All insights

Tools

13 September 2026
8 min read

Rolling out Microsoft 365 Copilot: a plan for the first ninety days

Microsoft 365 Copilot is the easiest AI assistant to buy and the easiest to waste. It arrives inside the applications people already have open all day, which sounds like adoption solved. In practice a licence appears in someone’s Outlook, they ask it something vague, get something vague back, and never open it again. The licence renews anyway.

The organisations that get value from Copilot treat the rollout as a piece of change work with a technical layer underneath, not the other way round. This is the plan we would put in front of an IT lead and an operations director together: what to fix before day one, who to give seats to first, what to teach in the first fortnight, and the numbers to look at in month three. Everything technical below links to Microsoft’s own documentation, which is good and free.

Before day one: permissions, labels and the tenant

Copilot can only show a person content they already have permission to see. That is the reassuring half of the sentence. The other half is that it will show them all of it, quickly, in a way that browsing SharePoint never did. A folder shared with "Everyone except external users" years ago for convenience becomes an answer in someone’s chat window. Microsoft’s setup guidance is blunt about this and gives you the tools to deal with it before the first licence is assigned.

  1. 1

    Run the permission reports on your busiest sites

    SharePoint Advanced Management can report the permission state of your most-used sites and flag oversharing. Start with the top hundred. You are looking for broad groups with access to HR, finance, legal and board material, and for anonymous or company-wide sharing links on documents that should never have had them.

  2. 2

    Switch off "Everyone except external users" where it should never have been on

    This one group is behind most of the surprises. Microsoft recommends disabling it at tenant level and using Restricted SharePoint Search to limit what Copilot can reach while you clean up, so the rollout does not wait for the tidy-up to finish.

  3. 3

    Apply sensitivity labels to the material that matters

    Copilot honours Microsoft Purview sensitivity labels and the encryption behind them. Label the board pack, the payroll files and anything under client confidentiality first. You do not need a perfect classification scheme on day one; you need the obvious things protected.

  4. 4

    Turn on audit logging and decide your retention

    Copilot interactions can be captured in the Purview audit log. Switch it on before rollout, agree how long you keep it, and tell staff in the one-page usage policy that it exists. Quiet monitoring discovered later does more damage to trust than the tool ever will.

  5. 5

    Check the update channel and MFA

    Copilot needs the Current or Monthly Enterprise update channel for Office, not Semi-Annual, and Microsoft expects multifactor authentication to be on for everyone. Neither is exciting. Both stop a rollout dead if missed.

Who gets the first seats

Not the executive team, not IT, and not the whole company. Copilot licences are expensive enough that the temptation is to hand them to the most senior people as a perk. Senior people have assistants, sit in meetings all day and write short emails; they see the least benefit and set the least useful example.

Give the first thirty to fifty seats to two or three teams whose weeks are heavy with reading, drafting and reporting, and whose manager will use the tool personally. Client service, bids and proposals, finance, HR and operations all qualify. Microsoft’s own adoption guidance recommends a pilot with early adopters and named champions across business groups before broad deployment, and the sequence matters more than the size.

  • Two or three teams, four to twelve people each, with a manager who attends the training and uses Copilot in front of them.
  • One named champion per team who owns the shared prompt library for that team afterwards.
  • A cohort of leaders trained separately, later, on the questions that are theirs: what to fund, what the policy says, how to read the dashboard.
  • A deliberate gap of four to six weeks between the pilot and the second wave, so the second wave learns from what the first one actually used.

What to teach in the first fortnight, by application

Copilot is not one tool. It behaves differently in Outlook, Teams, Word and Excel, and a session that shows the chat window and stops has taught the least useful part. Teach one repeatable workflow per application, on the team’s own material, and write each one down before moving on. These are the four we would build first with most teams.

Outlook: clear a thread you were copied into lateMicrosoft 365 Copilot
Summarise this email thread for me as the person who has just been copied in. Give me: the decision being asked for, who is waiting on whom, any dates or deadlines mentioned, and the one thing I need to do. Keep it under 120 words. Then draft a two-sentence reply that confirms what I will do and by when, in a plain, warm tone, ready for me to edit.

Run it from the Copilot pane on the open thread; no need to paste anything. Good output names the actual decision and the actual owner. If it hedges, the thread itself is unclear, which is worth knowing before you reply.

Teams: turn a meeting recap into actions people will recogniseMicrosoft 365 Copilot
From this meeting, list every action that was agreed as a table with three columns: owner, action in their own words, and the date or trigger mentioned. Mark any action where no owner was named. Below the table, list the decisions made in one line each, and any open questions that were raised but not resolved. Do not add actions that were only discussed as possibilities.

Works on a Teams meeting with transcription on. Good output has owners the room would agree with; the "no owner named" marks are the follow-up the manager needs to make.

Word: a first draft from your own notes and templateMicrosoft 365 Copilot
Using the attached [template document] for structure and headings, and the attached [notes file] for content, write a first draft of the [document type, e.g. client update for the quarter]. Keep every heading from the template. Where the notes do not cover a heading, write [GAP: what is missing] rather than inventing content. Use our house style: short paragraphs, UK English, no exclamation marks, numbers with units. Flag any figure you have taken from the notes with [CHECK] so I can verify it.

Reference both files with the / picker in Copilot in Word. Good output preserves your structure and leaves honest gaps. A draft with no [GAP] or [CHECK] marks is a draft you should trust less, not more.

Excel: understand a sheet someone else builtMicrosoft 365 Copilot
Explain what this worksheet does in plain English for someone who did not build it: what each column means, which cells are inputs and which are calculated, and what the main totals depend on. Then list anything that looks inconsistent: columns with mixed formats, totals that do not match their ranges, or hard-coded numbers where a formula would be expected. Do not change anything.

Data needs to be in a formatted table for Copilot in Excel to work well; select the range and press Ctrl+T first. Good output finds at least one thing you did not know about the sheet.

Notice what is missing from that list: a lesson on prompting. Microsoft’s guidance on Copilot prompts is worth ten minutes, and its four parts (goal, context, expectations, source) are exactly the structure of the prompts above. People learn it by building workflows, not by being taught it first.

Weeks three to twelve: the library, the champions and the second wave

The fortnight after training is where most rollouts quietly end. The fix is a place for the workflows to live and a person who tends it. A SharePoint page per team, with each workflow as a short entry: what it is for, the prompt, what to attach, what good output looks like, who owns it. Microsoft’s Prompt Gallery and Champion Playbook are free and worth raiding for structure, but the entries should be your team’s own.

  • Week three: the champion in each team adds two workflows the training did not cover, from real requests. The library grows or it dies.
  • Week four: a thirty-minute review with each pilot team. What is still in use, what fell away and why, what needs an IT fix rather than a training fix.
  • Weeks five to eight: the second wave of seats, trained by the same method but starting from the first wave’s library rather than a blank page.
  • Week twelve: leadership session. What the dashboard says, what the teams say, what the policy needs to change, and whether to extend licences to the next group or stop.

How to tell whether it is being used

The Copilot Dashboard in Viva Insights and the usage reports in the Microsoft 365 admin centre tell you who has a licence and who has touched Copilot in each application. That is necessary and not sufficient. A licence used once a fortnight to ask what the weather is doing counts as active.

Agree three numbers before the pilot and review them at week four and week twelve: minutes saved per person per week, self-reported against a short list of named tasks; the number of workflows from the library still in weekly use; and the number of people who used Copilot for a real task this week. The first is soft and the other two are hard, and together they tell you more than any single adoption percentage. If none of the three moved by week twelve, take the licences away from that team and give them to one that will use them. That is not failure. That is the point of a pilot.

Questions people ask

Two or three teams with heavy reading, drafting and reporting workloads and a manager who will use the tool personally. Not the executive team, who see the least benefit, and not everyone at once. A pilot of thirty to fifty seats with named champions, followed by a second wave four to six weeks later, is the pattern Microsoft recommends and the one that works.

Oversharing. Copilot surfaces anything a user can already open, so broad groups such as "Everyone except external users" on sensitive sites become visible fast. Run permission reports on your busiest sites, disable that group at tenant level, use Restricted SharePoint Search while you tidy up, and apply sensitivity labels to board, HR, finance and client-confidential material.

Microsoft states that prompts, responses and data accessed through Microsoft Graph are not used to train its foundation models, and that for EU customers Microsoft 365 Copilot is an EU Data Boundary service. Link to Microsoft’s privacy documentation in your policy so staff can read the commitment directly.

Use the Copilot Dashboard and admin centre usage reports for licence and activity data, then add three numbers agreed before the pilot: minutes saved per person per week on named tasks, workflows from the team library still in weekly use, and people who used Copilot for a real task this week. Review at week four and week twelve.

Further reading, all free

Not ready for a call

Tell us what you are trying to do.

A few lines is enough. We will reply by email with whether we can help and roughly what it would take. If a call would answer it faster, we will say so. Nothing to commit to either way.

Or email [email protected]

Used to reply to you. See our privacy notice.