1Security
Screens

Copilot readiness

Whether your tenant is ready for Microsoft Copilot and Copilot Autopilot - what they would reach in your tenant today, what to fix first, and how far you have come since the baseline.

Copilot readiness

Microsoft Copilot and Copilot Autopilot work within the permissions your tenant already has. Whether you are about to switch them on or have been running Copilot for a year, the Copilot readiness screen answers the same question: "What can they reach today, and what do we fix first?"

What You Can Achieve

Get a verdict, not a percentage to interpret

Each surface - Copilot and Autopilot - gets a verdict: Ready, Ready with fixes, or Not ready. The percent sits beside it, and a blocking check that is not met is named.

Fix the short lists first

Sensitive content crossed with each broad access path gives short lists. The screen ranks the open checks, and each one opens the matching files, sites, users or agents with its fix preselected.

Show before and after

Pin a snapshot as the baseline. Every check then shows its count against the baseline, so the assessment ends with a measured change.

Know what is not measured

The coverage figure says how many of the twelve exposure paths are measured. A path we cannot see yet is listed as not measured and left out of the score.

Surfaces and Verdicts

A surface is the thing you are about to switch on. Each check counts toward the surfaces it applies to.

VerdictMeaning
ReadyEvery measured check is met
Ready with fixesSome checks are at risk or not met, none of them blocking
Not readyA blocking check is not met
No verdict yetNothing has been measured

The percent is the share of measured checks that are met, with at-risk checks counted as half.

Checks

Checks are grouped in four pillars.

PillarWhat it covers
Data exposureSensitive content behind anyone links, organisation-wide links, Everyone grants, public sites, Copilot discovery, external access, broadly shared locations and shared OneDrives
Identities and accessDormant accounts and guests that reach sensitive content, sites and groups with no owner, large groups
Agents and AI appsAgents with no accountable person, agents with tenant-wide reach to sensitive content, apps waiting for review
GuardrailsRestricted data types kept out of AI reach, enforcing labels on sensitive files, AI activity monitoring

A count check is met up to the level you accept (zero by default), at risk up to its tolerance, and not met above it.

Targets and Snooze

Both numbers are yours to set, per check, in the check panel. A tenant that runs Copilot already and has decided to live with a known set of findings raises the accepted level; the check then reads met and the verdict follows. Reset returns to the defaults.

Snooze takes a check out of the verdict and the percent for a day, a week, a month, three months, or until you resume it. The check keeps its number and its place on the screen, marked as snoozed.

Targets and snoozes apply to the whole tenant, because they change the verdict everyone sees.

Unused Content

Two checks look at content nobody uses, across the whole tenant:

  • Unused sites still open to Copilot - sites with no activity for a year that Copilot can still read.
  • Files nobody has used in a year - the share of files with no view or edit in a year. Copilot still grounds answers on them, so stale content dilutes what it says.

Counts come from a daily scan. A check being measured for the first time shows "First scan in progress" until its number arrives.

The Check Panel

Click any check to open its panel:

  • why the finding matters and how it compares with the baseline
  • the 30-day line, with the change since yesterday and since last week
  • the matching resources, as a live list you can download
  • the fix

Fixing a Finding

Where an action exists, it is preselected: select rows in the list and run it. Two warnings appear before you run anything:

  • Removing sharing links cannot be undone. People who relied on a removed link lose access.
  • Blocking a site from Copilot discovery needs a Microsoft licence. The panel links to Action readiness to check it.

Running actions needs the write app and a paid plan. On a read-only connection the lists and the report still work.

Stage a cleanup fixes every match at once. It creates a Security Case that freezes today's matches and stages the action for each one; nothing runs until an admin approves it in the Action Center.

On a read-only connection or a trial, each check shows its fix as a fix plan instead, and the plan is printed with the report.

Where no one-click action exists, the panel opens the filtered list instead.

Show on Trends copies a check into a trend you can rename, tune and alert on.

Where to Start

Two rankings sit under the checks:

  • Sites by sensitive exposure - sensitive content weighted by how many people can enter and by each broad path into the site.
  • Users by sensitive reach - the sensitive files each person can open, which is what an agent acting for them would inherit.

Assessment History

A snapshot is a dated copy of the whole screen. One is taken automatically every Monday, and you can take one at any time. The first snapshot you take becomes the baseline; pin a different one from the table.

Print report opens Reports, where the verdicts and every check can be branded and downloaded for hand-over.

API

GET /copilot-readiness on the REST API and the get_copilot_readiness tool on the MCP server return the same document, so a partner can pull readiness for every customer tenant.

Access

The screen is available to administrators with the Compliance section.

On this page