Copilot Readiness Checklist: Permissions, Labels and Pilot Groups
Retrospective: this article looks back at events from November 2023, written in 2026 with the benefit of hindsight.
Use this checklist before expanding Microsoft 365 Copilot beyond a pilot.
Licensing and roles
- Copilot licenses assigned to a defined pilot group.
- SharePoint Advanced Management available (included with Copilot).
- Purview capabilities identified by license (E3 vs E5).
- Admin roles for SharePoint, Purview and Copilot assigned.
Permissions
- Data access governance reports run (sharing links, EEEU, sensitivity labels).
- Content management assessment run.
- Top overshared sites remediated or protected with Restricted Content Discovery.
- EEEU removed from sensitive sites.
- Ownerless and inactive sites addressed.
- Site access reviews completed for high-risk sites.
Labels and DLP
- Sensitivity labels published and in use.
- Default and auto-labeling configured for sensitive content.
- DLP for Copilot policies created for highly confidential labels.
Defaults
- Default sharing link set to Specific people.
- Anyone links restricted or disabled.
- Restricted Access Control applied to business-critical sites.
Monitoring and compliance
- Audit logging confirmed; Copilot interactions captured.
- Retention policies for Copilot interactions defined.
- DSPM for AI reports reviewed.
- Agents and plugins reviewed in the Microsoft 365 admin center.
Users
- AI acceptable use policy communicated.
- Pilot users trained on what Copilot can access.
- Process for reporting oversharing discovered through Copilot.
Test
- Pilot users tested prompts for salaries, HR, M&A, passwords and confidential projects.