Microsoft + ClaudeOne partner for the cloud you run and the AI you put on top of it.
Avalon Web ServicesMicrosoft · Claude · Security

Microsoft 365 Copilot implementation: what has to be true before you buy

Microsoft 365 Copilot answers using the signed-in user's existing permissions, through an index that is on by default and cannot be disabled. It adds no access control of its own. For a business under 300 seats, that makes implementation a SharePoint permissions and information-architecture exercise with a licence attached — not a deployment. This guide covers the licence paths and their commitment terms, the prerequisites that quietly exclude users, the governance controls the official guidance assumes you have licensed, and what independent government trials found once the vendor studies are set aside.

Written by
Arif Ali Mughal
Published
Reading time
9 min

01 / 10

Copilot has no permission model of its own

Every vendor deck says the same reassuring sentence: Copilot respects your existing permissions. It is true, and it is the single most misread sentence in the product. It is not a statement about security. It is a statement about inheritance — Copilot will faithfully reproduce whatever access decisions your tenant has accumulated, including the ones nobody remembers making.

Microsoft's own documentation is explicit that Copilot “presents only data that each individual can access using the same underlying controls for data access used in other Microsoft 365 services”. The grounding layer is the semantic index, which is generated from Microsoft Graph and is, in Microsoft's words, automatically enabled with no administrative involvement required — and cannot be disabled. There is no allow-list step between your permissions and the answer.

So the question that decides whether a rollout goes well is not “is Copilot secure”. It is “what can our people already reach, and would we be comfortable if a search engine that never gets bored made it one sentence away?”

HOW ONE COPILOT ANSWER IS ASSEMBLED 01 IDENTITY 02 PERMISSIONS 03 INDEX 04 LABEL GATE 05 RESPONSE The signed-in user's own token Existing Graph ACLs, unchanged Always on. No admin switch Purview DLP — only if configured Cites the files it actually used WHAT GOES WRONG AT EACH LINK Nothing. This is the link that actually holds. Ten years of “Everyone except external users”. Cannot be turned off or scoped. Mirrors 02 exactly. Unlabelled data is ungated data. Most SMB tenants. Correct answer, wrong reader — and it is auditable. Copilot adds no permission layer of its own. Every control you get is one you already owned.
Copilot adds no permission layer of its own. Stage 02 is the one carrying the risk, and it is the one you already owned before Copilot existed — which is why readiness work is permissions work, not deployment work.

02 / 10

Which licence, and what you are actually committing to

There are three doors, and the commercial constraints matter more than the feature differences for a business under 300 people. All figures below are the structure, not the price — Microsoft's commercial price list changed on 1 July 2026 and the SMB promotional discount has an end date that Microsoft's pricing page and at least one large reseller state differently. Price it at the point of purchase, not from a blog post, including this one.

PathWho it is forThe constraint that bites
Microsoft 365 Copilot ChatEveryone you already licenseIncluded at no additional cost with eligible Microsoft 365 plans. Web-grounded, and the entry point to the paid experience — not the in-app, work-grounded Copilot.
Microsoft 365 Copilot BusinessBusiness Basic, Standard or Premium tenants at 300 users or fewerCapped at 300 seats. Annual commitment. And the one to read twice: you cannot move to an Enterprise plan until your commitment end date.
Microsoft 365 CopilotE3, E5 and estates that will outgrow 300 seatsBusiness Standard and Business Premium are also eligible base plans for the full add-on, so the SMB SKU is a choice rather than the only route.

03 / 10

The prerequisites that stall pilots in week one

None of these are obscure. All of them are routinely discovered after the licences are assigned, which is the expensive order to discover them in.

CheckWhat Microsoft requiresWhat skipping it looks like
Update channelCurrent Channel or Monthly Enterprise Channel. Semi-Annual Enterprise Channel is not supported; a channel unification was scheduled for July 2026.Licences assigned, no Copilot button, no error message.
Mailbox locationPrimary mailboxes hosted in Exchange Online only. On-premises and hybrid mailboxes do not support grounding.Half the company works and half does not, for no visible reason.
Shared and delegate mailboxesNot supported as Copilot targets. Acting on a shared mailbox requires the user's own Copilot licence plus full delegate access — folder-only permissions are not supported.The info@ and accounts@ triage workflow you bought it for.
App licensing modelDevice-based licensing for Microsoft 365 Apps for enterprise is not supported.Shared-device and shop-floor staff silently excluded.
Browser configurationThird-party cookies enabled for the web apps.Works on the desktop, fails on the web, blamed on the network.

04 / 10

Oversharing is not a phase of the project. It is the project

Microsoft's own deployment blueprint puts this first, organised as three pillars: remediate oversharing, set up guardrails, meet regulations. The remediation half is where the calendar time goes.

The specific pathology in most small tenants is not exotic. It is a decade of files shared to “Everyone except external users”, inherited permissions on sites whose owner left in 2023, and a handful of libraries that were made broadly readable once, for a good reason, on a deadline. Microsoft's SharePoint reporting will show you the shape of it: the report on content shared with everyone except external users surfaces the top 100 sites shared organisation-wide in the past 28 days, and site access reviews let you push remediation to the site owners who actually know what the content is.

That delegation is not a convenience — it is structural. Microsoft's guidance notes that compliance reasons prevent IT administrators from accessing file-level detail, so site owners are the only people positioned to judge their own content. Any plan that assumes one admin will fix the permissions estate alone is a plan that has not started.

  • Run the access governance reports before you cost the project, not after. They determine the size of it.
  • Expect the remediation to be owned by people who do not report to IT, and schedule accordingly.
  • Archived content is not indexed for Copilot — archiving genuinely dormant sites is remediation, not avoidance.

05 / 10

The control that is retiring, and the one replacing it

If you have read a Copilot readiness article written before this year, it probably recommended Restricted SharePoint Search — an allow-list of sites that can appear in organisation-wide search while you fix permissions. Two things have changed.

First, Microsoft is retiring it: starting 31 July 2026, new enablement is blocked. Second, and more useful to know, Microsoft's own page is candid that it never was what people used it as. It “isn't a security boundary and doesn't change any permissions”, it is limited to 100 sites, and it does not guarantee that only allow-listed sites appear in Copilot — recently accessed files and content shared through Teams or Outlook can still surface.

The successor is Restricted Content Discovery, and it is worth understanding precisely what it does, because the name oversells it. RCD is a per-site setting that suppresses a site's content from organisation-wide search results and Copilot responses and removes the AI entry points from the site. Site permissions stay exactly as they were, and the content is not removed from the index. It buys you time while the real remediation happens. It is not the remediation.

06 / 10

Where the guidance quietly assumes an enterprise you are not

This is the part that SMB-focused Copilot content tends to skip, and it is the part that changes the budget. Microsoft's Copilot readiness guidance leans on Purview and Entra capabilities that Business Premium does not include. The primary licensing comparison page for Copilot readiness compares E3, E5 and E7 — there is no Business Premium column at all.

  • Microsoft sells a Purview Suite add-on aimed specifically at Business Premium, capped at 300 seats. When a vendor prices a patch for a gap, the gap is real.
  • Automatic labelling is the absence that matters most. The Purview control that stops labelled files being used as grounding is generally available — but a label nobody applied protects nothing.
Control the readiness guidance assumesIn Business Premium?How you actually get it
Automatic and default sensitivity labellingNo — manual labelling onlyPurview Suite add-on, or an E5-tier plan
DLP beyond Exchange, SharePoint and OneDriveNo — those three workloads onlyPurview Suite add-on, or an E5-tier plan
Insider Risk Management, Communication ComplianceNoPurview Suite add-on, or an E5-tier plan
Access reviews, PIM, entitlement managementNo — Business Premium ships Entra ID P1Entra ID P2 or the Entra ID Governance add-on
Copilot data residency commitmentsNoAdvanced Data Residency, required for all users in the tenant

07 / 10

A documentation conflict worth checking in your own tenant

SharePoint Advanced Management is the toolkit behind most of the oversharing reports above. Microsoft states that assigning at least one Microsoft 365 Copilot licence grants SharePoint administrators the SAM feature set that supports Copilot deployment. The same prerequisites page also enumerates the qualifying base licences as Office 365 E3, E5 and A5, and Microsoft 365 E1, E3, E5 and A5 — a list that does not include Business Premium or Business Standard, even though Microsoft's Copilot licensing page confirms both are eligible base plans for the add-on.

We are not going to resolve that here, because Microsoft's documentation does not. We are flagging it because the entire remediation plan above depends on which answer is true in your tenant. Assign one licence, open the SharePoint admin centre, and confirm the reports are actually there before you build a schedule on them.

One further gap worth knowing: we could not find any Microsoft documentation stating what happens to Copilot prompts and responses when no retention policy is configured. Prompts and responses are captured in the unified audit log and are discoverable through eDiscovery — but the default retention behaviour is not documented on any page we could find. If that matters to your regulator, get it in writing rather than inferring it.

08 / 10

What the evidence actually says, once you separate who paid

Copilot's business case is unusually well documented and unusually contested. The honest summary is that vendor-funded modelling and independent trials do not agree, and no source reconciles them.

  • Read the funding column before the headline number. Where vendor modelling and government trials disagree, no source reconciles them — including this one.
  • The widely-shared MIT statistic that 95% of organisations get zero return from AI is a general finding about generative-AI pilots, not a Copilot measurement. It is routinely cited as though it were the latter.
StudyFunded byWhat it found
Forrester Total Economic Impact for SMB, October 2024Microsoft-commissioned132% to 353% ROI across low, medium and high scenarios. The 353% figure quoted everywhere is the top of a range, not a typical result.
UK cross-government experiment, published June 2025Independent (UK government)20,000 employees, 7,115 survey responses. An average 26 minutes a day saved, self-reported — and the report states it was not possible to identify how the time saved was spent.
HMRC phase three evaluation, published July 2026Independent (UK government)3,000 licensed staff. Savings of 2 to 3% of a working week, about 60 minutes, after discounting roughly 20% for non-usage. 46% of non-users cited security and data privacy concerns.
Australian Treasury trial, 218 participantsIndependent (Australian government)Most participants used it two or three times a week or less, and found it applicable to fewer tasks than expected.
Microsoft Work Trend Index, May 2026Microsoft's own researchOnly 19% of AI users sit in the high-performing group; only 13% say they are rewarded for redesigning work around AI. Organisational factors mattered more than twice as much as individual ones.

09 / 10

A four-week readiness sequence

The most useful figure in that table is Microsoft's own. The binding constraint on value is organisational, not technical — which is consistent with every independent trial above, and is why the sequence below spends more time on people and permissions than on the product. Microsoft publishes a four-phase adoption framework — plan, implement, adopt, manage — but it publishes no recommended pilot size or duration for customers. The sequence below is ours, not Microsoft's, and it is built around a single opinion: gate each week on a condition you can state out loud, because the failure mode of Copilot projects is not moving too slowly, it is moving to the next phase without finishing the previous one.

A FOUR-WEEK READINESS SEQUENCE — AUTHOR-PROPOSED, NOT MICROSOFT GUIDANCE WEEK 1 — MEASURE WEEK 2 — CONTAIN WEEK 3 — PILOT WEEK 4 — DECIDE Run the access governance reports Inventory shared and delegate mailboxes Check the update channel Restricted Content Discovery on hot sites Site-owner access reviews Label the top three stores Eight to twelve users, named recurring tasks Baseline those tasks before the licences land One 30-minute clinic a week Compare against the baseline you took Widen, hold, or stop Write the reason down before the renewal date GATE — DO NOT START THE NEXT WEEK UNTIL THIS IS TRUE You can name every site shared org-wide. No unlabelled sensitive store is discoverable. A pilot user repeated a task without being asked. The decision is written down with its evidence. Weeks 1 and 2 are permissions work. Only week 3 needs a Copilot licence — which is the point.
Weeks one and two need no Copilot licence at all. That is deliberate: the work that decides whether a rollout succeeds happens before anything is bought.

10 / 10

What we would do, and what we sell

Our recommendation for a business under 300 seats is to buy the smallest number of licences that lets you run week three honestly, and to spend the first fortnight doing permissions work that has value whether or not you ever deploy Copilot. Fixing a decade of oversharing improves your position on every audit, every breach scenario and every future AI tool. It is the rare piece of prerequisite work that survives the technology choice.

The commercial disclosure, plainly: we sell exactly this. Our Copilot Pilot in a Box package is the four-week sequence above, and a Cloud Health Check is the wider version for tenants where Copilot is one of several open questions. You can also run all of it yourself with the Microsoft documentation linked below — the reports are in the SharePoint admin centre and the guidance is public. What you are buying from us is the sequence, the gates, and someone whose job it is to say the pilot failed if it failed.

Everything above was verified against Microsoft's published documentation and the primary studies on 18 August 2026. Product surfaces in this area change monthly; if you are reading this well after that date, re-check the retirement and preview items before acting on them.

Primary sources

Want us to run this for you?

Start here

Tell us what'skeeping you upat night.

Most engagements start with a Cloud Health Check — one week, full audit, top-10 findings, 90-day roadmap. Many turn into a longer engagement; either way, you walk away with a prioritized plan you own.