Microsoft 365How-To & HardeningRetrospectives

Copilot Readiness Checklist: Permissions, Labels and Pilot Groups

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from November 2023, written in 2026 with the benefit of hindsight.

Use this checklist before expanding Microsoft 365 Copilot beyond a pilot.

Licensing and roles

  • Copilot licenses assigned to a defined pilot group.
  • SharePoint Advanced Management available (included with Copilot).
  • Purview capabilities identified by license (E3 vs E5).
  • Admin roles for SharePoint, Purview and Copilot assigned.

Permissions

  • Data access governance reports run (sharing links, EEEU, sensitivity labels).
  • Content management assessment run.
  • Top overshared sites remediated or protected with Restricted Content Discovery.
  • EEEU removed from sensitive sites.
  • Ownerless and inactive sites addressed.
  • Site access reviews completed for high-risk sites.

Labels and DLP

  • Sensitivity labels published and in use.
  • Default and auto-labeling configured for sensitive content.
  • DLP for Copilot policies created for highly confidential labels.

Defaults

  • Default sharing link set to Specific people.
  • Anyone links restricted or disabled.
  • Restricted Access Control applied to business-critical sites.

Monitoring and compliance

  • Audit logging confirmed; Copilot interactions captured.
  • Retention policies for Copilot interactions defined.
  • DSPM for AI reports reviewed.
  • Agents and plugins reviewed in the Microsoft 365 admin center.

Users

  • AI acceptable use policy communicated.
  • Pilot users trained on what Copilot can access.
  • Process for reporting oversharing discovered through Copilot.

Test

  • Pilot users tested prompts for salaries, HR, M&A, passwords and confidential projects.
copilot readiness checklist checklistMicrosoft 365 Copilot GA2023

More on this story