Loading...
Assessing readiness to take MSFT Co-Pilot to the next level

Transforming Age, a nonprofit senior living organization growing rapidly through acquisition, had gone all-in on Microsoft AI. Copilot was live for 165 users, Microsoft Fabric had become the primary data platform, and an ambitious "One Customer 360" initiative was preparing to unify resident and donor data across affiliates.
But the organization's Microsoft 365 tenant told a more complicated story. Years of acquisition-driven growth had produced a shared tenant spanning 66 domains and nearly 4,000 users across seven affiliate organizations migrated under a deliberate "move now, clean up later" strategy. Now AI was the forcing function: Copilot indexes and surfaces everything users can technically access, and resident PII was already landing in the Fabric lakehouse, with clinical PHI ingestion planned next. Leadership had no clear picture of whether the governance foundations â sensitivity labels, data loss prevention, access controls, AI usage policies â were actually in place underneath the AI they'd already deployed.
The timing added pressure: the Copilot license renewal was weeks away, 25 Microsoft Agent 365 seats had been purchased with no framework to govern them, and a security demonstration during the engagement confirmed the risk was real â Copilot could surface restricted financial data from a department SharePoint site that the report front-end never exposed.
We ran a five-workstream governance audit built on a simple principle: every finding must be backed by evidence the client can independently verify.
- Read-only, least-privilege collection. A dedicated service principal with tightly scoped permissions queried the Microsoft Graph and Power Platform Admin APIs no changes to the tenant, ever. Automated collectors swept tenant and Copilot configuration, licensing, data governance, Power Platform, and Copilot adoption telemetry across the full estate: 4,387 SharePoint sites, 7,000+ paid licenses, 5 Power Platform environments, and per-user Copilot usage.
- AI-accelerated analysis, human judgment. Purpose-built audit tooling let us move from raw API data to structured findings in days rather than weeks while a consultant validated every gap and demonstrated the highest-risk exposure (the Copilot data "back door") live in the client's own environment.
- Interviews to find what APIs can't. Four stakeholder sessions â the technology sponsor, the data/BI lead, IT leadership, and the AI initiative's business owner surfaced four findings no scan could detect, including the absence of a governance operating model, an AI agent lifecycle, and cost guardrails for consumption-based AI.
- A verifiable, prioritized deliverable. Every one of the 29 findings shipped with its evidence, its risk framed for a senior living organization, the exact admin-portal path to confirm it, and a recommendation organized into a 30-day / 90-day / continuous roadmap and plotted as quick wins versus strategic investments.
The audit gave leadership a defensible, quantified picture of AI readiness — and a sequenced path to fix it:
- 29 findings across nine domains — 1 Critical, 7 High — including zero DLP policies across all five Power Platform environments, no sensitivity labels published tenant-wide, and privileged access management unconfigured despite being licensed.
- Six figures in licensing value surfaced. The audit mapped every SKU from purchased → assigned → deployed → utilized: 1,000 unassigned paid seats flagged for true-up, ~$4,680/year in Copilot licenses reclaimed from disabled accounts, and a $270K–$335K/year E5 Security investment with two major capabilities confirmed undeployed — activatable at zero incremental cost.
- Copilot renewal right-sized in time. Delivered 21 days before renewal, the seat analysis supported reducing the Copilot commitment by 23–26% while confirming the good news: 81% of assigned users were actively using Copilot — adoption worth protecting.
- PHI risk caught before it landed. Label and DLP gaps were identified while clinical PHI ingestion into Fabric was still in planning — a closing window the client can now act on rather than remediate after the fact.
- Governance made actionable. Findings converted directly into a client roadmap of scored opportunities (impact × complexity), with the top quick wins requiring 15–30 minutes of configuration each.