You can finally scope who sees sensitive organizational-data attributes
Share on LinkedIn!
#RegoConsulting #SimpleSharepoint #Microsoft365 #DataGovernance #DataPrivacy #InformationSecurity #CopilotReadiness #WorkforceInsights #Compliance #ITGovernance
Plenty of Microsoft 365 features quietly read your organizational data — job title, manager, department, cost center — to personalize what people see. Most tenants have never sat down and decided who should be able to see the sensitive attributes in that directory.
Microsoft is giving you that control. Starting mid-June 2026, Microsoft 365 Organizational Data adds granular access policies so admins can limit which custom attributes are released, and to which users — plus tighter control over how Workforce Insights delegates reach non-public data. Nothing changes for users unless an admin turns it on, so the default is status quo until you act.
As more people-analytics and Copilot experiences lean on org data, “who can see salary band or reporting chain” stops being a theoretical question. Attributes that feel harmless in a directory can become sensitive the moment they surface in a sidebar or an AI answer. This is a chance to scope that access before it’s a finding in an audit.
How the SimpleSharepoint team helps you get this done:
• Attribute audit — we map which custom attributes carry sensitive data and who currently has visibility into them.
• Policy configuration — we work with you to set the granular access and delegate controls so only the right people see the right fields.
• Ongoing review — we fold organizational-data access into a recurring data-governance review, so it keeps pace as you add attributes and analytics.
If you’re thinking through what your org data exposes as Copilot adoption grows, we’re happy to share what we’re seeing across tenants. Connect with us to learn more.



