M-Tech Labs AIClean up the permissions AI will quietly inherit from SharePoint and Entra.
Copilot and agents take whatever access your identity and sharing model already grants. We tighten that model before an LLM puts a search API across the top of it.
Where we look, and what we change.
A focused review across identity, privileged access and sharing — the three surfaces that decide what Copilot will be allowed to read.
Privileged role audit
Conditional Access baseline
SharePoint & Teams permissions
Guest & external access
Offboarding & account lifecycle
Defensible, documented, reproducible.
The same controls Assurix verifies live — privileged-access hygiene, MFA/CA posture, patch and supplier discipline — written down once so you stop rediscovering them.
- 01
Identity risk register
Every finding scored by likelihood and blast radius, with a named owner and a remediation step — the kind auditors actually like.
- 02
Privileged-access plan
PIM scope, break-glass design, standing-rights cleanup list — a pragmatic path to least privilege, not a purity exercise.
- 03
Conditional Access ruleset
Cleaned-up policy set, documented exclusions and a change log — so the next reviewer doesn't start from zero.
- 04
Sharing & lifecycle runbook
How new sites are provisioned, how sharing is defaulted, how leavers are offboarded — written so operations can run it.
What we usually find first.
None of these are rare. All of them matter more the moment an LLM can ask "show me everything about X".
- A dozen accounts with standing Global Admin rights and no PIM.
- Service accounts using password auth with scopes broader than any person has.
- Conditional Access policies in report-only mode since the original pilot.
- "Anyone with the link" as the tenant default sharing mode.
- Guest accounts from projects that finished 18 months ago, still active.
- Former employees' OneDrives still licensed and indexed by search.
Delivered by M-Tech Labs with the compliance and security discipline of M-Tech Systems — Cyber Essentials certified, aligned to NCSC CAF 4.0 and progressing through the Assurix trustmark programme.
Back to AI ConsultancyTighten identity before Copilot goes live.
A focused review, a prioritised fix list, and the option to stay on for the remediation sprint that actually closes the gaps.