The Microsoft 365 Work
That Determines Whether
Copilot Returns Value
None of it is AI work, and all of it is prerequisite. Identity baselines, oversharing remediation, migration completeness, label taxonomy, provisioning discipline, an agent lifecycle, a measured view of the tenant, and the automation that keeps it that way. This is the engagement catalogue: the foundational half of an AI programme, delivered by someone who has operated the estate.
Identity & Secure Foundation
Copilot does not grant access. It exercises access already granted, at conversational speed, on behalf of a user who no longer needs to know where the file resides. Each weakness in the identity model becomes a retrieval path.
Entra ID & Conditional Access
MFA enforced tenant-wide and phishing-resistant for privileged roles. Legacy authentication blocked. Conditional Access evaluating device compliance and sign-in risk rather than a correct password alone.
Privileged Access
Standing Global Admin removed. Just-in-time elevation with approval and time bounds through Privileged Identity Management, with access reviews that complete rather than expire.
Intune & Endpoint Compliance
Compliance policies the intended Copilot cohort genuinely meets, verified by report before seats are purchased rather than discovered through support volume afterwards.
Data Governance & Oversharing Remediation
The heaviest-weighted pillar in the assessment, and the one that pauses more pilots than any other. Not because the technology is difficult, but because the initial findings are substantial and remediation time was not scheduled.
| Finding | Why it matters under Copilot | Remediation |
|---|---|---|
| "Everyone except external users" grants | A convenience grant becomes an organisation-wide retrieval surface. Users surface documents they were always technically permitted to open but would not previously have located. | Inventory each grant, rank by content sensitivity, replace with scoped groups, and re-run the report to evidence the change. |
| Org-wide sharing links | Links created for a single meeting persist for years and remain resolvable during grounding. | Expire and restrict default link types at tenant level, then sweep existing links by age and site sensitivity. |
| Unlabelled high-value content | Without sensitivity labels there is no downstream enforcement: no restriction, no encryption, and no meaningful DLP. | Publish a minimal taxonomy of three to four labels and auto-apply to the highest-risk repositories in the first instance. |
| Gaps in DLP coverage | Policy applied to SharePoint but not Teams or Exchange leaves the workloads Copilot reads only partially covered. | Extend DLP to every Copilot-readable workload, then validate with realistic prompts rather than synthetic samples. |
| ROT content in the index | Redundant, obsolete, and trivial content does not merely consume storage; it degrades the quality of every answer. | Apply retention and lifecycle rules, then complete a clean-up on the highest-volume sites before the rollout widens. |
| No recurring site access review | Permissions drift back over time. A one-off remediation without a review cadence is a snapshot rather than a control. | Deploy SharePoint Advanced Management: site access reviews, restricted access control, and recurring oversharing reports. |
Content Estate & Modernisation
Copilot reasons over what has landed in Microsoft Graph. Content held on a file share, in a legacy document system, or behind a third-party boundary is not visible to it. The gap between what users expect it to know and what it can reach is where confidence is lost in the first week.
Migration & Consolidation
- File shares and legacy DMS content into SharePoint and OneDrive, with permissions rationalised during migration rather than replicated
- Tenant-to-tenant consolidation after acquisition, including identity, mail, and content
- Explicit out-of-scope declarations for what will not move, so expectations match reality
Sprawl & Provisioning
- Templated Teams and SharePoint provisioning with mandatory ownership
- Inactivity and orphan reviews that reassign or archive, rather than accumulate
- Naming, metadata, and information architecture that remains workable in day-to-day use
Search & Grounding Quality
- Microsoft Search relevance tested against real queries, to establish a baseline before Copilot is introduced
- Metadata and permission fixes on the failing cases, then re-test
- A published statement of what Copilot can and cannot reach in your estate
Connectors
- Graph and Copilot connectors prioritised by use-case value rather than by ease of connection
- Two high-value sources connected and measured before the catalogue is expanded
- Permission mapping checked end to end, so connected data respects source access
Copilot Deployment, Adoption & Licence Economics
Deployed licences are not adoption. Adoption is measured behaviour change against a baseline captured before rollout, which is why the baseline work is sequenced first, while an uncontaminated measurement remains available.
Licence Strategy
- Per-user inventory mapped against Copilot prerequisites before any purchase conversation
- Three to five personas, seats allocated accordingly, and a sixty-day reclamation rule for dormant licences
- E3 versus E5 modelled on real headcount, with agent consumption metered against an Azure budget alert
- A single named budget owner on record, as programmes stall fastest on unowned spend
Adoption & Measurement
- Five use cases, each with an owner and a quantified return, rather than a catalogue of possibilities
- An executive sponsor who demonstrates their own use, since sponsorship without usage reads as scepticism
- A champions cohort at approximately one per fifty seats, with an active channel and a monthly cadence
- Copilot Dashboard in Viva Insights reporting three agreed metrics to the sponsor, monthly
The renewal decision is determined in month two. Not because the product has changed, but because by that point there is either a baseline and three metrics, or anecdotes and a record of assigned licences.
Copilot Studio Agents Under Governance
Placing agent building with the business was the intent, since that is where the process knowledge resides. It also means the agent estate grows faster than any central team can inventory it, unless a gate and a register exist from the outset.
-
Gate 1 · Intake
Purpose and Ownership
A short intake capturing purpose, business owner, data sources, intended audience, and whether the agent acts or only answers. Agents that only answer follow a lighter path; agents that act do not.
-
Gate 2 · Review
Data Reach and Failure Modes
Data reach reviewed against the oversharing position. Connector permissions verified end to end. Failure modes assessed for any agent that writes, sends, approves, or spends.
-
Gate 3 · Publish
Scoped Audience, Logged Interactions, Review Date
Published to a defined audience rather than the whole tenant. Interactions captured in Purview Audit, retention aligned to the organisation's legal position, and a review date recorded in the register.
-
Standing · Register
Owner, Purpose, Identity, Data Reach, Review Date
Reviewed quarterly and reported to the risk committee. Agents require lifecycle management for the same reasons service accounts always have, and they proliferate considerably faster.
Tenant Health Check & Reporting Dashboards
Most tenants are administered on the evidence of whatever the last support ticket revealed. A health check replaces that with a measured position across every workload, and the dashboards that follow keep it measured — because a point-in-time audit starts decaying the day it is delivered.
| Domain examined | What the check measures | What it typically surfaces |
|---|---|---|
| Identity & security posture | MFA registration and enforcement state, authentication methods in use, administrative role distribution, guest accounts, password policy compliance and expiry, risky sign-ins, surviving legacy authentication. | Users with no MFA method registered, standing privilege held well beyond the people who need it, and guest accounts that outlived the project that invited them. |
| Licensing efficiency | Assigned versus actually used licences, unlicensed active users, licensed users dormant across every workload, overlapping SKUs, trial and unauthorised subscriptions. | A reclaimable seat count that is usually large enough to fund the remediation work outright. |
| Exchange Online | Inactive mailboxes by last send, read, and receive; mailbox sizes against quota; compliance holds; connection protocols, platforms, and client versions; forwarding and inbox rules. | Mailboxes forwarding externally that nobody authorised, and legacy protocol connections still succeeding. |
| SharePoint & OneDrive | Storage consumed per site, external sharing configuration, anonymous link inventory with creation and access history, inactive sites, orphaned sites, DLP rule matches and overrides. | Anonymous links created for a single meeting years ago and still resolvable — the same exposure the Copilot readiness work depends on closing. |
| Teams | Team and channel inventory with ownership, ownerless teams and private channels, guest and external membership, installed bots, tabs and connectors, inactivity by chat, call, and meeting. | Teams with no surviving owner, which means no one can approve membership or respond to an access review. |
| Groups & directory | Security and distribution group inventory, empty groups, ownerless groups, mail-enabled groups, recently deleted objects, group-based licensing dependencies. | Group sprawl that quietly determines access in places the access model was never documented. |
| Adoption & usage | Active users per workload, per-application activity across Outlook, Teams, Word, Excel, PowerPoint and OneNote, active days per user, activation counts, inactivity by platform. | Which workloads were paid for and never adopted, segmented by department rather than averaged into meaninglessness. |
Dashboards That Keep the Finding Current
The audit is delivered once. The dashboards are what stop the same findings reappearing in eighteen months, and they are built so that a named owner reviews each one on a stated cadence rather than opening it after an incident.
Executive Dashboard
- Adoption, licence efficiency, and security posture on a single board-facing view
- Trend rather than snapshot, so direction of travel is visible
- Sized for a monthly steering meeting, not for an administrator
Adoption & Usage
- Segmented by department, job title, and location rather than reported as a tenant average
- Per-workload and per-application activity, with active-days distribution
- Inactive user and inactive mailbox lists that feed licence reclamation directly
Security & Data Governance
- MFA coverage, administrative privilege distribution, guest population, password compliance
- External sharing, anonymous links, and DLP matches over time
- Thresholds that raise an alert rather than waiting to be noticed
Copilot Readiness & Value
- The six assessment pillars tracked as live metrics rather than a one-off score
- Seat allocation against actual usage, with dormant licences surfaced for reclamation
- The measured evidence the renewal decision will be judged on
Tooling is chosen after the requirement, not before it. Much of this is available from the Microsoft 365 admin centres and Viva Insights at no additional cost; deeper history, cross-workload correlation, and scheduled distribution generally justify either a Graph-to-Power BI pipeline or a dedicated reporting platform such as AdminDroid. The engagement establishes which reports are actually going to be read, by whom, and how often — and only then decides what needs buying.
Automation & Lifecycle Operations
Every finding in the health check has an administrator behind it performing the same sequence by hand, inconsistently, at whatever hour the request arrived. Automation is where the readiness work stops being a remediation project and becomes the way the tenant is operated.
Joiner, Mover, Leaver
Onboarding that provisions the correct licence, groups, and access from a single standardised definition rather than by copying the last person who joined. Offboarding that disables the account, revokes sessions and application consent, reassigns OneDrive content, converts the mailbox, and releases the licence in one auditable execution.
Account Remediation
A compromised account is a sequence, not a decision: disable, revoke every session, reset credentials, strip forwarding and inbox rules, remove illicit consent grants, force MFA re-registration. Written once as a runbook, it executes in seconds and produces the same evidence every time.
Approval Workflows
Licence requests, team and site creation, distribution list changes, and guest invitations routed through approval before they execute — sequential or parallel, with the approver resolved dynamically from the requester's manager, and a complete record of who approved what and when.
| Candidate | Trigger | What it returns |
|---|---|---|
| Dormant licence reclamation | Scheduled, against the inactivity threshold agreed in the health check | Recurring licence cost, recovered without anyone having to raise it as a project |
| Ownerless group and team remediation | Scheduled inventory sweep | Restores the ownership that access reviews and Copilot governance both depend on |
| Stale guest review | Guest account inactive beyond the agreed period | Removes external access that no longer has a sponsor |
| Over-permissive sharing alert | Anonymous link or organisation-wide grant created on a sensitive site | Stops the oversharing position degrading between audits |
| Leaked credential response | Entra ID Protection risk detection | Containment in seconds rather than at the next working day |
| Bulk changes at scale | CSV-driven, run on demand | Replaces one-off PowerShell written under time pressure and never reviewed |
Automation Needs the Same Governance as Agents
An automation that disables accounts is an agent that acts, whatever the vendor calls it. It belongs under the intake, register, and review discipline set out in Engagement 05, for the same reasons.
-
Control 1 · Least Privilege
Who May Build, Edit, and Run
Role-based control separating the ability to author an automation from the ability to execute it, so that a service desk operator can run an offboarding without holding the permissions to rewrite what offboarding means.
-
Control 2 · Reversibility
Pause Mid-Run, and Revert After It
Execution that can be held for review before the destructive step, and unwound afterwards — either a single action or an entire run. Bulk operations without a reverse path are the ones that turn a typo into an incident.
-
Control 3 · Evidence
Every Execution Produces a Record
Job history, the changes made, the approvals collected, and the operator who initiated it — retained to match the organisation's legal position, and available to an auditor without a reconstruction exercise.
-
Control 4 · Review
Automations Are Registered and Retired
Recorded in the same register as agents, with an owner and a review date. An automation that survives the process it was built for is an ungoverned privilege waiting to be inherited.
Start with an Honest Position
Four minutes across eight pillars will identify which of these seven engagements is required, and in what order.