Microsoft 365 Copilot is Microsoft's AI assistant that integrates across Word, Excel, Outlook, Teams, and other Microsoft 365 apps. Before rolling it out to your organisation, there are several security and configuration settings that need to be in place — not to use Copilot, but to use it safely.
Copilot can access and surface content from across Microsoft 365 — SharePoint, OneDrive, Teams, email. That means it will surface content that users have access to. If your permissions model is poorly configured — overshared SharePoint sites, broadly accessible files, everyone having access to everything — Copilot will reflect those weaknesses. A user asking Copilot about salary information could get results from an HR document they technically have access to but were never expected to find.
Copilot respects permissions but doesn't audit them. If a file is accessible to a user, Copilot can reference it. Getting permissions right before deploying Copilot is essential.
Copilot requires specific licences (Microsoft 365 Copilot, currently £25/user/month) on top of an existing Business Premium or E3/E5 subscription. Ensure you have the right base licence before purchasing Copilot add-ons.
Review who has access to what on SharePoint. Broad "Everyone" or "Everyone except external users" permissions on sites are particularly risky. Use the SharePoint admin centre to identify sites with overly permissive access.
Microsoft Purview sensitivity labels (Confidential, Highly Confidential) help Copilot understand which content is sensitive. It won't surface content labelled Highly Confidential in responses to users who don't have access. Setting up labels before deploying Copilot is strongly recommended.
With Copilot accessing sensitive business content, strong identity controls are non-negotiable. Ensure MFA is enforced for all users and Conditional Access policies are in place before rollout.
Copilot in Teams can reference meeting transcripts. Review your Teams recording and transcription policies to ensure meetings are being recorded and transcribed in line with your policies and legal obligations.
Tighten external sharing before deployment. You don't want Copilot surfacing information from documents that are overshared externally.
Review which guests have access to your Microsoft 365 environment. Guests don't get Copilot licences but Copilot references content guests have access to when responding to licenced users.
M365Clarity includes a dedicated Copilot Readiness tab that scans the relevant settings — SharePoint sharing, MFA status, sensitivity label configuration, Teams transcription settings, and guest access — and gives you a readiness score with plain-English guidance on what to fix before rolling out Copilot.
Connect your tenant, run a scan, and see exactly what needs attention — in plain English. Free plan available.
Scan your tenant free →Related articles