Your tenant has the licenses. SharePoint is running. Teams meetings happen daily. So Microsoft 365 Copilot should just work, right?
Not quite. A Copilot license proves you can pay for the service. It says nothing about whether your environment can run it, whether it can find useful information when employees ask, or whether existing permission problems will suddenly become visible. We've seen organizations at Calance pass a license audit and fail on 6 of the remaining 11 checks below.
This Microsoft 365 Copilot readiness checklist walks through 12 readiness problems in dependency order. The first 4 are deployment blockers: Copilot won't function correctly until they're resolved. The next 4 are governance and grounding risks: Copilot runs, but it either can't find useful answers or finds too much. The final 4 cover compliance, AI policy, and adoption: the controls and operating model you need before going broad.
Each fix follows the same structure: what can go wrong, where to check it, what to fix, and what proves readiness. The "where to verify" guidance points to specific Microsoft admin surfaces rather than generic advice, because a Copilot readiness assessment you can't act on is just a reading list.
DEPLOYMENT BLOCKER
The most common licensing mistake is checking the tenant instead of the person. Your organization bought Microsoft 365 E5, great. But is the specific pilot user assigned both a qualifying base license and the Copilot entitlement? Those are 2 separate things. Microsoft's current qualifying base licenses go well beyond E3 and E5, including Business Basic, Business Standard, Business Premium, several Office 365 plans, frontline plans, education plans, and Teams-specific plans. Microsoft 365 E7 now bundles Copilot in, removing the add-on requirement entirely. Old deployment guides that say "you need E3 or E5" are incomplete, and you can verify the full current list on the Microsoft 365 Copilot minimum requirements page.
User entitlement test:
DEPLOYMENT BLOCKER | QUALITY/GROUNDING RISK
Copilot needs the user's primary mailbox in Exchange Online for mailbox grounding. On-premises primary mailboxes and hybrid configurations where the primary mailbox remains on-premises don't support this. Microsoft currently states that Copilot grounding is also not supported on archive mailboxes, group mailboxes, shared mailboxes, or delegate mailboxes, and you can verify the full scope on the Microsoft 365 Copilot app and network requirements page. If your support team runs operations through support@company.com, Copilot won't use that email history when someone asks it to summarize customer issues. That's a documented limitation, and your pilot users need to hear it before day one, not after. This mailbox audit is a critical Copilot data readiness step that most organizations overlook.
| Mailbox type | Grounding status | Business implication | What to check |
|---|---|---|---|
| User's primary (Exchange Online) | Supported | Core Copilot experience works as expected | Confirm mailbox location in Exchange admin center |
| On-premises primary | Not supported | Copilot can't ground against this mailbox | Evaluate migration path to Exchange Online |
| Shared mailbox (e.g. support@) | Not supported for grounding | Team operational knowledge invisible to Copilot | Document the gap and set user expectations |
| Delegate mailbox | Not supported for grounding | Executive assistant workflows affected directly | Set realistic expectations before pilot launch |
| Archive mailbox | Not supported for grounding | Historical email content unavailable to Copilot | Decide which historical knowledge actually matters |
| Group mailbox | Not supported for grounding | Distribution group context missing from results | Assess impact on collaborative team workflows |
DEPLOYMENT BLOCKER | SECURITY/GOVERNANCE RISK
A Microsoft Entra ID account is a hard requirement: no Entra ID, no Copilot. Everything else in this section is a security baseline, not a licensing prerequisite. That distinction matters because several competing Microsoft 365 Copilot readiness checklist articles mix them up. MFA is a critical security measure that Microsoft explicitly recommends, but it sits in the "recommended" column, not the "required" column.
| Required | Recommended |
|---|---|
| Entra ID account for every Copilot user | MFA enforced across all Copilot-eligible accounts |
| Copilot won't function without this identity | Conditional Access policies for Copilot session control |
| No alternative identity path exists for Copilot | Least-privilege administrative roles properly assigned |
| AI Administrator role assigned to a named person | |
| Conditional Access designed for AI workloads specifically |
Microsoft now provides an AI Administrator role for managing Copilot settings, agents, and usage reporting. Assign it before go-live to a named person, not a group alias. Calance's Generative AI Solutions work includes designing the governance structure around enterprise AI, including role assignment and policy ownership.
DEPLOYMENT BLOCKER
A properly licensed user with a correctly configured Entra account can still find Copilot completely absent from Word, Outlook, or Teams. The apps themselves need to be deployed, updated, and configured on a supported update channel. Microsoft began unifying Semi-Annual Enterprise Channel with Monthly Enterprise Channel starting with Version 2606 in July 2026, as detailed on the unified update channels page, so "move everyone off Semi-Annual" is no longer complete advice. Check the actual version and channel state for each pilot device. This is a common gap in any Copilot readiness assessment.
ADOPTION/VALUE RISK
The worst pilot selection method is "whoever the CHRO emails first." Microsoft already provides a significant chunk of the analysis for any Microsoft 365 Copilot readiness checklist. The Copilot Readiness Report in the Microsoft 365 admin center shows prerequisite licenses, assigned Copilot licenses, available licenses, update-channel eligibility, and recent usage across the previous 28 days. It flags the top 25% of nonlicensed users based on their Microsoft 365 usage, reevaluated weekly. The report can take up to 72 hours to become available, and usage data has up to 72 hours of latency.
Calance helps organizations layer Microsoft's readiness data with role-based use-case assessment, so pilot selection reflects both technical eligibility and business fit. The Windows 11 Modern Workplace article covers related infrastructure preparation for AI-ready endpoints.
QUALITY/GROUNDING RISK
Your tenant passes every technical check. An employee types "Summarize our current return policy" and gets a generic web answer because the actual return policy lives in an archived SharePoint site that Copilot can't index. Technical readiness and Copilot data readiness are different conditions. Microsoft's semantic index works against searchable SharePoint Online and OneDrive content. Archived content is explicitly excluded, and sites with search turned off are invisible. This knowledge mapping is a critical part of any Microsoft 365 Copilot readiness checklist.
SECURITY/GOVERNANCE RISK
Copilot does not bypass Microsoft 365 permissions. What it does is make existing permissions much more exercisable. A finance spreadsheet shared with "Everyone except external users" was always broadly accessible, but before Copilot, finding it required knowing it existed. After Copilot, a natural-language question can surface it in seconds. Reviewing Copilot SharePoint permissions before deployment is one of the most important readiness steps.
The SharePoint Advanced Management for Copilot readiness page covers the Content Management Assessment for identifying overshared content and governance risks. Restricted Content Discovery lets admins exclude high-risk sites from search and Copilot while permissions are reviewed. Treat it as temporary containment, not permanent governance. Calance's SharePoint Governance Framework covers site ownership, sharing links, and Copilot SharePoint permissions remediation in more depth.
QUALITY/GROUNDING RISK | SECURITY/GOVERNANCE RISK
Permissions can be perfect and the information still wrong. A SharePoint site with 3 competing versions of a sales playbook gives Copilot 3 potential answers. Two Copilot data readiness questions belong here: is this information safe for Copilot to use, and is this information useful for Copilot to use? Both are separate from the Copilot SharePoint permissions review in the previous section.
| Content state | Safe? | Useful? | Action |
|---|---|---|---|
| Current, authoritative, properly scoped | Yes | Yes | Leave it as is |
| Current but overshared to broad audiences | Probably not | Yes | Fix permissions immediately |
| Stale and overshared to broad audiences | No | No | Archive or delete the content |
| Stale but correctly scoped for access | Yes | No | Archive, label, or remove it |
| Archived inside SharePoint Online storage | Permissions intact | Not available to Copilot | Accept the gap or restore it |
| Outside Microsoft 365 environment entirely | Unknown risk level | Not available to Copilot | Migrate or document the gap |
Microsoft explicitly includes site ownership and content lifecycle in its Copilot data readiness recommendations. Calance's Microsoft 365 Services cover content governance alongside license utilization and security settings.
SECURITY/GOVERNANCE RISK | COMPLIANCE RISK
Sensitivity labels and DLP are 2 separate layers that most Copilot deployment checklists collapse into "set up labels." Permission answers one question: can the employee see this? Copilot processing policy answers a different one: should Copilot use it in a generated response? Microsoft Purview now supports Copilot as a DLP policy location, with sensitivity labels as conditions, meaning you can restrict sensitive files from being processed in Copilot interactions even when the user has access.
Labels only work if defined, published, and applied. Organizations that created a taxonomy in 2023 and never checked adoption often find fewer than 15% of documents carry any label. A protection layer with 85% gaps provides the illusion of coverage. Start with the most sensitive content categories and fix adoption before adding Copilot processing rules on top.
COMPLIANCE RISK
Copilot audit shouldn't be configured after the first uncomfortable conversation with legal. This is where many organizations fail their own Microsoft 365 Copilot readiness checklist. Microsoft Purview automatically generates audit records for Copilot interaction activity when auditing is enabled, identifying the user, interaction time, workload, and the resources Copilot accessed.
Calance's security and compliance assessment work helps identify which Purview capabilities your regulatory model actually requires, so you configure what matters and skip what doesn't.
SECURITY/GOVERNANCE RISK | ADOPTION/VALUE RISK
If you still think of Microsoft 365 Copilot as a chat window inside Word, your mental model is about 18 months behind. By mid-2026, Copilot includes web grounding, agent installation, agent creation, agent publishing, connectors, extensions, and pay-as-you-go consumption. Each one is a policy decision you need to make consciously, and broadly enabling Copilot while having no answer to "who can install or create agents?" is how shadow AI starts.
| Capability | Default decision | Who approves? | Data implication | Cost implication |
|---|---|---|---|---|
| Public web search | Allow or restrict | IT/Security | Web content enters Copilot responses | None beyond existing license |
| Agent installation | Open or gated | AI Administrator | Agents access organizational data | Depends on agent type used |
| Agent creation | Open or gated | AI Administrator | Custom agents access scoped data | Copilot Studio costs may apply |
| Agent publishing | Approval required? | AI Admin + business | Published agents broadly available | Capacity and consumption costs |
| Connectors/extensions | Allow or restrict | IT/Security | External data flows into Copilot | Varies by connector and usage |
Make the policy decisions before the first agent appears. Calance's AI in SharePoint article covers related agent and AI capabilities within the SharePoint environment.
ADOPTION/VALUE RISK
You can pass all 11 checks above and still waste the deployment. A technically perfect Copilot environment with no recurring business workflow to improve will produce one outcome: people try it for a week and stop. This is the final gate in any Microsoft 365 Copilot readiness checklist.
Don't promise a particular adoption rate to leadership before you have data. Adoption barriers matter as much as wins: if 60% of users stop after week 2, the barrier data tells you what to fix for the next cohort. Calance's Copilot Readiness and Rollout article covers the strategic framework, following the Assess, Plan, Deploy, Adopt, Optimize approach.
What are the minimum Microsoft 365 Copilot requirements?
Microsoft requires a qualifying base license, Copilot entitlement, Entra ID account, primary mailbox in Exchange Online, supported Microsoft 365 Apps on a current update channel, and reachable network endpoints. Requirements can change, so verify against Microsoft's current documentation before deployment.
Do I need Microsoft 365 E5 to use Copilot?
No. Multiple Microsoft 365, Office 365, business, frontline, education, and Teams plans qualify as base licenses. Microsoft 365 E7 bundles Copilot directly. Check the current qualifying subscription list in the Microsoft 365 admin center rather than relying on older E3/E5 guidance.
Does Microsoft 365 Copilot require Exchange Online?
Yes, for mailbox grounding. The user's primary mailbox must reside in Exchange Online. On-premises primary mailboxes, shared mailboxes, delegate mailboxes, archive mailboxes, and group mailboxes don't support Copilot's mailbox grounding functionality.
How do I check whether users are ready for Microsoft 365 Copilot?
The Copilot readiness report in the Microsoft 365 admin center shows license status, update-channel eligibility, and application usage over the previous 28 days. It also identifies suggested pilot candidates based on Microsoft 365 usage patterns.
Does Copilot bypass SharePoint permissions?
No. Copilot respects existing Microsoft 365 user permissions and only surfaces content the current user is authorized to access. The risk is that existing permissions may already be too broad, and Copilot makes that authorized access easier to exercise through natural-language queries.
Should I clean up SharePoint before deploying Copilot?
Yes. Oversharing, ownerless sites, stale content, disabled search, and poor content lifecycle all affect either security or answer quality. SharePoint Advanced Management and its Content Management Assessment can identify governance gaps before Copilot makes them more visible.
Do sensitivity labels protect data used by Copilot?
Sensitivity labels are one component of Microsoft's protection model. When applied with encryption, they restrict access. Combined with DLP policies that include Copilot as a policy location, they can also restrict whether Copilot processes labeled content in AI interactions.
What is Restricted Content Discovery?
Restricted Content Discovery is a per-site control in SharePoint that prevents content from appearing in organization-wide search and Copilot responses while administrators review permissions. It replaces the retiring Restricted SharePoint Search feature and is intended as a temporary containment tool.
Should Copilot agents be included in the Copilot readiness assessment?
Yes. By mid-2026, Copilot includes agent installation, creation, publishing, and consumption governance. The AI Administrator role and Microsoft 365 admin center provide agent-management controls. Setting policies before agents proliferate is significantly easier than governing them after.
How can Calance help with Microsoft 365 Copilot readiness?
Calance provides Microsoft 365 environment assessments, security-settings reviews, SharePoint governance, license-utilization analysis, compliance-gap assessments, Copilot adoption guidance, role-based training, pilot planning, and monitoring. The approach follows Assess, Plan, Deploy, Adopt, Optimize, connecting technical readiness to measurable outcomes.