Oversharing is the single biggest cause of data exposure, and the thing Copilot inherits first. Set each control to how it really runs today and watch your score move.
You are 28 points below the posture we see in well-governed estates.
Sharing outside the organization is restricted and reviewed, not open by default.
"Anyone with the link" URLs are discovered, audited and expired.
Guest accounts expire automatically (typically 30 days) rather than lingering forever.
Users with excessive file and folder permissions are identified and cut back to least privilege.
Non-compliant and unused sharing links are deleted automatically on a rule-based schedule.
Dormant users and guests lose access automatically instead of retaining standing permissions.
Data owners periodically recertify who should have access, with a full audit trail.
Purview labels are applied and actually enforce protection, not just tag content.
AI agents and Copilot are monitored and restricted from sensitive data types.
This scorecard reflects what you know. A real assessment surfaces the anonymous links, overprivileged identities and AI agents already touching sensitive data across M365, Azure, AWS and on-premises file shares.