Copilot readiness assessment

Copilot will read what your users can reach. Check that first.

In a typical tenant an ordinary account can open hundreds of thousands of files, and dozens of sites hold card numbers, IDs or payroll data behind links anyone in the company can follow. Copilot honours every one of those permissions. 1Security scans your tenant read-only, ranks the sites Copilot would read by sensitive content and exposure, and - once you turn write access on - revokes, blocks or grants that access behind a review window, before the licenses go out.

The problem

The rollout is decided. Nobody can describe what Copilot will see.

The business wants Copilot this quarter, and security is asked to sign off on a tenant nobody has mapped: sites from projects that ended in 2022, sharing links from 2023, groups nested inside groups. Copilot does not break your permissions - it reads exactly what the signed-in user can already open. The permissions are the problem.

What we see on the first scan is consistent: a typical user can reach hundreds of thousands of files, most tenants hold several times more sites than IT believes they have, and 20-40% of the files with sensitive content carry no sensitivity label at all. Every one of those files is one plain prompt away from a summary on somebody's screen.

Assessing that by hand means months of per-site reviews that are stale before they finish. The assessment has to come from the tenant itself: what would Copilot read, where is the sensitive data concentrated, and which of it is exposed further than anyone intended.

And by the time the licenses go out, Copilot is rarely the only agent in the tenant. Agents built in Copilot Studio, agents from Azure AI Foundry, agents that arrive with a third-party SaaS tool - each inherits somebody's permissions exactly the way Copilot does. Readiness stopped being "what will Copilot read" and became "what can anything with a model behind it reach, and who is on the other side of it".

In practice

From read-only consent to a go decision in four steps.

The whole assessment runs on read-only consent and standard licenses - first numbers the same day.

  1. 01

    Connect read-only and let the scan run

    One consent, no agent, nothing installed. The inventory of sites, files, users and groups starts filling the same day, and 1Security's own engine scans content for 300+ sensitive information types - no E5, no Purview deployment required. Sensitive Info shows what has been found and how many files, sites and users can reach each type.

  2. 02

    Rank the sites Copilot would read

    Open Sites, filter to Copilot enabled + with sensitive info, sort by detections. Every row shows storage, external users, sharing links and how many people can enter. In a mid-size tenant this list is typically 30-80 sites - the exact places an AI answer could go wrong, in order.

  3. 03

    Stage the cleanup before rollout

    Enable the suggested automations - block Copilot org-wide search on externally exposed sensitive sites and on abandoned sites, expire the anyone links on files with sensitive content - and 1Security stages a proposal per site behind a 72-hour review window, with owners able to object before anything changes.

  4. 04

    Keep the gate closed after rollout

    The prebuilt "Sensitive Data Exposure to Copilot" trend counts the exposed sensitive files week over week, and the Agents screen carries every agent employees build or install - Copilot Studio, Foundry, Entra Agent ID and third-party - with its reach in files, sites, users and emails and an anomaly baseline of its own. Add Microsoft Agent 365 later and those agents join the same inventory with nothing to reconfigure.

From assessment to control

The assessment ends in a change, not in a report.

Ranking the sites Copilot would read is the measurement. What follows is always one of three decisions - leave it, close it, or hand the access out properly - and all three are one action away from the row you are already looking at.

Revoke the grant, the nested membership or the anyone-link behind an exposed site. Block Copilot org-wide search on it, close its external sharing, expire its links, or disable the account an agent runs under. Or grant what somebody legitimately needs, scoped to one site instead of the whole tenant.

Write access is a separate consent - the assessment itself never needs it. Every action is staged as a proposal inside a review window, 72 hours by default, and can be routed to the owner of the resource, who answers in their own restricted portal. Silence applies it; everything that ran sits in one audit trail with who approved it and when.

What makes it work

Four parts of the platform behind the assessment.

The assessment is not a separate product. Everything below keeps running after rollout.

  • Copilot security

    Every AI agent in the tenant, from every source, inventoried in one place, with its reach measured in files, sites, users and emails before employees start chatting with it.

    Explore the feature
  • SharePoint governance

    The Copilot-enabled flag, sensitive-info counts, external users and sharing links per site - the columns the readiness ranking is built from.

    Explore the feature
  • Access management

    Effective access resolved through groups, links and inheritance, so "what would Copilot read for this user" has an exact answer, not an estimate.

    Explore the feature
  • Agents beyond Copilot

    Copilot Studio, Azure AI Foundry, Entra Agent ID and third-party agents in one inventory - each with its reach resolved to content, its owner, and an anomaly baseline of its own.

    See it next to Agent 365

FAQ

Common questions.

Do we need E5 or Purview to run the assessment?

No. 1Security detects 300+ sensitive information types with its own engine, including OCR for scans and screenshots, on a Microsoft 365 Business Basic license upward. If you already run Purview, its detections and labels are synced in and shown right next to ours.

Does 1Security change how Copilot behaves?

Only where you tell it to. Blocking Copilot org-wide search per site and expiring sharing links are staged automations under the separately consented write module, each with a review window. Everything else is read-only measurement.

Does the assessment cover agents our own teams build?

Yes. Copilot Studio agents, declarative Copilot agents, Azure AI Foundry agents, Entra Agent ID identities and third-party SaaS agents all land in the same inventory, each with the files, sites, users and mailboxes it can reach and an anomaly baseline of its own. The ones nobody registered are usually the surprise.

Can 1Security close what the assessment finds?

Yes, once you turn write access on - a separate consent the read-only assessment never needs. Revoking a grant, expiring links, closing external sharing, blocking Copilot org-wide search on a site or granting scoped access are all staged as proposals inside a review window, optionally routed to the resource owner, and recorded in one audit trail.

How long until we have numbers?

The same day. The site ranking, the reach counts and the label coverage gap update continuously as the scan proceeds. Large tenants keep scanning in stages for weeks, but the top of the list is usually right within hours.

How does this relate to SharePoint Advanced Management?

They work together. SharePoint Advanced Management gives you site-level reports and controls inside SharePoint. 1Security adds what is inside those sites, the people, apps and AI agents that can reach them, and stages the fix - on standard Microsoft 365 licenses.

Assess it on your tenant, not on a slide.

Connect read-only and see the sites Copilot would read ranked by sensitive content and exposure - the same day, before the licenses go out. Then close what it finds, staged behind your own review window.

Or sign off on a permission state nobody can describe.