A Copilot readiness assessment is the work you do before a single licence is assigned: a structured audit of your Microsoft 365 tenant that establishes whether Copilot will surface the right information to the right people, and nothing else. It is the difference between a rollout that lands quietly and one that turns into an information-governance incident in week two.
This guide is the full Copilot tenant assessment, written as a checklist a UK IT leader can work through in order. It covers licensing and eligibility, Microsoft Entra ID and identity prerequisites, Microsoft Graph permissions and the semantic index, SharePoint and OneDrive hygiene, sensitivity labelling and Microsoft Purview controls, device and app baselines, pilot design, and the measurement layer you need afterwards. Every M365 Copilot prerequisite is treated as a verifiable item with a pass condition, an owner and a rough effort estimate, so the output is a plan rather than a reading list. If you want the wider context on what the product does before you assess for it, start with our complete guide to Microsoft 365 Copilot for UK businesses, then come back here to size the work.
What a Copilot readiness assessment actually is
Microsoft 365 Copilot does not have its own permission model. It inherits the one you already have. When a user asks Copilot a question, the orchestration layer queries Microsoft Graph on that user’s behalf, retrieves only the content that user could already open in SharePoint, OneDrive, Exchange or Teams, and grounds the language model’s answer in what came back. There is no separate access control list to configure, no Copilot-specific sharing setting that overrides the tenant, and no filter that quietly hides content the user technically has rights to.
That single architectural fact is why a Copilot tenant assessment is necessary. Most UK organisations have spent a decade accumulating permissions they never intended to grant: a finance workbook shared to “Everyone except external users” in 2019, a departed employee’s OneDrive still delegated to their old line manager, a Teams site created for a redundancy consultation whose membership was never trimmed. None of that mattered much when discovery depended on someone knowing the file existed and typing the right words into SharePoint search. Copilot removes that friction entirely. It reads across everything a user can reach, summarises it in natural language, and volunteers connections the user never asked for.
A readiness assessment therefore has two halves. The first is technical eligibility — the M365 Copilot prerequisites that determine whether the service will function at all: the right base licence, cloud-hosted mailboxes, provisioned OneDrive, a supported Apps channel, Entra ID accounts with modern authentication. The second, and by far the larger, is exposure and governance — establishing what your tenant would actually reveal if every employee started asking it questions on Monday morning. The first half takes days. The second half is where the real project sits.
The assessment is also the point at which you decide what “ready” means for your organisation. A 40-person architecture practice with one SharePoint site and no regulated data has a very different bar to a 900-person housing association handling tenant records under UK GDPR. Readiness is not a Microsoft-defined threshold; it is a risk decision your organisation makes, documented, with a named owner. The checklist below gives you the evidence to make it.
Run the assessment against your production tenant, not a sandbox. The entire value of the exercise is measuring real accumulated permissions and real content sprawl. A clean test tenant will pass every check and tell you nothing useful about what Copilot will do in front of your staff.
Two approaches to Copilot deployment — and why the sequence matters
Organisations preparing for Copilot broadly split into two camps. The first buys licences, hands them to the loudest enthusiasts, and deals with governance when something surfaces. The second treats the readiness assessment as a gate: no licence is assigned until the tenant clears a defined set of checks. Both get to the same place eventually, but the cost profile and the risk profile are very different.
Deploy first, govern later
Licences assigned before assessment
Readiness assessment first
Assessment gates the licence assignment
The second column is not a recommendation to move slowly. It is a recommendation to move the work forwards rather than backwards. Permission remediation is the same volume of effort either way; the only variable is whether you do it before your staff see the results or afterwards. Doing it afterwards adds an incident, a communications exercise and, in regulated sectors, a conversation with your data protection officer that you would rather have had in advance.
There is also a licensing dimension to the sequence. Microsoft 365 Copilot is sold on an annual commitment at roughly £24.70 per user per month on UK list pricing, so a 200-seat commitment is a material spend before a single readiness gap has been closed. Assessing first lets you size the pilot cohort against actual value rather than optimism. Our Microsoft 365 Copilot cost and ROI guide works through the commercial modelling in detail; the point here is simply that the assessment should inform the purchase order, not follow it.
Copilot tenant assessment scorecard — where UK organisations typically sit
The scorecard below reflects the pattern we see repeatedly when assessing mid-market UK tenants that have grown organically since a Microsoft 365 migration three to eight years ago. Ratings are risk ratings, not quality judgements: “high” means this item will materially affect what Copilot surfaces and should be remediated before broad rollout. Use it as a triage frame for your own assessment rather than a benchmark to beat.
Read the scorecard vertically rather than horizontally. Almost every organisation clears the licensing row easily and struggles with the sharing rows, because licensing is a procurement decision made once and sharing is thousands of small decisions made by end users over years. The assessment’s job is to convert those thousands of small decisions into a countable, prioritised remediation backlog.
Copilot readiness in numbers
The figures below are the planning assumptions we use when scoping a Copilot tenant assessment for a UK organisation of 100–500 seats. They are indicative ranges drawn from assessment engagements, not published research, and your own numbers will differ — but they are close enough to build a credible project plan and budget from before you have run a single scan.
That last figure is the one worth internalising. Oversharing is rarely evenly distributed. In most tenants a small minority of sites — typically the ones created early, before any provisioning standard existed, or the ones created in a hurry during a specific project — carry the overwhelming majority of the exposure. A readiness assessment that ranks sites by risk and fixes the top few per cent gets you most of the way there. An assessment that tries to review every site equally will stall.
Where readiness assessments find the most gaps
When we complete a Copilot readiness assessment, findings cluster into a predictable set of categories. The chart below shows the proportion of assessments in which each category produced at least one item requiring remediation before rollout. It is a useful prompt for your own review: if you have not looked at the top three, you have not assessed your tenant.
The shape of that chart is the argument for sequencing the assessment the way this checklist does. The purely technical prerequisites — update channel, mailbox location, OneDrive provisioning — are the least likely to block you and the quickest to fix. The governance items are the most likely to block you and the slowest to fix. Teams that plan a two-week readiness exercise are almost always planning against the bottom of the chart and will be surprised by the top.
Broad sharing links deserve particular attention because they are invisible in most reporting. A file shared with an “anyone with the link” URL does not appear as a permission on a site; it appears as a sharing link object. Copilot honours it exactly as SharePoint search does, which means content a site owner believes is restricted can be reachable by anyone who has ever been forwarded the URL. Auditing links, not just permissions, is a distinct step in the assessment.
M365 Copilot prerequisites — maturity benchmarks by control area
Readiness is not binary. Each prerequisite sits on a spectrum from “not started” to “operating and evidenced”, and the honest position for most organisations preparing for Copilot is somewhere in the middle. The benchmarks below give you a way to score your own tenant per control area rather than producing a single pass or fail. Score each line 0–100 against the description, then compare with the indicative mid-market position shown.
Indicative mid-market UK position before remediation
The gradient down that list is the story of the whole exercise. Anything Microsoft can enforce centrally — licence assignment, update channel, mailbox location — scores well because it has an owner and a console. Anything that depends on distributed human behaviour across years — who owns a site, who a link was shared with, what a document is classified as — scores badly, because nobody was ever accountable for it in a way that showed up on a dashboard.
The two lowest lines are worth calling out. Purview DLP scoped to AI interactions is a comparatively recent capability and is genuinely under-deployed; it lets you stop labelled content being summarised into a Copilot response or pasted into a prompt. Adoption measurement scores lowest of all because most organisations only think about it after go-live, at which point they have no baseline to compare against and no way to answer the board question “is this delivering anything?”. Both belong in the readiness assessment, not the post-deployment tidy-up.
The readiness timeline — eight weeks from assessment to first pilot
The sequence below is the one we run for a mid-market UK organisation with a single Microsoft 365 tenant, no active merger activity and a co-operative information governance function. Larger estates, multiple tenants or regulated data extend the middle phases rather than the ends. The critical dependency to protect is that discovery must complete before remediation is scoped, and remediation of the top-risk sites must complete before any licence is assigned.
Two scheduling notes. First, the technical eligibility audit and the permission discovery can start on the same day — they use different tooling and different people, and running them in series wastes a week. Second, resist compressing the remediation phase to hit a licence renewal date. Copilot licences bought before the tenant is ready still bill monthly while sitting unassigned, which is a worse outcome than a purchase order signed four weeks later.
Scoring your tenant — the readiness gauge
Once you have worked the checklist you need a single number to report upwards. The gauge below shows the composite readiness score of the indicative mid-market tenant described in the benchmarks section: a weighted average across licensing, identity, content governance, data protection and measurement, with the governance categories weighted most heavily because they carry the most risk.
Forty-six out of a hundred is not an alarming score and it is not a good one. It is the score of an organisation that runs Microsoft 365 competently, has never had a reason to audit its sharing model, and would be caught out by the first serious Copilot query. The distance between 46 and a defensible 80 is almost entirely governance work, and almost none of it is Copilot-specific — it is the tenant hygiene that a Cyber Essentials assessment, an ISO 27001 surveillance audit or a client security questionnaire would also expect to see.
We suggest three thresholds. Below 50, do not assign licences beyond a tightly controlled technical pilot with a cohort that has no access to sensitive content. Between 50 and 75, a departmental pilot is reasonable provided the top-risk sites identified in discovery have been remediated first. Above 75, a phased general rollout is defensible, with the remaining gaps tracked on a risk register with owners and dates. Publishing those thresholds before you measure keeps the conversation honest when the number comes back lower than the sponsor hoped.
What Copilot readiness costs
Budget for a readiness assessment as a project with three cost lines: the assessment and remediation effort, any additional licensing required to run the controls you decide you need, and the Copilot subscription itself. The table below gives indicative UK ranges for a 100–500 seat organisation. Figures exclude VAT and assume a single tenant with no merger or divestment activity in flight.
| Cost line | What it covers | Indicative UK range | Notes |
|---|---|---|---|
| Readiness assessment | Eligibility audit, permission and sharing discovery, ranked findings report, remediation plan | £4,500–£12,000 | Scales with number of SharePoint sites, not headcount |
| Remediation delivery | Sharing cleanup, site ownership, label design and rollout, DLP policy build | £6,000–£30,000 | The widest variable; driven by estate condition, not size |
| Supporting licences | Entra ID P1/P2 for Conditional Access and access reviews, Purview capabilities where not already held | £0–£9 per user per month | Often already covered by Business Premium or E5 |
| Microsoft 365 Copilot | The Copilot subscription itself, annual commitment | Approx. £24.70 per user per month | Check current list pricing with your CSP before budgeting |
| Adoption and enablement | Pilot facilitation, prompt training, champion network, usage reporting setup | £3,000–£15,000 | Consistently the most under-budgeted line |
The line that surprises people is remediation delivery, because its range is so wide. That width is real and it is the single strongest argument for running discovery before committing to a rollout date. An organisation that provisioned SharePoint through a controlled request process from day one may need a fortnight of tidying. An organisation that let anyone create a Team since 2020 may be looking at a genuine information management programme with a business change component. Discovery is what tells you which of those you are, and it costs a fraction of either outcome.
Note also that supporting licences are frequently already paid for. Business Premium and E5 tenants usually hold the Entra ID and Purview capabilities needed for the core controls; the gap is configuration, not procurement. Before adding a line to the budget, check what is already in the agreement — and check the same for SharePoint Advanced Management, whose oversharing reports are included with a Microsoft 365 Copilot licence.
The oversharing problem, in one chart
If you take one figure away from a Copilot tenant assessment, make it this one: the proportion of an organisation’s SharePoint and OneDrive content that is reachable by a materially wider audience than its owner believes. Across the mid-market UK tenants we assess, that share clusters uncomfortably close to a third.
The word doing the work in that sentence is “intended”. None of this content is exposed through a misconfiguration in the usual sense. Every permission was granted deliberately by somebody, at some point, for a reason that made sense at the time. The gap is between the intent behind an individual sharing decision and its cumulative effect years later, compounded by group nesting, inherited permissions and links forwarded outside the original conversation.
Copilot does not create that gap. It measures it, out loud, in front of your staff. A user who asks “what is our current position on the restructure?” is not attacking your permission model; they are exercising it exactly as configured. This is why remediation must precede rollout, and why the assessment is best framed to the business as an information governance exercise that Copilot has made urgent rather than a Copilot project with a governance appendix.
It is also why the fix is durable. Every hour spent tightening sharing, assigning site owners and applying sensitivity labels pays back against subject access requests, eDiscovery, insurer questionnaires and your next Cyber Essentials certification as much as it does against Copilot. Organisations that frame it that way get budget approved considerably faster.
The 12-point Copilot readiness checklist
This is the working checklist. Each item states what to verify, what a pass looks like, and where the work usually goes wrong. Assign every item an owner and a target date before you start; the most common failure mode of a readiness assessment is not that a check fails, but that nobody was accountable for closing it. Work the items in order — the sequence is deliberate, because later items depend on the visibility that earlier ones create.
- Confirm base licence eligibility for every intended user. Microsoft 365 Copilot is an add-on, not a standalone product. Each user needs a qualifying base licence — typically Microsoft 365 Business Standard, Business Premium, E3 or E5, or the equivalent Office 365 plan. Pass condition: every member of the pilot cohort appears in a licensing report with a qualifying base plan and no conflicting assignment. Where it goes wrong: mixed estates after an acquisition, where a subset of users sit on a legacy plan nobody has audited since migration. Run the report before you sign the order, not after.
- Verify every mailbox is in Exchange Online. Copilot in Outlook and the Teams meeting recap depend on cloud-hosted mailboxes. Users left on-premises in a hybrid configuration will see a licensed but partially functional experience, which generates support tickets and undermines the pilot. Pass condition: zero mailboxes for intended users remain on-premises. Where it goes wrong: long-running hybrid deployments where a handful of shared or resource mailboxes were never migrated and nobody remembers why.
- Confirm OneDrive is provisioned and in use for every user. OneDrive underpins several Copilot experiences, and users who still save to a local drive or a mapped legacy share will get thin results and conclude the product does not work. Pass condition: OneDrive provisioned for 100 per cent of the cohort with evidence of active use, not just existence. Where it goes wrong: organisations that migrated file shares to SharePoint but never moved personal storage, leaving a shadow estate outside Copilot’s reach and outside your governance.
- Put every user on a supported Microsoft 365 Apps update channel. Copilot features in Word, Excel, PowerPoint and Outlook require current builds. Devices parked on an extended-support channel or excluded from update policy will lag, sometimes by months. Pass condition: all cohort devices report a current channel and a build within the supported window in your endpoint management console. Where it goes wrong: a legacy exclusion group created years ago for one line-of-business add-in that still contains fifty devices.
- Enforce multi-factor authentication and review Conditional Access. Copilot inherits the identity posture of the tenant. If an account can be phished, everything that account can reach through Copilot can be reached by whoever phished it — faster and better summarised. Pass condition: MFA enforced for all users including service and break-glass exceptions documented, and Conditional Access policies reviewed to confirm they apply to the apps Copilot surfaces through. Where it goes wrong: MFA reported as “enabled” at the licence level but not actually enforced by policy. Our guide to phishing-resistant MFA and passkeys covers the stronger position worth aiming for.
- Audit sharing links, not just permissions. Anonymous and organisation-wide links are separate objects from site permissions and are missed by permission-only reviews. Pass condition: a complete inventory of active sharing links with an expiry policy applied, and anonymous link creation either disabled or restricted to specific sites with a maximum lifetime. Where it goes wrong: teams audit site membership carefully, declare themselves clean, and never look at the link inventory at all.
- Assign an accountable owner to every SharePoint site and Team. Ownerless containers cannot be governed, because there is nobody to ask whether the content should still be open. Pass condition: zero sites without at least two active owners, with a documented process for reassigning ownership when an owner leaves. Where it goes wrong: leaver processes that disable the account and remove licences but leave the person as the sole owner of eleven sites.
- Eliminate default broad sharing on high-value sites. “Everyone except external users” is the single most common source of unintended Copilot exposure. Pass condition: no site containing HR, finance, legal, board or personal data grants access to a tenant-wide group, with exceptions individually justified and recorded. Where it goes wrong: the broad group is nested three levels deep inside a group that looks specific, so the site’s permission page appears reasonable at a glance.
- Publish and apply sensitivity labels. Labels are what let you express “this is confidential” in a way that Purview controls, encryption and DLP can act on, including for AI interactions. Pass condition: a published label taxonomy with default labels applied at container level for the highest-risk sites, and label-based policy enforced rather than advisory. Where it goes wrong: an elaborate label scheme designed by committee, published, and then applied to nothing because manual application was left to end users.
- Extend data loss prevention to cover AI interactions. Microsoft Purview can prevent labelled content being used to ground a Copilot response or pasted into a prompt. Pass condition: DLP policies explicitly scoped to cover Copilot alongside Exchange, SharePoint, OneDrive, Teams and endpoints, tested with a deliberately sensitive query. Where it goes wrong: mature DLP estates built before AI interactions existed as a workload, which quietly leave the newest channel uncovered.
- Confirm retention, audit and eDiscovery cover Copilot activity. Prompts and responses are records. They are discoverable, they may contain personal data, and your obligations under UK GDPR apply to them. Pass condition: retention policy covers Copilot interactions, audit logging is enabled and retained for a period that matches your incident response needs, and your eDiscovery process has been tested against a Copilot interaction. Where it goes wrong: nobody asks the question until a subject access request arrives.
- Define measurement, then set the baseline before you deploy. Decide what you will report on — active usage by function, task categories, qualitative feedback from the pilot cohort — and capture the pre-deployment baseline while you still can. Pass condition: a named owner for adoption reporting, a defined reporting cadence, and a baseline recorded before the first licence is assigned. Where it goes wrong: the sponsor asks for value evidence at month three and there is nothing to compare against.
Items 1–5 are technical prerequisites and can usually be closed in a fortnight. Items 6–11 are governance and typically account for 80 per cent of the total effort. Item 12 costs almost nothing and is the one most often skipped — and it is the one you will wish you had done when the first review meeting arrives.
What a readiness assessment looks like in practice
A 240-person professional services firm in the North West approached a Copilot rollout after their leadership team saw a demonstration at a client event. The initial plan was 60 licences assigned within a fortnight. The readiness assessment ran instead, and the technical eligibility audit cleared in four days: Business Premium throughout, all mailboxes in Exchange Online, OneDrive provisioned, current update channel. On the technical prerequisites they were genuinely ready.
Permission discovery told a different story. Of 412 SharePoint sites, 78 had no active owner, most created during a 2021 push to move project work into Teams. Fourteen sites containing employee relations material, partner remuneration data or live client engagement letters granted access to a tenant-wide group through a nested security group nobody had reviewed since it was created. Just over 1,900 anonymous sharing links were active, of which more than 600 had been created over two years earlier and never expired.
The firm did not stop the project. It resequenced it. Remediation of the fourteen highest-risk sites and the expired link population took five weeks alongside a sensitivity label rollout covering the four site collections holding client and HR data. The pilot then ran with 22 users across four functions rather than 60 enthusiasts, with a defined feedback loop and audit log review each Friday. Broad rollout followed a further six weeks later, in two waves, with the same checks applied to each wave before licences were assigned.
We thought the assessment was going to be a licensing exercise and a two-week delay. What it actually found was that our sharing model had drifted a long way from what any of us assumed, and the tool would have shown that to two hundred people before it showed it to us. The delay bought us the ability to answer questions from our clients about it afterwards.
The detail worth borrowing is the pilot composition. Choosing 22 users across finance, delivery, business development and administration rather than the 60 most enthusiastic volunteers produced findings that generalised. Enthusiast-only pilots reliably report that Copilot is excellent, because enthusiasts are good at prompting and forgiving of poor answers. A representative cohort tells you what the rollout will actually feel like, and it surfaces the training gap while it is still cheap to close.
Common mistakes when preparing for Copilot
Most Copilot readiness projects that go badly go badly for a small number of repeated reasons. None of them are technical failures of the product; they are planning and sequencing errors that were avoidable at the point the project was scoped.
- Treating readiness as a licensing question. Confirming eligibility is item one of twelve and takes days. Organisations that scope the whole assessment as “check we have the right licences” discover the remaining eleven items after the licences are already billing.
- Auditing permissions but not sharing links. A site can have flawless membership and still be reachable through an anonymous link created three years ago. Link inventory is a separate exercise with separate tooling and it is skipped more often than any other check.
- Designing a sensitivity label taxonomy nobody applies. Twelve labels with sub-labels and a governance forum, applied manually by end users, produces near-zero coverage. Three or four labels applied by default at container level produces coverage that DLP can actually act on.
- Piloting only with enthusiasts. A volunteer cohort will report high satisfaction regardless of tenant condition, because they will work around poor results rather than report them. The pilot then fails to predict anything about the general rollout.
- Leaving information governance and the DPO until the end. Bringing the data protection function in at week seven means either a rushed sign-off or a stalled project. Bringing them in at week one usually means they help scope the discovery in a way that produces the evidence they need.
- Assuming Copilot respects an unstated intent. There is no setting that means “do not surface this even though the user can open it” short of changing the permission, applying a label with enforcement, or using restricted content discovery. Intent is not a control.
- Skipping the baseline measurement. Without a pre-deployment baseline, every subsequent value conversation is anecdote. The measurement setup costs a day and cannot be reconstructed retrospectively.
- Buying for the whole organisation before the pilot reports. An annual commitment across every seat removes your ability to sequence rollout by readiness, and leaves unassigned licences billing while remediation completes.
The most expensive version of this project is the one that assigns licences first and discovers the sharing model second. Remediation under incident conditions costs the same technical effort as planned remediation, plus a communications exercise, plus a conversation with your data protection officer, plus the adoption damage of asking staff to stop using a tool they were just given.
Copilot readiness at a glance
The summary table below condenses the assessment into the facts most often needed when briefing a board, a client or an auditor. Treat the ranges as planning assumptions to be replaced with your own measured figures once discovery completes.
| Item | Position |
|---|---|
| What Copilot readiness assessment means | Structured audit of licensing, identity, content permissions and data governance before licences are assigned |
| Permission model | Inherited from Microsoft 365; Copilot surfaces only what the user can already access |
| Base licence required | Microsoft 365 Business Standard, Business Premium, E3, E5 or equivalent Office 365 plan |
| Core technical prerequisites | Entra ID account, Exchange Online mailbox, provisioned OneDrive, supported Apps update channel |
| Approximate UK list price | Around £24.70 per user per month, annual commitment |
| Typical assessment duration | 4–8 weeks from kick-off to first pilot licence |
| Assessment cost range | £4,500–£12,000 for a 100–500 seat organisation |
| Remediation cost range | £6,000–£30,000, driven by estate condition rather than headcount |
| Most common finding | Broad or anonymous sharing links reaching a wider audience than intended |
| Effort distribution | Roughly 20 per cent technical prerequisites, 80 per cent governance and remediation |
| Recommended pilot size | 15–40 users spread across functions, not volunteers only |
| Key UK compliance touchpoints | UK GDPR records of processing, DPIA, ICO guidance on AI and data protection, NCSC secure design principles |
| Tooling for discovery | SharePoint Advanced Management oversharing reports, Microsoft Purview, Entra ID access reviews |
| Readiness score threshold for phased rollout | 75 or above on a weighted composite, with residual gaps on a tracked risk register |
How Cloudswitched approaches Copilot readiness
Cloudswitched runs Copilot tenant assessments for UK organisations as a defined engagement with a fixed discovery phase and a ranked, costed remediation plan at the end of it. The discovery covers the twelve checklist items above, uses SharePoint Advanced Management and Microsoft Purview reporting rather than assumptions, and produces evidence in a form your information governance function and your auditors can use directly. Where remediation is needed, we can scope it as a separate piece of work or hand the plan to your internal team — the assessment stands on its own either way.
The same capability sits alongside the wider Microsoft 365 work we do for UK clients: identity and Conditional Access design, email security hardening against phishing and business email compromise, and the tenancy hygiene that underpins both. Copilot readiness is not a separate discipline; it is a specific, urgent application of information governance that most organisations had been deferring.
Assess your tenant before you assign licences
A structured Copilot readiness assessment tells you what your tenant would surface, ranked by risk, with a costed plan to close the gaps.
Talk to a Copilot SpecialistFrequently Asked Questions
What is a Copilot readiness assessment?
A Copilot readiness assessment is a structured audit of your Microsoft 365 tenant carried out before Copilot licences are assigned. It has two parts. The first verifies the technical M365 Copilot prerequisites — qualifying base licences, Entra ID accounts, Exchange Online mailboxes, provisioned OneDrive and a supported Microsoft 365 Apps update channel. The second, and larger, part establishes what content Copilot would actually surface to each user, by auditing SharePoint and OneDrive permissions, sharing links, site ownership, sensitivity labelling and data loss prevention coverage. The output is a ranked findings report and a remediation plan, not a pass or fail.
How long does a Copilot tenant assessment take?
For a UK organisation of 100 to 500 seats with a single tenant, plan for four to eight weeks from kick-off to the first pilot licence. The technical eligibility audit typically completes in the first week or two. Permission and sharing discovery takes a further one to two weeks. Remediation of the highest-risk findings is the phase that varies most, commonly two to five weeks, and it runs in parallel with sensitivity labelling and data loss prevention work. Larger estates, multiple tenants or in-flight merger activity extend the middle phases rather than the ends.
What are the M365 Copilot prerequisites?
Each user needs a qualifying base licence — Microsoft 365 Business Standard, Business Premium, E3, E5 or an equivalent Office 365 plan — plus the Copilot add-on. Technically, each user needs a Microsoft Entra ID account, a mailbox hosted in Exchange Online rather than on-premises, OneDrive provisioned and in active use, and Microsoft 365 Apps on a supported update channel. Beyond those hard requirements sit the governance prerequisites that determine whether the deployment is safe rather than merely functional: reviewed sharing, owned sites, published sensitivity labels and data loss prevention scoped to cover AI interactions.
Does Microsoft 365 Copilot see data that users cannot already access?
No. Copilot queries Microsoft Graph in the context of the signed-in user and can only retrieve content that user is already permitted to open. There is no separate Copilot permission model and no elevation. The reason readiness matters is not that Copilot bypasses permissions, but that it removes the practical friction that used to keep over-permissioned content undiscovered. Content a user could technically reach but would never have found through search can now be summarised for them in a sentence, which is why auditing what people can reach is the core of the assessment.
What is the biggest risk when preparing for Copilot?
Oversharing within the organisation. In most mid-market UK tenants, a meaningful share of SharePoint and OneDrive content is reachable by a wider internal audience than its owner believes, usually through tenant-wide groups nested inside apparently specific ones, or through anonymous sharing links created years earlier and never expired. Copilot surfaces that exposure in natural language, quickly, to whoever asks. The assessment’s job is to find and rank that exposure before staff do, so remediation happens on a plan rather than under incident conditions.
How much does Microsoft 365 Copilot cost in the UK?
Microsoft 365 Copilot is priced at approximately £24.70 per user per month on UK list pricing with an annual commitment, on top of the qualifying base licence. Always confirm current pricing with your cloud solution provider before budgeting, as list prices and commitment terms change. Budget separately for the readiness assessment itself, typically £4,500 to £12,000 for a 100 to 500 seat organisation, and for remediation, which ranges from around £6,000 to £30,000 depending on the condition of the estate rather than its size.
Do I need Microsoft Purview to deploy Copilot?
Copilot will function without Purview configuration, but deploying without it means you have no mechanism to express which content is sensitive in a way the platform can enforce. Sensitivity labels are what allow encryption, access restriction and data loss prevention to apply consistently, including to AI interactions. Most organisations on Business Premium or E5 already hold the necessary Purview capabilities, so the gap is usually configuration rather than procurement. Check what is included in your existing agreement before adding a licensing line to the budget.
What size should a Copilot pilot be?
Between 15 and 40 users, spread deliberately across functions rather than drawn from volunteers. Enthusiast-only pilots consistently report high satisfaction regardless of tenant condition, because enthusiasts prompt well and work around poor results instead of reporting them. A representative cohort covering finance, operations, delivery and administration produces findings that generalise to the wider rollout, surfaces the training gap while it is still cheap to close, and gives you honest evidence for the decision on whether to scale.
How does a Copilot readiness assessment relate to UK GDPR?
Introducing AI-assisted processing across your Microsoft 365 estate is a change to how personal data is processed, so your records of processing should be updated and a data protection impact assessment is usually appropriate. Copilot prompts and responses may themselves contain personal data, which makes them subject to retention policy, subject access requests and eDiscovery. Bringing your data protection officer or information governance lead into the assessment at week one, rather than at sign-off, generally means the discovery is scoped to produce the evidence they will need.
Can we restrict what Copilot searches without changing permissions?
Partly. Restricted content discovery and restricted SharePoint search allow you to exclude specific sites from Copilot and organisation-wide search while leaving direct access unchanged, which is useful as a temporary control while remediation proceeds. They are a containment measure, not a substitute for fixing the underlying permissions, because direct access remains in place and the exposure still exists for anyone who knows where to look. Treat them as scaffolding with a removal date, not as the destination.
What happens if we deploy Copilot without an assessment?
Usually the deployment works technically and the governance problems surface within the first few weeks, typically when a user asks a broad question and receives a summary drawing on content they were not expected to see. At that point you are doing the same remediation work, but under time pressure, with an incident to manage, a communication to staff explaining why access is being changed, and in regulated sectors a conversation with your data protection officer. The technical effort is identical; the surrounding cost is not.
Who should own Copilot readiness inside the organisation?
Readiness needs an accountable owner in IT and a named counterpart in information governance, with an executive sponsor who can resolve disputes about content that a business unit wants left open. Site owners own remediation of their own containers, which is why assigning owners to ownerless sites is a checklist item rather than an afterthought. Adoption measurement usually sits best with whoever owns the internal communications and change function, since the questions it answers are business questions rather than technical ones.
Related reading
These articles cover the neighbouring ground — what Copilot does, what it costs, and the identity and email security posture your readiness assessment depends on.
- The Complete Guide to Microsoft 365 Copilot for UK Businesses
- Microsoft 365 Copilot Cost & ROI: A 2026 UK SME Buying Guide
- Email Security in Microsoft 365: Stopping Phishing, Spoofing and Business Email Compromise
- Phishing-Resistant MFA and Passkeys: The 2026 UK Business Guide
- Cyber Essentials Certification: A UK Business Step-by-Step Guide
Ready to work through the checklist properly?
Cloudswitched runs Microsoft 365 Copilot readiness assessments for UK organisations, covering licensing, identity, data governance and content hygiene, with a ranked remediation plan at the end.
Talk to a Copilot Specialist