot with a small group

Do not roll out to the whole firm at once.

  1. Choose a small pilot group with varied roles.
  2. Provide a short usage guide and a clear rule: the assistant helps draft and summarize, and humans verify everything.
  3. Ask pilot users to report any case where the assistant surfaces something unexpected, which indicates a permission problem to fix.
  4. Review feedback and adjust before widening access.

Step 6: Set usage rules

Update your AI policy to cover:

  • Which assistant features are approved and for whom.
  • Verification requirements. Attorneys remain responsible for citations, facts and legal analysis.
  • Handling of client consent and outside counsel guideline restrictions on AI use.
  • Retention and discovery implications. Prompts and responses may be stored and may be discoverable, so ask your counsel and vendor how they are retained.

Step 7: Monitor and review

Ask for usage reports and audit logs. Revisit permissions quarterly, because new sites and groups accumulate. Watch vendor announcements, since features and data handling change often.

Cost and licensing

Licenses for AI features are typically an added per-user cost. Pilot results help you decide who benefits most, rather than buying for everyone. Ask your provider to help estimate the value against the cost based on actual usage.

How we can help

Counsel Cyber performs Microsoft 365 permission audits for law firms and helps plan AI pilots that respect confidentiality. If you are considering Copilot or a similar tool, we recommend starting with an access review, and we can run it with your administrator.