Microsoft Copilot readiness is the question NZ businesses keep skipping. Copilot answers staff questions using everything their accounts can access across SharePoint, OneDrive, Teams and email, which means it is only as safe as the permissions underneath it. Switch it on before checking those permissions and the salary spreadsheet nobody was meant to find becomes one prompt away.
This guide is for general managers and operations managers at NZ firms of 18 to 110 plus users. It covers what a Copilot readiness assessment involves, why oversharing is the risk that matters, what Copilot costs, how to prepare your tenant and how to run a pilot that proves value. OxygenIT is a Christchurch based Microsoft partner, operating since 2005 and certified to ISO 42001 for AI management, which is still rare for an MSP.
What is a Microsoft Copilot readiness assessment?
A Microsoft Copilot readiness assessment is a structured review of your Microsoft 365 tenant before Copilot licences are switched on. It measures who can access what across SharePoint and OneDrive, finds oversharing, checks data classification, DLP and licence prerequisites, and ends with a remediation plan and a designed pilot group.
The reason it comes first is simple: Copilot does not create new access, it exploits existing access at machine speed. A readiness assessment answers five questions. Which sites and files are shared more widely than intended? Where does sensitive data actually live? Are the licence and identity prerequisites in place? What governance policies exist for staff AI use? And who should pilot Copilot, measuring what?
The output should be a decision, not a document. A good assessment lands as a prioritised remediation list, a fixed cost to close the gaps and a pilot plan with named users and metrics. It is the same discipline we apply in our broader AI readiness assessment, narrowed to the Microsoft 365 estate Copilot will draw on.
Why is oversharing the number one Copilot risk?
Oversharing is the number one Copilot risk because Copilot can only surface what a user can already access, and in most tenants that is far more than anyone realises. Default sharing links, organisation wide groups and years of ad hoc permissions mean Copilot answers can quote documents staff were never meant to read.
The mechanics are mundane. A SharePoint link created as “People in your organisation” quietly grants the whole company access. A Teams site from 2021 still holds a salary review spreadsheet. A board pack sits in a folder inherited by an “Everyone except external users” group. None of this surfaces day to day, because nobody goes looking. Copilot goes looking. It is the best search engine your business has ever had, pointed at every permission mistake you have ever made.
Microsoft knows this is the failure mode, which is why SharePoint Advanced Management ships Data Access Governance reports that list overshared sites, org wide links and sites holding sensitive content. Running those reports is the first concrete step of any readiness engagement, and the results are consistently sobering.
The wider evidence says governance, not technology, is where AI projects fail. Gartner predicts that “by 2027, 60% of organisations will fail to realise the anticipated value of their AI use cases due to incohesive ethical governance frameworks.” For a 40 person Kiwi firm, that governance gap starts with who can open which folder.
What does Copilot cost in NZ?
Microsoft 365 Copilot costs around NZ$45 per user per month, on top of an eligible base plan such as Business Standard, Business Premium, E3 or E5. For a 30 person firm that is roughly $16,000 a year at full rollout, which is exactly why readiness work and a small pilot come first.
The licence is only the visible cost. The expensive failure modes are the invisible ones: a privacy incident because Copilot surfaced personal information to the wrong staff member, or a company wide rollout where most licences sit unused because nobody was trained and no use cases were agreed. Both are avoidable for less than the cost of getting them wrong.
We keep the spend staged: readiness assessment first, three to five pilot licences next, and expansion only once the pilot numbers justify it. For the full pricing picture, our guide to what Copilot does, what it costs and whether it is worth it for NZ SMBs breaks down the licence maths in detail.
How do you prepare a Microsoft 365 tenant for Copilot?
Preparing a tenant for Copilot means closing access gaps before switching on AI. The core steps are running Data Access Governance reports, applying Restricted Access Control to sensitive sites, deploying sensitivity labels, enabling Purview DLP policies and starting with a pilot of three to five users rather than a company wide rollout.
If you are researching how to prepare for Microsoft Copilot, this checklist is the practical sequence. Microsoft includes SharePoint Advanced Management with Copilot licences, so the tooling for the first three rows is already paid for.
Copilot readiness checklist
| Step | What it does | Where it lives |
|---|---|---|
| 1. Run Data Access Governance reports | Finds sites shared with everyone and links open to the whole organisation | SharePoint Advanced Management |
| 2. Fix default sharing links | Changes new links from organisation wide to specific people | SharePoint admin centre |
| 3. Apply Restricted Access Control | Locks HR, finance and board sites to named security groups | SharePoint Advanced Management |
| 4. Deploy sensitivity labels | Classifies documents so confidential content is marked and protected | Microsoft Purview |
| 5. Turn on data loss prevention | Stops sensitive content moving where it should not, including through Copilot | Microsoft Purview |
| 6. Archive stale sites | Removes dead SharePoint sites from the content Copilot draws on | Inactive site reports and owner review |
| 7. Confirm licences and prerequisites | Eligible Microsoft 365 plan, Entra ID accounts and OneDrive provisioned | Microsoft 365 admin centre |
| 8. Write an AI acceptable use policy | Sets what staff may and may not put into prompts | Your governance framework |
| 9. Choose the pilot group | Three to five users across roles, with metrics agreed up front | Pilot plan |
Steps one to three remove the worst exposure within days. Steps four and five take longer and can run alongside the pilot, provided the pilot group works on sites already reviewed. This tenant hardening is the same work we do inside our Microsoft 365 optimisation service, so none of it is wasted if you decide Copilot can wait.
What does a Copilot pilot look like?
A good Copilot pilot runs for 30 days with three to five licensed users drawn from different roles. Each user tracks time saved, output quality and prompt use every week, while the tenant is monitored for oversharing incidents. At the end you have real numbers to decide whether to scale.
The structure matters more than the size. Week one is training and a short list of agreed use cases per role: the operations manager drafting client updates, the finance lead summarising supplier contracts, the GM preparing meeting packs. Weeks two and three are measured daily use. Week four is the review against a gate you set before starting.
Measure four things: hours saved per user per week, the share of Copilot drafts usable without heavy rework, prompts per user per day as an adoption signal, and any security or accuracy incidents logged. If a pilot user saves even an hour a week, the licence pays for itself several times over. If nobody does, you have spent a few hundred dollars to avoid a five figure mistake.
This discipline is what separates the firms that scale from the ones that stall. The Datacom 2025 State of AI Index found only 12 percent of organisations have scaled AI across the business. The rest mostly ran enthusiastic pilots with no metrics and no governance, then drifted. Our guide to running an AI pilot without risking client data covers the same method beyond Copilot.
How does ISO 42001 governance reduce Copilot risk?
ISO 42001 is the international standard for AI management systems. It reduces Copilot risk by forcing the questions oversharing hides: what data can the AI reach, who owns each use case, how are outputs checked and what happens when something goes wrong. OxygenIT is certified to ISO 42001, which remains rare for an MSP.
In practice the standard translates to a handful of working artefacts: an AI risk register, an acceptable use policy staff have actually seen, named owners for each AI use case, human review rules for outputs that leave the business, and an incident path when Copilot surfaces something it should not. None of that requires your firm to certify. Working with a certified partner imports the discipline without the audit.
The NZ context makes this worth doing properly. There is no AI specific law here yet, but the Privacy Act 2020 fully applies to personal information moving through prompts and outputs, and AI Forum NZ guidance points firmly at governance first adoption. Documented AI governance is also starting to appear in tender questionnaires and insurance renewals, so the artefacts pay for themselves beyond Copilot. We cover the small business version of this in our guide to AI governance and ISO 42001, and it underpins all of our AI implementation work.
Microsoft Copilot readiness NZ: frequently asked questions
How long does a Copilot readiness assessment take?
For a business of 18 to 110 staff, allow one to two weeks. Most of that time is running Data Access Governance reports, scanning for sensitive data and reviewing permissions on key sites. The output is a remediation plan, a licence check and a pilot design, so the work ends with a decision rather than a report that sits in a drawer.
Can Copilot see data our staff cannot already see?
No. Copilot honours existing Microsoft 365 permissions and only surfaces content the signed in user can already open. The risk is that most tenants carry years of oversharing, so staff can technically open far more than anyone intended. Copilot turns that quiet exposure into search results.
Which Microsoft 365 plans support Copilot?
Copilot is an add on licence for Business Standard, Business Premium, E3 and E5 plans. You do not need to upgrade every user, and licences can be assigned to a small pilot group first. Checking prerequisites is part of our Microsoft 365 optimisation service.
Is our company data used to train Microsoft AI models?
No. Microsoft states on Microsoft Learn that prompts, responses and data accessed through Microsoft Graph are not used to train the underlying foundation models. Your data stays within the Microsoft 365 service boundary, subject to the same privacy and residency commitments as the rest of your tenant.
Should we roll Copilot out to everyone at once?
No. Start with three to five users for 30 days, measure time saved and output quality, and fix any oversharing the pilot exposes. Scaling on evidence keeps the spend defensible and gives managers real examples of where Copilot genuinely helps in your business.
We already switched Copilot on without any of this. What now?
Run the readiness work now rather than switching Copilot off. Data Access Governance reports show what is exposed, Restricted Access Control closes the worst gaps quickly, and sensitivity labels with DLP policies contain the rest. Contact us if you want the oversharing report run this week.
Book a Copilot Readiness assessment with OxygenIT
OxygenIT has run Microsoft environments for New Zealand businesses since 2005. We are a Microsoft partner, certified to ISO 27001 for security and ISO 42001 for AI management, based in Christchurch with coverage in Wellington. A Copilot Readiness assessment gives you the oversharing report, a costed remediation plan and a pilot design in one fixed price engagement.
Book a Copilot Readiness assessment and we will show you exactly what Copilot would see in your tenant today. Or call us on 0800 101 095.