An AI-enabled small or medium business on Microsoft 365 is one where staff use the AI already included in the tenant every day, with the data estate secured underneath it. The order of operations: confirm what is licensed, ready the data, pick three use cases, pilot paid seats, set guardrails, then scale into agents.
Most Australian businesses of 10 to 300 people already pay for Microsoft 365, and that subscription already includes an AI chat with enterprise data protection at no additional cost. The gap between owning the licence and running an AI-enabled business is not a software purchase. It is a sequence, and most businesses run it backwards: seats first, permissions later, governance after the first incident. This guide is the sequence in the right order, written so a business can run it internally, stage by stage, with the evidence to show for each one.
What AI does the business already license?
Start with an inventory, because Microsoft ships two distinct levels of AI to a business tenant and most owners only know about the paid one. Every user signed in with a Microsoft Entra account on an eligible Microsoft 365 business plan already has Microsoft 365 Copilot Chat at no additional cost. The paid Microsoft 365 Copilot seat is a separate add-on, and the difference between the two shapes the whole rollout plan.
- Copilot Chat is secure AI chat grounded in the web and powered by current models, with enterprise data protection, indicated by the green shield in the interface.
- It includes file upload, image generation and Copilot Pages on standard access, which means capacity is shared and performance can vary at peak times.
- In Teams and Outlook it runs side by side with the user's open content, so an email thread or document that is already open can be worked on without uploading anything.
- It can reach agents on a pay-as-you-go basis, metered on use rather than licensed per seat.
The boundary matters more than the feature list. Copilot Chat is not grounded in organisational content as part of the chat experience. It reads the web, plus whatever the user gives it: a pasted excerpt, an uploaded file, or the content open beside it in Teams or Outlook. It does not search the tenant. That is what the paid seat buys.
What the paid Microsoft 365 Copilot seat adds
- Chat grounded in work sources: files, meetings, emails and Teams chats. This is the point at which Copilot starts answering questions about the business rather than about the web.
- Copilot inside Word, Excel, PowerPoint, Outlook and Teams, including meeting recap, with drafting and editing in the app rather than beside it.
- The Researcher and Analyst reasoning agents, prebuilt Microsoft agents, and custom agents grounded in tenant data.
- Priority access to capabilities and models, plus admin-side tooling including SharePoint Advanced Management and Copilot Analytics.
On pricing, briefly. For businesses on Microsoft 365 Business plans the add-on is sold as Microsoft 365 Copilot Business, listed on Microsoft's Australian pricing page at $31.40 AUD per user per month excluding GST on an annual term, with a dearer monthly term and a promotional annual price running at the time of writing (checked August 2026). Microsoft also sells Business Standard and Business Premium bundles with Copilot included. The plan structure has moved more than once, which is the kind of navigation Frontrow does with clients weekly, and the checker below reads your current position rather than a remembered one.
Why does the data estate come before the AI?
Because of the design decision that governs everything else: Copilot respects the identity model and permissions already in the tenant, inherits sensitivity labels, applies retention policies and supports audit of its interactions. It grants nobody new access. Which means the AI is precisely as safe as the permissions underneath it, and in most tenants that have been running for a few years, those permissions have drifted.
The classic failure is not a breach. It is a folder shared with everyone in the business years ago, technically exposed and practically invisible, until an AI that answers questions directly removes the invisibility. The fix is a permissions review with a deadline attached, and Microsoft's own tooling does most of the discovery.
- 1Run the site permissions snapshot report from the SharePoint admin centre, under Reports and then Data access governance. It covers every SharePoint and OneDrive site and surfaces the ones with the broadest access, including 'Everyone except external users' permissions.
- 2Run the two activity reports, sharing links and 'Shared with Everyone except external users'. They track the last 28 days and show oversharing as it happens rather than as history.
- 3Fix the HR, finance, legal and executive sites first, replacing broad grants with named groups so nobody loses access they genuinely need.
- 4Apply Restricted Content Discovery to sites still under review. It holds them out of organisation-wide search and Copilot responses without changing anyone's permissions.
- 5Set the cadence Microsoft itself recommends: snapshot reports quarterly, activity reports monthly, each with a named owner.
Try it
Get a read on the oversharing before any AI reads the tenant
Broad internal sharing, Anyone links and stale guests turn up in nearly every tenant more than a couple of years old. Two minutes for an initial picture, ahead of a full review with Frontrow.
Score each dimension · 4 options
Is your tenant ready for Microsoft 365 Copilot?
Copilot is as smart as your tenant is tidy. Twelve quick questions — each mapped to a Microsoft-native capability that closes the gap. Takes about ten minutes.
- 01
Anonymous "anyone with the link" shares
External access
How does your tenant handle anonymous sharing links?
- 02
Tenant-wide / "Everyone except external" site sharing
Permissions hygiene
Do you have sites shared with "Everyone" or "Everyone except external users"?
- 03
External guest access hygiene
External access
How do you manage external guest users in Entra ID?
- 04
Site collection admin sprawl
Identity & privileged access
How tightly is SharePoint site collection admin access controlled?
- 05
Broken permission inheritance
Permissions hygiene
How much unique (non-inherited) permissioning exists across your sites?
- 06
Orphaned sites with no active owner
Permissions hygiene
How do you handle sites whose owner has left or gone inactive?
- 07
OneDrive personal sharing patterns
External access
Do staff share sensitive documents (HR, finance, contracts) from OneDrive?
- 08
Sensitivity label coverage
Content classification
How much of your content is classified with Microsoft Purview sensitivity labels?
- 09
Restricted SharePoint Search / content discovery controls
Content classification
Have you enabled Restricted SharePoint Search or equivalent discovery controls for sensitive sites?
- 10
Microsoft Teams / Groups public vs private hygiene
Permissions hygiene
How strict is the hygiene on Team / Microsoft 365 Group privacy settings?
- 11
Legacy classic SharePoint sites
Permissions hygiene
Do you still have classic (pre-modern) SharePoint sites in the tenant?
- 12
Access review cadence for sensitive sites + external access
Identity & privileged access
How often do you review access to sensitive sites and external user lists?
Which use cases should go first?
Three per role, not ten per business, chosen with one test: the source material already exists, it lives somewhere the AI can see, and the person asking can tell whether the answer is right. Use cases that fail any leg of that test get demonstrated once and abandoned. These are the ones that hold up in Australian businesses of 20 to 100 people, by the role that actually runs them.
Finance
- Interrogating a spreadsheet someone else built. Copilot in Excel works through tables, PivotTables and formulas, and can run in a chat mode that analyses without changing the workbook, which is what makes a finance manager willing to trust it near the model.
- Reducing the month-end pack to the three pages worth reading before the management meeting.
- First drafts of the awkward recurring emails: debtor follow-ups, payment plan confirmations, the note explaining a variance.
Operations
- Meeting recap and actions in Teams, the single most reliable habit in any rollout. It depends on transcription, so the transcription default is a decision to make before launch, and participants should be told when a meeting is being transcribed.
- Turning the document that exists into the document that is needed: site report into client update, scope of works into subcontractor brief.
- Catching up on a Teams channel or a project thread after leave, instead of scrolling three weeks of messages on the first morning back.
Sales
- Summarising the 40-message email thread before the call, then drafting the reply that has been sitting for two days.
- Building the proposal from the last three proposals and the scope document, never from a blank prompt. Generic drafts cost more time than they save; drafts built from the business's own material hold up.
- Rewriting technical content for the buyer's audience, with the author checking it, because the author is the only person who can.
Admin and office
- Email triage: summarising, prioritising and drafting across the inbox, which is where the paid seat's grounding in mail earns its keep.
- Recurring documents: agendas, minutes, standard operating procedures, position ads.
- Finding the document everyone knows exists but nobody can locate, which works exactly as well as the permissions work from the previous stage allows.
Say the limits out loud at launch. Out of the box, Copilot does not see the job management system, the accounting package or the server share that never got migrated. Most week-two disappointment is a user asking about data the AI was never connected to. Those systems can come into scope later, through agents, once the habits exist.
How do you prove value with a small paid pilot?
A pilot proves value only if the before state was measured, so measure it first. Frontrow runs pilots as somewhere between five and 10 paid seats over a quarter, in one cohort rather than scattered across the business, because a cohort produces peer learning and comparable numbers.
- 1Pick one document-heavy or meeting-heavy cohort and write down why each person is in it.
- 2Baseline for a week before assigning anything: minutes spent on meeting notes, first drafts, thread catch-up and report assembly. Rough numbers beat no numbers.
- 3Assign the seats in one batch on one day, run a launch session against the business's real documents, and give each person three prompts written for their actual job.
- 4At 30 days, ask which of the three use cases stuck. Fix devices, habits and missing content before judging the product.
- 5At 60 days, read the Microsoft 365 Copilot usage report in the admin centre alongside the Copilot Dashboard in Viva Insights, which together show whether use is broad or concentrated in two enthusiasts.
- 6At 90 days, capture two worked before-and-after examples with real time attached, reclaim any seat with no meaningful use, and decide the expansion on evidence rather than optimism.
Try it
Size the return before buying the seats
Puts headcount, salary bands and time saved into a defensible number for the pilot decision, rather than a vendor average.
Assumptions
Tune your Copilot business case.
Roles
Live result
$704,668
Net annual benefit
- Active users
- 73
- ROI
- 1788%
- Hours / year
- 8,786
- Payback
- 0.6 mo
- Value saved
- $744,088
- Licence cost
- $39,420
Directional only. Real outcomes depend on licence mix, adoption and which workflows you actually target. Book a review to ground the model against tenant telemetry.
Role-by-role breakdown
| Role | Active | Hours/yr | Value | Licence | Net |
|---|---|---|---|---|---|
| Leadership / Exec | 5 | 920 | $143,000 | $2,700 | $140,300 |
| Managers | 14 | 1,932 | $191,100 | $7,560 | $183,540 |
| Knowledge workers | 42 | 4,830 | $324,187 | $22,680 | $301,507 |
| Sales & client-facing | 12 | 1,104 | $85,800 | $6,480 | $79,320 |
What governance does an SMB actually need?
One page, owned by a named person, written before launch. An Australian SMB does not need an AI committee, a 40-page framework or a risk register with its own risk register. It needs ground rules staff can remember, and answers ready for the day a client asks.
- Which tools are approved: the in-tenant Copilot and Copilot Chat, signed in with the work account. The OAIC's best-practice position is that personal information, particularly sensitive information, should not be entered into publicly available generative AI tools, and staff will not distinguish a consumer chatbot in a browser tab from the licensed tenant version unless the difference is spelled out for them.
- The review rule: nothing AI-drafted leaves the business without a human owner who has checked it and would sign it.
- The meeting rule: the transcription default, who can change it, and the expectation that participants are told.
- What stays out of scope: decisions about people, such as hiring and performance, advice the business carries professional liability for, and any task where the person asking cannot verify the answer.
- Where to ask: the named owner, so a question gets answered in a day instead of becoming a workaround.
The data protection position underneath both Copilot and Copilot Chat is worth stating plainly, because clients ask. Prompts and responses sit under the same Data Protection Addendum terms that cover email in Exchange and files in SharePoint, encrypted at rest and in transit. Prompts, responses and data accessed through Microsoft Graph are not used to train the foundation models. Web queries generated by Copilot go to the search service with user and tenant identifiers removed. That is a stronger position than most software an SMB already runs, and it belongs word for word in the client-facing version of the policy.
Revisit the page quarterly, alongside the permissions reports. Governance that lives in a drawer protects nobody.
When do agents and automation enter the picture?
After the pilot, and only for processes the pilot proved. The order matters: agents amplify whatever workflow and whatever permissions they are built on, so an agent built in month one automates guesswork, and an agent built on an unreviewed tenant automates oversharing.
Copilot Studio is Microsoft's graphical, low-code tool for building agents and agent flows. An agent combines instructions, knowledge sources, tools and triggers, and can be published to Teams, used to extend Microsoft 365 Copilot, or embedded in a website. Agent flows automate the repetitive steps around it. None of it requires a developer, though the agents that earn their keep get built with the same discipline as the pilot: one process, measured before and after.
- A policy and induction agent grounded on the HR library, answering the questions the office manager currently answers 40 times a year.
- A quoting assistant grounded on price lists and the last two years of proposals, drafting for a person to finish.
- An internal service-desk agent in Teams that resolves the password and how-do-I questions and hands the rest to a human.
Copilot Chat's pay-as-you-go agents are the low-commitment way in: metered on use, no per-seat licence, which suits a business that wants one agent for one process before deciding anything bigger. Two guardrails from earlier stages carry forward. An agent grounded on an overshared site inherits the oversharing, and the question of who may create and share agents belongs in the one-page policy, decided before staff discover they can.
The 90-day sequence
The stages above compress into one quarter for a business of 20 to 100 people. The sequence assumes no consultant on site and roughly an afternoon a week of internal effort outside the pilot itself.
- 1Weeks 1 and 2: confirm the licence and plan position, run the site permissions snapshot report, and enable activity report data collection if the tenant lacks SharePoint Advanced Management. Start the baseline measurements.
- 2Weeks 3 and 4: permissions clean-up on the HR, finance and executive sites, Restricted Content Discovery on anything still under review, and the report cadence booked with a named owner.
- 3Week 5: publish the one-page ground rules, decide the meeting transcription default, then launch Copilot Chat to everyone with three approved use cases demonstrated on the business's own documents.
- 4Weeks 6 and 7: pick the pilot cohort, baseline their working week, and buy five to 10 Microsoft 365 Copilot seats on a monthly term rather than an annual commitment on untested seats.
- 5Weeks 8 to 11: run the pilot. Launch session against real work, three prompts per person, champions posting what worked, and the 30-day habit check.
- 6Week 12: read the usage report and the Copilot Dashboard against the seat list, capture two worked examples with time attached, reclaim what sits idle, and decide the expansion.
- 7Week 13: pick the single process the quarter proved and scope one agent for it. Re-run the activity reports, revisit the ground rules, and put the next quarter's reviews in the calendar.
Nothing in the quarter requires software the business does not already pay for until the paid pilot in week seven, and by then the spend is justified by measurement rather than by a demonstration. That is the point of starting from the tenant instead of from a product brochure.