Tenant Readiness and Rollout

Readiness means reconciling licenses, channels, and reports into a chain of evidence that has to agree before you flip Copilot on. Run the rollout through the Copilot Control System and close it with a go/no-go call that names its own gaps.


What you'll learn

  • Reconcile license, update-channel, and readiness-report evidence before a rollout
  • Tell web-based Copilot Chat apart from licensed work-based Copilot
  • Explain why a suggested candidate or a license count is not an approval
  • Map a rollout to the three Copilot Control System pillars
  • Issue a go/no-go recommendation that names the evidence still missing
On this page

The readiness report is green, so the whole pilot group gets Copilot. By Friday, two people are asking why it can't reach files their colleagues can use. The report wasn't wrong. It answered a narrower question than "is this rollout ready?"

A rollout depends on several records agreeing about the same people: qualifying subscriptions, the approved pilot list, supported update channels, assigned licenses, reviewed settings, and reports that match your own records. If one record disagrees, readiness is still unresolved. Reports, counts, and saved settings are evidence. An authorized rollout decision is a separate record.

Readiness is a chain of evidence

Microsoft's setup guidance sequences readiness as a chain, and each link answers its own question:

Link The question it answers
Qualifying base plan Does each user have a subscription Copilot can attach to?
Approved population Is this user in the pilot you were authorized to run?
Update channel Is the device on a deployment path Copilot supports?
License assignment Does the user's admin record show the exact entitlement?
Settings review Has an owner reviewed and recorded the Copilot settings?
Reconciliation Do these independent sources agree with each other?

Buying licenses does not complete the chain. A subscription can be purchased but unassigned. A user can hold the right license and still fail the channel check. Two admin records can disagree. Readiness work means surfacing those disagreements before a person hits a wall, or before they reach content they were never meant to see. A blank cell in the worksheet is not a pass. It's an unanswered question.

One row per user, controlled states only

Build a readiness worksheet with one row per pilot user, and fill each cell with a controlled state: Pass, Fail, Not checked, Needs owner, or Blocked. Never leave a cell blank. A blank hides an unanswered question behind a tidy table. An explicit "Not checked" keeps the gap visible until someone closes it.

Choose the pilot's access model

Copilot opening for a user doesn't tell you which license is behind it. There are two different access models, and confusing them produces the Friday-afternoon confusion from the opening example.

Web-based Copilot Chat comes with an eligible Microsoft 365 subscription at no extra cost, but it only answers from the open web, without drawing on your organization's content. Work-based chat requires a Microsoft 365 Copilot license and can ground answers in your Microsoft Graph data: email, calendars, SharePoint, OneDrive. If someone opens Copilot but can't use company context, they most likely have only the web-based experience. Nothing is broken. Record which model the pilot requires as a licensing fact.

Licenses reach users through three documented methods: individual assignment, group-based assignment, and PowerShell. The method only changes how you start the operation. What you verify afterward stays the same. The verification unit is always the user. When you assign to a group, the group is the target, but you still confirm every intended member's resulting license state, and that nobody outside the approved population was swept in. Submitting a change is not proof of its result.

Another record often gets folded into licensing: the update channel. Copilot's supported deployment path here is Current Channel or Monthly Enterprise Channel. Assigning a license does not move a device onto either one. Licensing and channel readiness have separate owners and separate evidence. If the configured channel, observed device channel, and readiness report disagree, record Mismatch — investigate. That mismatch needs an owner, not a rounding adjustment.

Draft the readiness worksheet· copilot-chat
Bad example

Turn my pilot notes into a Copilot readiness worksheet and decide who is ready.

Good example

Build a Microsoft 365 Copilot readiness worksheet as a table with one row per pilot user and columns: user, base plan, access model needed (web-based or work-based), assignment method, license state, configured update channel, observed channel, readiness-report state, and decision. Here are my raw notes: [paste your pilot list]. Use only these states - Pass, Fail, Not checked, Needs owner, Blocked. If a value is absent, write "Not checked". Do not invent a license, channel, or approval.

Why this works: A reconciled worksheet where every gap is a visible "Not checked" you can assign. A blank cell never reads as done.

Suggested candidates still need approval

Microsoft's readiness report uses a 28-day window. It shows total prerequisite licenses, users on an eligible update channel, assigned and available licenses, and suggested candidates. Suggested candidates are the top 25% of non-licensed users by Microsoft 365 app usage. That makes the field useful for prioritization. It grants no approval.

High app usage says nothing by itself about purchasing authority, security readiness, or business need. If the ranking is treated as an approved list, the pilot can expand beyond the population anyone authorized. Keep the evidence in three separate columns because each has a different owner:

  • Observed fact: "40 licenses are assigned."
  • Recommendation: "Consider adding 20 users once dependencies clear."
  • Approved decision: "The named approver authorized the expansion."

Pricing needs the same separation. The enterprise Microsoft 365 Copilot add-on is recorded at $30 per user per month, paid yearly, as of mid-2026. Business plans have different bundled and add-on options. Check the price and terms in your own agreement before reusing a figure from a slide. Record the option, price, seat count, and annual commitment. Keep Copilot cost separate from its qualifying base plan.

A count is not an approval

"80 licenses are assigned" and "the rollout is approved for 80 users" are different claims. The first is an observation from a report. The second needs a named approver and a recorded decision. Never let a license or candidate count stand in for the sign-off. That substitution is how a pilot outgrows its authorization without anyone deciding to expand it.

The Copilot Control System: three pillars, one go/no-go

Readiness gets the rollout started. The Copilot Control System (CCS) is how you keep operating it afterward. CCS organizes Copilot administration into three pillars that have to be read together: a strong signal in one never rescues a gap in another.

  • Security & Governance: data access, oversharing, labels, DLP, audit, Zero Trust. (Two whole lessons, data protection and audit and Zero Trust, live here.)
  • Management Controls: who can use Copilot, how it's licensed or metered, and the agents that exist and who owns them.
  • Measurement & Reporting: readiness, adoption, impact, and value evidence.

Measurement is a hierarchy. The numbers in it aren't interchangeable. Microsoft documents five distinct reporting tools:

Reporting tool Surface Question it answers
Readiness and adoption report Microsoft 365 admin center Are prerequisites and usage baselines in place?
Copilot Dashboard Viva Insights What do adoption, impact, and sentiment show?
Agent Dashboard Viva Insights Which agents and users are active?
Consumption Dashboard Viva Insights How is consumption distributed?
Advanced Reporting Power BI / custom queries Do we need deeper analysis?

Treat each CCS control as a record with an owner, an observed state, evidence, the decision still required, and a review date. When "not visible" shows up, write it as an observation about your access. Whether the control itself is disabled remains a separate, unconfirmed question. The exercise is meant to produce a defensible recommendation: Go, Go with narrower scope, No-go pending remediation, or Pause for evidence, each paired with the evidence that would change it. A 120-user proposal backed by an 80-user group, an unfinished site review, and no adoption baseline is a no-go for 120. The 80-user version is a candidate. It still needs its own yes.

Turn the inventory into a go/no-go· copilot-chat
Bad example

Review this Copilot Control System inventory and give me a go/no-go decision.

Good example

Using only the CCS inventory below, produce a separate status for each pillar (Security & Governance, Management Controls, Measurement & Reporting), prioritize the unresolved gaps, and recommend Go, Go with narrower scope, No-go pending remediation, or Pause for evidence. Keep observations, recommendations, and approved decisions in separate lines. If a value is absent, write "MISSING EVIDENCE". Do not invent owners, dates, approvals, or compliance conclusions. Inventory: [paste your table]

Why this works: A three-pillar summary and a recommendation whose reasoning names the exact gaps to close, reusable as the first slide of a rollout review.

Making the call

Put the pieces together in order: review Security & Governance for unresolved dependencies, Management Controls for any mismatch between approved scope and observed access, and Measurement & Reporting for a real baseline. Prioritize a data-exposure risk over a scope mismatch, and a scope mismatch over missing measurement. Then write the recommendation and, separately, the approved decision. The recommendation is yours to make. The authorization belongs to the named approver. Copilot's generated summary is a formatting aid. The site review, the license record, and the approval are the evidence.

Try it yourself

Reconcile a three-user pilot

Practice the reconciliation on a small, deliberately messy pilot so the failure modes are obvious.

  1. 01

    Take these three users. Alex: approved, qualifying plan, license assigned, Current Channel, readiness "assigned and eligible." Maya: approved, license assigned, but on an unsupported channel, readiness "assigned, not eligible." Lee: not approved, plan unconfirmed, no license, listed only as a suggested candidate.

  2. 02

    Write a decision for each user using a controlled state, and say which single link failed.

    Hint: Maya's problem isn't licensing. Read the channel row.

  3. 03

    Explain in one sentence why Lee's suggested-candidate status does not authorize an assignment.

  4. 04

    Give the overall pilot decision and the one condition that would let it proceed.

A worksheet that proceeds for Alex, fixes a prerequisite for Maya, rejects Lee, and holds the pilot until Maya passes or is removed, with each call traceable to a specific link in the chain.

Key takeaways

  • Readiness is a chain of independent facts that have to agree before a rollout counts as ready.
  • Web-based Copilot Chat and licensed work-based Copilot are different access models. "Copilot opens" proves neither one on its own.
  • When you assign by group, the verification unit is still the individual user's resulting license state.
  • A suggested candidate is a usage ranking, and a license count is an observation. Neither is an approval.
  • A CCS go/no-go recommendation must name the unresolved evidence and the condition that would change it.

Check your understanding

  1. 1. The readiness report lists a heavy Microsoft 365 user as a "suggested candidate." What does that status entitle them to?

  2. 2. A pilot user has a Copilot license assigned, but their device is on an update channel Copilot doesn't support. What's the correct call?

  3. 3. How does work-based chat really differ from web-based Copilot Chat?

  4. 4. You assign Copilot licenses to a pilot group. What proves only the intended users received the entitlement?

  5. 5. A 120-user rollout has 80 users approved and assigned, a site access review still in progress, a DLP policy configured but not validated, and no adoption baseline. What is the defensible CCS recommendation?

Frequently asked questions

Terms used in this lesson

readiness chain
The sequence of independent checks (plan, population, channel, license, settings, reconciliation) that must all agree before a Copilot rollout.
work-based chat
The licensed Copilot experience that can ground answers in your organization's Microsoft Graph data, as opposed to web-only chat.
Copilot Control System (CCS)
Microsoft's framework organizing Copilot administration into three pillars: Security & Governance, Management Controls, and Measurement & Reporting.
suggested candidate
A readiness-report signal identifying the top 25% of non-licensed users by app usage: a prioritization hint that still requires a separate approval before assigning a license.

Further reading