How-to guide

Microsoft 365 Copilot: Readiness Questions

Microsoft 365 Copilot readiness is primarily an identity, licensing, mailbox, data-access and change-management question rather than a use-case one.

SCSB is asked about Microsoft 365 Copilot more often than about any other Microsoft capability, and the question is nearly always about use cases: what could it do for our finance team. SCSB's consistent position is that the use case is the second question. The first is whether the environment can support the service at all — and for finance teams in particular, there are documented constraints that decide the answer before anyone writes a prompt.

This article sets out those constraints, what Microsoft commits to on data handling, what remains the organisation's own obligation, and how SCSB would scope a pilot that produces a decision rather than an impression.

Readiness is an environment question first

Microsoft's app and network requirements set out the prerequisites plainly. Users must have an eligible Microsoft 365 licence assigned, and must have Microsoft Entra ID accounts. Microsoft 365 Apps must be deployed. Some features, including file restore and OneDrive management, require the user to have a Microsoft OneDrive account.

Two exclusions are easy to miss and both are absolute rather than configurable. Microsoft 365 Copilot is not available where device-based licensing is used for Microsoft 365 Apps for enterprise. And for the web versions of the core applications, third-party cookies must be enabled — a setting many organisations have deliberately restricted for unrelated reasons.

Feature-specific conditions apply on top. To let Microsoft 365 Copilot reference meeting content after a meeting ends, transcription or recording must be enabled — which is itself a decision with consent and retention consequences, not a switch to flip on the way to a demonstration. Microsoft Loop and Microsoft Whiteboard each have to be enabled for the tenant separately. And the Office Feature Updates task must be allowed to run on its normal schedule and reach the network resources it needs, because core experiences depend on it.

The mailbox constraint that decides it for many finance teams

SCSB raises this before anything else with a finance audience, because it is the constraint most likely to invalidate the intended use case outright.

Microsoft states that Microsoft 365 Copilot is only supported on primary mailboxes hosted on Exchange Online, and that it is not available on a user's archive mailbox, on group mailboxes, or on shared and delegate mailboxes that they have access to.

Finance functions run on exactly those mailboxes. Payables, receivables, and general finance correspondence are typically handled through a shared mailbox precisely so that cover is possible and no single person owns the queue. An expectation that the service will summarise a supplier thread, or find the last exchange about a disputed invoice, frequently assumes access to a mailbox the entitlement does not reach. Where the work sits in a shared mailbox and the correspondence is not also in the individual's primary mailbox, the capability the team was sold on is not the capability they will get.

This is worth establishing on day one, against the actual mailboxes the team uses, rather than discovering it after licences are assigned.

Permissions become the deployment decision

Microsoft's data, privacy and security documentation states that Microsoft 365 Copilot only surfaces organisational data to which individual users have at least view permissions, and that the grounding process honours the user identity-based access boundary. Microsoft is direct about what follows: it is important that organisations use the permission models available in the underlying services so that the right users have the right access to the right content.

The practical consequence is that the service does not create an access problem — it makes an existing one legible. Historic oversharing that nobody noticed while it required someone to know a file existed becomes discoverable when a colleague can simply ask a question in natural language.

SCSB's recommended sequence is therefore to review before enabling: identify the locations in scope, establish who currently has access and whether that remains appropriate, confirm how sensitive material is labelled, and resolve what the review turns up. Where content is encrypted through sensitivity labels or information rights management, Microsoft records that Microsoft 365 Copilot honours the usage rights granted to the user, so labelling done properly continues to do its work. Enabling a new tool is not a substitute for fixing a permissions problem the review reveals.

Where data goes, and what Microsoft commits

Three commitments are documented and worth stating accurately, because they are frequently overstated in both directions.

  • Prompts, responses, and data accessed through Microsoft Graph are not used to train foundation large language models, including those used by Microsoft 365 Copilot.
  • Interactions are stored — the prompt, the response, and citations to the information used — as the user's activity history. That data is encrypted at rest, and administrators can view and manage it using Content search or Microsoft Purview, including setting retention policies for it. Users can delete their own activity history from the My Account portal.
  • On residency, Microsoft states that for European Union users traffic stays within the EU Data Boundary, and that customers outside the EU may have their queries processed in the US, the EU, or other regions.

That last point is the one Malaysian organisations should read carefully rather than skip. A Malaysian tenant is outside the EU Data Boundary. Microsoft's Advanced Data Residency and Multi-Geo offerings carry data residency commitments for Microsoft 365 Copilot customers, so residency is a subject an organisation can address — but it is addressed by examining the commitments that apply to its own tenant and agreements, not by assuming a default.

PDPA 2010 obligations stay with the organisation

Microsoft documents product behaviour, controls and contractual commitments. It does not determine an organisation's obligations under the Personal Data Protection Act 2010, and no configuration of Microsoft 365 Copilot discharges them.

Where personal data is processed, the obligations sit with the organisation as data user: the basis for processing, the notice given to data subjects, security measures, retention, and the treatment of any transfer outside Malaysia. Those questions are for the organisation's own legal or compliance advisers, and where a determination is needed on the current requirements, the Personal Data Protection Commissioner is the authority to consult rather than a vendor's documentation or a consultancy's article. SCSB's role here is to describe accurately what the technology does with data so that the assessment can be made on correct facts — not to reach the conclusion.

Network conditions that break it quietly

Microsoft records that several Microsoft 365 Copilot integrations rely on WebSockets, and that networks must support full WSS connectivity to the relevant Microsoft domains. Three common configurations interfere: a perimeter that blocks the WebSocket protocol, devices attempting TLS inspection of those connections, and proxy servers enforcing aggressive connection timeouts.

All three are ordinary in a well-run corporate network, and the failure mode is unhelpful — features behave inconsistently rather than failing cleanly. SCSB checks this before a pilot rather than after, because a pilot that fails on network configuration will be reported as the service not working.

Separately, privacy controls for connected experiences can remove Microsoft 365 Copilot features entirely from the core applications. An organisation that has turned off connected experiences that analyse content will find the features unavailable, and will usually have no record of who made that decision or why.

Designing a pilot that produces a decision

A useful pilot has one defined audience, a small number of permitted tasks, a named owner, and a way to record what was learned. SCSB would fix the success criteria in advance, because otherwise the outcome is a set of impressions.

Set expectations with users explicitly: which data sources are in scope, when to verify an answer, how to handle an error, and where to escalate a suspected information-access concern. Microsoft states plainly that responses generative AI produces are not guaranteed to be entirely factual and that users should apply judgement before relying on output. For finance work, that means generated text is a draft for review, never a substitute for the source record, professional review, or an approval process.

If agents are in scope, treat them as a separate decision. Administrators can review the permissions and data access an agent requires, along with its terms and privacy statement, and control which agents are permitted.

When a simpler answer is the right one

Not every organisation should adopt Microsoft 365 Copilot, and SCSB will say so where the facts point that way. Where a finance team's work sits mainly in shared mailboxes, where content is poorly organised or permissions are known to be untidy, or where the pressing problem is a manual reconciliation that better structured data would fix, the honest answer is that the prerequisites are not met and the money is better spent elsewhere first. A permissions and information-architecture exercise is often the higher-value project, and it is the one that has to happen anyway.

Where an organisation concludes the readiness work is worth doing, an agreed Microsoft 365 implementation scope can be discussed under SCSB's Microsoft 365 implementation service. Any rollout remains subject to the organisation's own licensing, permissions, data governance and approval decisions.

General-information limitation

This article is general technology information about Microsoft 365 Copilot requirements and documented behaviour. It is not legal, privacy, security or compliance advice, and it does not determine any organisation's obligations under the PDPA 2010 or any other requirement, nor confirm that a particular configuration meets them. Product requirements, controls and commitments are set by Microsoft and change over time. Confirm the current position against Microsoft's published material, and obtain appropriate legal or privacy advice for any compliance conclusion.

Exchange Online, Microsoft, Microsoft 365, Microsoft 365 Copilot, Microsoft Entra ID, Microsoft Graph, Microsoft Loop, Microsoft OneDrive, Microsoft Purview and Microsoft Whiteboard are trademarks of the Microsoft group of companies.

Related service

MOVE FROM PLAN TO SYSTEM

Modernise the workflow—not just the software.

Bring us the process, control or reporting bottleneck. We will clarify the target state and the next implementation decision.

Plan the next step