
Many managers think that implementing AI in a company is a „checkbox” in the Microsoft 365 dashboard: „we have licenses, let people click”.”. Under the pressure of demands they even do so, buy and on the spot the same day give access to users.
This approach, it's a simple the road to problems: image or related to data disclosure or even dissatisfaction of users themselves (the expected effect requires training in prompt creation). Fortunately, however, many organizations are figuring out how to get this process right before they click the „checkbox.”.
Copilot is not a „magic overlay.”. He works on what the user already has access to in M365. If SharePoint and Teams have been a mess for years, and permissions were handed out „to make it faster,” Copilot will simply start taking advantage of that mess. Fast. And effectively, but not necessarily with the principles of the ISMS (Information Security Management System)
5 steps before „handing out licenses.”
- Data hygiene and permissions Copilot respects permissions. If a file is available to „Everyone in the company,” Copilot will see it too. Analyses and audits even before the advent of Copilot showed that organizations had a huge problem with data order on Sharepoint/Teams and Onedrive. Too many permissions, too many shares, undefined permissions for folders and subfolders, sites and subsites. All of this gave wider access than the owner expected. Do an oversharing review: how many sensitive files are accessed more widely than needed. Limit access with the principle of least privilege: everyone sees only what they need to work with.
- Classification and sensitivity labels. Without labels, Copilot does not distinguish between „confidential” and „to be sent to the client.”.Enable and configure sensitivity labels (for example, in Microsoft Purview). Set protection rules for confidential documents: copy/share restrictions, appropriate access conditions. This is your fuse. Purview was important before the AI era and blocked the sending of sensitive data.
- Limits of processing and tenant identity. Make sure where the data „lives” and in what mode Copilot is running. In enterprise plans, prompts and responses should not feed public training, but you still need to make sure you are working in a properly configured corporate tenant and business accounts. And do not test adoption on „clean” accounts without data, you will come out that „it does not work”, because there is simply nothing to work on. If one heard before implementing Copilot from IT that it could be a separate tenant without data, the point was negligible. Give the tool with its data, then it makes sense.
- Use scenarios, rather than „give to everyone and let them search.”. When people get Copilot without a purpose, they end up either entertained or frustrated. Choose 2-3 areas (e.g., sales, HR, IT). Define specific tasks (summarizing meetings in Teams, preparing a memo after a meeting, comparing bids). Measure the effect: time, quality, number of repetitions, decrease in manual work. Functions such as meeting notes, developing materials based on documentation, searching knowledge in files on Sharepoint are the first scenarios. We often start with a training for business groups called „prompt master” and show how to write such prompts.
- Training: less „trust,” more habits. The biggest risk is blind faith in the answers. Copilot can make up and confuse facts, and the result always requires human verification. Set simple rules: what data we don't paste anywhere (e.g., passwords, access keys, customer data, code for critical systems) and what to do if someone accidentally reveals the data.
Buying a license is usually the last step, not the first. If you don't have your data and permissions in order, Copilot will not „increase productivity.” He will only accelerate the chaos. And what does it look like for you? - First cleaning and rules, or first licenses and „somehow it will happen”? You can book a consultation with us and we will check what the current state is, book an appointment: https://outlook.office.com/book/Konsultacjewobszarzeaplikacjibiznesowych@ISCG.onmicrosoft.com/s/fKddgNyppECh3KThb8VNMw2?ismsaljsauthenabled
