Why “Copilot readiness” is a tenant question, not a licensing question
Microsoft 365 Copilot answers from whatever the signed-in user can reach through Microsoft Graph. That makes readiness a property of the tenant — its identities, its labels, its content estate, its conversations, its data models, its business applications, its infrastructure and its ownership — rather than of the license. A tenant that has never remediated oversharing, never labeled sensitive data and never designed Conditional Access for the accounts that will use Copilot is not made ready by buying the add-on; it is made ready by closing those gaps in the right order. TAR-8 exists to make that order explicit and scorable.
The assessment applies the standard to your tenant with your evidence. Each surface is scored 0–3 against the published rubric, each score is backed by the setting, report or policy that produced it, and each finding is classified as a blocker or a maturity gap so the go-live decision for each population is a fact you can defend to a risk committee, an auditor or a board.
The eight surfaces the assessment scores
Identity
Microsoft Entra ID, Conditional Access, Entra Agent ID — when the AI acts, who is it, and what may it reach?
Sensitive data
Microsoft Purview sensitivity labels, DLP for Copilot, DSPM for AI — does the label still apply inside the prompt and the answer?
Content estate
SharePoint, OneDrive and Exchange data-access governance, Restricted Content Discovery — can you explain every exposure before a model finds it?
Conversations
Teams chats, meetings, transcripts and recordings — retention and meeting policy, governed as data.
Reports and dashboards
Power BI semantic models, Microsoft Fabric, Prep data for AI, Fabric data agents — is the model certified to be answered from?
Business applications and CRM
Dynamics 365, Dataverse, Power Platform, Copilot Studio agents and connector policies — what may an agent change?
Infrastructure and external models
Azure, Microsoft Foundry, private networking, external models behind a governed integration layer — one tenant, several models, one permission model.
Ownership and evidence
The governance operating model, the Agent 365 registry, the audit trail, the vCAIO — who answers when the AI is wrong?
Scoring: 0 — no control; 1 — the control exists but is not applied to the populations Copilot will serve; 2 — applied, with gaps the register names; 3 — applied, evidenced and owned. The full rubric is on the standard’s page.
Cost governance is one of the eight surfaces the assessment scores; the Copilot Credits spending-limit calculator gives the per-user figure the spending policy is written against.
The six deliverables
TAR-8 scorecard
Every surface scored 0–3 on the published rubric, with the evidence behind each score (the setting, the report, the policy) so an auditor or a successor can re-derive it. A 24-point tenant is Copilot-ready on every surface; an 8-point tenant is not ready on any.
Blocker register, ranked against maturity
Every finding classified as a blocker (Copilot must not be enabled for the affected population until it is closed), a maturity gap (enable, then close inside the first quarter) or an observation — with the owning team, the Microsoft control that closes it and the order of work.
Identity and access design
The Conditional Access policy set (multi-factor, device compliance, sign-in and user risk, legacy-authentication block, administrator hardening, BYOD app protection, guest controls) and the Entra Agent ID posture for agents, written as the change requests your identity team will execute.
Sensitivity-label and DLP plan
The label taxonomy for your industry (PHI, MNPI, CUI, clinical-trial or FERPA sub-labels as they apply), the auto-labeling and DLP-for-Copilot rules, the DSPM-for-AI configuration and the coverage target — sequenced before Copilot, not after.
Content-estate exposure report
Oversharing across SharePoint, OneDrive and Exchange found by the tenant's own signals — broken inheritance, anyone links, orphaned sites, external sharing — with Restricted Content Discovery and remediation waves so Copilot never becomes the discovery tool for content nobody meant to share.
Rollout and governance roadmap
Persona use cases from the stakeholder workshops, pilot population, wave sequence, licensing model, the measurement framework and the operating model for surface 8 — who owns each control after the consultants leave. Delivered with a 90-minute executive readout.
Blockers versus maturity score
The scorecard and the blocker register answer two different questions, and conflating them is how most Copilot programs stall. The score says how mature each surface is. The register says what must be true before a given population is enabled. A tenant can score well overall and still carry one blocker that stops the finance department going live — anyone links on a site that holds board packs, say — and a tenant can score poorly on conversations or infrastructure and still enable a pilot population safely, because those surfaces are maturity work for that population rather than blockers.
So every finding in the register carries a classification, the population it affects, the owning team and the Microsoft control that closes it: a Conditional Access policy, a sensitivity label and its DLP rule, Restricted Content Discovery on a set of sites, a Teams retention policy, a semantic-model certification, a connector policy for agents, a private endpoint, or a named owner in the operating model. The roadmap then sequences the blockers by population so the first wave goes live on a defensible date rather than an aspirational one.
Participants, duration, prerequisites
Your executive sponsor; the Microsoft 365 or identity administrator (about two hours a week); the security or compliance lead; a records or legal contact for retention questions; four to six business stakeholders for ninety-minute persona workshops. EPC Group: one senior architect who scopes, leads and presents.
Four weeks single-tenant — inventory and surfaces 1–3, then surfaces 4–7 and the workshops, then the register and designs, then validation and the executive readout. Multi-tenant, multi-geo or hybrid-identity estates are scoped to six weeks, in writing, before work starts.
A named sponsor; read-only administrative access (Global Reader, Security Reader, Compliance Administrator read scopes, Power BI administrator read); an inventory of AI already in use, including consumer tools; current Conditional Access and label exports if they exist; workshop time on the calendar. No licensing change is required to be assessed.
A real deliverable set with the client, tenant identifiers and scores removed: the scorecard with its evidence column, the blocker register, an excerpt of the Conditional Access change requests, the label taxonomy, one page of the exposure report and the first roadmap phase. Walked through on the scoping call; the underlying numbers belong to that client and are not published.
Why EPC Group for this assessment
- The standard is ours. TAR-8 is published in full, with the rubric, so the assessment can be checked against it rather than against a slide.
- Scale on the surfaces that matter. 300+ Copilot initiatives, 6,500+ SharePoint implementations behind the content-estate work, 1,500+ Power BI deployments behind surface 5, 70+ Fortune 500 organizations served.
- Microsoft Solutions Partner holding all six designations, including Security and Modern Work; Microsoft consulting since 1997.
- G2 Leader — seven consecutive quarters (4.4/5 on G2).
- Proof, not logos. Contracted engagement records — purchase orders, statements of work, countersignatures — are published, redacted, in the EPC Group Evidence Center.
- Senior architect on every statement of work — the person who scopes the assessment leads it and presents the readout.
Frequently Asked Questions
What is the Microsoft 365 Copilot Readiness Assessment?
A fixed-scope engagement in which EPC Group scores your Microsoft 365 tenant against TAR-8 — the eight-surface tenant AI readiness standard the firm publishes — and delivers a blocker register ranked against maturity, the identity, labeling and content-estate designs that close the blockers, and a rollout roadmap. It is the commercial form of the standard: the same eight surfaces, scored on the same 0–3 rubric, with the evidence behind every score. EPC Group has led 300+ Copilot initiatives and serves 70+ Fortune 500 organizations.
Who takes part, and how much of their time does it need?
From your side: an executive sponsor (the readout and the go/no-go), the Microsoft 365 or identity administrator (read-only tenant access, roughly two hours a week for four weeks), the security or compliance lead (Purview, DLP and Conditional Access decisions), a records or legal contact for retention questions, and four to six business stakeholders for the persona workshops (ninety minutes each). From EPC Group: a senior architect who leads the assessment end to end and presents the readout — the same person who scoped it.
How long does the assessment take?
Four weeks for a single-tenant enterprise. Week one inventories the tenant and scores surfaces 1–3 (identity, sensitive data, content estate); week two scores surfaces 4–7 (conversations, reports and dashboards, business applications, infrastructure and external models) and runs the persona workshops; week three drafts the blocker register and the designs; week four validates them with your administrators and delivers the readout. Multi-tenant, multi-geo or hybrid-identity estates are scoped to six weeks and the extension is written into the scope before work starts.
What are the prerequisites?
A named executive sponsor; read-only administrative access to the tenant for the assessment period (Global Reader, Security Reader, Compliance Administrator read scopes and Power BI administrator read access — no write access is requested); an inventory of AI already in use, including consumer tools; the current Conditional Access and sensitivity-label exports if they exist; and calendar time for the persona workshops. No licensing change is required to be assessed — the assessment models the Microsoft 365 E3, E5 and Copilot add-on decision rather than assuming it.
What does the redacted sample assessment show?
The sample we walk through on the scoping call is a real deliverable set with the client, the tenant identifiers and the scores redacted: the eight-surface scorecard with the evidence column, a blocker register with the classification, owner and closing control for each finding, an excerpt of the Conditional Access change requests, the label taxonomy page, one page of the exposure report and the first phase of the roadmap. It shows the shape and depth of what you receive; the numbers in it belong to that client and are not published.
What is the difference between a blocker and a maturity gap?
A blocker is a finding that makes Copilot unsafe to enable for an affected population until it is closed — for example, sensitive content reachable through anyone links in a site Copilot can ground on, or no Conditional Access on the accounts that will use it. A maturity gap is a control you should have but can enable Copilot without, provided it is closed in the first quarter — for example, Restricted Content Discovery on a long tail of legacy sites, or a Teams transcript retention policy. The register states which is which, so the go-live decision is a fact, not a feeling.
How does this relate to the eight-surface standard on the insights page?
The insights page publishes the standard — the eight surfaces, the rubric, the 24-point tenant and the 8-point tenant, and the mapping to NIST AI RMF and ISO/IEC 42001. This engagement applies it to your tenant with your evidence. The standard is free to use on your own; the assessment is for organizations that want the scoring done, defended and turned into change requests by an architect who has done it before.
What happens after the assessment?
Three paths, and the roadmap says which fits: your team executes the change requests and enables Copilot in waves; EPC Group runs the remediation and the rollout as a fixed-scope implementation; or the vCAIO retainer takes over surface 8 — the operating model, the agent registry and the quarterly re-scoring — so the score does not decay after go-live. None of the three is required; the deliverables are complete without follow-on work.
Does the assessment cover Copilot Studio agents and Agent 365?
Yes, on surfaces 6 and 8: connector and DLP policies for agents, Entra Agent ID identities, the Agent 365 registry and the shutdown and logging controls an agent needs before it can act on business data. Organizations already building agents can extend the scope with the Copilot Studio agent governance engagement, which goes deeper on approvals, testing and actions.
How is the assessment priced?
Fixed-scope, priced after a scoping call that confirms tenant size, identity model and the number of surfaces already governed; there is no rate card. Microsoft licensing, where the roadmap recommends a change, is quoted at Microsoft list price. Contracted engagement records for comparable work are published, redacted, in the EPC Group Evidence Center.
Related EPC Group services and references
- • TAR-8 — the eight-surface tenant AI readiness standard
- • Microsoft Copilot consulting (hub)
- • Agentic AI governance and Agent 365
- • Copilot Studio agent governance consulting
- • Copilot Studio agent development
- • AI governance consulting
- • Virtual Chief AI Officer (surface 8 as a retainer)
- • Microsoft Entra ID consulting
- • Copilot now reads SharePoint library metadata, and Purview can archive what it should not see — the September 2026 governance checklist
- • Microsoft 365 E7 vs E5 vs E3 comparison
- • EPC Group Evidence Center — contracted engagement records
Book the scoping call
Thirty minutes with the architect who will lead the assessment. You leave with the scope, the participant list, the access request and the redacted sample walkthrough — and a straight answer on whether your tenant is four weeks or six.
Before the October 19 / December 1 cut-overs, read the Copilot usage-based billing defaults on (Oct 19 / Dec 1, 2026): the 12-step spending-policy playbook. For what Microsoft still funds after the September 30 promotions ended, see funded Microsoft 365 Copilot pilots in FY27.
Related reading
- Shadow AI in the Enterprise: Why 67 Unsanctioned Tools Are Breaching Your Tenant
- EPC Group Introduces Copilot and Microsoft 365 Tenant Security Review
- Recommend a Copilot Consulting Firm for Healthcare
- Guide: Top 15 Microsoft 365 Copilot Rollout Mistakes (2026)
- Why Microsoft Copilot Isn't Right for 40% of Enterprises (2026)
