What we look at before Copilot is switched on.
54 checks
Licensing
Every Copilot user has an eligible base licence
Copilot is an add-on. It can only be assigned on top of a qualifying plan such as Business Basic, Standard or Premium, or E3/E5.
Licensing
Enough Copilot licences for a meaningful pilot (10+ seats or around 10% of users)
Microsoft recommends starting with a pilot phase. Fewer than around 10 seats rarely produces enough evidence to justify a wider rollout.
Licensing
Copilot licences assigned through a pilot security group
Makes moving from pilot to wider rollout a group membership change rather than per-user admin.
Licensing
Copilot users have a Teams licence
Some UK/EEA subscriptions are sold without Teams. Copilot in Teams meetings and chat needs it.
Identity
Every user has a Microsoft Entra ID account (cloud or synced)
A Microsoft minimum requirement for Copilot.
Identity
MFA enforced for all users
With Copilot, a compromised account can ask for everything that user can reach in seconds.
Identity
Legacy authentication blocked
Legacy protocols bypass MFA.
Identity
Few Global Admins, with dedicated admin accounts
Microsoft recommends least-privilege roles. Global Admins can see and change everything Copilot touches.
Identity
Inactive accounts disabled or removed
Dormant accounts keep their access and can be abused. They also waste licences.
Identity
Guest users reviewed and stale guests removed
Guests with access to Teams and sites widen the data Copilot can surface in shared spaces.
Identity
Access from unmanaged devices controlled
Stops Copilot answers containing company data being pulled onto personal devices.
Apps
Microsoft 365 Apps deployed to Copilot users
Microsoft requires the apps to be deployed for Copilot in Word, Excel, PowerPoint and Outlook.
Apps
Apps on Current Channel or Monthly Enterprise Channel, not Semi-Annual
Copilot isn't available on Semi-Annual Enterprise Channel.
Apps
Primary mailboxes hosted in Exchange Online
Copilot supports only primary mailboxes hosted in Exchange Online. It doesn't work on group mailboxes.
Apps
OneDrive provisioned for every Copilot user
Some Copilot features, such as file restore and OneDrive management, need a OneDrive account.
Apps
Teams meeting transcription or recording allowed
Without it, Copilot can't reference meeting content after the meeting ends.
Apps
Connected experiences privacy settings allow Copilot
Microsoft 365 Apps privacy settings can switch Copilot features off.
Apps
Loop and Whiteboard enabled (if the client uses them)
Copilot in Loop and Whiteboard only works when they're enabled for the tenant.
Apps
Third-party cookies allowed for Office web apps
Microsoft requires this for Copilot in Word, Excel and PowerPoint Online.
Apps
Office Feature Updates scheduled task running on devices
Microsoft says this task is required for core Copilot experiences in Word, PowerPoint, Excel and OneNote.
Network
*.cloud.microsoft and Microsoft 365 endpoints allowed, with WebSockets not blocked or TLS-inspected
Copilot uses WebSockets. Firewalls, proxies or TLS inspection that break them cause Copilot failures.
Network
No Conditional Access or tenant restriction blocking copilot.cloud.microsoft
Microsoft calls out legacy blocking rules and restrictions as a common cause of Copilot not loading.
Oversharing
Anonymous "Anyone" links disabled or restricted at tenant level
Microsoft's blueprint recommends disabling or restricting Anyone links as a secure default.
Oversharing
Default sharing link set to "Specific people"
Reduces company-wide links being created by default. The same tenant settings apply to OneDrive.
Oversharing
"Everyone except external users" and Everyone not granted on sites
This is the most common cause of internal oversharing. It makes site content reachable, and therefore surfaceable by Copilot, for every user.
Oversharing
Existing Anyone and organisation-wide sharing links reviewed
Broad links on sensitive files widen who can reach them.
Oversharing
Public Teams and Microsoft 365 Groups reviewed
Public groups give the whole organisation access to their files and conversations.
Oversharing
Every site and team has at least two active owners
Microsoft's blueprint requires accountable ownership so access reviews can happen.
Oversharing
Inactive sites identified and archived or removed
Stale content lowers answer quality and widens exposure.
Oversharing
Broken permission inheritance reviewed on sensitive libraries and folders
Unique permissions hide oversharing that site-level checks miss.
Oversharing
Site-level external sharing matches client policy
Sites more permissive than the tenant default are a common gap.
Oversharing
Restricted Content Discovery applied to sensitive sites still being remediated
Hides a site from Copilot and org-wide search without changing anyone's access.
Oversharing
Restricted SharePoint Search allow-list, if a pilot must start before oversharing is fixed
A stop-gap: Copilot only searches vetted sites plus the user's own content.
Oversharing
Restricted Access Control on business-critical sites
Limits a site to a named group regardless of sharing, as a durable guardrail.
Data protection
Unified audit logging enabled
Records Copilot prompts, responses and referenced content for investigation and compliance.
Data protection
Sensitivity label taxonomy published (e.g. Public, Internal, Confidential, Highly Confidential)
Labels are how you tell Copilot what it mustn't use. Label encryption is respected by Copilot, and Copilot DLP is label-based.
Data protection
Default label applied to new documents and emails
Improves label coverage without relying on users.
Data protection
Sensitivity labels enabled for sites, Teams and groups
Lets site privacy and sharing be enforced by label at creation.
Data protection
Auto-labelling for sensitive content
Microsoft's blueprint recommends it. Manual labelling alone rarely achieves enough coverage.
Data protection
DLP policies for Exchange, SharePoint and OneDrive
Stops sensitive data leaving via email and sharing, and underpins the Copilot-specific DLP controls.
Data protection
DLP policy for the Copilot location: exclude labelled content, block sensitive prompts, restrict web search and exclude external email
This stops Copilot from using labelled files or sensitive data in prompts, even when the user has access.
Data protection
Retention policy decided for Copilot interactions
Copilot prompts and responses are stored and can be discovered. The client needs to choose how long they're kept.
Data protection
Legacy IRM-protected documents moved to sensitivity labels
Microsoft notes that documents using legacy IRM aren't used for Copilot grounding.
Data protection
DSPM for AI and Insider Risk Management configured
Microsoft's optimised tier. It gives ongoing visibility of risky AI use and data exposure.
Apps & connections
Third-party app consents with mail or file access reviewed
Shows which external services already read company data, and where data lives outside Microsoft 365.
Apps & connections
User consent restricted, with the admin consent workflow enabled
Stops users connecting third-party AI tools to company data without approval.
Apps & connections
Third-party AI and storage services identified (e.g. ChatGPT, Dropbox, Google Drive)
Shows data stored outside Microsoft 365. Copilot can't see that data, and staff may be pasting company data into these tools.
Apps & connections
App registrations with high privileges or expired secrets reviewed
Over-privileged apps are a route to all tenant data.
Apps & connections
Existing Copilot connectors inventoried
Connectors extend what Copilot grounds on beyond Microsoft 365.
Apps & connections
Agent, plugin and web grounding settings agreed with the client
These decide who can create or use agents and whether Copilot can search the web.
Adoption
Usage reports show real user names (report concealment off)
Needed to pick pilot users from usage data. Needs the client's agreement for privacy reasons.
Adoption
Microsoft 365 app usage reviewed to shortlist pilot users
Users who already rely heavily on Microsoft 365 get the most from Copilot, so they make the strongest pilot group.
Adoption
Copilot usage reporting available for measuring the pilot
Lets you review adoption after the pilot and supports the ROI conversation.
Adoption
Copilot admin tasks delegated to the AI Administrator role
Microsoft recommends least privilege. Global Admin isn't needed to manage Copilot.