Skip to content
Microsoft 365 & Cloud

Rolling Out Microsoft 365 Copilot: A Roadmap

A Microsoft 365 Copilot rollout without surprises: goals per department, permission clean-up, data protection, pilot group and training in four phases.

Published on 4 min read

Meeting room with a wall display showing a blue path with several stations.

A Microsoft 365 Copilot rollout does not start with the licence but with the tenant. Copilot accesses emails, files, chats and calendars with exactly the rights each user holds. Years of accumulated shares, groups and legacy data become searchable in one step.

Define use cases per department

A rollout without named use cases ends in sporadic usage. The first step is a short survey of recurring tasks involving text, spreadsheets, meetings and research in each department. Typical candidates:

  • Management and assistants: summaries of long email threads, meeting preparation from calendar and documents.
  • Sales: proposal drafts based on earlier proposals, summaries of customer contacts.
  • Finance and controlling: explanations of formulas in Excel, preparation of figures for reports.
  • HR: drafts for job advertisements, summaries of policies.
  • IT and project management: minutes from Teams meetings, status reports, documentation drafts.

Two or three cases per department are enough. They determine who joins the pilot group, what is trained and how benefit is measured.

Clean up permissions and classify data

Copilot uses the tenant’s existing permissions one to one. The problem lies the other way round: many users have access to more than they know. A SharePoint library shared years ago with “Everyone except external users” or a Teams channel with salary lists went unnoticed because nobody searched for it.

Before the start, the following items belong on the list:

  • Reduce organisation-wide shares in SharePoint and OneDrive to actual need
  • Clean up orphaned teams and groups without owners or with former members
  • Review security groups with access to HR, finance and management data
  • Remove guest accounts that are no longer needed
  • Set the default for new sharing links to “specific people”
  • Define archiving and retention periods for legacy data

This clean-up is the most laborious part of the rollout and the one with the greatest security gain, regardless of Copilot.

The second building block is classification. Sensitivity labels from Microsoft Purview mark documents and emails by protection need. Copilot respects them: encrypted content the user cannot read stays out of scope, and answers inherit the label of the source. Three or four levels with automatic labelling for obvious cases such as bank details are enough to begin with.

Clarify data protection and co-determination

Microsoft states that company data, prompts and responses are not used to train the foundation models. Processing stays within the Microsoft 365 service boundary, for European customers within the EU Data Boundary. On the company side, three things remain:

  1. Update the record of processing activities. Copilot is a new processing activity. Purpose, data categories, legal basis and retention periods belong in the GDPR record, plus a data protection impact assessment if the data protection officer requires one.
  2. Involve the works council. A system that could analyse how employees work and communicate is subject to co-determination in Germany under section 87 BetrVG. A works agreement setting out purpose, limits and prohibited analyses creates clarity.
  3. Write a usage policy. It defines what may be created with Copilot and requires results to be checked before they are passed on, because answers sound convincing but are not always correct.

Four phases to live operation

Duration depends on the state of the tenant, not the number of licences.

PhaseContentOutcome
PreparationUse cases, permissions, labels, data protection, co-determinationApproved tenant, usage policy, works agreement
Pilot10 to 20 people, fixed use cases, weekly exchangeEvaluated use cases, training material
RolloutWaves per department, training before licences, contact per areaAll intended users active
OperationEvaluate usage, review permissions, update policyFixed review cycle, named owners

The pilot group should mix people with a high affinity for new tools and sceptics. Every participant runs at least one named use case regularly and records their experience.

Training has two parts: how Copilot works (structuring a prompt, adding context, knowing the limits) and department-specific practice on real documents. In our projects, sessions of 60 to 90 minutes followed by a practice period have worked better than full-day events.

Measurement follows the defined use cases: whether each is handled with Copilot regularly, how users rate the quality and how much rework is needed.

Key points

  • Copilot finds everything a user has access to. Cleaning up permissions before assigning licences is the most important step.
  • Two or three named use cases per department decide the pilot group, the training and how benefit is measured.
  • Record of processing activities, works agreement and usage policy belong in preparation, not in live operation.

How DEVACON supports companies with tenant, permissions and licensing is described on the page Microsoft 365.

Topics Microsoft 365 Copilot AI Permissions Data protection

This article comes from the DEVACON blog and was editorially revised for the new website.