Two weeks from today, Microsoft 365 Copilot goes generally available for enterprise customers. November 1 has been on the calendar since Microsoft confirmed the date publicly in September, and the pricing — thirty dollars per user, per month, on top of an existing Microsoft 365 E3 or E5 seat, with a three-hundred-seat purchase minimum — has been public since July. None of that is news to anyone reading this. What is new is the call volume: clients who read the GA date and decided they want a Copilot readiness assessment finished before Halloween, not after.
Almost none of those calls open with a question about prompts, plugins, or the Semantic Index. They open with some version of "can it see things it shouldn't." That is the right instinct and the wrong emphasis, because the honest answer has nothing to do with Copilot's model and everything to do with SharePoint and OneDrive permissions that predate Copilot by the better part of a decade. Copilot does not grant access to anything. It respects whatever access your tenant already grants, and then it does something classic SharePoint search never quite managed: it turns scattered, technically-permitted access into one confident, conversational answer, delivered to whoever happened to ask, phrased as if it were fact.
That is the entire readiness problem in one paragraph, and it is why every Copilot engagement we are running this month starts the same way — an oversharing scan, before a single license gets assigned. Buying seats is a purchase order. Fixing permissions is the actual project, and it is the one nobody wants to start first because it does not feel like progress on the thing leadership asked for.
The readiness gate we're actually enforcing
We stopped answering "are we ready for Copilot" with an opinion and started answering it with a gate. No client goes from pilot to a broader rollout until every row below is either done or has a named owner and a date:
| Gate | What "done" looks like | Typical owner |
|---|---|---|
| Oversharing scan complete | Every site shared "Everyone except external users" is inventoried; the highest-risk offenders are re-permissioned or pulled from search | SharePoint admin + security |
| Restricted search scope defined | An interim allow list covers what is safe to surface while remediation continues, with an expiry date | SharePoint admin |
| Label coverage on crown jewels | Finance, HR, legal, and M&A libraries carry a Microsoft Purview sensitivity label with correct permissions attached | Compliance / Purview owner |
| Guest and stale-account cleanup | Microsoft Entra ID access reviews closed; orphaned guest accounts removed | Identity team |
| Pilot cohort named | A specific business process, a named cohort, three success metrics, a start date | Business sponsor + IT |
| Helpdesk script ready | A documented response for "Copilot showed me something I should not have seen" | Helpdesk lead |
None of those six rows mention a model, a plugin, or a prompt library. That is deliberate. The product two weeks from GA is not the risk surface; the eight-to-ten years of default sharing decisions underneath it are.
Running the oversharing scan first
The SharePoint admin center now surfaces what Microsoft is calling oversharing reports — a rundown of sites and libraries with unusually broad sharing, weighted toward the ones with the most content and the most recent activity. It is a reasonable starting point, but we do not wait on the polished report. We run the blunt version the same afternoon a client signs the engagement:
Connect-SPOService -Url https://contoso-admin.sharepoint.com
Get-SPOSite -Limit All -IncludePersonalSite $false |
Where-Object { $_.SharingCapability -eq "ExternalUserAndGuestSharing" } |
Select-Object Url, Owner, StorageUsageCurrent, SharingCapability |
Sort-Object StorageUsageCurrent -Descending
Sort by storage descending, and the top twenty rows are almost always where the real exposure lives — the sites people actually use, not the abandoned ones. On a 4,000-seat healthcare group's Copilot readiness review last month, that query surfaced a clinical-operations library still shared "Everyone except external users" from a project that wrapped up two reorganizations ago, sitting a few clicks from onboarding files with the kind of detail nobody wants a chat answer summarizing for the wrong person. Nobody had opened it in months. Copilot would have opened it in seconds, the moment someone asked a related question.
SharePoint Advanced Management, still a preview add-on license as of this month, adds site access review workflows and sharing-link aging reports on top of this — worth budgeting for once the program is running, not something to wait on before starting the manual pass.
Restricted SharePoint Search as the stopgap, not the fix
Microsoft rolled out restricted SharePoint search this year: an admin center control that lets you define an explicit allow list of sites eligible to appear in org-wide search results, and by extension in whatever Copilot grounds its answers on. Everything outside the allow list stays out of both. For a tenant with a long oversharing tail and a GA date it cannot move, this is the honest stopgap.
It is also, bluntly, a scope reduction dressed up as a control. If a site's permissions are wrong, restricted search hides the symptom from Copilot's index without touching who can still open the document directly by its link. We will turn it on for clients who need the extra two or three weeks, but only with an exit date attached to the remediation plan, in writing, in the same change ticket. A regional bank we advised this quarter wanted to flip the switch and call the readiness project finished. We asked for the exit criteria — the date the allow list gets widened back out as remediation closes gaps. They did not have one until we wrote it into the statement of work ourselves.
Sensitivity labels earn their keep two weeks before GA
Copilot respects Microsoft Purview sensitivity labels the same way it respects folder permissions: encryption tied to a label will keep Copilot from summarizing content for anyone outside the label's permitted audience, provided the label was actually applied. That "provided" is the whole game. Unlabeled sensitive content gets no such check — it is governed only by whatever the underlying library permission happens to say, which loops straight back to the oversharing problem above.
We are pushing every pre-GA client toward mandatory default labeling on finance, HR, legal, and deal-room libraries this month, not after launch. Retrofitting labels once Copilot is in daily use is a slower, more political project than doing the same work now as routine admin hygiene. A quick way to see where a tenant actually stands:
Connect-IPPSSession -UserPrincipalName admin@contoso.com
Get-Label | Select-Object Name, DisplayName, Priority
Get-LabelPolicy | Select-Object Name, Labels, SharePointLocation
Cross-reference the SharePoint locations in each label policy against the site list from the oversharing query above. Any high-value library that shows up in one list and not the other is exactly where an unlabeled document will surface in a Copilot answer with nothing to stop it.
Choosing the pilot cohort deliberately
We talk clients out of two default choices. The executive team is the wrong first cohort — too visible if something goes sideways, and too inclined to trust a confident-sounding answer without checking it. The lowest-stakes team is also wrong, for the opposite reason: it will not touch enough real data or cross enough site boundaries to tell you anything about whether permissions hygiene actually held.
The cohort that earns its seat count is cross-functional, tied to one recurring business process, and touching data of genuinely moderate sensitivity — a sales-operations group preparing proposals, a program office pulling status across several project sites. We ask for three numbers before day one: time saved on a specific weekly task, the count of "wrong or concerning answer" tickets, and adoption rate after thirty days of access. A cohort like that also does something the oversharing scan cannot: its queries cross site and department boundaries in ways a single team's never would, which is exactly when a permission gap the scan missed tends to surface.
Rings still apply. IT and security first, for a few days, with people who know what they are looking for. The named business cohort next, for two to three weeks, with the three metrics tracked from day one. Broader rollout only after that gate review, not on the GA date itself just because the calendar says so.
The $30-a-seat conversation nobody wants to have yet
The three-hundred-seat minimum turns this into real budget fast — thirty dollars a seat, three hundred seats, nine thousand dollars a month before a single pilot metric exists. We have had two clients this month propose buying the minimum block before finishing a single remediation ticket, on the theory that seats purchased during the pre-GA window read well in a board deck. We push back every time. Money spent on licenses sitting on top of unresolved oversharing is money that bought a bigger blast radius, not readiness.
Our sequencing stays the same regardless of how the budget conversation started: close the gate table first, run the smallest pilot the licensing agreement allows, and only commit to the three-hundred-seat purchase once the gate is green and the pilot's three metrics point the right direction. It is a slower way to spend the same money. It is also the difference between a rollout and an incident with a per-seat invoice attached.
If you're facing this
If your GA date is circled on a calendar and the oversharing scan has not started, start there this week — the license purchase order can wait two weeks longer than your permissions cleanup can. We help Microsoft-centric estates sequence Copilot rollouts around permissions, labels, and a pilot cohort that actually proves something, instead of around a purchase order someone already signed. Bring us your SharePoint sprawl and the business process you want to pilot, and we will tell you honestly how many of those six gates you have already cleared.