Frontrow Technology
← All insights & guides
Guide

Copilot adoption

Microsoft 365 Copilot rollout checklist for an Australian business (the order that works, and the step most rollouts skip)

A phase-by-phase checklist for turning Microsoft 365 Copilot on in an Australian business: licence position, identity and audit, the data governance work that has to happen before a single seat is assigned, the Australian privacy layer, launch, and the measurement that decides renewals. Includes the Restricted SharePoint Search retirement and what replaces it.

Daniel Brown · 29 July 2026 · 14 min read

Buying Copilot licences takes about four minutes in the admin centre, and that is the problem. Nothing sits between the purchase and the assignment. A business can have thirty people using Copilot against a tenant nobody has properly reviewed since the migration, and the first sign that something is wrong is a staff member asking an innocent question and getting an answer built out of the payroll folder.

This is the sequence Frontrow works through with Australian clients turning Copilot on properly. It is written as a checklist because that is how it actually gets used: phases in order, each with an owner, each finishing with something you can point at. The order matters more than any individual item on it. Phase 3 is the phase most rollouts skip, and it is the phase that produces the incident.

How to use this checklist

  • Work the phases in order. The single most common failure is assigning licences first and doing the governance work afterwards, at which point the governance work is being done under pressure while people are already using the product.
  • Give each phase one named owner inside the business. A rollout owned by 'IT' in the abstract stalls at the first decision that needs a business answer, such as who is allowed to see the board papers site.
  • Finish each item with evidence: a report exported, a policy published, a setting screenshotted. Six months later, when somebody asks what was done before Copilot went on, the evidence is the answer.
  • For a business of 20 to 100 people this runs comfortably over three to six weeks. Almost all of that time is Phase 3, and almost none of it is technical.

Phase 1: confirm the licence position before you plan anything

  1. 1Confirm the base subscription every intended user is on. Microsoft 365 Copilot is sold as an add-on to other licensing plans and is included in the Microsoft 365 E7 suite. Check the current licence options rather than relying on what was true at the last renewal, because the plan structure has moved more than once.
  2. 2Decide the commitment term before you decide the seat count. An annual term on seats you have not tested is the most common way a Copilot budget gets stranded.
  3. 3Name the first cohort and write down why each person is in it. Document-heavy and meeting-heavy roles produce a clearer signal than a cross-section of the business.
  4. 4Confirm which Office update channel your devices are on, because Copilot capability arrives through it, and a fleet parked on a slow channel will not have the features your launch session demonstrates.
  5. 5Check your network against Microsoft's published Copilot network requirements, particularly if traffic is being inspected or broken out through an appliance.
  6. 6Confirm who holds the SharePoint Administrator role. If nobody in the business does, and the only holder is an outgoing IT provider, resolve that now rather than in Phase 3.

Phase 2: identity and audit, before anything is assigned

Copilot inherits your identity posture exactly as it stands. It does not improve it and it does not compensate for it. Microsoft's own setup guidance puts multifactor authentication, audit logging and conditional access ahead of licence assignment, and that ordering is not decorative.

  1. 1Multifactor authentication enforced for every user, not just administrators, and not just the users in the Copilot cohort.
  2. 2Conditional access policies reviewed against the cohort. Microsoft 365 Copilot supports tenant-level conditional access policies in SharePoint, so a policy that assumes a managed device will carry through to what Copilot can reach.
  3. 3Unified audit logging turned on in the Microsoft Purview portal, with a retention period set deliberately rather than left at whatever the tenant defaulted to. An audit log that only goes back ninety days is not much use to an investigation that starts four months after the event.
  4. 4Administrator roles right-sized. The SharePoint Advanced Management Administrator role includes everything a SharePoint Administrator can do plus the ability to view metadata across SharePoint content and remove permissions at scale, which is a role worth assigning deliberately and to a small number of people.
  5. 5Guest accounts reviewed and the dead ones removed. Every guest still in the directory is a guest whose access Copilot will honour.
  6. 6Break-glass account in place and excluded from conditional access, tested, with the credentials held somewhere that is not the tenant you are locking down.

Phase 3: the data governance step most rollouts skip

Copilot does not grant anybody access to anything. It honours the permissions already in place. What it removes is the friction that used to keep bad permissions harmless. Before Copilot, a folder shared with everyone in the business was technically exposed but practically invisible, because finding it required knowing it existed and knowing where to look. Copilot answers the question directly.

That is the whole risk, and it is not an AI risk. It is a permissions debt that has been accruing since the tenant was built, being called in all at once. The work below is the work that pays it down.

  1. 1Export the top 100 most used sites from the SharePoint admin centre. This is Microsoft's own starting instruction, and it is the right one: the sites people actually use are the sites Copilot will draw on.
  2. 2Run the data access governance site permissions snapshot report. It covers every SharePoint and OneDrive site and surfaces the sites with the broadest access, including those with thousands of users, external guests, or 'Everyone except external users' permissions.
  3. 3Run the 'Shared with Everyone except external users' activity report. It tracks the last 28 days and shows where content has been exposed to every internal user in the organisation, which is the single most common finding in an Australian mid-market tenant.
  4. 4Run the sharing links activity report to see where users have recently created Anyone links, organisation links and specific-people links. This catches oversharing as it happens rather than as history.
  5. 5Deal with OneDrive explicitly. Personal sites hold a surprising amount of the business's real working content, they are in scope for the same reports, and they are the blind spot in most Copilot readiness plans.
  6. 6Apply Restricted Content Discovery to the sites that still need a permissions review, so they stay out of Copilot responses while the review happens.
  7. 7Confirm sensitivity labels behave the way you expect with AI. Where a label applies encryption, Microsoft Purview requires the user to hold the EXTRACT usage right as well as VIEW before an AI app will return the content, so a label configured for viewing only will silently keep content out of Copilot answers.
  8. 8Open Data Security Posture Management for AI in Microsoft Purview and use it as the standing view of what AI is touching, rather than treating readiness as a one-off exercise.
  9. 9Set the cadence now. Microsoft's own recommendation is snapshot reports quarterly and activity reports monthly. Put both in a calendar with a name against them.

Restricted Content Discovery, in practice

  • From the SharePoint admin centre: expand Sites, select Active sites, choose the site, open the Settings tab and turn on 'Restrict content from Microsoft 365 Copilot', then save.
  • A restricted site keeps its permissions exactly as they were. Anyone who already had access still has access directly. What changes is discovery: the site stops surfacing in organisation-wide search and Copilot responses, and users lose the AI entry points on it, including the Copilot button, the AI actions menus and Create pages with AI.
  • It applies to SharePoint sites only. It is not supported for OneDrive, which is why OneDrive has to be handled through permissions and labels rather than through this control.
  • The setting has to propagate across the indexing systems, so it is not instant. Plan the review window around that rather than flipping it the morning of the launch.
  • Microsoft cautions against using it broadly. Restrict too much and Copilot answers get thin and unreliable, which will be read by the business as the product not working.
  • By default only SharePoint administrators can manage it. Delegation to site administrators is a tenant-level switch, which is worth considering only once site owners have been trained on what it does.
"Set-SPOSite -Identity <site-url> -RestrictContentOrgWideSearch $true"

Try it

Check your SharePoint exposure before Copilot goes on

Broad internal sharing, anonymous links and stale guests are the three findings that turn up in almost every tenant that has been running a few years. This gives an initial read before a full review with Frontrow.

Score each dimension · 4 options

Is your tenant ready for Microsoft 365 Copilot?

Copilot is as smart as your tenant is tidy. Twelve quick questions — each mapped to a Microsoft-native capability that closes the gap. Takes about ten minutes.

  • 01

    Anonymous "anyone with the link" shares

    External access

    How does your tenant handle anonymous sharing links?

  • 02

    Tenant-wide / "Everyone except external" site sharing

    Permissions hygiene

    Do you have sites shared with "Everyone" or "Everyone except external users"?

  • 03

    External guest access hygiene

    External access

    How do you manage external guest users in Entra ID?

  • 04

    Site collection admin sprawl

    Identity & privileged access

    How tightly is SharePoint site collection admin access controlled?

  • 05

    Broken permission inheritance

    Permissions hygiene

    How much unique (non-inherited) permissioning exists across your sites?

  • 06

    Orphaned sites with no active owner

    Permissions hygiene

    How do you handle sites whose owner has left or gone inactive?

  • 07

    OneDrive personal sharing patterns

    External access

    Do staff share sensitive documents (HR, finance, contracts) from OneDrive?

  • 08

    Sensitivity label coverage

    Content classification

    How much of your content is classified with Microsoft Purview sensitivity labels?

  • 09

    Restricted SharePoint Search / content discovery controls

    Content classification

    Have you enabled Restricted SharePoint Search or equivalent discovery controls for sensitive sites?

  • 10

    Microsoft Teams / Groups public vs private hygiene

    Permissions hygiene

    How strict is the hygiene on Team / Microsoft 365 Group privacy settings?

  • 11

    Legacy classic SharePoint sites

    Permissions hygiene

    Do you still have classic (pre-modern) SharePoint sites in the tenant?

  • 12

    Access review cadence for sensitive sites + external access

    Identity & privileged access

    How often do you review access to sensitive sites and external user lists?

Phase 4: the Australian layer

None of the Microsoft documentation covers this phase, because it is not a Microsoft problem. Australian privacy obligations apply to personal information the moment it goes into an AI system, and to the output where that output contains personal information.

  1. 1Write the AI use policy before launch, not after the first incident. The OAIC's guidance on commercially available AI products is explicit that organisations should establish policies and procedures for the use of AI systems to support transparency and good privacy governance.
  2. 2Conduct a privacy impact assessment. The OAIC frames this as part of a privacy-by-design approach to adopting AI products, and for a business that handles client health, financial or identity information it is not optional in practice.
  3. 3Update the privacy policy and collection notices with clear information about the use of AI. This is one of the OAIC's stated top takeaways and it is the item Australian businesses most consistently miss.
  4. 4Check the secondary use question. Under APP 6, personal information put into an AI system may only be used or disclosed for the primary purpose it was collected for, unless there is consent or the secondary use would be reasonably expected and is related to the primary purpose. A notice given at collection time is what makes a secondary use reasonably expected.
  5. 5Record that AI output is personal information too. The OAIC's position is that inferred, incorrect or artificially generated information about an identifiable individual, including hallucinations, is personal information and must be handled under the Australian Privacy Principles.
  6. 6Draw the line between the tenant and the open internet. The OAIC recommends as best practice that organisations do not enter personal information, and particularly sensitive information, into publicly available generative AI tools. Staff will not distinguish between a consumer AI chatbot in a browser tab and a licensed in-tenant Copilot unless somebody tells them the difference in plain language.
  7. 7Handle meeting records deliberately. Copilot in Teams meetings works either during and after a meeting, which requires a transcript, or only during the meeting using speech-to-text that is not retained afterwards. Decide which of those is the default for your business, and make sure participants are told when a meeting is being transcribed.
  8. 8Answer the data residency question before a client asks it in a tender. Microsoft publishes Advanced Data Residency as a distinct offering rather than something every tenant already has, so check your actual position instead of assuming it.
  9. 9Align the policy to a recognised framework so the board has something to hold. The National AI Centre's Voluntary AI Safety Standard sets out ten voluntary guardrails, and its Guidance for AI Adoption, published in October 2025, condenses this into six essential practices for safe and responsible AI governance.
  10. 10Read the ACSC material on artificial intelligence alongside it, so the security view and the privacy view of the same rollout are written by the same people at the same time.

Phase 5: assign, enable, and land the habit

Everything up to here is preparation. This phase is where a rollout either becomes a habit or becomes a line item somebody questions at renewal.

  1. 1Assign the cohort's licences in one batch on one day. A trickle of assignments over three weeks produces no shared experience, no peer learning and no clear before-and-after.
  2. 2Run a launch session of about ninety minutes, in person if the business has an office. Demonstrate against the organisation's own documents and meetings, not a Microsoft demo tenant.
  3. 3Give every person three prompts written for their actual job, not a prompt library. Three that work beat fifty that have to be browsed.
  4. 4Tell people what Copilot cannot see. It cannot reach the accounting system, the job management system or the shared drive that was never migrated. Most early disappointment traces back to this, not to output quality.
  5. 5Nominate two or three champions who are respected rather than senior, and give them somewhere to post what worked.
  6. 6Publish the support route on day one. A question that goes unanswered for a week becomes a person who has stopped using the product.
  7. 7Brief meeting organisers separately. Copilot in Teams behaves differently depending on the meeting option chosen, transcription policy sits with the administrator, and turning Copilot off for a meeting also turns off its recording and transcription.
  8. 8Set the review date in the same session, so nobody is surprised when usage data gets looked at.

Phase 6: measure, and be willing to reclaim

  1. 1Use the Microsoft 365 Copilot usage report in the Microsoft 365 admin centre as the factual baseline of who is using what.
  2. 2Use the Copilot Dashboard in Viva Insights for the adoption view across the cohort, which is the one that shows whether use is broad or concentrated in three enthusiasts.
  3. 3At 60 days, identify the seats with no meaningful use and talk to those people before touching the licence. The reason is usually a missing habit, an unsupported workflow or a device problem, and all three are fixable.
  4. 4At 90 days, reclaim the seats that are still unused and reassign them to people on the waiting list. Unused seats are the entire cost problem with Copilot in a small business.
  5. 5Capture two worked before-and-after examples from real work with real time attached. These are what a renewal conversation actually turns on.
  6. 6Re-run the phase 3 reports. Three months of ordinary sharing activity will have produced new exposure, and this is where you find out whether the cadence you set is being honoured.

The five checks worth repeating every quarter

  • The site permissions snapshot report, so you can see the current breadth of access rather than the breadth you signed off on in month one.
  • The 'Everyone except external users' and sharing links activity reports, which show what has changed in the last 28 days.
  • Guest accounts, because project guests outlive the projects that invited them.
  • Site ownership, because a site with a single owner who has left the business has no route to an access decision.
  • Copilot seat usage against the licence count, so the reclaim conversation happens on a schedule rather than in a panic at renewal.

Common questions

Frequently asked

What has to be done before assigning Microsoft 365 Copilot licences?
Three things, in order. Confirm the licence and base subscription position, including whether your plan supports the governance tooling you will need. Get identity and audit right, meaning multifactor authentication for everyone, conditional access reviewed and unified audit logging turned on with a deliberate retention period. Then do the data governance work: export the most used sites, run the data access governance reports, remove broad internal sharing, and restrict discovery on the sites still under review. Assigning licences first and doing this afterwards is the most common cause of a Copilot incident.
Does Microsoft 365 Copilot give staff access to files they could not previously see?
No. Copilot honours the permissions that already exist. What changes is discoverability. A folder shared with everyone in the business was previously exposed but practically invisible, because finding it required knowing it existed. Copilot answers the question directly instead. The risk is not new access, it is permissions debt being called in all at once.
Is Restricted SharePoint Search still an option for a Copilot rollout?
Not for new deployments. Microsoft has marked Restricted SharePoint Search as retiring and states that starting 31 July 2026, new enablement is blocked. It was always positioned as a short-term measure rather than a security boundary, it capped out at 100 sites, and it did not stop users seeing content they owned or had recently accessed. Restricted Content Discovery is the current control, applied per site, and it also removes the AI entry points from restricted sites.
Do we need SharePoint Advanced Management to roll out Copilot safely?
You need the reporting it provides, and most organisations get it as a side effect. Microsoft's prerequisites state that if at least one user is assigned a Microsoft 365 Copilot licence, SharePoint administrators automatically receive SharePoint Advanced Management capabilities to support the deployment. The constraint is the base subscription: Microsoft lists Office 365 E3, E5 or A5, and Microsoft 365 E1, E3, E5 or A5. Microsoft 365 Business Premium is not on that list, which matters because it is the plan most Australian businesses under 300 staff are on. Check your position before planning around it.
What are the Australian privacy obligations when rolling out Copilot?
Privacy obligations apply to personal information put into an AI system and to output that contains personal information. The OAIC's guidance on commercially available AI products asks organisations to conduct due diligence on the product, take a privacy-by-design approach including a privacy impact assessment, establish policies and procedures for AI use, and update privacy policies and collection notices to describe that use clearly. It also notes that under APP 6 personal information may only be used for the primary purpose it was collected for unless consent exists or the secondary use would be reasonably expected, and that inferred or incorrect information generated about an identifiable person is still personal information.
How long does a Copilot rollout take for a business of 50 people?
Three to six weeks is realistic when the tenant is in reasonable shape, and most of that time is the permissions and governance work rather than anything technical. Tenants that have been running for years without a permissions review take longer, because the review keeps finding sites that need a business decision about who should have access. That decision is not an IT decision and cannot be made quickly by IT alone.

The matched next step

Working out where Copilot actually pays for itself?

Frontrow's Copilot readiness review looks at your data hygiene, licensing position and the three or four roles where the numbers stack up first — before you commit to seats for everyone.

Want Frontrow to run this with your team?

A 30-minute call with a senior consultant. No deck. Frontrow walks through your tenant, your priorities and the next sensible move.