A Microsoft 365 tenant is AI-ready when all eight surfaces an AI model touches — identity, sensitive data, content, conversations, reports, business applications, infrastructure, and ownership — are inventoried, controlled, and evidenced. Copilot readiness is one-eighth of that. TAR-8 scores each surface 0–3, in dependency order, against the artifact an auditor accepts.
By Errin O'Connor, Founder & Chief AI Architect, EPC Group · Published September 11, 2026 · Last updated September 11, 2026
Standard version: TAR-8 v1.0 (September 2026) · Re-verified against Microsoft Learn every 90 days
Key facts
- AI doesn't add a surface to your tenant. It reads all eight at once. Microsoft Copilot, a Copilot Studio agent, a Fabric data agent, or an external model reaching in through a governed integration layer all inherit the same identity, permission, label, and retention state your tenant already has.
- Copilot readiness ≠ tenant AI readiness. Microsoft's Copilot readiness report measures licensing eligibility and usage; it does not score whether Purview labels apply inside a prompt, whether Teams transcripts have a retention policy, whether a semantic model is certified to be answered from, or whether an agent has an identity, an owner, and an expiry.
- The eight surfaces: 1 Identity (Entra) · 2 Sensitive data (Purview) · 3 Content estate (SharePoint, OneDrive, Exchange) · 4 Conversations (Teams) · 5 Reports and dashboards (Power BI, Fabric) · 6 Business applications and CRM (Dynamics 365, Dataverse, Power Platform, Copilot Studio) · 7 Infrastructure and external models (Azure, Microsoft Foundry) · 8 Ownership and evidence (governance, vCAIO).
- Scoring: 0 unknown · 1 inventoried · 2 controlled · 3 evidenced. 24 points. Two gating rules: any surface at 0 means "not ready" regardless of total, and surfaces 1–3 must reach 2 before Copilot is enabled tenant-wide.
- What changed in 2026 (dated in the section below): Copilot in SharePoint became an opt-out preview in mid-June; Restricted SharePoint Search stopped accepting new enablement on July 31; Microsoft Entra Agent ID reached GA in April and every Copilot Studio agent now gets one automatically; Microsoft Agent 365 reached GA on May 1 as the unified agent registry; Purview DSPM (new version) reached GA in May; Anthropic and OpenAI models are selectable inside Microsoft Copilot under Microsoft's subprocessor terms; the EU AI Act's Annex III high-risk deadline moved to December 2, 2027.
- Who this is for: CIOs, CISOs, Microsoft 365 architects, compliance leads, and boards of organizations in healthcare, financial services, government, and other regulated industries — the environments where an auditor will read the architecture.
- EPC Group: founded in 1997, in our 30th year; 11,000+ enterprise engagements; 300+ Copilot initiatives; 300+ AI implementations; 6,500+ SharePoint implementations; 1,500+ Power BI deployments; 500+ Microsoft Fabric projects; a Microsoft Solutions Partner.
Quick facts
| Question | Answer |
|---|---|
| What is TAR-8? | EPC Group's 8-Surface Tenant AI Readiness Standard: a 24-point, evidence-based rubric for whether a Microsoft 365 and Azure environment is ready for Copilot, agents, and external AI platforms. |
| What does it score? | Eight surfaces an AI model reads — identity, sensitive data, content, conversations, reports, business apps, infrastructure, ownership — each 0 (unknown) to 3 (evidenced). |
| How is it different from Microsoft's Copilot readiness report? | Microsoft's report measures license eligibility and usage. TAR-8 measures whether the tenant's controls are enforced and provable across every surface a model touches — for Copilot and for every other model. |
| Which models does it cover? | Microsoft Copilot (native, now multi-model under Microsoft's subprocessor terms), Copilot Studio and Fabric agents, and Claude (Anthropic), OpenAI ChatGPT, Google Gemini, Perplexity, and private models reaching the tenant only through a governed integration layer. |
| What is "ready"? | Every surface ≥1, surfaces 1–3 ≥2 before tenant-wide Copilot, surfaces 4–6 ≥2 before agents take actions, surface 7 ≥2 before any external model, surface 8 continuous. 21–24 = evidenced. |
| What comes out of an assessment? | A scored tenant, a prioritized remediation sequence, and the evidence pack — the artifact per surface an auditor, insurer, or board accepts. |
| Who maintains the standard? | EPC Group, Houston, Microsoft-first since 1997; re-verified against Microsoft Learn every 90 days. |
Why is "Copilot readiness" the wrong unit of measure?
Every readiness checklist published in 2026 scopes to the same three things: licenses, SharePoint oversharing, and Purview labels. They are necessary. They are not the tenant. We documented what Microsoft's own Copilot readiness checklist misses and published a CIO-level AI readiness checklist; TAR-8 is the standard both of those now roll up to.
When a licensed user asks Copilot a question, the answer is assembled from identity (who is asking and under which Conditional Access policy), classification (which labels and DLP rules apply to the prompt and the response), content (which sites, libraries, mailboxes, and files the identity can open), conversation history (Teams chats, transcripts, and recordings the identity can read), reports (which semantic models the identity can query and whether their measures mean what the model thinks they mean), business applications (which records an agent acting for the user may read or change), infrastructure (where the model runs and what it logs), and ownership (who decided any of this and who answers when it is wrong).
A tenant that has "prepared for Copilot" has typically addressed surface 3 and part of surface 2. The incidents come from the other six — the transcript nobody classified, the semantic model nobody certified, the agent nobody owns, the browser tab a model was pasted into.
The unit of measure is the tenant, not the license.
What are the eight surfaces AI reads in a Microsoft 365 tenant?
| # | Surface | What the model touches | The readiness question | Service line |
|---|---|---|---|---|
| 1 | Identity | Who the model is when it acts — human, guest, workload, or agent | Does every AI request run as a known, scoped identity, and can Entra tell a human from an agent? | Identity and Conditional Access |
| 2 | Sensitive data | What the model may read and what it may say back | Is regulated data labeled, and do labels and DLP apply inside AI prompts and responses? | Microsoft Purview |
| 3 | Content estate | Where the model reads from | Can you explain every external and org-wide exposure before a model finds it? | SharePoint · Microsoft 365 |
| 4 | Conversations | What the model overhears | Are Teams chats, meetings, transcripts, and recordings governed as data, not just as UI? | Microsoft Teams |
| 5 | Reports and dashboards | What the model answers numbers from | If Copilot answers from your semantic model, is that model certified to be answered from? | Power BI · Microsoft Fabric |
| 6 | Business applications and CRM | What the model may change | Can an agent update a CRM record or approve a flow — and on whose authority? | Dynamics 365 · Agentic AI governance |
| 7 | Infrastructure and external models | Where non-Copilot models run | Do external and private models reach the tenant only through a governed, logged, private path? | Azure · Azure OpenAI |
| 8 | Ownership and evidence | Who answers for all of it | Can you show governance operating — owners, registry, audit trail — not a policy PDF? | vCAIO · Microsoft Agent 365 |
Surfaces 1–3 are prerequisites for enabling Copilot broadly. Surfaces 4–6 are prerequisites for agents that act. Surface 7 is the prerequisite for any non-Microsoft model. Surface 8 is what keeps the other seven true next quarter.
How is each surface scored? The TAR-8 rubric
| Score | Meaning | Test |
|---|---|---|
| 0 — Unknown | Nobody can say what the state is | No inventory exists, or the last one is older than a year |
| 1 — Inventoried | You know what exists and who owns it | A dated inventory with a named owner; exceptions listed, not fixed |
| 2 — Controlled | The Microsoft control that enforces the decision is configured and active | Policy export shows the control on; exceptions have a reason and an expiry |
| 3 — Evidenced | You can prove the control operated over the period | A report, log, or audit export from the last 90 days, reviewed and signed by the owner |
Bands (24 points): 0–8 exposed · 9–15 inventoried · 16–20 controlled · 21–24 evidenced. Gating rules: any surface at 0 = not ready, whatever the total; surfaces 1–3 must be ≥2 before Copilot is enabled tenant-wide; surfaces 4–6 ≥2 before agents may take actions; surface 7 ≥2 before any external model is connected; surface 8 is scored every quarter.
The score is yours. It is a rubric, not a benchmark — we do not publish "average tenant" numbers because the surfaces that matter differ by industry, and because a rubric that flatters you is not a rubric.
Score your tenant against TAR-8
Score each surface 0–3 using the definitions in the rubric above. Nothing is sent anywhere; the result is encoded in this page's address so you can copy it.
- Surface 1 — IdentityEntra ID · Conditional Access · Entra Agent ID
- Surface 2 — Sensitive dataPurview labels · DLP for Copilot · DSPM for AI
- Surface 3 — Content estateSharePoint · OneDrive · Exchange — DAG reports, RCD
- Surface 4 — ConversationsTeams chats, meetings, transcripts, recordings
- Surface 5 — Reports and dashboardsPower BI semantic models · Fabric · Prep data for AI
- Surface 6 — Business applications and CRMDynamics 365 · Dataverse · Power Platform · Copilot Studio
- Surface 7 — Infrastructure and external modelsAzure · Microsoft Foundry · governed integration layer
- Surface 8 — Ownership and evidenceOwners · Agent 365 registry · audit trail · vCAIO
- Any surface at 0 means the tenant is not ready, regardless of total.
- Surfaces 1–3 must reach 2 before Copilot is enabled tenant-wide.
- Surfaces 4–6 must reach 2 before agents are allowed to take actions.
- Surface 7 must reach 2 before any external model reaches tenant data.
- Surface 8 is scored every quarter; below 2 the other seven decay.
Surface 1 — Identity: when your AI acts, who is it?
AI-ready means every AI request runs as a known, scoped identity — including the identities that are not people. Microsoft Entra Agent ID reached general availability in April 2026; since July 2026 every new Copilot Studio agent receives an Entra agent identity automatically, with no environment-level opt-out. The identity surface is no longer a human-only problem.
| What AI touches | What breaks | Control (feature · status) | Evidence artifact |
|---|---|---|---|
| The policy under which a request is evaluated | Copilot and third-party AI apps outside Conditional Access scope | Conditional Access targeting All resources (Copilot honors CA and MFA) · GA | Get-MgIdentityConditionalAccessPolicy export; CA gap analyzer workbook |
| Agents acting on behalf of users or autonomously | Agents with no identity, no owner, standing privilege | Microsoft Entra Agent ID (blueprints, agent identities, agent user accounts) · GA April 2026; Conditional Access for agents (three templates: block high-risk, autonomous, on-behalf-of) · Agent 365 license required | Entra admin center → Agents → Agent identities export; CA policies with "Agents" assignments; sign-in logs, Agent category |
| Admin roles the AI stack depends on (AI Administrator, Search Administrator) | Standing Global Admin behind an agent | PIM just-in-time activation; Conditional Access enforced on every PIM activation · GA April 2026 | PIM audit history; role eligibility schedule export |
| Guests | Guests who left in 2023 and still have a token | Access reviews for inactive guests; inactive guest report · GA (guest governance billing enforced January 2026) | Access review decisions export; inactive guest report |
| App consent | "Read all files" granted by a user to a shadow AI app | User consent limited to low-impact; admin consent workflow · GA | Get-MgPolicyAuthorizationPolicy; consent-request policy |
| Workload identities | Secrets nobody rotates; service principals nobody owns | Conditional Access for workload identities; ID Protection for workload identities (Workload ID Premium) · GA | Service-principal sign-in logs; risky workload identities report |
| AI traffic at the network edge | Prompts to unsanctioned AI apps; MCP traffic nobody inspects | Entra Internet Access: AI web-content category, Shadow AI discovery, Generative AI Insights (prompt and MCP logging, preview), MCP firewall (preview), prompt injection protection · GA November 2025 | NetworkAccessGenerativeAIInsights and NetworkAccessTraffic tables in Log Analytics or Sentinel |
Score 3 on this surface = the CA export with the AI apps and agents in scope, the PIM log, the consent policy, and a signed identity inventory that lists every agent with an owner, a blueprint, and an expiry.
Surface 2 — Sensitive data: does the label apply inside the prompt?
AI-ready means labels and DLP apply to what the model reads and to what it says back — in Copilot, in agents, and in the AI apps employees actually use. A label that is configured but not enforced at the AI boundary is a sticker.
| What AI touches | What breaks | Control (feature · status) | Evidence artifact |
|---|---|---|---|
| The classification of everything a prompt can reach | Labels applied by hand; the newest documents unlabeled | Sensitivity labels with auto-labeling (new apply/remove flow GA April 2026; simulation mode and Insights tab August 2026) | Get-Label, Get-LabelPolicy; policy configuration export ZIP (GA April 2026); label coverage report |
| Prompts and responses in Copilot | A user asks Copilot to summarize a spreadsheet of SSNs the email DLP policy would have blocked | DLP location "Microsoft 365 Copilot and Copilot Chat" — block labeled files, block sensitive info types in prompts and web grounding; external-sender condition (preview June 2026) · GA | Get-DlpCompliancePolicy / Get-DlpComplianceRule export; DLP activity explorer; audit PolicyDetails on AccessedResources |
| Data pasted or uploaded to non-Microsoft AI | The browser tab | Endpoint DLP for AI sites; Edge for Business AI policies; Network Data Security via Entra Global Secure Access (preview July 2026); DLP for non-Microsoft connected apps (preview August 2026) | Advanced Hunting DeviceInfo.DlpInfo; device health dashboard |
| Posture across all AI apps and agents | Nobody has looked at what AI touched | Purview Data Security Posture Management (new version) — "Prevent data exposure in Copilot interactions," Apps and agents dashboard, AI observability, data risk assessments · GA May 2026 | DSPM reports; Activity explorer "AI activities" tab; Export-ActivityExplorerData |
| Risky AI use by people and by agents | An agent acting on a user's behalf invisible to insider-risk signals | Insider Risk Management templates Risky AI usage and Risky Agents (Copilot Studio and Foundry agents); select which GenAI apps to monitor · GA June 2026 | IRM alerts and cases export |
| Every interaction, for the record | No audit trail of what a model read | Unified audit log CopilotInteraction, ConnectedAIAppInteraction, AIAppInteraction with AccessedResources, SensitivityLabelId, AgentId, ModelProvider / ModelName · GA | Search-UnifiedAuditLog -RecordType CopilotInteraction |
| Retention of AI interactions | Copilot conversations kept forever, or not at all, by accident | Retention locations Microsoft Copilot experiences, Enterprise AI apps, Other AI apps (separate from Teams chats) · GA | Get-AppRetentionCompliancePolicy; eDiscovery "Copilot activity" condition |
| Third-party AI platforms your people already use | Claude, ChatGPT Enterprise, Foundry apps outside Purview's view | Anthropic Claude Enterprise connector (preview May 2026); ChatGPT Enterprise, Foundry, Entra-registered apps; Purview for Agent 365 (GA May 2026) and for Copilot Cowork (GA June 2026) | Data connectors health; DSPM AI observability page |
Score 3 = the label-coverage report, the DLP export with the Copilot and AI-app locations in it, the DSPM report, and the retention policy for AI interactions — dated, owned, reviewed.
Surface 3 — Content estate: can you explain every exposure before a model finds it?
AI-ready means the permission model that Copilot in SharePoint, Copilot in Outlook, and every agent inherits is inventoried at item level, contained where it is dangerous, corrected where it is wrong, and constrained so it cannot regress. Two dated facts make this the surface to start on: Copilot in SharePoint has been an opt-out preview since mid-June 2026 — on by default for every Copilot-licensed user unless an admin scopes it — and Restricted SharePoint Search stopped accepting new enablement on July 31, 2026, so the allow-list stopgap is gone.
| What AI touches | What breaks | Control (feature · status) | Evidence artifact |
|---|---|---|---|
| Every site, library, and item the identity can open | "Everyone except external users" on a finance library; Anyone links from 2019 | SharePoint Advanced Management data access governance reports — permissions baseline, sharing links, EEEU and Everyone at item level (module ≥16.0.27215.12000, April 30, 2026), label snapshot · GA (SAM is included with Copilot licenses) | Start-SPODataAccessGovernanceInsight -ReportEntity EveryoneExceptExternalUsers; report CSV |
| Which sites Copilot in SharePoint reads | Tenant-wide by default | Set-SPOTenant -KnowledgeAgentScope AllSites | IncludeSelectedSites | ExcludeSelectedSites | NoSites · opt-out preview June 2026 | Get-SPOTenant | Select KnowledgeAgentScope |
| High-risk sites during remediation | Correction cannot outrun the deployment date | Restricted Content Discovery (removes Copilot and agent entry points per site; delegable to site admins with justification) · GA | Get-SPOSite | Select RestrictContentOrgWideSearch |
| Sites that should never be broadly open | Sprawl regressing after cleanup | Restricted Access Control; site ownership policy; inactive-site policy; site attestation; Microsoft 365 Archive · GA (SAM) | Policy reports; change history report |
| Content that should be treated as the truth | Copilot grounding on a 2014 policy | SharePoint Authoritative Sites (prioritized in Copilot search) · rolling out from August 11, 2026 | Admin-center authoritative-site flag |
| The agents living in SharePoint | .agent files with their own permissions; abandoned agents | Agent files in Site Assets governed by file permissions; Agent access insights and Agent insights reports · GA | Export-SPOM365AgentAccessInsightsReport; Get-SPOCopilotAgentInsightsReport |
| Mailboxes and delegation | Copilot in Outlook reads what a delegate can read; on-premises mailboxes are not grounded | Full Access / Send As inventory; cloud mailbox requirement · GA | Get-MailboxPermission, Get-RecipientPermission exports; Copilot readiness report |
The sequencing model is Contain → Correct → Constrain: restrict discovery on the worst sites today, fix permissions on your own schedule, then make the defect non-recurring through tenant defaults, RAC at provisioning, and mandatory site labels. The permission checks that precede it are in SharePoint permissions best practices for the enterprise, and the remediation playbook is at fixing SharePoint oversharing before Copilot.
Score 3 = an Exposure Register with no unowned high-risk sites and no company-wide links on labeled content, the RCD and RAC scope lists, and an archive log.
Surface 4 — Conversations: are Teams transcripts governed as data?
AI-ready means chats, channel messages, meeting recordings, transcripts, and the recaps Copilot writes are governed with the same retention, labels, and access boundaries as documents — because to a model, they are documents. No readiness checklist published this year covers this surface; the incidents on it are quiet: a summary of a conversation that was never meant to have one.
| What AI touches | What breaks | Control (feature · status) | Evidence artifact |
|---|---|---|---|
| Whether a meeting is transcribed and whether the transcript persists | Copilot on, transcript retained forever, organizer unaware | Meeting policy Copilot = Disabled / Enabled / EnabledWithTranscript (default; saved transcript required) / EnabledWithTranscriptDefaultOn; organizer option "Only during the meeting" (Copilot without a retained transcript) · GA | Get-CsTeamsMeetingPolicy | Select Identity, Copilot, AllowTranscription, AllowCloudRecording |
| Where recordings and transcripts land and who can open them | Recording in the organizer's OneDrive, shared to the channel, downloadable | Storage in organizer OneDrive or channel SharePoint; expiration (default 120 days); block download; sensitivity label inheritance to MP4 recordings (July 2026) · GA | Retention label policy for recordings; SharePoint and OneDrive audit |
| Sensitive meetings | A board meeting recorded without a label | Sensitivity labels and meeting templates enforce who can record or transcribe and restrict copying of chat and transcript · GA | Label policy export; template inventory |
| Retention of chat and meeting content | "Forever by default" | Retention locations Teams chats, Teams channel messages, Teams call logs (April 2026) — separate from Copilot interaction retention · GA | Get-AppRetentionCompliancePolicy |
| Guests and federated users | A guest in a shared channel asking Copilot about it | External access and trusted organizations; Copilot for B2B members in multi-tenant organizations; Channel Agents non-functional for external users · GA | Get-CsTenantFederationConfiguration |
| The agents inside Teams | Facilitator and Channel Agent created automatically | Built-in Teams agents managed in Teams admin center (July 15, 2026); Channel Agent auto-creation toggle · preview | Agent availability settings; Purview for Channel Agent |
Score 3 = the retention policy export, a storage map for transcripts and recordings, the meeting policy export with the Copilot value per policy, and the external-access report.
Surface 5 — Reports and dashboards: is the model certified to be answered from?
AI-ready means Copilot in Power BI, Copilot in Fabric, and Fabric data agents ground only on semantic models whose security is tested as the user, whose measures are defined, whose endorsement is real, and whose lineage is visible. For fifteen years the control on a bad model was a human reading the report and noticing the number looked wrong. Copilot removed the human.
| What AI touches | What breaks | Control (feature · status) | Evidence artifact |
|---|---|---|---|
| Whether Copilot is on, where, and for whom | On by default on F2 and larger capacities; delegated to capacity admins | Tenant setting "Users can use Copilot and other features powered by Azure OpenAI"; cross-geo processing setting; standalone Copilot setting; "Only show approved items in standalone Copilot" (preview) · GA | Tenant-settings export; Fabric admin REST "List tenant settings" |
| What the model is allowed to answer from | Four models, four definitions of "revenue" | Prep data for AI — AI data schema, verified answers, AI instructions, "Approved for Copilot" flag · preview | Semantic model settings; approved-items list |
| Who sees which rows | RLS wrong, leaked politely | Row-level and object-level security honored by Copilot and data agents · GA | RLS test evidence as the user; Power BI admin API |
| What "certified" means | Promoted by a click, not certified by a signer | Endorsement (promoted → certified) with a named certifier · GA — the Groundable Model Standard (GMS-9) is the certification rubric | Certified-model register |
| Data agents and their sources | Agents routing across sources nobody governs | Fabric data agent: data source routing GA August 2026; Copilot Studio integration GA August 2026 (as a Fabric IQ Data MCP tool); Copilot-in-Power-BI integration and Assistants API retired August 26, 2026 — move to the MCP endpoint | Purview audit CopilotInteraction, App = Fabric Data Agent |
| The semantic layer itself | Meaning living in DAX nobody reads | Fabric IQ (preview workload; ontology preview since November 2025; Plan GA July 2026) · preview | OneLake catalog lineage; ontology bindings |
| Data protection in OneLake | Structured data outside DLP | Purview DLP for structured OneLake data (preview); DSPM for AI for Fabric Copilots and data agents (preview); workspace outbound access protection (preview); networking communication policies admin API (GA September 2026) | Networking policies export; Purview hub in OneLake catalog |
The Fabric capacity and Power BI governance decisions sit under this surface; prep data for AI in regulated industries is the field guide.
Score 3 = a certified-model register with named certifiers, RLS test evidence as the user, and a lineage export.
Surface 6 — Business applications and CRM: what may an agent change?
AI-ready means an agent that can update a record, approve a flow, or email a customer does so under a least-privilege identity, through connector policies, with a registry entry and an approval gate that a human sees when models disagree. This is the surface where AI stops answering and starts acting — and the one no readiness checklist covers.
| What AI touches | What breaks | Control (feature · status) | Evidence artifact |
|---|---|---|---|
| The identity an agent acts under | Agent inherits the maker's role | Copilot Studio auto-creates an Entra Agent ID per agent (July 2026, no opt-out); Dataverse agent users with Entra agent identity and least-privilege security roles · preview June 2026 (GA planned) | Agent inventory fields entraAgentId, entraAgentBlueprintId; security role export |
| Which connectors an agent or flow may reach | A flow moving CRM data to a personal drive in one step | Power Platform DLP connector policies; advanced connector policies; connector inventory (preview) · GA | Get-DlpPolicy; registry "Applied DLP policies" |
| Every agent, app, and flow that exists | Agents nobody owns, acting after their creator leaves | Power Platform inventory (agents, apps, flows, connectors; Azure Resource Graph and Inventory API); Copilot Studio inventory (GA March 31, 2026); quarantine and reassign (preview); registry sync to Microsoft Agent 365 | ARG query export; Agent 365 registry entries |
| Actions that matter | Money moves on one model's opinion | Power Automate approval gates with three states — proceed, fail, contested — the Decision Fabric pattern | Approval-gate flow definitions; action audit log |
| How agents reach tools and data | Unmanaged tool calls | MCP tools in Copilot Studio; Dataverse MCP server (GA December 2025); MCP server certification (preview July 2026); Microsoft MCP Server for Enterprise | PPAC MCP server and allowed-clients configuration; environment telemetry |
| Which models agents use | An external LLM enabled tenant-wide by a maker | PPAC "Allow external LLMs"; primary model selection (Claude Sonnet 5 and GPT-5.5 Chat GA June 2026) · GA | PPAC setting state; audit ModelProvider |
| Copilot inside CRM | Sales Copilot summarizing a regulated account | PPAC Copilot settings per environment group; Entra-group control for Dynamics 365 Sales Copilot and AI agents · GA | PPAC Copilot settings export |
Score 3 = the agent registry, the connector-policy export, the approval-gate flow definitions, and the action audit log.
Surface 7 — Infrastructure and external models: one tenant, five models, one permission model
AI-ready means non-Copilot models — Claude, OpenAI ChatGPT, Google Gemini, Perplexity, and private models — reach tenant data only through a governed, logged, private path, and never through a browser tab and a pasted paragraph. The rule that makes the surface hold: if a user could not open a document yesterday, no model will summarize it for them today. Microsoft Copilot honors that natively; everything else honors it only because the integration layer makes it.
Two 2026 facts change how this surface is designed. First, Microsoft Copilot is now itself multi-model: Anthropic and OpenAI models are selectable inside Copilot and Cowork as Microsoft subprocessors, with tenant, group, and user-level admin controls and a separate opt-in for models with data retention — and the audit log records ModelProvider and ModelName for every interaction. Second, Claude models are generally available hosted on Azure in Microsoft Foundry, which means the "external model" of 2024 can be an in-boundary model in 2026 if it is deployed that way.
| What AI touches | What breaks | Control (feature · status) | Evidence artifact |
|---|---|---|---|
| Where a private or partner model runs | A consumer app with a personal login | Microsoft Foundry (formerly Azure AI Foundry) projects; Foundry Agent Service standard setup with private networking (bring-your-own VNet, storage, search; customer-managed keys; no public egress) · GA | publicNetworkAccess state; private endpoint list; Bicep or Terraform in the repository |
| How it authenticates | API keys in a config file | Entra ID authentication instead of keys; managed identity; Key Vault; disableLocalAuth · GA | disableLocalAuth state; Key Vault access policies |
| What it is allowed to say | No content filters, no prompt-injection defense | Content filters, Prompt Shields, abuse detection; Foundry RBAC (Foundry User / Owner / Project Manager) · GA | Content-filter configuration per deployment; IAM export |
| Which models are in the estate | Nobody knows | Foundry model catalog; Claude Opus 5, Sonnet 5, Haiku 4.5 hosted on Azure (GA); Claude Fable 5.1 on Anthropic infrastructure; billing via Claude Consumption Units · as listed | Deployment inventory; Marketplace subscription |
| AI resources across Azure, AWS, and GCP | Shadow deployments | Defender for Cloud AI security posture management (discovers Azure OpenAI, Foundry, ML, Bedrock, Vertex); AI threat protection · GA; threat protection for AI agents · preview; agent discovery and posture require an Agent 365 license from July 1, 2026 | Defender recommendations export; AI agent inventory |
| Prompts and MCP calls leaving the network | No log of what left | Entra Internet Access Generative AI Insights and MCP firewall (preview); prompt injection protection · GA | Log Analytics tables; SecOps queries |
| Experimental Microsoft features | Frontier agents on for everyone | Microsoft Frontier program setting (default: no access; new Frontier agents only to enrolled users from March 29, 2026) | Frontier setting state |
The reference patterns for a Microsoft-first estate that also runs SAP, Salesforce, Databricks, or Snowflake are published as hybrid-estate integration architectures; the multi-model governance model is at Multi-AI governance, and the employee-side controls at BYOAI and shadow AI governance.
Score 3 = the network diagram, the endpoint inventory, the log-retention proof, and a model-access policy that names every approved model and its path.
Surface 8 — Ownership and evidence: who answers when the AI is wrong?
AI-ready means a named person owns each surface, every agent has a lifecycle, decisions are written down, and the evidence chain — not the policy PDF — is what the board, the auditor, the regulator, and increasingly the insurer receive. Seven surfaces can be inventoried and controlled and it still is not readiness until someone's job is to keep it true.
| What ownership requires | What breaks | Control (feature · status) | Evidence artifact |
|---|---|---|---|
| A control plane for Copilot and agents | Settings changed by whoever was in the admin center | Copilot Control System (Microsoft 365 admin center → Copilot → Settings; data access; allowed agent types; AI providers as subprocessors) · GA | Audit UpdateTenantSettings; tenant health score |
| One registry of every agent | Four inventories, none complete | Microsoft Agent 365 — unified registry, block/reassign/delete, observability; AI Reader, AI Administrator, Agent ID Administrator roles · GA May 1, 2026 (Entra agent-registry blades retired the same day) | All-agents export; governance actions in Purview audit |
| Usage and consumption | Copilot credits and Cowork consumption nobody reconciles | Copilot readiness, usage, and Agents usage reports; Viva Insights Copilot Dashboard and Consumption Dashboard (August 2026) · GA | Graph reports API export |
| A framework mapping the board recognizes | "We have a policy" | Compliance Manager premium templates: EU AI Act, ISO/IEC 42001:2023, ISO/IEC 23894:2023, NIST AI RMF 1.0; automatic assessments synced from Foundry evaluations · GA | Assessment report; audit-ready export |
| Microsoft's own attestations | Nothing to hand the auditor about the platform | Microsoft ISO/IEC 42001 certification (Copilot Studio added to scope in 2026); 2026 Responsible AI Transparency Report | Service Trust Portal certificate |
| Regulatory clock | Planning to the old dates | EU AI Act: GPAI obligations applied August 2, 2025; transparency obligations August 2, 2026; Annex III high-risk moved to December 2, 2027 and Annex I to August 2, 2028 under the Digital Omnibus agreement of May 2026 (formal publication pending at the time of writing) | Compliance Manager EU AI Act assessment |
| Which AI providers your tenant uses | Anthropic models on by default in commercial tenants, off in EU/EFTA/UK | Copilot Control System "AI providers operating as Microsoft subprocessors" — per-user and per-group access (May 19, 2026); data-retention models as a separate opt-in · GA | Setting state; audit ModelProvider |
This is the surface a virtual Chief AI Officer owns — not the technology, the accountability. Three questions, every week: what may AI read, what may AI do, and who answers when it is wrong. The operating model for it is the AI Center of Excellence; the audit posture is AI governance consulting.
Score 3 = a RACI with names, an agent lifecycle with dates, a decision register, the quarterly evidence pack, and a framework mapping.
How do NIST AI RMF and ISO/IEC 42001 map to Microsoft 365 controls?
Most published mappings stop at the framework; this one runs to the control and the artifact, because that is the row an auditor fills in.
| Framework element | TAR-8 surface | Microsoft control | Evidence artifact |
|---|---|---|---|
| NIST AI RMF Govern 1–6 (policies, roles, accountability, inventory) · ISO 42001 5, 6, A.2–A.3 (leadership, roles, AI policy) | 8 | Copilot Control System; Agent 365 registry; Compliance Manager AI templates; Entra Agent ID sponsors | RACI; all-agents export; assessment report |
| NIST Map 1–5 (context, risks, impacts) · ISO 42001 6.1, A.5 (risk and impact assessment) | 2, 8 | Purview DSPM data risk assessments; Insider Risk AI templates; Defender AI-SPM | DSPM report; IRM alerts; Defender recommendations |
| NIST Measure 1–4 (metrics, monitoring, testing) · ISO 42001 9, A.6.2.6 (monitoring, evaluation) | 2, 5, 7 | Purview audit CopilotInteraction and AIAppInteraction; Copilot and Agents usage reports; Foundry evaluations synced to Compliance Manager; Entra GenAI Insights | Audit exports; usage reports; evaluation results |
| NIST Manage 1–4 (risk response, incident, decommissioning) · ISO 42001 8, A.6.2.8, A.10 (operations, incident response, third parties) | 1, 6, 8 | Conditional Access for agents; Agent 365 block/reassign/delete; Copilot Studio quarantine; Entra ID Governance agent lifecycle; approval gates | CA policy export; governance actions log; lifecycle workflow history |
| ISO 42001 A.7 (data for AI systems — quality, provenance, preparation) | 3, 4, 5 | Sensitivity labels and auto-labeling; SAM data access governance; Teams retention; Power BI prep data for AI and endorsement; Fabric lineage | Label coverage; DAG reports; retention export; certified-model register; lineage export |
| ISO 42001 A.8 (information for interested parties — transparency) · EU AI Act Art. 50 | 8 | Responsible AI Transparency Report; Copilot Control System provider settings; user-facing AI notices | Setting state; published notices |
| ISO 42001 A.9 (responsible use) · EU AI Act Annex III preparation (December 2, 2027) | 6, 8 | Human approval gates; decision register; Compliance Manager EU AI Act assessment | Approval-gate definitions; register; assessment |
The full implementation guide is NIST AI RMF on the Microsoft stack; the seven-layer operating framework is Governed AI on Microsoft.
What does a 24-point tenant look like — and an 8-point one?
| Failure mode | Surface | What it looks like | What a 3 looks like instead |
|---|---|---|---|
| Copilot enabled tenant-wide before permissions were inventoried | 3 | A user asks Copilot for "the severance spreadsheet" and gets it | RCD on high-risk sites first; Exposure Register; KnowledgeAgentScope set deliberately |
| DLP policies cover email but not Copilot | 2 | The policy that blocks emailing SSNs does nothing in a prompt | Copilot DLP location in the policy export |
| Transcripts retained forever | 4 | A board discussion summarized for a channel member a year later | Meeting policy value chosen per meeting type; retention on chat and meeting content |
| Four definitions of revenue | 5 | Copilot answers confidently, differently, from each model | One certified model per measure family; verified answers |
| An agent created on a Tuesday | 6, 1 | It still runs after its maker left; nobody can name its owner | Agent ID with a sponsor; Agent 365 registry; lifecycle with an expiry |
| A model in a browser tab | 7 | A paragraph of customer data pasted into a consumer app | Endpoint DLP; Entra Internet Access AI category; an approved in-boundary path |
| "We have an AI policy" | 8 | A PDF from 2024 | A RACI with names, a decision register, and a quarterly evidence pack |
What changed in 2026?
- January — Entra ID Governance guest billing enforced; Copilot Studio enhanced audit logging (preview).
- February 2 — Defender for Cloud threat protection for AI agents (preview).
- March — Copilot Studio inventory in the Power Platform admin center GA (March 31); agent-registry consolidation announced; Frontier agents limited to enrolled users (March 29); Microsoft 365 E7 announced (March 9).
- April — Microsoft Entra Agent ID platform GA; Conditional Access on every PIM activation GA; Purview auto-labeling new flow and policy export ZIP GA; Agent-to-Agent protocol GA in Copilot Studio; SharePoint Add-ins and Azure ACS retired (April 2).
- May 1 — Microsoft Agent 365 GA; Microsoft 365 E7 GA; Entra agent-registry blades retired. Also in May: Purview DSPM new version GA; Purview for Agent 365 GA; Anthropic Claude Enterprise connector (preview); agent sponsorship lifecycle workflows GA; per-user and per-group AI provider access (May 19).
- June — Copilot Cowork GA; Claude Sonnet 5 and GPT-5.5 Chat GA as primary models in Copilot Studio; Conditional Access for agent user accounts (preview); Copilot in SharePoint opt-out preview (mid-June); Purview for Cowork GA; Insider Risk "select GenAI apps" GA.
- July — Copilot Studio auto-creates an Entra Agent ID for every agent (opt-out removed); MCP server certification (preview); Defender agent posture requires an Agent 365 license (July 1); Purview Network Data Security via Global Secure Access (preview); Teams core agents managed in the Teams admin center (July 15); sensitivity-label inheritance to meeting recordings; Fabric IQ Plan GA; Restricted SharePoint Search new enablement blocked (July 31).
- August — Fabric data agents in Copilot Studio GA; data source routing GA; Fabric data agent Copilot-in-Power-BI integration and Assistants API retired (August 26); SharePoint Authoritative Sites rolling out (August 11); Viva Insights Consumption Dashboard; auto-labeling simulation and Insights tab.
- September — Fabric networking communication policies admin API GA; Power Platform release plans replaced by the AI at Work roadmap; Microsoft's 2026 Responsible AI Transparency Report.
What should a tenant prepare for in 2027?
- Agents as first-class principals. Every Copilot Studio agent now has an Entra Agent ID; Conditional Access, Identity Protection, and lifecycle for agents are licensed through Agent 365; agent user accounts — digital workers with mailboxes — are in preview. Surface 1 becomes the largest surface in the tenant.
- MCP and A2A as the standard plumbing. Agent-to-Agent is GA in Copilot Studio; Fabric data agents connect over MCP (the Assistants API is gone); Entra's MCP firewall inspects MCP at the network edge; MCP servers can be Microsoft-certified. Tool access becomes a network-governed object.
- Multi-model Microsoft Copilot. GPT-5.5 and successors, Claude Opus 5, Claude Sonnet 5, and Claude Fable 5.1 are selectable inside Copilot and Cowork under subprocessor terms; "data retention" models are a separate opt-in; the audit log names the model. Model choice is now a tenant setting, an audit field, and a governance decision — not a procurement one.
- Copilot Tuning and organizational models. Tenant-private, ACL-honoring task models are in early access. A fine-tuned model inherits every surface score of the data it was tuned on.
- Microsoft IQ as the semantic layer. Fabric IQ (ontology, plan, graph), Work IQ, and Foundry IQ move meaning out of DAX and into a governed ontology that Copilot Chat, Cowork, and Copilot Studio read. Surface 5's certification question moves up a level.
- Entra Internet Access for AI. Prompt logging with TLS inspection, agent-versus-user traffic rules, and prompt-injection protection at the secure service edge make "which model did that prompt go to" answerable from the network, not the app.
- Purview for agents. Insider Risk "Risky Agents," AI observability for Agent 365, DSPM agents that remediate, and a Claude Enterprise connector: the data-security plane now sees agents as actors.
- Agents on managed endpoints. Windows 365 for Agents, the Conditional Access "agent execution environments" condition, and computer-use agents put an endpoint-management question under surface 7.
- Consumption billing as a governance object. Copilot credits, Cowork consumption, Fabric capacity units for Copilot, Claude Consumption Units in Foundry, and pay-as-you-go insider risk: the finance evidence pack joins the security one.
- The regulatory clock. EU AI Act transparency obligations already apply; Annex III high-risk obligations land December 2, 2027; Compliance Manager templates for the Act, ISO 42001, ISO 23894, and NIST AI RMF are the artifact. Insurers are asking for the same evidence carriers asked for in 2026 — see AI insurance readiness.
Every one of these changes a surface score. None of them changes the eight surfaces.
How do Copilot, Claude, ChatGPT, Gemini, and private models fit into one tenant?
Microsoft Copilot is the native experience and honors Conditional Access, permissions, labels, and DLP directly; in 2026 it is also multi-model, with Anthropic and OpenAI models running as Microsoft subprocessors under the Copilot Control System's provider settings. Copilot Studio agents and Fabric data agents inherit the same controls plus an Entra Agent ID. Claude (Anthropic), OpenAI ChatGPT, Google Gemini, Perplexity, and custom or private LLMs deployed within the Microsoft 365 trust boundary (Azure OpenAI and Microsoft Foundry) reach tenant data only through a governed integration layer — permission-aware retrieval, labels and DLP applied to what is transmitted, logging, and a private network path.
SharePoint and Microsoft 365 permissions determine which information the authenticated user is authorized to retrieve, while EPC Group's governed integration architecture controls what approved context is subsequently transmitted to a selected AI model. The three lanes that implement this — ANALYZE for Power BI, the SharePoint AI Knowledge Mesh, and the Power Automate Decision Fabric — are documented in full.
How long does a TAR-8 assessment take, and what comes out of it?
The assessment is scoped after a discovery call against the tenant's size, the surfaces in scope, and the evidence you already hold; it runs read-only against the reports and exports named in each surface table above and never changes a tenant setting. Three things come out: a scored tenant with the rubric applied per surface and the gating rules called; a remediation sequence in dependency order (containment first, correction on your schedule, constraint before broad rollout); and the evidence pack — the artifact per surface, dated and owned, that a board, an auditor, a regulator, or an insurer accepts.
Start with the self-serve Copilot Readiness Score for surfaces 2 and 3, or request an Enterprise Tenant AI Readiness Review for all eight — the Microsoft 365 Copilot readiness assessment covers surfaces 1–3 as the first, scoped engagement. If the concern is immediate — Copilot is already on and something surfaced — the Copilot Security Review and the Microsoft 365 security hardening checklist come first.
Request the eight-surface review
A scored tenant, a remediation sequence in dependency order, and the evidence pack an auditor, insurer, or board accepts. Read-only against your tenant; nothing is changed.
Frequently asked questions
What is a Microsoft 365 tenant AI readiness assessment?
An assessment of whether a Microsoft 365 and Azure environment can safely support AI — Copilot, agents, and external models — across the eight surfaces a model touches: identity, sensitive data, content, conversations, reports, business applications, infrastructure, and ownership. TAR-8 scores each surface 0–3 against the Microsoft control that enforces it and the artifact that proves it operated.
How do I check if my Microsoft 365 tenant is ready for Copilot?
Score surfaces 1–3 first. If Conditional Access covers Copilot, labels and DLP apply in the Copilot location, and the SharePoint data access governance reports show no unowned high-risk exposure, you can enable Copilot for a scoped group. Microsoft's Copilot readiness report tells you who is licensed; it does not tell you whether the tenant is governed.
What does Microsoft's Copilot readiness report actually measure?
Licensing eligibility, Microsoft 365 app usage, and suggested candidate users. It is an adoption report, not a governance report. It does not evaluate permissions, labels, DLP, retention, semantic models, agents, or external models.
What does Microsoft's Copilot readiness checklist miss?
Teams transcripts and recordings as data; Power BI semantic-model certification and RLS tested as the user; agent identities, connector policies, and approval gates for actions; the path external models take to tenant data; and the evidence artifact per control. Those are surfaces 4–8 of TAR-8.
How do you score AI readiness for a Microsoft 365 tenant?
Eight surfaces, each 0 (unknown), 1 (inventoried), 2 (controlled), or 3 (evidenced), for 24 points. Any surface at 0 means not ready. Surfaces 1–3 must reach 2 before tenant-wide Copilot; 4–6 before agents act; 7 before any external model; 8 is scored quarterly.
Do I need Conditional Access policies for Microsoft 365 Copilot and AI agents?
Yes. Copilot honors Conditional Access and MFA, so a policy targeting all resources covers it; agents need the Conditional Access for agents templates (block high-risk agents, autonomous agents, on-behalf-of agents), which require Microsoft Entra Agent ID and an Agent 365 license.
What is Microsoft Entra Agent ID and do I need it before deploying agents?
Entra Agent ID, generally available since April 2026, gives each agent an identity, a blueprint, an owner (sponsor), and a lifecycle, and lets Conditional Access and Identity Protection evaluate agents as principals. Since July 2026 every Copilot Studio agent receives one automatically, so the question is not whether you have agent identities but whether they are inventoried, sponsored, and scoped.
Are Teams meeting transcripts retained when Copilot is used, and who can access them?
By default the meeting policy value is EnabledWithTranscript, which requires a saved transcript for Copilot to work; the transcript is stored with the meeting and is readable by anyone who can open the meeting's chat and recording. Organizers can choose "Only during the meeting" so no transcript is retained, and retention policies for Teams chats and meeting content govern how long the rest persists.
How do I prepare a Power BI semantic model for Copilot and Fabric data agents?
Test row-level and object-level security as the user, define every measure, complete the Prep data for AI settings (AI data schema, verified answers, AI instructions, "Approved for Copilot"), have a named certifier endorse the model, and confirm lineage in OneLake. The Groundable Model Standard (GMS-9) is the certification rubric.
How do you govern Copilot Studio agents with Power Platform DLP connector policies?
Assign connectors to business, non-business, and blocked groups per environment; use advanced connector policies for action-level control; confirm every agent has an Entra Agent ID and a Dataverse security role of its own; and route high-stakes actions through an approval gate. The Power Platform inventory and the Agent 365 registry are where you prove it.
What evidence do auditors expect for Microsoft 365 Copilot governance?
Exports, not policies: Conditional Access and PIM logs, label and DLP policy exports with the Copilot location, SharePoint data access governance reports, Teams retention and meeting policy exports, the certified-model register, the agent registry with owners, the Foundry network configuration, the Purview audit log of Copilot interactions, and a Compliance Manager assessment against ISO 42001 or NIST AI RMF — each dated, owned, and reviewed within the period.
Sources and verification
- Microsoft Learn — Get started with Copilot in SharePoint (preview)
- Microsoft Learn — Restricted SharePoint Search (retirement)
- Microsoft Learn — Restricted Content Discovery
- Microsoft Learn — Data access governance reports
- Microsoft Learn — Manage access to agents in SharePoint
- Microsoft Learn — What is Microsoft Entra Agent ID
- Microsoft Learn — Conditional Access for agents
- Microsoft Learn — Secure generative AI with Microsoft Entra
- Microsoft Learn — Generative AI Insights (Entra Internet Access)
- Microsoft Learn — Data loss prevention for Microsoft 365 Copilot
- Microsoft Learn — Learn about Data Security Posture Management
- Microsoft Learn — Audit logs for Copilot and AI activities
- Microsoft Learn — Retention policies for Copilot and AI apps
- Microsoft Learn — Insider risk management policy templates
- Microsoft Learn — Manage Copilot in Teams meetings (transcription)
- Microsoft Learn — Teams meeting recording storage and permissions
- Microsoft Learn — Prep data for AI (Power BI)
- Microsoft Learn — Enable Copilot in Fabric
- Microsoft Learn — Fabric data agent security and governance
- Microsoft Learn — What is Fabric IQ
- Microsoft Learn — Copilot Studio: use Entra agent identities
- Microsoft Learn — Power Platform inventory
- Microsoft Learn — Dataverse agent users
- Microsoft Learn — Extend agents with MCP (Copilot Studio)
- Microsoft Learn — Foundry Agent Service networking options
- Microsoft Learn — Claude models in Microsoft Foundry
- Microsoft Learn — Defender for Cloud AI security posture management
- Microsoft Learn — Microsoft Agent 365 overview
- Microsoft Learn — Agent registry convergence
- Microsoft Learn — AI providers operating as Microsoft subprocessors (Anthropic models)
- Microsoft Learn — Copilot Cowork models
- Microsoft Learn — Compliance Manager assessments for AI regulations
- Microsoft Learn — ISO/IEC 42001 offering
- Microsoft Learn — Microsoft 365 Copilot release notes
- Microsoft Learn — Copilot Tuning overview
- Microsoft — 2026 Responsible AI Transparency Report
- Gibson Dunn — EU AI Act Digital Omnibus agreement (May 2026)
- NIST — AI Risk Management Framework 1.0
- ISO — ISO/IEC 42001:2023
Feature status and dates verified against Microsoft Learn on September 11, 2026; re-verified every 90 days. Items marked preview may change before general availability.
