Microsoft 365 Copilot Readiness: What It Means for Your Organization
Microsoft 365 Copilot, which Microsoft now calls Microsoft Copilot (the work version, signed in with your organization account), answers questions and drafts content using the email, files, chats and meetings each person can already open. It does not create new access. It makes existing access easier to use. If a payroll file or a folder of patient records was shared too widely years ago, Copilot can surface it in seconds. Getting ready means checking who can see what, labeling sensitive information, confirming your licenses and deciding the rules before the tool goes wider. ALCON DTS can help you review your Microsoft 365 environment, fix the sharing gaps and plan a careful pilot.
This page answers:
At a glance
- Product: Microsoft 365 Copilot. Microsoft’s documentation now says “Microsoft 365 Copilot is now named Microsoft Copilot, and Microsoft 365 Copilot Chat is now named Microsoft Copilot Chat.” Some licenses, screens and contract documents (including Microsoft’s Product Terms) may still show the old names during the transition.
- How it sees your data: Copilot “only surfaces organizational data to which individual users have at least view permissions” (Microsoft Learn)
- Licensing: a Copilot license is an add-on to an eligible Microsoft 365 or Office 365 plan. Web-based Copilot Chat is included with eligible plans; work-based chat needs a Copilot license.
- Data protection: use by organizations is covered by the Microsoft Data Protection Addendum and Product Terms, with Microsoft acting as a data processor (Enterprise data protection, Microsoft Learn)
- Training: Microsoft says “Prompts, responses, and data accessed through Microsoft Graph aren’t used to train foundation LLMs”
- HIPAA: Microsoft says Copilot and Copilot Chat “support HIPAA compliance for properly configured implementations,” and that web search queries are not covered by the DPA and Business Associate Agreement. Preview features, third-party models that require the provider to retain data, and agents from other publishers also fall outside or under separate terms
- Official documentation: Data, Privacy, and Security for Microsoft Copilot
- Last reviewed: September 30, 2026
What is Microsoft 365 Copilot readiness?
Copilot works with large language models, your organization’s content in Microsoft 365 (email, chats, meetings and documents) and the Microsoft 365 apps people use every day. When someone asks a question, Copilot grounds the answer in what that person can reach.
That is the whole readiness issue in one sentence from Microsoft: Copilot “only surfaces organizational data to which individual users have at least view permissions.” Microsoft says it is important to use the permission models in Microsoft 365 services such as SharePoint so the right users or groups have the right access to the right content.
Microsoft also says plainly that AI raises the stakes, because “generative AI amplifies the problem and risk of oversharing or leaking data” when content can be surfaced so quickly.
Readiness is the work you do before a wider rollout so Copilot shows each person what they should see, and nothing more.
What does readiness cover, and what doesn’t it?
It covers: who can sign in and with what protection, how files and sites are shared inside and outside the organization, which information is sensitive and how it is labeled, which licenses you hold, how Copilot activity is kept and audited, and the written rules staff follow.
It is not:
- A license purchase. A license turns Copilot on. It does not fix permissions.
- A new lock on your files. Copilot uses the permissions already in place. If a file is overshared today, it is overshared to Copilot too.
- A compliance certificate. Microsoft’s commitments help, but you still decide how Copilot is used with your information and you still carry your legal obligations.
- A reason to stop AI use. The goal is useful AI with business information kept in approved systems.
Does Copilot readiness apply to you?
Readiness matters to any organization that runs its email, files and chats in Microsoft 365 and is using or considering Copilot. It matters most when:
- You hold sensitive information in Microsoft 365. Patient information, HR and payroll files, financial records, legal matters or client work.
- Your sharing has grown without a plan. Company-wide links, sites nobody owns, guests who never left, and folders that stopped inheriting the right permissions.
- Staff already use AI tools. If people are pasting business information into public AI sites, you need rules and an approved option.
Quick check: does this apply to you?
- Your organization uses Microsoft 365 for email, files or chat.
- You are licensed for Copilot, or you are thinking about it, or staff already use Copilot Chat.
If both are true, Copilot readiness very likely applies to you. If you are a HIPAA covered entity or business associate, or you hold other regulated data, talk with your attorney about how your obligations apply to AI use.
What do you need to have in place?
Microsoft’s own deployment guidance for a secure and governed Copilot foundation is organized around three goals: remediate oversharing, set up guardrails and meet regulations. The table below turns those into the readiness areas most organizations work through.
| Readiness area | Why it matters for Copilot | What to look at |
|---|---|---|
| Identity and sign-in | Copilot acts as the signed-in user | Multifactor authentication for everyone, tight administrator roles, prompt removal of departed users, guest accounts reviewed |
| Oversharing and permissions | Copilot can surface anything a user can view | Company-wide sharing links, “anyone with the link” sharing, sites with no owner, broken permission inheritance, overshared sites with sensitive content |
| Sensitivity labels | Labels add protection and are carried into Copilot interactions | A small, clear label set; labels on sensitive sites and files; encryption on the most sensitive labels |
| Data loss prevention | Rules can keep specific sensitive information out of Copilot responses | Policies for the kinds of information you most need to protect |
| Retention and audit | Copilot prompts and responses are stored and can be audited | Retention rules for Copilot interactions, audit logging turned on and reviewed |
| Licensing and settings | Features and controls depend on your plan | Eligible base plan, Copilot licenses for the pilot group, web search setting, which optional AI models and agents are allowed |
| Rules for people | Staff need to know what is approved | An acceptable AI use policy, a pilot group, a way to ask “is this tool approved?” |
How do you find and fix oversharing?
Microsoft’s guidance recommends finding sites that are overshared, have no owner, are inactive or hold sensitive data Copilot could surface, then fixing access. The steps it describes include:
- Run sharing reports. Microsoft’s data access governance reports for sites help identify overshared data, and you can send a site access review to site owners.
- Hold sensitive sites back while you review them. Microsoft offers a site-level setting that limits discovery of content from selected sites in organization-wide search and Copilot responses. Microsoft says it is “designed as a temporary governance control” that buys time to review and right-size access.
- Fix access at the source. Remove excess users, groups and company-wide sharing links, rescope links to approved people, correct broken permission inheritance, and confirm an owner for every site.
- Prevent it from coming back. Restrict company-wide sharing groups and “anyone” links, and use site sensitivity labels to set privacy and sharing by default.
Microsoft says its SharePoint Advanced Management tools, which provide many of these site controls, are included with a Microsoft Copilot license.
How do sensitivity labels work with Copilot?
Sensitivity labels are the names you give to kinds of information, such as Confidential or Patient Information, with protection attached. Microsoft explains:
- Copilot and other supported AI apps do not return data to a user who does not have access to it. Labels add protection on top of permissions.
- When a label applies encryption, a user needs both the view and extract usage rights for Copilot to return that content.
- Copilot honors the encryption and usage rights that labels apply.
Microsoft recommends turning on sensitivity labels for files in SharePoint and OneDrive. Without that setting, the encrypted files Copilot can work with are limited. Start small: a few labels people understand will be used, and a long list will not.
What licenses do you need?
Microsoft sells Copilot as an add-on. Its licensing page lists eligible base plans, including:
- For smaller organizations (Microsoft Copilot Business): Microsoft 365 Business Premium, Business Standard, Business Basic, Apps for Business and Teams Essentials.
- For larger organizations (Microsoft Copilot): Microsoft 365 E5 and E3, Office 365 E5, E3 and E1, frontline plans, and several standalone service plans.
Microsoft also distinguishes two kinds of Copilot Chat. Web-based chat draws on the internet and is included with eligible Microsoft 365 plans at no extra cost. Work-based chat draws on the work information a person can access and needs a Microsoft Copilot license.
Some protections named on this page, such as advanced audit retention and some data governance tools, depend on your plan. Check the current licensing page before you buy.
What does Microsoft commit to?
Microsoft calls its commitments “Enterprise data protection.” They include:
- Use of Copilot by organizations “is covered by the terms of the Microsoft Products and Services Data Protection Addendum (DPA) and Microsoft Product Terms, with Microsoft acting as a data processor.”
- Prompts and responses get the same contractual terms and commitments Microsoft applies to email in Exchange and files in SharePoint.
- “Copilot respects your identity model and permissions, inherits your sensitivity labels, applies your retention policies, supports audit of interactions, and follows your administrative settings. The specific controls and policies will vary depending on the underlying subscription plan.”
- “Prompts, responses, and data accessed through Microsoft Graph aren’t used to train foundation LLMs” (Microsoft Learn privacy page).
Two limits are worth knowing:
- Web search is handled differently. When Copilot searches the web, generated search queries go to the Bing search service, which Microsoft operates under separate terms as an independent controller. Microsoft states that HIPAA compliance “doesn’t apply to web search queries as they aren’t covered by the DPA and Business Associate Agreement (BAA).” In commercial Microsoft 365 environments, web search is available unless an admin turns it off with the “Allow web search in Copilot” policy, so decide that setting before patient information is involved.
- Optional models and agents need a decision. Microsoft offers third-party AI models in Copilot and lets admins decide whether to use them. For most commercial customers outside the EU, EFTA and UK, Microsoft turns some of these models on by default. Microsoft says its Product Terms and Data Protection Addendum apply to those models, with the model provider acting as a Microsoft subprocessor, except models Microsoft labels “with Data Retention,” which are off by default and run under the model provider’s own terms. Admins also control which agents are allowed, and agents from other publishers have their own privacy statements and terms. Decide these settings on purpose, especially if you handle patient information.
How can ALCON DTS help you?
You keep the compliance decisions. We run the controls. You decide which AI tools are approved and who gets them. ALCON DTS can help review your Microsoft 365 environment, close the identity and sharing gaps, help configure retention and audit, help with Copilot licensing, and plan a pilot for the right people first.
Our approach starts with readiness, not a license. As our AI Readiness page puts it, “New AI tools do not create a new lock on your files. They use the permissions already in place.” Our Acceptable AI Use service is the written rulebook that goes with it.
| Readiness area | What ALCON DTS provides |
|---|---|
| Identity and sign-in | Multifactor authentication and enrollment, sign-in rules based on user, device and location (plus sign-in and user risk where you have Microsoft Entra ID P2), least-privilege administrator roles, and joiner, mover and leaver access changes |
| Oversharing and permissions | A review of sharing defaults, guest access, external sharing and permissions for collaboration spaces, with clear ownership for shared content |
| Data loss prevention, retention and audit | Help configuring data loss prevention aligned with how your organization shares, plus retention and audit logs you can produce |
| Devices | Devices kept updated, protected and encrypted, with approved apps |
| Licensing | Help with Copilot licensing: confirming an eligible base plan, right-sizing the licenses you have, and buying Copilot licenses through ALCON DTS for your pilot group first |
| Rules for people | An acceptable AI use rule set with data classes, approved tools, owners and a written exception process |
| Pilot and rollout | A short pilot for the people who should have Copilot first, with the rest of the organization added when the rules and access picture are clear |
The exact work depends on your ALCON DTS plan and any project work, and we will show you what is in place today and what would close a gap. Your EHR, line-of-business platforms and legal obligations stay with their owners. ALCON DTS does not provide legal advice, and turning on Copilot with our help does not make your organization compliant with any law.
Want to know what Copilot would see if you turned it on tomorrow? We will review identity, sharing, devices and data classes in your Microsoft 365 environment and show you what to fix first.
How does Copilot readiness fit with other rules?
- HIPAA. Microsoft lists Microsoft Copilot and Microsoft Copilot Chat among the services in scope for its HIPAA Business Associate Agreement, and says they “support HIPAA compliance for properly configured implementations.” Some parts are not covered. Web search queries are not covered by the DPA and BAA. Microsoft’s Data Protection Addendum says its HIPAA Business Associate terms do not apply to preview features. Some advanced third-party models that require the model provider to retain data are not covered by Microsoft’s DPA at all. Agents from other publishers follow their own terms. HIPAA also still expects your own safeguards: a current security risk analysis (45 CFR 164.308(a)(1)(ii)(A)), access limited to those with access rights (164.312(a)(1)) and audit controls (164.312(b)). Talk with your attorney about patient information and AI use. See our guides on ePHI in Microsoft 365 and the HIPAA security risk analysis, and our HIPAA Consulting service.
- Texas Cybersecurity Safe Harbor (SB 2610, Bus. and Com. Code Ch. 542). A qualifying program must contain administrative, technical and physical safeguards for personal identifying information and sensitive personal information, and be designed to protect against unauthorized access to it (Sec. 542.004(a)). Access and sharing controls that keep Copilot from surfacing sensitive files are part of that picture. See Texas SB 2610 Cybersecurity Safe Harbor.
- Texas duty to protect sensitive personal information (Bus. and Com. Code Sec. 521.052). Businesses must implement and maintain reasonable procedures to protect sensitive personal information. Overshared files that an assistant can surface are worth fixing either way.
- Your own policies and contracts. Client contracts, confidentiality duties and professional rules may limit how information is used with AI. Your acceptable AI use rules should reflect them.
Frequently asked questions
Is Microsoft 365 Copilot the same as Microsoft Copilot?
Can Copilot see files a user cannot open?
Will Microsoft use our data to train its AI?
Do we need sensitivity labels before we turn on Copilot?
Is Copilot covered by Microsoft's HIPAA Business Associate Agreement?
Can we keep some sites out of Copilot while we clean up?
Are Copilot conversations kept?
Should everyone get Copilot on day one?
Sources
- Data, Privacy, and Security for Microsoft Copilot (Microsoft Learn)
- Enterprise data protection in Microsoft Copilot and Microsoft Copilot Chat (Microsoft Learn)
- License Options for Microsoft Copilot (Microsoft Learn)
- Microsoft Purview data security and compliance protections for Microsoft 365 Copilot and other generative AI apps (Microsoft Learn)
- Configure a secure and governed foundation for Microsoft Copilot (Microsoft Learn)
- Secure and Governed Data Foundation for Microsoft Copilot: Foundational Deployment Guidance (Microsoft Learn)
- Copilot controls: security and governance (Microsoft Learn)
- Restrict discovery of SharePoint sites and content (Microsoft Learn)
- HIPAA and the HITECH Act (Microsoft Learn)
- 45 CFR 164.308, 164.312, HIPAA Security Rule safeguards (eCFR)
- Texas Business and Commerce Code, Chapter 542, Cybersecurity Program (Texas Constitution and Statutes)
- Texas Business and Commerce Code, Chapter 521, Unauthorized Use of Identifying Information (Texas Constitution and Statutes)
Last reviewed: September 30, 2026
This page is general information about preparing for Microsoft Copilot and related rules, not legal advice for your situation.
Talk with ALCON DTS about Copilot readiness
Not sure what Copilot would surface in your Microsoft 365 environment, or who should get it first? We will walk through identity, sharing and data classes, show you what is ready and give you a clear plan for the rest.
Email: info@alcondts.com ยท Phone: 512-892-6900

