Calance Content

The Microsoft 365 Copilot Readiness Checklist: 12 Things to Fix First | Calance

Written by Team Calance | Aug 31, 2026, 7:25:04 PM

Your tenant has the licenses. SharePoint is running. Teams meetings happen daily. So Microsoft 365 Copilot should just work, right?

Not quite. A Copilot license proves you can pay for the service. It says nothing about whether your environment can run it, whether it can find useful information when employees ask, or whether existing permission problems will suddenly become visible. We've seen organizations at Calance pass a license audit and fail on 6 of the remaining 11 checks below.

This Microsoft 365 Copilot readiness checklist walks through 12 readiness problems in dependency order. The first 4 are deployment blockers: Copilot won't function correctly until they're resolved. The next 4 are governance and grounding risks: Copilot runs, but it either can't find useful answers or finds too much. The final 4 cover compliance, AI policy, and adoption: the controls and operating model you need before going broad.

Each fix follows the same structure: what can go wrong, where to check it, what to fix, and what proves readiness. The "where to verify" guidance points to specific Microsoft admin surfaces rather than generic advice, because a Copilot readiness assessment you can't act on is just a reading list.

Verify the Exact License and Entitlement Path for Every Pilot User

DEPLOYMENT BLOCKER

The most common licensing mistake is checking the tenant instead of the person. Your organization bought Microsoft 365 E5, great. But is the specific pilot user assigned both a qualifying base license and the Copilot entitlement? Those are 2 separate things. Microsoft's current qualifying base licenses go well beyond E3 and E5, including Business Basic, Business Standard, Business Premium, several Office 365 plans, frontline plans, education plans, and Teams-specific plans. Microsoft 365 E7 now bundles Copilot in, removing the add-on requirement entirely. Old deployment guides that say "you need E3 or E5" are incomplete, and you can verify the full current list on the Microsoft 365 Copilot minimum requirements page.

User entitlement test:

  1. Qualifying base license. Confirm the user holds an eligible plan from the current Microsoft 365 Copilot requirements list, not an outdated E3/E5-only reference.
  2. Copilot entitlement assigned. The add-on must be toggled on for the specific account, not just purchased at the tenant level. IT teams batch-assigning through PowerShell often miss this step.
  3. User account active in Entra ID. The identity backing the license must be current and valid inside your directory. Disabled or stale accounts won't surface Copilot features.
  4. Required Microsoft 365 services enabled. Exchange Online, OneDrive, Teams, and Microsoft 365 Apps must all be provisioned for the user before Copilot can appear in their apps.
  5. Diagnostic confirmation. Run the Copilot License Details diagnostic in the Microsoft 365 admin center for every pilot user individually. This is the first gate in any Copilot deployment checklist.

Check Where the User's Mailbox and Working Knowledge Actually Live

DEPLOYMENT BLOCKER | QUALITY/GROUNDING RISK

Copilot needs the user's primary mailbox in Exchange Online for mailbox grounding. On-premises primary mailboxes and hybrid configurations where the primary mailbox remains on-premises don't support this. Microsoft currently states that Copilot grounding is also not supported on archive mailboxes, group mailboxes, shared mailboxes, or delegate mailboxes, and you can verify the full scope on the Microsoft 365 Copilot app and network requirements page. If your support team runs operations through support@company.com, Copilot won't use that email history when someone asks it to summarize customer issues. That's a documented limitation, and your pilot users need to hear it before day one, not after. This mailbox audit is a critical Copilot data readiness step that most organizations overlook.

Mailbox type Grounding status Business implication What to check
User's primary (Exchange Online) Supported Core Copilot experience works as expected Confirm mailbox location in Exchange admin center
On-premises primary Not supported Copilot can't ground against this mailbox Evaluate migration path to Exchange Online
Shared mailbox (e.g. support@) Not supported for grounding Team operational knowledge invisible to Copilot Document the gap and set user expectations
Delegate mailbox Not supported for grounding Executive assistant workflows affected directly Set realistic expectations before pilot launch
Archive mailbox Not supported for grounding Historical email content unavailable to Copilot Decide which historical knowledge actually matters
Group mailbox Not supported for grounding Distribution group context missing from results Assess impact on collaborative team workflows

Confirm Entra Identity, Access Controls, and Administrative Ownership

DEPLOYMENT BLOCKER | SECURITY/GOVERNANCE RISK

A Microsoft Entra ID account is a hard requirement: no Entra ID, no Copilot. Everything else in this section is a security baseline, not a licensing prerequisite. That distinction matters because several competing Microsoft 365 Copilot readiness checklist articles mix them up. MFA is a critical security measure that Microsoft explicitly recommends, but it sits in the "recommended" column, not the "required" column.

Required Recommended
Entra ID account for every Copilot user MFA enforced across all Copilot-eligible accounts
Copilot won't function without this identity Conditional Access policies for Copilot session control
No alternative identity path exists for Copilot Least-privilege administrative roles properly assigned
  AI Administrator role assigned to a named person
  Conditional Access designed for AI workloads specifically

Microsoft now provides an AI Administrator role for managing Copilot settings, agents, and usage reporting. Assign it before go-live to a named person, not a group alias. Calance's Generative AI Solutions work includes designing the governance structure around enterprise AI, including role assignment and policy ownership.

Resolve Microsoft 365 Apps, Update, Privacy, and Network Blockers

DEPLOYMENT BLOCKER

A properly licensed user with a correctly configured Entra account can still find Copilot completely absent from Word, Outlook, or Teams. The apps themselves need to be deployed, updated, and configured on a supported update channel. Microsoft began unifying Semi-Annual Enterprise Channel with Monthly Enterprise Channel starting with Version 2606 in July 2026, as detailed on the unified update channels page, so "move everyone off Semi-Annual" is no longer complete advice. Check the actual version and channel state for each pilot device. This is a common gap in any Copilot readiness assessment.

  • License confirmed. The user passed the entitlement test from the previous section and has Copilot properly assigned to their account.
  • Apps deployed and supported. Microsoft 365 Apps are installed and provisioned for the user. Device-based licensing is not supported for Copilot.
  • Version and channel current. Post-July 2026, check whether the device received the unified update. The Copilot readiness report flags channel eligibility.
  • Connected experiences enabled. Disabling the connected experiences that analyze content privacy setting makes Copilot unavailable in Word, Excel, Outlook, PowerPoint, and OneNote.
  • Network endpoints reachable. Microsoft requires specific endpoints for Copilot. Firewalls and proxies built for a pre-AI environment may block them silently.

Use the Copilot Readiness Report Before Choosing the Pilot Group

ADOPTION/VALUE RISK

The worst pilot selection method is "whoever the CHRO emails first." Microsoft already provides a significant chunk of the analysis for any Microsoft 365 Copilot readiness checklist. The Copilot Readiness Report in the Microsoft 365 admin center shows prerequisite licenses, assigned Copilot licenses, available licenses, update-channel eligibility, and recent usage across the previous 28 days. It flags the top 25% of nonlicensed users based on their Microsoft 365 usage, reevaluated weekly. The report can take up to 72 hours to become available, and usage data has up to 72 hours of latency.

  • Technical eligibility. The Copilot readiness report confirms the user meets licensing, channel, and app requirements. This is the baseline for any Copilot deployment checklist.
  • Recurring workflow. The user has a repeatable process where Copilot can save measurable time, such as weekly reports, meeting summaries, or document drafting.
  • Manager support. The user's manager is willing to support the learning curve rather than demand instant ROI. Unsupported pilots fail quietly without feedback.
  • Feedback commitment. The user will actually report what works and what doesn't, rather than abandoning the tool after the first imperfect answer from Copilot.

Calance helps organizations layer Microsoft's readiness data with role-based use-case assessment, so pilot selection reflects both technical eligibility and business fit. The Windows 11 Modern Workplace article covers related infrastructure preparation for AI-ready endpoints.

Test Whether Copilot Can Find the Knowledge Users Expect It to Know

QUALITY/GROUNDING RISK

Your tenant passes every technical check. An employee types "Summarize our current return policy" and gets a generic web answer because the actual return policy lives in an archived SharePoint site that Copilot can't index. Technical readiness and Copilot data readiness are different conditions. Microsoft's semantic index works against searchable SharePoint Online and OneDrive content. Archived content is explicitly excluded, and sites with search turned off are invisible. This knowledge mapping is a critical part of any Microsoft 365 Copilot readiness checklist.

  1. Pick 10 questions. Choose questions your pilot users would genuinely ask Copilot in their first week of use at work.
  2. Trace each to its source. Find the actual document or site that holds the answer to each question you identified above.
  3. Check the location. Is it in searchable SharePoint Online or OneDrive? Archived sites, file shares, and third-party tools are invisible to Copilot.
  4. Check freshness. Is the content current and authoritative, or is there a stale duplicate that might compete for retrieval?
  5. Document gaps. Record which workflows have knowledge coverage and which don't. Do this before the pilot starts, not after the first feedback survey.

Reduce Oversharing Before Copilot Makes Existing Access Easier to Use

SECURITY/GOVERNANCE RISK

Copilot does not bypass Microsoft 365 permissions. What it does is make existing permissions much more exercisable. A finance spreadsheet shared with "Everyone except external users" was always broadly accessible, but before Copilot, finding it required knowing it existed. After Copilot, a natural-language question can surface it in seconds. Reviewing Copilot SharePoint permissions before deployment is one of the most important readiness steps.

  • Low. A properly scoped site with named member groups and reviewed access. Standard operating state for well-governed tenants.
  • Medium. Unmanaged sharing links and company-wide links created for convenience and never revoked. Common across tenants older than 3 years.
  • High. Broad tenant-level access applied by default across collaboration spaces. Usually the result of a migration or convenience choice turned permanent.
  • Critical. Sensitive HR, legal, or financial content exposed to a much larger internal audience than anyone realized. The kind of exposure triggering incident review.

The SharePoint Advanced Management for Copilot readiness page covers the Content Management Assessment for identifying overshared content and governance risks. Restricted Content Discovery lets admins exclude high-risk sites from search and Copilot while permissions are reviewed. Treat it as temporary containment, not permanent governance. Calance's SharePoint Governance Framework covers site ownership, sharing links, and Copilot SharePoint permissions remediation in more depth.

Clean Up Site Ownership, Stale Content, and Lifecycle Gaps

QUALITY/GROUNDING RISK | SECURITY/GOVERNANCE RISK

Permissions can be perfect and the information still wrong. A SharePoint site with 3 competing versions of a sales playbook gives Copilot 3 potential answers. Two Copilot data readiness questions belong here: is this information safe for Copilot to use, and is this information useful for Copilot to use? Both are separate from the Copilot SharePoint permissions review in the previous section.

Content state Safe? Useful? Action
Current, authoritative, properly scoped Yes Yes Leave it as is
Current but overshared to broad audiences Probably not Yes Fix permissions immediately
Stale and overshared to broad audiences No No Archive or delete the content
Stale but correctly scoped for access Yes No Archive, label, or remove it
Archived inside SharePoint Online storage Permissions intact Not available to Copilot Accept the gap or restore it
Outside Microsoft 365 environment entirely Unknown risk level Not available to Copilot Migrate or document the gap

Microsoft explicitly includes site ownership and content lifecycle in its Copilot data readiness recommendations. Calance's Microsoft 365 Services cover content governance alongside license utilization and security settings.

Decide What Copilot May Process with Purview Labels and DLP

SECURITY/GOVERNANCE RISK | COMPLIANCE RISK

Sensitivity labels and DLP are 2 separate layers that most Copilot deployment checklists collapse into "set up labels." Permission answers one question: can the employee see this? Copilot processing policy answers a different one: should Copilot use it in a generated response? Microsoft Purview now supports Copilot as a DLP policy location, with sensitivity labels as conditions, meaning you can restrict sensitive files from being processed in Copilot interactions even when the user has access.

  • Identity. Who is the user requesting the Copilot interaction in this session?
  • Permission. Can they access the file or content that Copilot might reference in its response?
  • Sensitivity classification. What label does the content carry, and what protection applies to it?
  • DLP policy. What rules apply when the labeled file is used in a Copilot interaction?
  • Copilot processing controls. Should Copilot process this content in AI-generated responses at all?
  • User behavior. Does the person understand the handling requirement for this content category?

Labels only work if defined, published, and applied. Organizations that created a taxonomy in 2023 and never checked adoption often find fewer than 15% of documents carry any label. A protection layer with 85% gaps provides the illusion of coverage. Start with the most sensitive content categories and fix adoption before adding Copilot processing rules on top.

Make Copilot Auditable Before the First Investigation

COMPLIANCE RISK

Copilot audit shouldn't be configured after the first uncomfortable conversation with legal. This is where many organizations fail their own Microsoft 365 Copilot readiness checklist. Microsoft Purview automatically generates audit records for Copilot interaction activity when auditing is enabled, identifying the user, interaction time, workload, and the resources Copilot accessed.

  • Who interacted with Copilot? Audit records must identify the user account. Confirm logging is enabled and records are generating.
  • In which workload? The record should show whether the interaction happened in Word, Teams, Outlook, or another application.
  • What resource was referenced? Files, sites, and content used for generating the response should be traceable for investigation purposes.
  • What policy applied? DLP, sensitivity labels, and Copilot processing controls should be reflected in the audit trail clearly.
  • Who investigates, and what's retained? Decide retention period and investigation workflow before the pilot. Default retention may be shorter than compliance requires.

Calance's security and compliance assessment work helps identify which Purview capabilities your regulatory model actually requires, so you configure what matters and skip what doesn't.

Set Policies for Web Grounding, Agents, and Extensions Before They Spread

SECURITY/GOVERNANCE RISK | ADOPTION/VALUE RISK

If you still think of Microsoft 365 Copilot as a chat window inside Word, your mental model is about 18 months behind. By mid-2026, Copilot includes web grounding, agent installation, agent creation, agent publishing, connectors, extensions, and pay-as-you-go consumption. Each one is a policy decision you need to make consciously, and broadly enabling Copilot while having no answer to "who can install or create agents?" is how shadow AI starts.

Capability Default decision Who approves? Data implication Cost implication
Public web search Allow or restrict IT/Security Web content enters Copilot responses None beyond existing license
Agent installation Open or gated AI Administrator Agents access organizational data Depends on agent type used
Agent creation Open or gated AI Administrator Custom agents access scoped data Copilot Studio costs may apply
Agent publishing Approval required? AI Admin + business Published agents broadly available Capacity and consumption costs
Connectors/extensions Allow or restrict IT/Security External data flows into Copilot Varies by connector and usage

Make the policy decisions before the first agent appears. Calance's AI in SharePoint article covers related agent and AI capabilities within the SharePoint environment.

Define the Pilot Workflow and Go/No-Go Evidence Before Broad Rollout

ADOPTION/VALUE RISK

You can pass all 11 checks above and still waste the deployment. A technically perfect Copilot environment with no recurring business workflow to improve will produce one outcome: people try it for a week and stop. This is the final gate in any Microsoft 365 Copilot readiness checklist.

  1. Gate 1. Technical prerequisites pass, covering license, mailbox, identity, and apps from the Copilot deployment checklist.
  2. Gate 2. Grounding and knowledge coverage pass, confirming the Copilot readiness report and knowledge test results are acceptable.
  3. Gate 3. Access and governance risks are acceptable, with oversharing reduced and Copilot SharePoint permissions cleaned up.
  4. Gate 4. Sensitive-data and audit controls are defined, with labels, DLP, audit, and retention all configured and tested.
  5. Gate 5. AI expansion policies are set, covering web search, agents, connectors, and cost governance decisions clearly documented.
  6. Gate 6. Pilot users are selected with evidence from the readiness report and use-case fit, not from politics or seniority.
  7. Gate 7. Specific recurring workflows exist for each pilot user, documented and agreed with their managers before launch day.
  8. Gate 8. Success measures are defined: usage frequency, return behavior, workflow completion, time effects, and adoption barriers.

Don't promise a particular adoption rate to leadership before you have data. Adoption barriers matter as much as wins: if 60% of users stop after week 2, the barrier data tells you what to fix for the next cohort. Calance's Copilot Readiness and Rollout article covers the strategic framework, following the Assess, Plan, Deploy, Adopt, Optimize approach.

Microsoft 365 Copilot Readiness FAQs

What are the minimum Microsoft 365 Copilot requirements?

Microsoft requires a qualifying base license, Copilot entitlement, Entra ID account, primary mailbox in Exchange Online, supported Microsoft 365 Apps on a current update channel, and reachable network endpoints. Requirements can change, so verify against Microsoft's current documentation before deployment.

Do I need Microsoft 365 E5 to use Copilot?

No. Multiple Microsoft 365, Office 365, business, frontline, education, and Teams plans qualify as base licenses. Microsoft 365 E7 bundles Copilot directly. Check the current qualifying subscription list in the Microsoft 365 admin center rather than relying on older E3/E5 guidance.

Does Microsoft 365 Copilot require Exchange Online?

Yes, for mailbox grounding. The user's primary mailbox must reside in Exchange Online. On-premises primary mailboxes, shared mailboxes, delegate mailboxes, archive mailboxes, and group mailboxes don't support Copilot's mailbox grounding functionality.

How do I check whether users are ready for Microsoft 365 Copilot?

The Copilot readiness report in the Microsoft 365 admin center shows license status, update-channel eligibility, and application usage over the previous 28 days. It also identifies suggested pilot candidates based on Microsoft 365 usage patterns.

Does Copilot bypass SharePoint permissions?

No. Copilot respects existing Microsoft 365 user permissions and only surfaces content the current user is authorized to access. The risk is that existing permissions may already be too broad, and Copilot makes that authorized access easier to exercise through natural-language queries.

Should I clean up SharePoint before deploying Copilot?

Yes. Oversharing, ownerless sites, stale content, disabled search, and poor content lifecycle all affect either security or answer quality. SharePoint Advanced Management and its Content Management Assessment can identify governance gaps before Copilot makes them more visible.

Do sensitivity labels protect data used by Copilot?

Sensitivity labels are one component of Microsoft's protection model. When applied with encryption, they restrict access. Combined with DLP policies that include Copilot as a policy location, they can also restrict whether Copilot processes labeled content in AI interactions.

What is Restricted Content Discovery?

Restricted Content Discovery is a per-site control in SharePoint that prevents content from appearing in organization-wide search and Copilot responses while administrators review permissions. It replaces the retiring Restricted SharePoint Search feature and is intended as a temporary containment tool.

Should Copilot agents be included in the Copilot readiness assessment?

Yes. By mid-2026, Copilot includes agent installation, creation, publishing, and consumption governance. The AI Administrator role and Microsoft 365 admin center provide agent-management controls. Setting policies before agents proliferate is significantly easier than governing them after.

How can Calance help with Microsoft 365 Copilot readiness?

Calance provides Microsoft 365 environment assessments, security-settings reviews, SharePoint governance, license-utilization analysis, compliance-gap assessments, Copilot adoption guidance, role-based training, pilot planning, and monitoring. The approach follows Assess, Plan, Deploy, Adopt, Optimize, connecting technical readiness to measurable outcomes.