Data & AI
Preparing Microsoft 365 for AI
Before Copilot creates value it can expose years of neglected permissions. What to fix in your Microsoft 365 estate first.
For organisations invested in Microsoft 365, Copilot is the most immediate route to enterprise AI. It is also the one most likely to surprise, because it does not create a new information estate — it reads the one you already have. Every permission that is too broad, every document shared more widely than intended, every forgotten site with open access becomes newly discoverable the moment an assistant can search across it on a user’s behalf.
This is not a flaw in the technology; it is a consequence of it working as designed. Copilot surfaces information the user already has permission to see. The problem is that in most organisations, permissions have accumulated loosely over many years, and few have ever been tested by a tool this capable of finding things.
Permissions are the first exposure
The single most important preparation is to understand and tighten access. Oversharing that was invisible when finding a document required knowing where to look becomes visible when an assistant can retrieve it in seconds. Before deployment, an organisation should know where sensitive material lives, who can reach it, and whether that access is deliberate.
- Where is sensitive or confidential content stored, and who currently has access to it?
- How much has been shared organisation-wide or via open links that no one remembers creating?
- Are labelling and classification applied consistently enough to control what an assistant can use?
- Which sites and libraries should be excluded from AI discovery entirely?
Copilot does not create a new information estate. It reads the one you already have — including the permissions you have forgotten.
Data quality shapes the experience
Beyond security, the usefulness of Copilot depends on the quality of the content it draws on. Duplicated, outdated and contradictory material produces duplicated, outdated and contradictory answers. A period of information hygiene — retiring stale content, consolidating duplicates, clarifying what is authoritative — materially improves both the safety and the value of what follows.
Identity and governance underneath
Strong identity management, sensible retention, and clear classification are the quiet foundations that make AI safe in this environment. They are unglamorous, and they are frequently where organisations have under-invested. Addressing them before deployment is far cheaper than discovering the gaps through an incident, and it is the difference between an AI rollout that reassures the board and one that alarms it.
Prepare, then deploy
The organisations that get the most from Copilot are not those that deploy it fastest, but those that prepared the ground first. A short, deliberate programme to tidy permissions, improve data quality and confirm governance turns a risky rollout into a confident one — and ensures the value arrives without the surprises.
If this raises a question for your firm, we are always glad to discuss it in confidence.
Book a Confidential Discussion