What we check

Sign in

What we look at before Copilot is switched on.

54 checks

  • Licensing

    Every Copilot user has an eligible base licence

    Copilot is an add-on. It can only be assigned on top of a qualifying plan such as Business Basic, Standard or Premium, or E3/E5.

  • Licensing

    Enough Copilot licences for a meaningful pilot (10+ seats or around 10% of users)

    Microsoft recommends starting with a pilot phase. Fewer than around 10 seats rarely produces enough evidence to justify a wider rollout.

  • Licensing

    Copilot licences assigned through a pilot security group

    Makes moving from pilot to wider rollout a group membership change rather than per-user admin.

  • Licensing

    Copilot users have a Teams licence

    Some UK/EEA subscriptions are sold without Teams. Copilot in Teams meetings and chat needs it.

  • Identity

    Every user has a Microsoft Entra ID account (cloud or synced)

    A Microsoft minimum requirement for Copilot.

  • Identity

    MFA enforced for all users

    With Copilot, a compromised account can ask for everything that user can reach in seconds.

  • Identity

    Legacy authentication blocked

    Legacy protocols bypass MFA.

  • Identity

    Few Global Admins, with dedicated admin accounts

    Microsoft recommends least-privilege roles. Global Admins can see and change everything Copilot touches.

  • Identity

    Inactive accounts disabled or removed

    Dormant accounts keep their access and can be abused. They also waste licences.

  • Identity

    Guest users reviewed and stale guests removed

    Guests with access to Teams and sites widen the data Copilot can surface in shared spaces.

  • Identity

    Access from unmanaged devices controlled

    Stops Copilot answers containing company data being pulled onto personal devices.

  • Apps

    Microsoft 365 Apps deployed to Copilot users

    Microsoft requires the apps to be deployed for Copilot in Word, Excel, PowerPoint and Outlook.

  • Apps

    Apps on Current Channel or Monthly Enterprise Channel, not Semi-Annual

    Copilot isn't available on Semi-Annual Enterprise Channel.

  • Apps

    Primary mailboxes hosted in Exchange Online

    Copilot supports only primary mailboxes hosted in Exchange Online. It doesn't work on group mailboxes.

  • Apps

    OneDrive provisioned for every Copilot user

    Some Copilot features, such as file restore and OneDrive management, need a OneDrive account.

  • Apps

    Teams meeting transcription or recording allowed

    Without it, Copilot can't reference meeting content after the meeting ends.

  • Apps

    Connected experiences privacy settings allow Copilot

    Microsoft 365 Apps privacy settings can switch Copilot features off.

  • Apps

    Loop and Whiteboard enabled (if the client uses them)

    Copilot in Loop and Whiteboard only works when they're enabled for the tenant.

  • Apps

    Third-party cookies allowed for Office web apps

    Microsoft requires this for Copilot in Word, Excel and PowerPoint Online.

  • Apps

    Office Feature Updates scheduled task running on devices

    Microsoft says this task is required for core Copilot experiences in Word, PowerPoint, Excel and OneNote.

  • Network

    *.cloud.microsoft and Microsoft 365 endpoints allowed, with WebSockets not blocked or TLS-inspected

    Copilot uses WebSockets. Firewalls, proxies or TLS inspection that break them cause Copilot failures.

  • Network

    No Conditional Access or tenant restriction blocking copilot.cloud.microsoft

    Microsoft calls out legacy blocking rules and restrictions as a common cause of Copilot not loading.

  • Oversharing

    Anonymous "Anyone" links disabled or restricted at tenant level

    Microsoft's blueprint recommends disabling or restricting Anyone links as a secure default.

  • Oversharing

    Default sharing link set to "Specific people"

    Reduces company-wide links being created by default. The same tenant settings apply to OneDrive.

  • Oversharing

    "Everyone except external users" and Everyone not granted on sites

    This is the most common cause of internal oversharing. It makes site content reachable, and therefore surfaceable by Copilot, for every user.

  • Oversharing

    Existing Anyone and organisation-wide sharing links reviewed

    Broad links on sensitive files widen who can reach them.

  • Oversharing

    Public Teams and Microsoft 365 Groups reviewed

    Public groups give the whole organisation access to their files and conversations.

  • Oversharing

    Every site and team has at least two active owners

    Microsoft's blueprint requires accountable ownership so access reviews can happen.

  • Oversharing

    Inactive sites identified and archived or removed

    Stale content lowers answer quality and widens exposure.

  • Oversharing

    Broken permission inheritance reviewed on sensitive libraries and folders

    Unique permissions hide oversharing that site-level checks miss.

  • Oversharing

    Site-level external sharing matches client policy

    Sites more permissive than the tenant default are a common gap.

  • Oversharing

    Restricted Content Discovery applied to sensitive sites still being remediated

    Hides a site from Copilot and org-wide search without changing anyone's access.

  • Oversharing

    Restricted SharePoint Search allow-list, if a pilot must start before oversharing is fixed

    A stop-gap: Copilot only searches vetted sites plus the user's own content.

  • Oversharing

    Restricted Access Control on business-critical sites

    Limits a site to a named group regardless of sharing, as a durable guardrail.

  • Data protection

    Unified audit logging enabled

    Records Copilot prompts, responses and referenced content for investigation and compliance.

  • Data protection

    Sensitivity label taxonomy published (e.g. Public, Internal, Confidential, Highly Confidential)

    Labels are how you tell Copilot what it mustn't use. Label encryption is respected by Copilot, and Copilot DLP is label-based.

  • Data protection

    Default label applied to new documents and emails

    Improves label coverage without relying on users.

  • Data protection

    Sensitivity labels enabled for sites, Teams and groups

    Lets site privacy and sharing be enforced by label at creation.

  • Data protection

    Auto-labelling for sensitive content

    Microsoft's blueprint recommends it. Manual labelling alone rarely achieves enough coverage.

  • Data protection

    DLP policies for Exchange, SharePoint and OneDrive

    Stops sensitive data leaving via email and sharing, and underpins the Copilot-specific DLP controls.

  • Data protection

    DLP policy for the Copilot location: exclude labelled content, block sensitive prompts, restrict web search and exclude external email

    This stops Copilot from using labelled files or sensitive data in prompts, even when the user has access.

  • Data protection

    Retention policy decided for Copilot interactions

    Copilot prompts and responses are stored and can be discovered. The client needs to choose how long they're kept.

  • Data protection

    Legacy IRM-protected documents moved to sensitivity labels

    Microsoft notes that documents using legacy IRM aren't used for Copilot grounding.

  • Data protection

    DSPM for AI and Insider Risk Management configured

    Microsoft's optimised tier. It gives ongoing visibility of risky AI use and data exposure.

  • Apps & connections

    Third-party app consents with mail or file access reviewed

    Shows which external services already read company data, and where data lives outside Microsoft 365.

  • Apps & connections

    User consent restricted, with the admin consent workflow enabled

    Stops users connecting third-party AI tools to company data without approval.

  • Apps & connections

    Third-party AI and storage services identified (e.g. ChatGPT, Dropbox, Google Drive)

    Shows data stored outside Microsoft 365. Copilot can't see that data, and staff may be pasting company data into these tools.

  • Apps & connections

    App registrations with high privileges or expired secrets reviewed

    Over-privileged apps are a route to all tenant data.

  • Apps & connections

    Existing Copilot connectors inventoried

    Connectors extend what Copilot grounds on beyond Microsoft 365.

  • Apps & connections

    Agent, plugin and web grounding settings agreed with the client

    These decide who can create or use agents and whether Copilot can search the web.

  • Adoption

    Usage reports show real user names (report concealment off)

    Needed to pick pilot users from usage data. Needs the client's agreement for privacy reasons.

  • Adoption

    Microsoft 365 app usage reviewed to shortlist pilot users

    Users who already rely heavily on Microsoft 365 get the most from Copilot, so they make the strongest pilot group.

  • Adoption

    Copilot usage reporting available for measuring the pilot

    Lets you review adoption after the pilot and supports the ROI conversation.

  • Adoption

    Copilot admin tasks delegated to the AI Administrator role

    Microsoft recommends least privilege. Global Admin isn't needed to manage Copilot.