Enterprise SaaS
Microsoft 365 Copilot rollout with permissions first
A Microsoft 365 Copilot deployment sequenced as a governance project: inventory and correct over-shared content, set default sharing and retention so it stays fixed, label what must never be summarised, read the enterprise data-protection scope, establish where prompts are processed, confirm the audit path, and only then pilot — with a Copilot Studio agent as a later, separate project.
- Source
- Editorial recipe — no step evidence has been fetched yet
- Verified
- Evidence not verified
- Confidence
- Low
01Objective
Roll out Microsoft 365 Copilot to the company without turning existing over-sharing into answers, by doing the tenant permissions, labelling and audit work before anyone gets a seat.
- use caseEmployee helpdeskAn internal assistant that answers staff questions about IT, facilities, expenses and policy, and can perform routine service actions such as resets and access requests. Same shape as customer support, different audience and different data.
- use caseInternal company searchOne search box over the documents a company already has — shared drives, wikis, ticket systems, email attachments — answered by a model that quotes the source. The value is finding the right paragraph in a corpus nobody has read end to end, not writing new text.
- use caseKnowledge managementCapturing what the organisation knows — process notes, decisions, answers given once already — and keeping it findable and current. AI helps by drafting entries, spotting duplicates and flagging pages that contradict each other.
- use casePrivate company ChatGPTA chat assistant for staff that behaves like a consumer chatbot but runs under company control: your accounts, your logging, your retention, your choice of model, and optionally your own documents attached.
02Recommended stack
| Role | Component |
|---|---|
| Authentication | Microsoft Entra ID (SSO + SCIM) |
| Ingestion | Connected Microsoft 365 content (SharePoint, OneDrive, Teams) |
| Observability | Microsoft Purview (labels, audit, retention) |
| Orchestrationoptional | Microsoft Copilot Studio |
| Ui | Microsoft 365 Copilot |
Architecture and data flow
Components
- Employees — people
- Microsoft 365 Copilot (Office apps, Business Chat) — application
- Microsoft Entra ID (SSO + SCIM) — identity
- Copilot retrieval over Microsoft Graph (Semantic Index) — retrieval
- Vendor-managed storage (interactions, index) — database
- Vendor model service — inference server
- Vendor-hosted frontier model (OpenAI, Anthropic) — model
Connections
- Employees to Microsoft 365 Copilot (Office apps, Business Chat) — HTTPS (confidential data)
- Microsoft 365 Copilot (Office apps, Business Chat) to Microsoft Entra ID (SSO + SCIM) — OIDC sign-in (personal data)
- Microsoft 365 Copilot (Office apps, Business Chat) to Copilot retrieval over Microsoft Graph (Semantic Index) — question + user groups (confidential data)
- Copilot retrieval over Microsoft Graph (Semantic Index) to Vendor-managed storage (interactions, index) — documents + permissions (confidential data)
- Microsoft 365 Copilot (Office apps, Business Chat) to Vendor-managed storage (interactions, index) — chats, users, settings (personal data)
- Copilot retrieval over Microsoft Graph (Semantic Index) to Vendor model service — prompt + retrieved passages (confidential data)
- Vendor model service to Vendor-hosted frontier model (OpenAI, Anthropic) — loaded weights
External data transfer · YES
- confidential content leaves your control on the Employees → Microsoft 365 Copilot (Office apps, Business Chat) link.
- Content, prompts and responses are processed by Microsoft under the Products and Services DPA, with Microsoft as processor. What Copilot can read is bounded by each user’s existing permissions, which is why correcting them is the project.
- Web-grounded queries leave the Copilot scope for the Bing search service, where Microsoft acts as an independent controller — a separate decision to make and record.
03Suitable for
- Organisation size
- 300–100000 employees
- Data classes
- confidential, personal
- Constraints
- Microsoft 365 already in place, with the licences Copilot requires; someone who owns SharePoint and OneDrive permissions and can correct over-sharing; agreement that content may be processed by Microsoft under the Products and Services DPA
- Industries
- Professional services, Financial services, Insurance, Public sector, Technology
- Jurisdictions
- any
04Hardware
No hardware profile was sized for this answer.
Indicative costUSD · one-off plus monthly
- Per-seat licences
- Not estimated. No per-seat price was fetched, and enterprise pricing is negotiated. Get a quote for your seat count and term; Advanced Data Residency, if required, is a separate add-on requiring full licence coverage.
- Not estimated
- Model usage
- Not estimated separately: model use is bundled into the Copilot seat licence rather than metered per token to you. Confirm the inclusions for the plan you buy.
- Not estimated
- Implementation (10–30 FDE-days)
- 10–30 FDE-days at US$760–1940 per day, converted from the HK$6,000–15,000 band at the HKMA Linked Exchange Rate band of HK$7.75–7.85 to one US dollar. One-off; excludes internal staff time.
- US$7,600 – US$58,200
- Implementation is dominated by the permissions remediation, not the software: inventory, re-scoping over-shared sites, labelling, the audit path and a departmental pilot.
- Assumes Microsoft 365 and Entra ID are already in place; the licence line is the largest cost and only Microsoft can price it.
- The day band is wider than a plain SaaS assistant because the tenant clean-up varies enormously with the state of the estate.
05Difficulty
3 / 5
A project week with Linux, Docker and GPU experience
06Skills
- Change managementchange-management
- operations
- Compliance and governancecompliance-governance
- compliance
- Identity and SSOidentity-sso
- security
- Security hardeningsecurity-hardening
- security
- Workflow automationworkflow-automation
- operations
07Deployment steps
Commands are copied from each project’s own documentation, and the page they came from is linked under the step. 0 of 9 steps currently open an evidence record. The rest are linked to their source; §10 says which of those documents were fetched and which were fetched without their anchor being found — two different states, named differently there.
- 01
Inventory what Copilot will be able to read, before anyone gets a licence
AssessmentCopilot answers from content the user can already open. Microsoft states it "only surfaces organizational data to which individual users have at least view permissions", and that the "Semantic Index honors the user identity-based access boundary". That is a promise about retrieval; it is not a promise that your permissions are right. Produce one list: every SharePoint site, Team and OneDrive folder shared organisation-wide or with an everyone-type group, with the file count and the named owner of each. That list is the project.
- 02
Correct the over-shared sites and the content nobody owns
AssessmentWork down the list. Re-scope tenant-wide sharing, repair broken permission inheritance on the libraries that matter, and archive or delete content with no owner. Two categories cause most of the surprises: a finance or HR site opened to an everyone-group years ago, and a leaver’s OneDrive re-shared during a handover. Neither is visible while people browse for documents. Both are visible the moment retrieval is switched on. Finish this before licences are assigned, not after the first complaint.
- 03
Give the corpus a lifecycle, or it drifts straight back
AssessmentA one-off clean-up decays within two quarters. Set the default sharing link so a new link is not a tenant-wide one — Microsoft documents this as a way to "help prevent users from oversharing" — require a named owner per site, put a recurring review on organisation-wide sharing, and apply retention so superseded documents leave the index instead of ageing in it. The test of success is that a site created next quarter cannot become over-shared without somebody deciding to make it so.
- 04
Label the content that must never be summarised
AssessmentA sensitivity label is the one control that travels with the file. Where the label applies encryption, Microsoft states that "Copilot and agents return data from an item only if the user is granted permissions to copy" from it — so a label that withholds the extract right keeps a document out of an answer even for a reader who may open it. Label the small set that actually matters (board papers, deal files, HR cases, client matters under a duty of confidence) rather than attempting to label the estate.
- 05
Read the enterprise data protection scope, then write down what it excludesversion-sensitive
AssessmentMicrosoft describes organisational use of Copilot as covered by the Products and Services Data Protection Addendum and the Product Terms, "with Microsoft acting as a data processor", and states that prompts, responses and data accessed through Microsoft Graph are not used to train foundation models. The exclusions are what you write down. Web search queries leave that scope for the Bing search service, where Microsoft states it "acts as an independent data controller responsible for complying with all applicable laws and controller obligations". Decide whether web grounding stays on, and record who decided.
- 06
Establish where prompts are processed, not only where files are storedversion-sensitive
AssessmentThese are two different questions and only one of them is answered by your tenant location. Microsoft states that "Customers outside the EU may have their queries processed in the US, EU, or other regions", and that models provided by Anthropic as a subprocessor "are currently excluded from the EU Data Boundary". A committed in-country storage location is a separate, paid add-on: for Advanced Data Residency Microsoft states that "ADR does not impose a minimum licensing threshold; however, 100% license coverage is required to establish and maintain a data residency commitment". If a residency rule is driving this project, price that add-on before promising anything.
- 07
Confirm the audit and eDiscovery path for prompts before the pilot
AssessmentInteractions are logged. Microsoft states the audit records "contain details about which user interacted with Copilot, when the interaction took place, and where it occurred", and that they "include references to files, sites, or other resources" Copilot read to generate the response. Those resource references are also your over-sharing detector: an answer grounded on a site the person should never have reached shows up in the log. Establish the retention period, the export path and who is allowed to search it — then tell employees that prompts and responses are recorded and discoverable.
- 08
Pilot with one department and treat wrong answers as findings
AssessmentThirty people, six weeks, three named tasks, and a before-and-after measure agreed in advance. Collect two lists: answers that were wrong, and answers that were correct but should not have been available to that person. The second list is the more valuable one — every entry is a permission to fix, and finding it in a pilot costs less than finding it in a subject access request.
- 09
Only then consider a Copilot Studio agent
AssessmentCopilot Studio is "a graphical, low-code studio for building and managing AI-powered agents and workflows", and it is where a department-specific assistant with its own instructions and knowledge sources gets built. Treat it as a second project: separate grounding sources, a separate billing basis, a separate review. Starting it before the tenant-wide permissions work is finished means debugging two problems at once, and the answers will not tell you which one you are looking at.
08Compliance considerations
Structured issue-spotting to support your own review — not legal advice. Verify against the cited primary sources and your counsel.
Applies everywhere
Confidentiality · Human oversighthigh
Copilot only surfaces content the user can already open, but that is a promise about retrieval, not that your permissions are correct. Inventory organisation-wide sharing and correct it before licences are assigned; the over-sharing was always there, retrieval just makes it reachable.
Data residency · Cross-border transfershigh
Where prompts are processed is a different question from where files are stored. Microsoft states queries for customers outside the EU may be processed in the US, EU or other regions, and that Anthropic models are currently excluded from the EU Data Boundary. A committed storage location (Advanced Data Residency) is a separate paid add-on requiring 100% licence coverage — price it before promising residency.
Data processing agreement · Model training · Retentionhigh
Organisational use is covered by the Products and Services DPA with Microsoft as processor, and prompts and responses are not used to train foundation models. Web search queries leave that scope for the Bing service, where Microsoft acts as an independent controller — decide whether web grounding stays on, and record who decided.
Sensitive data · Confidentialityhigh
A sensitivity label is the one control that travels with the file. Where a label applies encryption, Copilot returns data from an item only if the user has copy/extract rights — so labelling the small set that truly matters keeps it out of answers even for readers who may open it. Label that set rather than attempting to label the estate.
Logging · Auditability · Transparencymedium
Copilot interactions are audited: the records name the user, time, and the resources read to generate the response. Establish the retention period, the export and eDiscovery path, and who may search it — then tell employees prompts and responses are recorded and discoverable.
09Alternatives
A neutral enterprise assistant across mixed systems
When the knowledge lives across Microsoft 365, Google Workspace and other systems equally, a connector-based assistant such as Glean may fit the estate better than a Microsoft-native one — at the cost of a second vendor relationship.
- — Indexes across mixed systems rather than assuming Microsoft 365
- — A separate vendor, contract and permissions model to run
Self-hosted, where confidentiality rules out a processor
Where professional secrecy or a residency rule makes processing by Microsoft unattractive, run the assistant on your own infrastructure and remove the processor question entirely.
- — No vendor in the data path
- — You build and operate the stack, and lose the Office integration
- Enterprise SaaSEnterprise SaaS assistant with governance controlsA business or enterprise plan from an established vendor — ChatGPT Enterprise, Microsoft 365 Copilot, Glean or an equivalent — connected to your identity provider, scoped by existing permissions, covered by a DPA, and rolled out behind a written policy.
- Self-hostedPrivate company knowledge base (self-hosted RAG)Open WebUI as the employee interface, vLLM serving a Qwen2.5-14B-Instruct model on a single 24 GB GPU, PostgreSQL with pgvector for chats and embeddings, and OIDC single sign-on — all in Docker on one server in your office or colocation rack. Ollama replaces vLLM for teams under about 20 users; a 48 GB GPU lets you run a 32B model for better answers.
10Evidence
Not yet in the ledger
not yet fetched
not yet fetched
not yet fetched
not yet fetched
not yet fetched
not yet fetched
not yet fetched
not yet fetched
not yet fetched
not yet fetched
not yet fetched
not yet fetched
not yet fetched
11Community
Deployed this stack, or hit something this page does not cover? Corrections, sources and implementation reports are what keep a recipe worth reading.
Improve this page
Sign in to contribute
From the field
0 deployments · 0 questions
Nobody has reported deploying this here yet, and no question has been opened against this page. Both appear once a reviewer accepts them.
12Hire an FDE
If you would rather not build it, we can introduce a forward-deployed engineer who has deployed this stack before. The enquiry form starts from this recipe.