Copilot Readiness: The 5 Things to Fix Before Rollout

A woman pilot in a pilot's jacket and a friendly robot assistant standing side by side like pilot and co-pilot, both wearing headsets, a friendly

Most Microsoft 365 organizations I talk with have the same plan for AI: turn on Copilot. It makes sense. The licenses are available through a vendor you already use, it works inside the apps people already know, and it respects the permissions you already manage. That last point is exactly why Microsoft Copilot readiness deserves a few weeks of preparation before the licenses go out.

Copilot doesn’t create new access. It uses the access people already have, and it’s very good at finding things. Whatever is overshared, mislabeled, or left over from old projects becomes something an assistant can surface in an answer. Organizations that fix five things first tend to have smooth rollouts. Those that skip them tend to have a pause, a cleanup, and a restart.

Why Copilot readiness is mostly about what you already have

Microsoft documents that Microsoft 365 Copilot only surfaces content the signed-in user can already access, and that it respects sensitivity labels. Both are good design choices. They also mean the quality of your permissions and labels becomes the quality of your Copilot controls. There’s no separate AI security layer to configure that will compensate for a SharePoint site shared with everyone in the company.

The five fixes below come from the AI Readiness assessment, and each has a detailed guide in this series. Do them in this order.

First, check what you already have

Before buying licenses, confirm what your current Microsoft 365 plan already includes. Many organizations already have access to Microsoft 365 Copilot Chat, with enterprise data protection, alongside the paid Microsoft 365 Copilot that works across your documents, mail, and meetings. They’re different products, with different reach into your data. Knowing which your people already have tells you what the pilot is actually testing, and it gives everyone outside the pilot a governed option in the meantime. Check the prerequisites listed in your admin center, and confirm which governance features your plan includes, before buying any add-ons.

Fix 1: oversharing

This is the single most common reason I recommend delaying a Copilot rollout. Sites shared with everyone, organization-wide sharing links, old team sites nobody owns: before Copilot, these were protected by the fact that nobody went looking. Afterward, a simple question can surface them.

The fix is a focused cleanup, not an audit of every file. Run the sharing reports you already have, identify your most sensitive sites, remove broad access on them, assign owners, and change sharing defaults. If your plan includes tools to restrict what Copilot can search while cleanup continues, use them as a temporary fence. The 30-day plan is in fix SharePoint oversharing before you turn on Copilot.

Fix 2: sensitivity labels and DLP

Labels tell Microsoft 365 which content is sensitive, and DLP enforces what can happen to it. With labels in place, content Copilot generates from labeled files can carry the label forward, and the protections that come with labels apply. Start with four labels and your two or three most sensitive data types, in audit mode before enforcement. The rollout is in sensitivity labels and DLP before AI: the 30-day rollout.

Fix 3: access reviews

Oversharing is about sites; access reviews are about people. Years of role changes leave people in groups they no longer need, and Copilot will search on their behalf across everything those groups can reach. Review membership of the groups that grant access to finance, HR, legal, and executive content, starting with the people in your pilot group. Guidance on doing reviews that actually remove access is in identity is your AI control plane.

Fix 4: policy and training

People need to know what they’re allowed to do with Copilot and how to get value from it. Publish a short acceptable use policy that covers data tiers and the rule that people are responsible for checking output, and pair the rollout with practical training built on real tasks from each team. Untrained users try Copilot a few times, get a vague answer to a vague question, and stop. Publish your AI acceptable use policy this month has a template.

Fix 5: a measured pilot

Don’t license everyone at once. Start with a pilot group of a few dozen people across several roles, choose two or three specific tasks for them, and measure how long those tasks take before the pilot starts. That baseline is what turns “people like it” into a renewal case. Baseline before you build covers the method.

Choosing the pilot group

  • Mix roles: people who write a lot, people who attend a lot of meetings, people who search for information all day. Different roles reveal different value.
  • Include IT, so the team that will support Copilot learns it first.
  • Include a few skeptics. They’ll find the weaknesses early.
  • Be careful with executives. Senior leaders usually have the broadest access, so they’re the most likely to see overshared content. Include them after the permission cleanup, not before.

Getting value, not just safety

A safe rollout that nobody uses is a wasted license. During the pilot, collect the prompts that work for each role: summarizing a long email thread before a meeting, pulling action items from a recording, drafting a document from existing files, finding patterns in a spreadsheet. Put the best ones in a shared library, and name a champion in each pilot team to share tips. The people who get the most from Copilot are almost never the ones who received the most training. They’re the ones who saw a colleague use it well on a task they recognized.

The asset: a Copilot rollout gate checklist

Use this as a go or no-go gate before licensing goes beyond the pilot group.

  1. Broad sharing removed from the most sensitive sites, each with a named owner.
  2. Default sharing links changed to specific people.
  3. Sensitivity labels published, with auto-labeling for the most sensitive data types.
  4. DLP in place for email, cloud storage, and endpoints.
  5. Access reviews completed for sensitive groups.
  6. User consent to third-party apps restricted.
  7. Acceptable use policy published and acknowledged.
  8. Training delivered, with examples from each team’s own work.
  9. Pilot baselines captured and results measured.
  10. Usage reports reviewed, with a plan to reassign unused licenses.
  11. Audit logging on for Copilot activity.
  12. A named owner for the rollout and its results.

After the pilot

Expand in waves, team by team, repeating the permission and access checks for each new group’s content. Keep measuring: usage shows whether people are using it, and the baseline tasks show whether it’s worth it. Check usage reports monthly, and reassign licenses that go unused. If Copilot is your first AI rollout, the same five fixes will also prepare you for whatever comes next, because they’re foundations rather than Copilot-specific settings.

What if you can’t do all five first?

You don’t have to finish everything before a small pilot. A pilot group of a few dozen people can start once their own access has been reviewed and the most sensitive sites are cleaned up. What you shouldn’t do is license the whole organization before fixes 1 and 3 are done. Those two are what stand between a useful assistant and an unplanned disclosure.

Where does your team actually stand?

The free AI Readiness Score uses 10 of the 24 assessment questions, spread across all six dimensions, and gives you a score in a few minutes.

Get your free AI Readiness Score →

The sample report follows a Microsoft 365 organization through exactly this sequence. Flip through all 38 pages.

Related guides

Frequently asked questions

What should be fixed before rolling out Microsoft 365 Copilot?

Five things, in order: oversharing on sensitive sites, sensitivity labels and DLP, access reviews for sensitive groups, an acceptable use policy with practical training, and a measured pilot with a baseline. Fixes 1 and 3 are the ones not to skip before licensing everyone.

Does Copilot create new access to data?

No. Microsoft documents that Microsoft 365 Copilot only surfaces content the signed-in user can already access, and that it respects sensitivity labels. That's why your permissions and labels effectively become your Copilot controls.

Who should be in a Copilot pilot group?

A few dozen people across roles, including people who write a lot, attend many meetings, or search for information all day, plus IT and a few skeptics. Include executives after the permission cleanup, because they usually have the broadest access.

Is Microsoft 365 Copilot Chat the same as Microsoft 365 Copilot?

No. Many organizations already have Microsoft 365 Copilot Chat, with enterprise data protection, alongside the paid Microsoft 365 Copilot that works across your documents, mail, and meetings. They reach your data differently, so check which your people already have before buying.

Scroll to Top