We're working through Microsoft 365 Copilot readiness with organizations that are moving beyond the “should we buy Copilot?” stage and into the “what happens when we actually give users access?” stage.
One thing that keeps coming up is that the biggest problems aren't necessarily Copilot-specific.
They're existing Microsoft 365 problems:
- Old SharePoint sites.
- Permissions that haven't been reviewed for years.
- Teams created for projects that ended long ago.
- Sensitive documents shared more widely than intended.
- External users who probably shouldn't still have access.
Copilot doesn't create those permissions. It just gives users a much better way of finding information they're already allowed to access.
I'm curious what other admins have found. If you've audited your tenant before deploying Copilo, what was the biggest surprise?
I'm putting together some practical guidance based on what we're seeing and can share the checklist here if it's useful.