
Copilot Readiness: 47 Questions Before Go-Live
Microsoft Copilot readiness checklist — 47-point enterprise audit across 8 domains: identity, data surface, license, governance, sensitivity labeling, compliance, use case, adoption. Common critical gaps with mitigations.
Microsoft Copilot readiness checklist — 47-point enterprise audit across 8 domains: identity, data surface, license, governance, sensitivity labeling, compliance, use case, adoption. Common critical gaps with mitigations.

Before Microsoft 365 Copilot is licensed, an enterprise-grade readiness audit determines whether the tenant is positioned for safe deployment — or whether oversharing, identity gaps, sensitivity-label coverage, and governance immaturity will cause compliance findings or pilot abandonment within 90 days.
This is the working enterprise readiness checklist EPC Group uses for Fortune 500 organizations. Built from 90+ Microsoft Copilot deployments across healthcare, financial services, government, manufacturing, and technology.
EPC Group has delivered Microsoft Copilot readiness assessments for Fortune 500 organizations since the M365 Copilot GA wave.
| Domain | Checks |
|---|---|
| 1. Identity readiness | 7 checks |
| 2. Data surface readiness | 8 checks |
| 3. License readiness | 6 checks |
| 4. Governance readiness | 6 checks |
| 5. Sensitivity labeling | 5 checks |
| 6. Compliance readiness | 6 checks |
| 7. Use case readiness | 5 checks |
| 8. Adoption readiness | 4 checks |
47 total checks. Each must score "ready" or "remediation in progress" before tenant-wide Microsoft 365 Copilot licensing.
Typical findings: 5-15% inactive accounts, MFA gaps in service accounts, weak Conditional Access.
Typical findings: 30-50% of sites with broad permissions; 10-20% of OneDrive folders shared with anonymous links; weak external sharing posture.
Typical findings: E3 backbone with no E5 add-on; Microsoft Fabric capacity not provisioned; Microsoft Defender for Cloud Apps not licensed.
Typical findings: AI Hub not configured; AI ethics committee not established; AUP doesn't cover AI tools.
Typical findings: Sensitivity-label coverage at 5-15% pre-assessment; auto-labeling rules not configured; container labels not applied.
Typical findings: BAA execution unverified; supervision program absent; NIST AI RMF mapping not started.
Typical findings: Use cases unidentified; ROI not modeled; persona prioritization absent.
Typical findings: Champion network absent; pilot scope undefined; training plan absent.
90%+ of Fortune 500 tenants have significant oversharing — sites with "Everyone except external users" permissions, OneDrive folders with anonymous links, Microsoft 365 Groups with public membership.
Impact: Microsoft 365 Copilot will surface content the user shouldn't see in practice — HR documents, M&A planning, performance reviews.
Mitigation: Microsoft Restricted SharePoint Search Day 1 + permissions cleanup over 90-180 days.
Most enterprise tenants have 5-15% sensitivity-label coverage on regulated content. For healthcare (PHI), financial services (MNPI), government (CUI), this is a critical gap.
Impact: Restricted-tier protection doesn't function; Microsoft Copilot grounding can surface regulated content.
Mitigation: Microsoft Purview auto-labeling rules + 90-day coverage push to 80%+.
Default Microsoft Purview Audit retention is 90 days. HIPAA, FINRA, SEC, and FedRAMP-regulated tenants require 7-year (or 10-year for SEC Rule 17a-4) retention.
Impact: Audit log gaps prevent compliance attestation.
Mitigation: Microsoft Purview Audit (Premium) license + retention policy update.
Many tenants have Conditional Access policies but they don't enforce required posture for Copilot — MFA exceptions, legacy auth allowed, weak device compliance.
Impact: Copilot accessible from compromised credentials or unmanaged devices.
Mitigation: Conditional Access policy hardening before Copilot rollout.
Most enterprises have no AI literacy training program. Users don't understand Copilot grounding, what data they can prompt with, or compliance obligations.
Impact: Inadvertent compliance violations, low utilization, support burden.
Mitigation: Microsoft Viva Learning required course + acceptable use policy update.
EPC Group offers a 4-week fixed-fee Microsoft Copilot Readiness Assessment that covers all 47 checks above, produces an Architecture Decision Record (ADR), and delivers a 12-month roadmap. See AI Readiness Assessment.
Most gaps remediate in 90-180 days. Critical gaps (oversharing, sensitivity labeling) take longer. EPC Group standard remediation timeline:
Microsoft Restricted Search lets you deploy Copilot to a curated allowlist of sites while permissions cleanup proceeds. This is the recommended approach for most enterprises.
EPC Group standard pattern: Microsoft Restricted Search Day 1 + permission cleanup wave per department. Pilot Copilot to allowlisted sites; expand as cleanup progresses.
EPC Group standard scoring:
Healthcare (HIPAA), financial services (FINRA, SEC), government (FedRAMP, CMMC), and pharma (GxP) have stricter compliance requirements. Domain 6 of the checklist expands to industry-specific requirements.
EPC Group senior architects with combined Microsoft 365, Microsoft Purview, Microsoft Defender, Microsoft Sentinel, and AI governance experience. Errin O'Connor is a 4-time Microsoft Press author.
Schedule a 30-minute Microsoft Copilot Readiness Assessment scoping call at /schedule or call (888) 381-9725. Senior architects (not sales) take discovery calls.
Related reading: AI Readiness Assessment, Copilot for Microsoft 365 Complete Deployment Guide, Microsoft Copilot Governance Framework for Regulated Industries, Microsoft Copilot Adoption Enterprise Playbook, and Microsoft 365 Copilot Security & Data Protection Enterprise Guide.
CEO & Chief AI Architect
Microsoft Press bestselling author with 29 years of enterprise consulting experience.
View Full ProfileAI in the boardroom 2026 — Microsoft 365 Copilot Wave 4, Agent 365, EU AI Act August 2026, and the three questions every director needs to answer about agents in production.
AI GovernanceAI cybersecurity in 2026 — Microsoft Defender Agent Security Posture Management, Sentinel with Copilot for Security, SASE for agents, and the agent-era zero-day playbook for Fortune 500.
AI GovernanceVirtual CAIO in 2026 — fractional Chief AI Officer engagement model, EU AI Act compliance ownership, agent governance, and the five-tier retainer pattern EPC Group runs for clients.
Our team of experts can help you implement enterprise-grade ai governance solutions tailored to your organization's needs.