Free technical checklist
Microsoft 365 AI Security and Governance Checklist
The identity, data and governance controls to verify in your tenant before Copilot and agents are switched on.
- 66 verifiable checks
- 37 cited sources
- 81 KB PDF
What this is
Copilot and Microsoft 365 agents inherit the permissions and the data hygiene that already exist in a tenant. Where sharing is loose or labeling is absent, an assistant that can search everything a user can reach will surface that fact quickly and at scale. This checklist walks twelve control areas, each item stating what to verify, why it matters for AI specifically, and where to check it, with a Microsoft Learn reference for every technical assertion.
Who it is for: IT managers, security leads and Microsoft 365 administrators preparing a tenant for Microsoft 365 Copilot, Copilot Studio agents, or any assistant that reads organizational content.
What is inside
- Twelve control areas from Entra ID through to ongoing operations
- Each item states what to verify, why it matters for AI, and where to look
- A Microsoft Learn reference on every technical item, with the date it was verified
- A pre deployment gate listing the items to close before Copilot is enabled
- A short glossary for stakeholders who are not administrators
- Space to record owner, status and date against each item
Contents
- Domain 1. Microsoft Entra ID foundations 6 items
- Domain 2. Conditional Access 5 items
- Domain 3. Least privilege and privileged access 6 items
- Domain 4. Microsoft Purview foundations 5 items
- Domain 5. Information protection 6 items
- Domain 6. Data loss prevention 5 items
- Domain 7. Retention and lifecycle 5 items
- Domain 8. Auditability and monitoring 5 items
- Domain 9. Copilot readiness and oversharing 6 items
- Domain 10. Agent governance 6 items
- Domain 11. Human approval and acceptable use 5 items
- Domain 12. Ongoing operations 6 items
Read a section before you decide
This is the whole of "Domain 9. Copilot readiness and oversharing" as it appears in the document, not a sample rewritten for the web.
Domain 9. Copilot readiness and oversharing
The domain that determines whether switching Copilot on is uneventful. Copilot surfaces only content the signed in user already has permission to access, which is reassuring exactly to the degree that those permissions are correct.
-
The licensing and tenant prerequisites for Microsoft 365 Copilot are met and confirmed rather than assumed.
Why it matters Prerequisites change, and discovering a gap after announcing a rollout date is an avoidable and public failure.
How to verify Check the current requirements article against the tenant configuration.
Microsoft documented. Sources are cited in the document.
-
Data access governance reports have been run and the sites with broad access have been remediated.
Why it matters These reports name the sites shared with everyone, shared anonymously, or shared widely. This is where oversharing stops being a theory and becomes a list.
How to verify SharePoint admin center, run the data access governance reports and work the list.
Microsoft documented. Sources are cited in the document.
-
Restricted Content Discovery is applied to sites that must stay out of Copilot results.
Why it matters Some sites hold content that specific people legitimately need and that should not be surfaced through search or an assistant. This is the control for that case.
How to verify Review Restricted Content Discovery configuration against a list of sensitive sites agreed with the business.
Microsoft documented. Sources are cited in the document.
-
Restricted Access Control is used where site membership itself should be constrained.
Why it matters It limits access to a defined group regardless of individual sharing, which is what stops a well meaning share reopening a closed site.
How to verify Review Restricted Access Control policy on the sites identified as sensitive.
Microsoft documented. Sources are cited in the document.
-
Default external sharing settings have been reviewed at both tenant and site level.
Why it matters SharePoint defaults to the most permissive sharing option, so an unreviewed tenant is permissive by inheritance rather than by decision.
How to verify SharePoint admin center sharing settings, tenant level then per site, particularly sites created before any review.
Microsoft documented. Sources are cited in the document.
-
A site lifecycle policy handles inactive sites so the estate stops growing unowned.
Why it matters Oversharing remediation is a one off project unless something prevents the estate regenerating the problem.
How to verify Confirm inactive site policy is configured and that site owners receive and act on the attestations.
Microsoft documented. Sources are cited in the document.
Download your free copy
Get the complete document below. No registration is needed.
Download M365 AI Security and Governance Checklist (PDF, 81 KB)