Copilot readiness
Whether your tenant is ready for Microsoft Copilot and Copilot Autopilot - what they would reach in your tenant today, what to fix first, and how far you have come since the baseline.
Copilot readiness
Microsoft Copilot and Copilot Autopilot work within the permissions your tenant already has. Whether you are about to switch them on or have been running Copilot for a year, the Copilot readiness screen answers the same question: "What can they reach today, and what do we fix first?"
What You Can Achieve
Get a verdict, not a percentage to interpret
Each surface - Copilot and Autopilot - gets a verdict: Ready, Ready with fixes, or Not ready. The percent sits beside it, and a blocking check that is not met is named.
Fix the short lists first
Sensitive content crossed with each broad access path gives short lists. The screen ranks the open checks, and each one opens the matching files, sites, users or agents with its fix preselected.
Show before and after
Pin a snapshot as the baseline. Every check then shows its count against the baseline, so the assessment ends with a measured change.
Know what is not measured
The coverage figure says how many of the twelve exposure paths are measured. A path we cannot see yet is listed as not measured and left out of the score.
Surfaces and Verdicts
A surface is the thing you are about to switch on. Each check counts toward the surfaces it applies to.
| Verdict | Meaning |
|---|---|
| Ready | Every measured check is met |
| Ready with fixes | Some checks are at risk or not met, none of them blocking |
| Not ready | A blocking check is not met |
| No verdict yet | Nothing has been measured |
The percent is the share of measured checks that are met, with at-risk checks counted as half.
Checks
Checks are grouped in four pillars.
| Pillar | What it covers |
|---|---|
| Data exposure | Sensitive content behind anyone links, organisation-wide links, Everyone grants, public sites, Copilot discovery, external access, broadly shared locations and shared OneDrives |
| Identities and access | Dormant accounts and guests that reach sensitive content, sites and groups with no owner, large groups |
| Agents and AI apps | Agents with no accountable person, agents with tenant-wide reach to sensitive content, apps waiting for review |
| Guardrails | Restricted data types kept out of AI reach, enforcing labels on sensitive files, AI activity monitoring |
A count check is met up to the level you accept (zero by default), at risk up to its tolerance, and not met above it.
Targets and Snooze
Both numbers are yours to set, per check, in the check panel. A tenant that runs Copilot already and has decided to live with a known set of findings raises the accepted level; the check then reads met and the verdict follows. Reset returns to the defaults.
Snooze takes a check out of the verdict and the percent for a day, a week, a month, three months, or until you resume it. The check keeps its number and its place on the screen, marked as snoozed.
Targets and snoozes apply to the whole tenant, because they change the verdict everyone sees.
Unused Content
Two checks look at content nobody uses, across the whole tenant:
- Unused sites still open to Copilot - sites with no activity for a year that Copilot can still read.
- Files nobody has used in a year - the share of files with no view or edit in a year. Copilot still grounds answers on them, so stale content dilutes what it says.
Counts come from a daily scan. A check being measured for the first time shows "First scan in progress" until its number arrives.
The Check Panel
Click any check to open its panel:
- why the finding matters and how it compares with the baseline
- the 30-day line, with the change since yesterday and since last week
- the matching resources, as a live list you can download
- the fix
Fixing a Finding
Where an action exists, it is preselected: select rows in the list and run it. Two warnings appear before you run anything:
- Removing sharing links cannot be undone. People who relied on a removed link lose access.
- Blocking a site from Copilot discovery needs a Microsoft licence. The panel links to Action readiness to check it.
Running actions needs the write app and a paid plan. On a read-only connection the lists and the report still work.
Stage a cleanup fixes every match at once. It creates a Security Case that freezes today's matches and stages the action for each one; nothing runs until an admin approves it in the Action Center.
On a read-only connection or a trial, each check shows its fix as a fix plan instead, and the plan is printed with the report.
Where no one-click action exists, the panel opens the filtered list instead.
Show on Trends copies a check into a trend you can rename, tune and alert on.
Where to Start
Two rankings sit under the checks:
- Sites by sensitive exposure - sensitive content weighted by how many people can enter and by each broad path into the site.
- Users by sensitive reach - the sensitive files each person can open, which is what an agent acting for them would inherit.
Assessment History
A snapshot is a dated copy of the whole screen. One is taken automatically every Monday, and you can take one at any time. The first snapshot you take becomes the baseline; pin a different one from the table.
Print report opens Reports, where the verdicts and every check can be branded and downloaded for hand-over.
API
GET /copilot-readiness on the REST API and the
get_copilot_readiness tool on the MCP server return
the same document, so a partner can pull readiness for every customer tenant.
Access
The screen is available to administrators with the Compliance section.
Compliance
See exactly which regulations you're ready for, which requirements are holding you back, and prove it with a dated evidence pack - without re-mapping the same control for every framework by hand.
Reports
Turn Copilot readiness, compliance status and trends into a branded document - PDF, PowerPoint, HTML, CSV or JSON - from the dashboard or over the API.