How to Prepare SharePoint for Microsoft 365 Copilot
A safe Microsoft 365 Copilot pilot starts with a known SharePoint access model. This guide gives Microsoft 365 administrators a repeatable process: inventory the tenant, put an owner against each site, reduce broad access, protect records, improve source content and prove the result with test accounts before assigning more seats.
Microsoft says Copilot works inside each signed-in user's existing permissions. Copilot cannot reach a file that the user cannot open.[15] That boundary helps when the permissions express the business need. Old links, oversized groups and forgotten grants make the same boundary dangerous.
Documentation and testing scope
I checked the paths and behaviours below against Microsoft Learn on 11 October 2026. I did not run them in a production tenant. Microsoft changes admin pages often, and licence availability varies by agreement and cloud. Treat every Tenant check as work your administrator must complete before the pilot.
Prerequisites before you touch a site
- Give each pilot user a qualifying Microsoft 365 base plan and a Microsoft Copilot licence. Microsoft lists the eligible business, enterprise, education and government plans on its licence page.[1] Use the Copilot License Details diagnostic against each pilot account before launch.[1]
- Use a SharePoint Administrator or SharePoint Advanced Management Administrator for SharePoint governance work. SharePoint Advanced Management also needs a supported base subscription plus one Copilot licence in the tenant, its Plan 1 add-on, or Microsoft 365 E7. Some features still need the add-on.[3]
- Give licence assignment, Purview and Entra group work to staff with the least privilege for each task. Microsoft lists Groups Administrator or User Administrator for group membership, while the Copilot DLP location accepts several Purview and AI administration roles.[12][17]
- Prepare at least two test identities with different access. Add a third identity with no access to the pilot sites. Use ordinary user accounts with the same Conditional Access rules as the pilot group.
- Name a records manager, security owner and SharePoint owner for decisions. An administrator should not decide that an old contract or case file has lost its business value.
Tenant check: Record the base plan, Copilot licence, administrator role and test-account owner in the rollout log. Stop if any field has no answer.
1. Build a site inventory and freeze the pilot scope
Documentation-verified path: SharePoint admin centre > Sites > Active sites. Add columns for primary administrator, last activity, site creation, storage, template and group connection. Select Export on the command bar to save the current view as CSV.[5]
Keep active and stale sites in one register. A stale site can hold a current record, while a busy site can expose the wrong material. Rank sites with more than one signal: no owner, old activity, external sharing, large audience, broken inheritance, missing label or sensitive subject matter.
Run SharePoint admin centre > Advanced Management > Start assessment. Microsoft's Content Management Assessment looks for oversharing, inactive sites and owner gaps, then lets you repeat the assessment after remediation.[4]
Choose a bounded pilot scope. Include the sites that pilot users need for their jobs, plus several high-risk sites that they should never see. Record every site URL, owner, purpose, last activity date, sharing state, label and pilot decision.
Tenant check: Reconcile the CSV against the Content Management Assessment. Account for each business-facing site, including sites tied to Teams channels. Record exclusions with an owner and review date.
2. Make a person accountable for every site
Documentation-verified path: SharePoint admin centre > Sites > Active sites > select a site > Membership. Review site administrators, owners, members and visitors. For group-connected team sites, review Microsoft 365 group owners as well.[7]
Ask the nominated owner to confirm four facts: the site still serves a business need, the owner list has a backup, the member list matches that need and the sharing model fits the content. A name in the owner field proves nothing until that person accepts the duty.
For scale, use SharePoint admin centre > Site lifecycle management. Open Site ownership policies, Inactive site policies or Site attestation policies. These policies can flag owner gaps, inactivity and sites that need a fresh review of members, permissions and sharing.[4]
Tenant check: Require an owner response for every pilot site. Put sites with no response into the exception queue. Do not grant them a silent pass because a directory entry exists.
3. Audit links, groups and inherited access
Documentation-verified path: SharePoint admin centre > Reports > Data access governance > Site permissions across your organisation > View reports > Create report. The report shows audience size, Entra group grants, broken inheritance, guests, external participants, Anyone links, organisation links, Everyone and Everyone except external users grants.[6]
The first report can take up to five days. Later reports can take 24 hours, the data can lag by 48 hours and Microsoft limits reruns to one each 30 days.[6] Build that delay into the project plan.
Review each risk route:
- Remove anonymous links with no owner or end date.
- Review external guests and specific-people links against a current business sponsor.
- Find organisation links and Everyone except external users grants on material with a narrow audience.
- Expand broad Entra and Microsoft 365 groups. Check nested membership, leavers, role changes and service accounts.
- Inspect files and folders with unique permissions. Restore inheritance when the business wants the parent site's audience.
- For a Teams-connected site, manage membership through its Team or Microsoft 365 group. Private and shared channels have separate SharePoint sites and need their own review.[16]
Review the tenant default at SharePoint admin centre > Policies > Sharing. Microsoft lets you set the SharePoint and OneDrive external-sharing level, guest expiry, domain limits, link defaults and Anyone-link expiry. A site can use a stricter setting than the tenant.[8]
Tenant check: For each pilot user, record the sites and sensitive documents they should see. Record a second list that they must not see. This becomes the access oracle for testing.
4. Remove ROT content without deleting records
Redundant, obsolete and trivial content hurts retrieval, but a cleanup project can also destroy evidence. Put each item into one of four outcomes: keep, supersede, archive or dispose. Give the owner and records manager the decision.
Check retention labels, retention policies, legal holds and record status before deletion. Purview records management can block deletion, control retention and route items through disposition review.[13] Do not strip a label to make cleanup easier.
Use Microsoft 365 Archive for an inactive site that the organisation must retain. Archive preserves content, permissions and metadata, removes user access until reactivation and keeps the site out of Copilot use.[4] For active sites, remove duplicates and drafts after the records check. Keep one approved source and link older material to it when policy requires retention.
Tenant check: Sample deleted and archived decisions with the records manager. Test one restore path. Record who approved each disposal batch and which policy supported it.
5. Improve the documents Copilot will retrieve
Permission cleanup limits risk. Content cleanup improves the answer.
Replace names such as Final_v7_NEW.docx with a title that states the subject, status and period. Put an owner, approval state and review date inside the document. Remove empty templates, abandoned drafts and duplicate PDFs from active libraries. Mark superseded files in the title and body so a reader cannot mistake them for the current version.
Add a small metadata set to important libraries: document type, business owner, status, effective date, review date and sensitivity. SharePoint managed metadata gives sites a shared term set and helps users find content through search and filters.[14] Keep the taxonomy small enough for owners to maintain.
Tenant check: Give a reviewer ten common business questions. Search SharePoint without Copilot and inspect the top results. Fix vague titles, stale copies and missing ownership before the AI test.
6. Add labels and DLP where the risk calls for them
Sensitivity labels need a business rule. Label high-risk files and sites, then test what each audience can open, copy and summarise. A site or group label does not flow down to each file. Label the files when item-level protection matters.[11]
Encrypted content also needs the right usage rights. Copilot needs EXTRACT rights to return protected text. A user with VIEW but no EXTRACT can open the file, while Copilot cannot summarise its contents.[11]
For a Copilot processing rule, use Microsoft Purview > Data Loss Prevention > Policies > Create policy > Custom > Custom policy. On Locations, turn on Microsoft 365 Copilot and Copilot Chat. A rule based on sensitivity labels can stop Copilot from processing matching files and emails, though the result can still cite the item.[12]
Microsoft marks prompt blocking based on sensitive information types as preview. Leave preview controls out of the readiness gate unless your tenant has the feature and your governance body accepts preview behaviour.[12]
Tenant check: Test one public, one internal and one protected document with each test identity. Capture the source citation, response and open-file result. Check DLP after its documented policy delay of up to four hours.[12]
7. Contain unresolved sites with the right control
Restricted Content Discovery can hide a SharePoint site from organisation-wide search and Copilot while an owner fixes access. It leaves permissions intact, does not cover OneDrive and can still allow retrieval of content that a user owns or used in recent work. Microsoft describes it as a temporary control.[9]
Documentation-verified path: SharePoint admin centre > Sites > Active sites > select the site > Settings > turn Restrict content from Microsoft Copilot on > Save.[9]
Use Restricted Access Control when a sensitive site needs a fixed audience. Enable it at SharePoint admin centre > Policies > Access control > Site-level access restriction, then open the site's Settings tab and add the approved Microsoft 365 or Entra groups. A user needs both normal SharePoint permission and membership in a control group.[10]
Tenant check: Test both an allowed and blocked user after search propagation. Keep the site in the exception queue until the owner fixes the underlying permission or confirms the permanent restricted audience.
8. Build the pilot and run permission-aware queries
Create a dedicated security group at Microsoft Entra admin centre > Entra ID > Groups > All groups > New group. Add named owners and members.[17] Choose staff from different business areas and access profiles. Microsoft recommends a small group across business functions before wider deployment.[2]
Assign licences at Microsoft 365 admin centre > Billing > Licences > Microsoft Copilot. Check each user under Users > Active users.[2]
Run the same query pack as three identities: expected access, limited access and no access. Include questions for current policy, old project plans, staff data, commercial terms, an archived site, a protected file and a known organisation link. For every answer, open each citation and score it:
- Correct: the answer uses the approved source and the user should have access.
- False positive: the answer uses stale, duplicate or irrelevant content.
- Overshared: the answer or citation exposes content outside the approved access oracle.
- Inaccessible: Copilot cites a source that the user cannot open.
- Missing: the approved source exists, but Copilot does not use it.
Calculate rates from the test log, not from memory. Divide each failure count by the query count for that identity. Set launch thresholds before testing. Any overshared result should block expansion until the owner removes the access route or signs a dated exception.
Tenant check: Repeat failed prompts after remediation and keep the original evidence. Review Copilot usage reports for adoption, but use the query log for permission and retrieval accuracy.[2]
9. Write rollback and exception handling before launch
Rollback starts with licence removal, then control reversal. Keep the pilot group's membership export, site baseline, label and DLP changes, Restricted Content Discovery list, Restricted Access Control groups and owner approvals in one change record.
For a pilot stop, remove Copilot licences from the pilot group, preserve the test log and review any access finding as a SharePoint issue. Removing a licence does not repair an overshared file. Reverse a new DLP or access control under its change owner's approval, with a reason and a fresh test.
Every exception needs a site, risk, owner, compensating control, approval, expiry date and closure test. An exception without an expiry date becomes the next stale permission.
My recommendation: do not expand the pilot while any known overshared result remains open. False positives can enter a content backlog. Access failures need action before the next licence wave.
Sources: [1] License options for Microsoft Copilot (Microsoft, 2026); [2] Set up Microsoft Copilot and assign licenses (Microsoft, 2026); [3] Prerequisites for SharePoint Advanced Management (Microsoft, 2026); [4] Get ready for Microsoft Copilot with SharePoint Advanced Management (Microsoft, 2026); [5] Customise the SharePoint admin centre site list (Microsoft, 2026); [6] Site permission states snapshot report for SharePoint sites (Microsoft, 2026); [7] Manage sites in the SharePoint admin centre (Microsoft, 2026); [8] Manage sharing settings for SharePoint and OneDrive (Microsoft, 2026); [9] Restrict discovery of SharePoint sites and content (Microsoft, 2026); [10] Restrict SharePoint site access with groups (Microsoft, 2026); [11] Purview considerations for Microsoft 365 Copilot (Microsoft, 2026); [12] Purview DLP for Microsoft 365 Copilot and Copilot Chat (Microsoft, 2026); [13] Records management for documents and emails in Microsoft 365 (Microsoft, 2026); [14] Introduction to managed metadata (Microsoft, 2026); [15] Microsoft 365 Copilot architecture and how it works (Microsoft, 2026); [16] Sharing and permissions in the SharePoint modern experience (Microsoft, 2026); [17] How to manage groups in Microsoft Entra (Microsoft, 2026).
Connect with me on LinkedIn.
A note on the process: I used AI to help with research, drafting and editing. I checked every factual claim against the source material, and the guidance and final judgement are mine.