Before Copilot licenses go out, someone has to audit the tenant they will run against. That audit answers one question. Can Copilot be switched on safely, and will it give useful answers once it is? We run it as 12 checks across 4 gates, from license pairing through agent spend. Work through all 12 below before you buy seats or book managed AI services.
An AI readiness assessment checks whether your Microsoft 365 tenant meets Copilot’s licensing, identity and mailbox prerequisites, whether your content is indexed well enough to ground useful answers, and whether existing oversharing will surface data Copilot should never repeat.
Most Copilot rollouts do not fail on day 1. They fail in week 3, when somebody in finance asks a plain-English question and gets back a salary band, or asks for last quarter’s numbers and gets nothing useful at all. Opposite failures. Same root cause. Nobody audited the tenant first.
We have run this assessment enough times to notice a pattern. The check that fails is almost never the one the client braced for. Teams arrive expecting a permissions nightmare, clear that gate cleanly, and then get stopped by an update channel setting or a shared mailbox Copilot cannot read at all. So order matters more than thoroughness, because 4 of the 12 checks can invalidate remediation work you would otherwise do on the other 8. Sequence first. Depth second.
What follows is the sequence we actually use, with the admin center path for each check and what a failure costs you. Uprite has supported Texas businesses for 25 years and we deliver this as a fixed-scope AI readiness assessment, but there is nothing on this list your own administrator cannot verify in an afternoon. No special tooling. No consultant required.
What an AI readiness assessment actually covers
An AI readiness assessment is a structured audit of a Microsoft 365 tenant carried out before Copilot licenses are assigned. It verifies entitlement, content grounding quality, data exposure risk and audit coverage. The output is a pass or fail per check, a remediation list ordered by effort, and a defensible go or no-go date. Nothing more exotic than that.
The 12 checks group into 4 gates. Three checks per gate. Exposure is where most rollouts stall.
- Gate 1, entitlement. Can the tenant legally and technically turn Copilot on for these users?
- Gate 2, grounding. Is enough of your working content indexed for the answers to be worth reading?
- Gate 3, exposure. What will Copilot surface in plain English that was only ever hidden by obscurity?
- Gate 4, accountability. Can you prove afterwards what it read, what it said, and what it cost?
Why most Copilot readiness checklists start in the wrong place
In August 2026 we pulled the 6 pages ranking for “copilot readiness checklist,” including Microsoft’s own adoption guide, and searched every one of them for the terms that decide real deployments. Delegated mailboxes, archived SharePoint data, the semantic index, Copilot Credits, Restricted Content Discovery, eDiscovery and Microsoft 365 Apps update channels returned zero hits across all 6 pages. “Shared mailbox” appeared once. “Exchange Online” appeared 3 times. That is the whole gap.
Nearly every published checklist is a permissions story. Permissions genuinely matter, and they are checks 7 through 9 below. But a tenant can pass every permissions test you can invent and still hand your pilot group an assistant that cannot read the shared inbox where half the customer history lives, cannot see the project sites somebody archived last year to save storage, and quietly bills an Azure subscription nobody remembers connecting. All 3 pass a permissions audit.
The blunt version. Permissions decide whether Copilot is safe. Licensing, mailbox location and indexing decide whether it is useful. A rollout that only audits the first one buys a very expensive search box.
Gate 1, entitlement. Can you even turn Copilot on?
Three checks. Every one is a yes or no, and all 3 can be answered from the admin center inside an hour. Do these first. Always. A tenant that fails check 2 does not need a permissions project yet, it needs a mailbox migration plan.
1. Confirm the base license sitting underneath the Copilot license
This is the check where we most often correct a client, and it is also where we had to correct ourselves. The guidance that circulated through 2024 and 2025 was that Copilot needed a full Microsoft 365 suite and that Office 365 plans did not qualify. That is no longer accurate. It changed quietly.
Microsoft’s minimum requirements page, refreshed in June 2026, lists Office 365 E1, E1 Plus, E3 and E5 alongside Office 365 F3, the A-series plans, Microsoft 365 Business Basic, Business Standard and Business Premium, Microsoft 365 E3, E5 and E7, Microsoft 365 F1 and F3, and the standalone Teams plans. If somebody told you last year that your Office 365 E3 tenant was disqualified, go and check again. The list grew.
Pull the assigned-license report under Billing, then Licenses, in the Microsoft 365 admin center. Confirm that every pilot user holds both a qualifying base plan and the Copilot add-on. A user with the add-on and no qualifying base gets an add-on that does nothing. You still get the invoice.
2. Confirm every pilot user’s primary mailbox is in Exchange Online
Copilot grounds on mailbox content. Emails, calendar events, metadata. Microsoft states plainly that this only works when the mailbox lives in Exchange Online, and that on-premises and hybrid mailboxes do not support that grounding. No exceptions.
Any manufacturer or law firm still running hybrid Exchange hits this wall, and it turns a 2-week rollout into a migration project. Find that out in week 1. We have seen it discovered in week 5, after the licenses were already billing. There is no clever workaround.
3. Move pilot devices onto Current or Monthly Enterprise Channel
Microsoft 365 Apps have to run on Current Channel or Monthly Enterprise Channel for Copilot features to appear inside Word, Excel, Outlook, PowerPoint and Teams. Semi-Annual Enterprise Channel does not surface them, and Microsoft’s channel guidance for Copilot is explicit about it.
There is a 2026 wrinkle worth knowing. Starting July 2026 Microsoft began unifying channels, so Semi-Annual Enterprise Channel now receives feature and security updates monthly on the same basis as Monthly Enterprise Channel. That is convergence. Not an exemption. Verify the channel on the devices your pilot group actually uses instead of assuming the change covered you.
Two operational details catch people out. A channel change can take up to 24 hours to trigger on a device, and it is a point-in-time action, so anyone you add to the targeting group afterwards never gets moved. You have to run it again. Every time. Neither of those is documented anywhere near the licensing page, which is exactly why they surprise people at go-live.
Gate 2, grounding. Will the answers be worth reading?
Gate 1 decides whether Copilot switches on. Gate 2 decides whether anyone keeps using it after the novelty wears off. This is the gate that quietly produces unused licenses. Security barely enters into it.
4. Work out how much of your real content is actually in SharePoint or OneDrive
The tenant-level semantic index that grounds Copilot is generated from text-based SharePoint Online files. If your drawings, contracts and job files still live on a file server or a NAS in the back office, Copilot cannot reach them. Not restricted. Invisible. There is a difference.
Two indexing behaviors set realistic expectations. Microsoft’s semantic indexing documentation says new documents added to SharePoint sites reachable by 2 or more users are indexed daily rather than instantly, while documents a user creates are indexed in near real time in that user’s own mailbox, and updates to already-indexed documents index immediately. A pilot that starts the morning after a large content migration will therefore look worse than the tenant really is. Wait a few days before judging it. Patience is cheaper than a rebuild.
One practical ceiling worth knowing. PDF, PPTX and DOCX files up to 512 MB are supported, which covers almost everything except video-heavy decks and scanned archives. Check your outliers.
5. Map the mailboxes Copilot cannot read at all
This is the check that surprises people most, and it is the one no other readiness checklist we scraped mentions. Not one.
Copilot’s user-level index covers a user’s own mailbox. Microsoft’s supported-content table marks delegated mailboxes, shared mailboxes and archived mailbox data as not supported. Archived SharePoint data is unsupported at both the user and the tenant level. Read that table before you promise anything.
For a small or mid-sized business that is a serious hole. The ap@, info@, support@ and quotes@ addresses holding most of your institutional memory are almost always shared mailboxes. Ask Copilot to summarize what a customer has been asking for and it will confidently summarize one person’s slice of the conversation. Confidently is the problem.
Write that list down before the pilot starts, then tell the pilot group. An assistant with a published blind spot gets trusted and used. An assistant that silently misses half the story gets abandoned within two weeks. Nobody ever tells you why.

6. Check which sites are hidden from search, and what is sitting in archive
A SharePoint site only feeds the semantic index while it stays searchable. If somebody once set Search and offline availability to No on a site, that site is out of Microsoft Search and out of Copilot together. You cannot separate the two. It is one switch. Microsoft supports excluding content from the tenant-level index only, and the action applies to both surfaces at once.
Microsoft 365 Archive is the other trapdoor. Archiving a site preserves its content, permissions and metadata and drops it out of your active storage quota, but Copilot is not trained on archived content and users cannot reach it until the site is reactivated. That is the right answer for dead project sites. It is the wrong answer for the knowledge base someone archived last year to shave a storage bill. Go and look.
Gate 3, exposure. What will Copilot surface that it should not?
Copilot does not break permissions. It respects them exactly, which is the problem. Every over-permissive share your organization has accumulated since 2019 becomes answerable in plain English by anyone holding a license. Obscurity was doing more work than your access model was, and Copilot removes the obscurity in an afternoon. Overnight, really.
7. Get an oversharing baseline before anyone holds a license
Start in the SharePoint admin center under Advanced Management and choose Start assessment. The Content Management Assessment hub runs a suite of reports, flags potentially overshared content, surfaces inactive and ownerless sites and produces a Copilot readiness view. Microsoft’s readiness guidance recommends rerunning it every 30 days to track progress.
Then pull 2 specific Data Access Governance reports, both under Reports, then Data access governance.
- The Everyone except external users report lists the top 100 sites where content was shared with your entire organization in the past 28 days, plus the security policies applied to those sites.
- The sharing links activity reports show which sites had the most links created in the last 28 days, split into Anyone links, People in the organization links and Specific people links.
Both windows are 28 days, and that detail changes how you use them. A site that was badly overshared 6 weeks ago and has been quiet since will not appear in either report. So run them, remediate what shows up, then run them again a month later before you widen the pilot. One pass is a snapshot. Two passes are a baseline.

8. Publish sensitivity labels, then scope a DLP policy to the Copilot location
Labels on their own do not stop Copilot. You need a Microsoft Purview DLP policy with the Microsoft 365 Copilot and Copilot Chat location switched on. Pair a Content contains, Sensitivity labels condition with the Prevent Copilot from processing content action and labelled files and emails stop being used to generate responses, although the item can still appear in the response citations. Worth knowing before a demo.
Four limits belong in your plan before you build the policy, and all 4 come straight from Microsoft’s DLP for Copilot documentation.
- You cannot put a sensitive information types condition and a sensitivity labels condition in the same rule. Use 2 rules inside 1 policy instead.
- Policy changes take up to 4 hours to show up in the Copilot experience, so do not test a new rule 5 minutes after saving it.
- Files a user uploads straight into a prompt are not scanned at all. DLP only evaluates the text typed into the prompt itself.
- Email coverage starts at 1 January 2025, and calendar invites are not supported.
That last pair catches compliance teams flat. If your data protection story assumes every email in the tenant is covered, it is not. The gap is silent.
9. Turn on Restricted Content Discovery for your high-risk sites
Restricted Content Discovery keeps a site’s content out of Copilot, out of agents and out of organization-wide search while leaving its permissions completely untouched. It is the right tool for content that has to stay reachable but should not be discoverable. You set it per site in the SharePoint admin center under Sites, then Active sites, then the site’s Settings tab.
If you were planning to lean on Restricted SharePoint Search instead, that door has closed. Permanently. Microsoft blocked new enablement of Restricted SharePoint Search on 31 July 2026. Even before that it capped out at 100 sites and Microsoft described it as a short-term measure that was never intended to be scalable. We covered what the retirement means for file-heavy organizations on our managed AI services in Houston page.
Gate 4, accountability. Can you prove what Copilot did?
The last 3 checks are the ones that get skipped because nothing breaks when you skip them. They break later, during an investigation or an invoice review, when the answer to “what did it read” needs to be better than a shrug. Skip them anyway and you pay for it later.
10. Confirm audit retention, and who is actually allowed to read prompts
Copilot interactions are logged automatically under Audit (Standard). If auditing is already on in your tenant, there is nothing extra to configure, which is the good news. Rare, in this list.
What surprises people is how much those records carry. According to Microsoft’s Copilot audit documentation, each interaction record lists every resource Copilot touched, including the file name, the SharePoint URL and the sensitivity label ID of each item it read. There is an XPIADetected flag for cross-prompt injection attempts and a JailbreakDetected flag on prompts. That is a lot of forensic detail.
What the audit record does not give you is the prompt and response text. For that you go to Purview eDiscovery, and reading that content needs eDiscovery permissions a Global Administrator does not hold by default. Decide who holds that role now. Not later. Deciding it mid-investigation is considerably worse.
One budget note that belongs here rather than in check 11. Audit logs for non-Microsoft AI applications are not included in your enterprise subscription. They run on pay-as-you-go billing, are retained for 180 days, and are charged by the number of audit records ingested. Microsoft’s own Copilots stay covered under Audit Standard. Third-party AI tools are not.
11. Set a billing policy before anyone builds an agent
A per-user Copilot license is not the whole cost picture in 2026. Microsoft 365 Copilot Chat, SharePoint agents and the Copilot Retrieval API bill through pay-as-you-go Copilot Credits, charged to an Azure subscription that you connect.
Setting it up takes 2 steps that are easy to half-finish. You add a billing policy, which pairs an Azure subscription with a defined set of users, and then you connect that policy to a Copilot service. Neither step completes the setup on its own. People stop after the first. Pay-as-you-go is off by default, and you can attach a budget limit to the policy with email notifications at percentage milestones.
Set the budget on day 1. Not day 30. Agent usage scales with enthusiasm rather than headcount, and the first uncomfortable invoice usually arrives from the department that did exactly what you asked them to do.
12. Define the pilot cohort, the task, and the measure
The last check is not technical at all. Pick a group small enough to support properly and specific enough to measure, then write down, per person, the one task they are meant to stop doing the old way. One task. Written down.
That sentence is the entire adoption programme. Licenses handed out without a named task get used enthusiastically for a week and then quietly forgotten, and no amount of tenant hygiene fixes it. Give the group a named owner, a check-in at 2 weeks and a real decision point at 6. Microsoft’s own rollout guidance runs pilot, then deploy, then operate. The stage almost everybody skips is operate. Every single time.

The 12-check scorecard
Print this, run it top to bottom, and record a pass or fail against each row. The fix-time column is what we typically see on tenants between 25 and 250 seats, not a contractual commitment. Your mileage will vary.
| # | Check | Where you verify it | What a failure blocks | Typical fix time |
|---|---|---|---|---|
| 1 | Qualifying base license under the Copilot add-on | M365 admin center, Billing, Licenses | Copilot does nothing, add-on still bills | Same day |
| 2 | Primary mailbox in Exchange Online | Exchange admin center, Recipients | All mailbox grounding | Weeks, it is a migration |
| 3 | Apps on Current or Monthly Enterprise Channel | M365 Apps admin center, Inventory | Copilot absent from Word, Excel, Outlook | 24 to 72 hours |
| 4 | Working content is in SharePoint or OneDrive | SharePoint admin center, Active sites | Answer quality, permanently | Weeks to months |
| 5 | Shared and delegated mailboxes documented | Exchange admin center, Shared mailboxes | Trust, once users notice the gap | Half a day to document |
| 6 | Sites searchable, nothing critical archived | Site settings, Search and offline availability | Whole sites invisible to Copilot | Same day per site |
| 7 | Oversharing baseline captured | SharePoint Advanced Management, Start assessment | Every exposure decision below it | 1 to 2 weeks to remediate |
| 8 | Sensitivity labels published and DLP scoped | Purview, Data Loss Prevention, Policies | Labelled content still grounds answers | 1 to 3 weeks |
| 9 | Restricted Content Discovery on high-risk sites | SharePoint admin center, Active sites, Settings | Sensitive sites stay discoverable | Same day per site |
| 10 | Audit retention and eDiscovery roles assigned | Purview, Audit and eDiscovery | Any post-incident investigation | 1 to 2 days |
| 11 | Billing policy and budget connected | M365 admin center, Cost Management | Uncapped agent spend | Same day |
| 12 | Pilot cohort, task and measure written down | Your own document | Adoption, and the business case | 1 to 2 days |
How long a real assessment takes
The audit is fast. The remediation is not. Confusing the two is how Copilot dates slip.
On a tenant of 25 to 250 users, checks 1 through 3 and 10 through 12 are typically a single day of admin work. Checks 4 through 9 need report runs that have to sit for a while, and the 28-day windows on the Data Access Governance reports mean a genuinely defensible baseline takes a month of elapsed time even though it takes very few hours of labour. Plan for 2 to 3 weeks to a go or no-go decision, and treat any remediation uncovered along the way as a separate project with its own dates. Separate budget too.
If your tenant fails check 2 or check 4, stop the readiness work there. Mailbox migration and content migration are the parent projects, and everything below them has to be re-audited afterwards anyway. Do not audit twice.
What to do when the scorecard comes back ugly
A failing scorecard is a normal first result. In our experience most tenants that have been running since before 2020 fail somewhere in Gate 3, and a meaningful minority fail check 2 as well. That is a sequencing problem. Not a verdict on your IT team.
What matters is the order you fix things in. Entitlement first because it is cheap, grounding second because it decides whether anybody keeps using the tool, exposure third because it is the longest, and accountability alongside all of it because it is nearly free once you know who owns which role. That is the order. Hold it.
Uprite has supported Texas businesses for 25 years, we are a 6-time MSP 501 winner, and our 42-person team handles this work across Houston, San Antonio, Dallas and Fort Worth. If you would rather not run the 12 checks yourself, our AI readiness assessment delivers the scorecard, the remediation plan and the go-live date as a fixed scope. When you are ready to move past the audit, our Copilot deployment services pick up from the remediation list.
Two related reads before you start. Texas businesses deploying any AI system now sit inside TRAIGA, the Texas AI law that took effect on 1 January 2026, which carries no headcount or revenue threshold. And before your pilot group types its first prompt, you want an AI acceptable use policy and a wider AI governance framework in place, because a readiness assessment tells you what Copilot can reach and a policy tells your people what they may do with it.
Questions Texas IT leaders ask before turning Copilot on
Can we run an AI readiness assessment ourselves or do we need an MSP?
Your own administrator can run all 12 checks. Everything on the list is visible in the Microsoft 365, SharePoint, Exchange and Purview admin centers with no third-party tooling. Where teams usually want help is the remediation, particularly the oversharing work in Gate 3, which is judgement-heavy and hard to do part-time alongside a day job. The permissions half of that work is broken down step by step in our guide to fixing copilot data oversharing before rollout.
How long does an AI readiness assessment take?
Two to 3 weeks to a go or no-go decision for a tenant of 25 to 250 users. The admin work is closer to 2 days. The elapsed time comes from the Data Access Governance reports, which look back 28 days, so a single run is a snapshot rather than a baseline and you want a second pass before widening the pilot.
Does Microsoft 365 Copilot require an E5 license?
No. E5 is not required and never was. Microsoft’s current minimum requirements list Office 365 E1, E3 and E5, Microsoft 365 Business Basic, Standard and Premium, Microsoft 365 E3 and E5, the F-series and the standalone Teams plans as qualifying base plans. E5 does bring Purview capabilities that make Gate 3 considerably easier, which is a different argument.
Will Copilot expose salary files and HR documents to everyone?
Only if your permissions already do. Copilot runs every prompt in the security context of the user asking, so it cannot show somebody a file they could not already open. The risk is that broad shares nobody remembers become findable in plain English. That is why the oversharing baseline in check 7 comes before licenses, not after.
What happens to Copilot if our mailboxes are still hybrid?
Mailbox grounding stops working. Microsoft supports it only when the user’s primary mailbox is in Exchange Online, and states that on-premises and hybrid mailboxes do not support it. Copilot will still function in SharePoint and file contexts, but summarizing a mail thread or drafting a reply is off the table until those mailboxes move.
Is there anything TRAIGA requires before we deploy Copilot in Texas?
It changes the paperwork rather than the tenant work. TRAIGA took effect on 1 January 2026 and applies with no headcount or revenue threshold, so a 20-person firm carries the same scope triggers as a large enterprise. Run the 12 technical checks either way, then make sure your acceptable use policy and disclosure practices line up with the statute.










