Copilot Playbook
Copilot Readiness Engagement
Updated August 28, 2026
Engagement Guide · Readiness, Governance and MRR

The Copilot Readiness Engagement

Seven phases from the first scan to recurring governance — for the customers you actually have, on Business Premium, who are not buying E5.

Prepared by Ken Lince — Sr. Director, Cloud Engineering, TD SYNNEX

Your customer cannot safely turn Copilot on until the plumbing is fixed. That is true, and it is why you keep losing the deal.

This guide is about running the governance journey as a sold, profitable, recurring motion — and about the one licensing fact that means the sequence most of the channel is running today does not execute in most SMB tenants.
This is the background reference, not the engagement guide

Start with The Copilot Readiness & Governance Engagement — the same seven phases as gates, checklists, decision tables and effort bands, and the version to work from when you are scoping, quoting or standing up Purview. This page is where its figures come from: the reasoning in full, the evidence and its weaknesses, the practice-building material and the workshop run of show. Read it once; deliver from the other one.


1 · The Conversation That Stalls

There is a version of this meeting that every partner has had. The customer asks about Copilot. You explain, correctly, that before they turn it on you need to look at permissions, data classification, DLP and retention. You are technically right about every word of it. And you watch the energy leave the room.

The usual diagnosis is that the customer is not mature enough, or that they will learn the hard way. Both are comfortable and neither is useful. Here is the more uncomfortable reading, and it is the reason this session exists.

What partners believe

Leading with governance is the responsible opening. You are protecting the customer from an outcome they cannot see coming. If they will not engage with the prerequisite work, the deal was never real.

What the room actually hears

A list of reasons they cannot have the thing they asked for. You have converted a demand conversation into a compliance conversation, and you did it before establishing that anything is wrong.

Watch the order carefully, because it is the whole problem. The customer arrived with demand. You replaced it with an obligation. Nothing in that exchange established that their tenant actually has a problem — you asserted a general truth about Copilot and asked them to fund a project on the strength of it.

The observation this session is built on

In most stalled Copilot deals, the governance objection was raised by the partner, not the customer. Ask any room of partners who has had a Copilot conversation stall on “we need to sort our data out first,” and most hands go up. Ask whose customer said it and whose partner said it for them, and the room gets quiet. That second question is the session.

1.1 · There is a second way to lose this deal, and it is newer

The first failure is the one above — leading with the plumbing. The second is more recent and it is spreading fast among partners who have actually done their homework.

A partner reads up on Copilot readiness, discovers that Microsoft’s oversharing toolkit requires an enterprise license base their customer does not have, and concludes the customer must move to E5. They put a number in front of a 78-person business that roughly doubles its Microsoft bill, and the conversation ends there.

Failure one — the unprepared partner

Opens with governance. Kills the demand before establishing that anything is wrong. Loses on sequence.

Failure two — the well-informed partner

Finds the licensing constraint, believes it means E5, and quotes accordingly. Loses on a conclusion that is wrong.

Both end the same deal. The second one is worse, because the partner walks away believing they did the responsible thing. Section 2 is the correction, and it is deliberately the next thing you read.

This is not an argument for skipping the work. The work is real, the risk is real, and section 9 will show you a licensing wall that makes the standard approach to it fail outright. It is an argument about sequence and about who is carrying the burden of proof.

1.2 · What this guide assumes about you

It assumes you have not really turned Purview on. Perhaps you enabled a label once in a demo tenant. It assumes you have never sat four people from a customer's business down in a room and walked them to a decision about how their documents should be classified. It assumes that when you have quoted this work, you guessed, and that the guess was probably too low or too high by a factor that would embarrass you if you saw the real numbers.

That is not a criticism. It describes most of the channel, including partners who are excellent at everything else. This work sits at an awkward intersection — too advisory for a technician, too technical for a vCIO, and until recently too expensive to tool for a sub-100-seat customer. What follows is written for that reader specifically, which means it explains things a Purview specialist would find obvious and refuses to hand-wave things a salesperson would rather not read.

1.3 · What this guide is not

It is not the shadow AI conversation. That one is already written up in the Shadow AI Assessment Guide — how to open with discovery rather than product, what SMBs actually have running, Microsoft's discovery model, the thirty-app enterprise onboarding matrix, and how to read Partner Center propensity signals into a weekly call list. This guide starts where that one ends: the scan came back, the findings are real, and now somebody has to fix the tenant and get paid for it.

It is also not the post-deployment usage story. Once Copilot is live and you need to prove it is working, that is the Copilot Adoption Audit.

↑ Back to Table of Contents

2 · The Short Version — They Are Not Buying E5

Everything after this section is detail. If you read nothing else, read this page.

Your customer is on Business Premium. They are not buying E5. They do not need to.

Nobody has to forklift. The licenses you sold are not wrong — the AI conversation added one requirement they were never scoped for, and it is addressable for a few dollars a seat.

2.1 · What your customers actually own

Across the 25–300 seat market the answer is almost always Microsoft 365 Business Premium, often mixed with Business Standard on the seats nobody got around to upgrading. That is the normal case, not the failure case, and this guide is written for it.

It matters because Business Premium was sold, correctly, as a complete small-business security stack — Entra ID P1, Defender for Business, Intune, Defender for Office. It is a good SKU and it did the job it was bought for. Copilot did not make it inadequate. Copilot added one requirement that nobody was scoping for in 2023.

2.2 · Split the problem in two, because the licensing does

Half one — data protection

Fully reachable on Business Premium

Sensitivity labels, DLP, retention, insider risk, audit, and the controls that keep labeled content out of Copilot — all of it, through the Purview Suite for Business Premium add-on.

There is no gap here. Do not let anyone tell your customer they need E5 for this.

Half two — permissions

The one thing Business Premium cannot reach

SharePoint Advanced Management — the oversharing toolkit. Data Access Governance reports, Everyone Except External Users insights, Restricted Content Discovery, site access reviews.

Microsoft requires an Office 365 or Microsoft 365 E-SKU base for it. Business Premium and Business Standard are not on the list, and buying Copilot does not change that. Full detail and the verbatim requirement in section 9.

That is the entire gap. One toolkit, one requirement. Everything else in this guide is reachable on the licenses your customer already owns.

2.3 · Three supported ways to cover it. None of them is E5.

Every option below is documented, buyable today, and produces a defensible engagement. They differ in cost, in effort, and in what they leave you unable to do — so the risks are stated with each one rather than buried.

1
Deliver it natively on Business Premium

The SharePoint admin center exposes sharing settings, site permissions and sharing reports. The SharePoint Online PowerShell module enumerates permissions across the estate. Free tooling covers the configuration baseline. This is a complete, legitimate delivery path and it is where most partners should start.

Risk: the output is raw rather than client-ready, so you supply the judgment and the report. There is no continuous monitoring, so you are re-running work rather than watching for drift. Effort grows with site count, and past roughly 100 seats or a handful of customers the consultant hours stop being cheaper than a tool.

License cost $0Best for your first engagementsDetail Section 13
2
A third-party governance platform

Some platforms read Microsoft's security and activity feeds rather than depending on SharePoint Advanced Management, so they run on a Business Premium tenant with no Microsoft license change at all. That is an architectural difference, not a loophole. It is also the only option here that gives you continuous drift monitoring, which is what the recurring fee in section 12 is actually for.

Risk: seat minimums can price out your smallest tenants, and pricing in this category is largely unpublished, so you are quoting against a number you have to go and get. Label-enforcement features generally still inherit Microsoft's E5 requirement, and no platform replaces Restricted Content Discovery.

License change noneBest for a book of customersDetail Section 14
3
Move the base to an enterprise SKU

Microsoft's own documented path. On an Office 365 or Microsoft 365 E-SKU base, a single assigned Copilot license unlocks the whole SharePoint Advanced Management toolset — the governance reports, Restricted Content Discovery, site access reviews. If the customer is heading to E3 anyway, or genuinely needs Restricted Content Discovery, this is the right answer and not a defeat.

Risk: it is the most expensive option per seat, and it does not solve the other half — E3 does not carry the control that keeps labeled content out of Copilot, which still needs the Purview Suite family. Confirm the exact entitlement in writing with Microsoft licensing or your distributor before you quote it, including how it applies in a mixed-SKU tenant. Microsoft states the requirement at organization level and does not publish a partial-adoption scenario, so this is a question to ask, not one to assume.

Highest per-seat costBest for customers who need RCDDetail Section 7
The recommendation

Start with option 1. It costs nothing, it proves you can deliver the engagement, and the findings are the same findings. Move to option 2 once you have enough customers that re-running manual work is the bottleneck — roughly ten, per section 13. Reach for option 3 when the customer specifically needs Restricted Content Discovery, or is moving to an enterprise SKU for reasons that have nothing to do with you.

What you should not do is present an enterprise upgrade as the only way through. It is one of three, and it is the one your customer is least likely to accept.

2.4 · What Microsoft itself recommends

Partners consistently do not know that Microsoft publishes SMB-scale guidance for exactly this, and citing it removes the suspicion that the whole conversation is a partner upsell. Five things Microsoft says, in Microsoft's own words, that you should be repeating.

Microsoft saysWhy it matters to you
Contain, remediate, then un-containApply interim protections, fix the permissions, then remove the interim protections. Partners routinely skip the third step and leave the customer paying for a Copilot that cannot see their own content. Section 8.3.
Start from the default label setMicrosoft auto-creates Personal, Public, General, Confidential and Highly Confidential for eligible customers. Cut that down rather than designing from a blank page.
Keep it to 5×5“Effectiveness is noticeably reduced when users have more than five main labels or more than five sublabels per main label.” At this size, four top-level labels is plenty. Section 10.3.
DLP in audit mode firstThree documented stages — simulation, then policy tips, then enforcement. Enforcing on day one produces the false-positive flood that retires the control permanently.
FabrikamMicrosoft publishes an 18-person startup DLP persona with a prescribed approach. It is the closest thing to official SMB guidance that exists and almost nobody in the channel has seen it. Section 10.5.

2.5 · What it costs, and what you charge

At a 78-seat customerFigureDetail in
Assessment~$100 per seat RangeSection 18.2
Remediation — roughly 2× the assessment$160–$240 per seat ModelSection 18.3
Remediation effort at 50 seats40–60 hours over 30 days Rangenot the 200–400 the channel repeatsSection 17
Ongoing governanceNobody publishes a price. You set the reference.Section 12

2.6 · What to say

The whole conversation, in six sentences

“You are on Business Premium, and that was the right call — it is a genuinely good security stack and it did the job you bought it for. Copilot adds one requirement nobody was scoping for when you bought it, which is knowing who can see what across your SharePoint.

The good news is that the data protection side is a ten-dollar add-on, and Microsoft is running it at half price alongside Copilot until the end of the year. Nobody is asking you to move to E5.

The permissions side needs one extra piece, and there are three ways to get it — one of which costs about as much as three licenses. Let me find out which one applies to you before either of us assumes it is expensive.”

Two ways partners lose this deal, and both are avoidable

One: open with the governance work and watch the demand evaporate before anything has been established. Section 1.

Two: discover the SharePoint Advanced Management requirement, conclude the customer has to buy E5, and quote a number that ends the conversation. That conclusion is wrong, and this section is the reason.

↑ Back to Table of Contents

3 · What Actually Goes Wrong — And What Doesn't

Every guide in this category opens with a statistic designed to frighten a business owner. Most of those statistics come from companies selling the remedy, and a prospect with a search engine can work that out in ten minutes. So this section does something less satisfying and more durable: it separates what is actually documented from what is merely repeated, and it tells you which arguments survive a skeptical room.

3.1 · The incident worth knowing by its ID

In January 2026, Microsoft 365 Copilot Chat began returning summaries derived from content in users' Drafts and Sent Items — including messages carrying confidentiality sensitivity labels and covered by DLP policies specifically configured to exclude them from Copilot processing.

Microsoft tracking IDCW1226324
First reported by customers21 January 2026
Fix rolloutBegan early February 2026; remediation still incomplete mid-February
Approximate exposure windowFour weeks
Content categories involvedLegal memos, business agreements, government correspondence, protected health information
Named affected organizationUK National Health Service, tracked internally as INC46740412. NHS stated patient information was not exposed.
Microsoft's positionThat users only accessed information they were already authorized to see
Number of tenants affectedNot disclosed

Read Microsoft's response again, because it is the reason this incident matters more than any statistic in this guide. Users only accessed information they were already authorized to see. That is the exact sentence your prospect will say to you when you raise oversharing. Here it is being said by Microsoft, about an incident in which a customer had configured labels and DLP correctly and the control plane bypassed both anyway.

What this actually proves — and what it does not

It does not prove Copilot is unsafe. It proves something more useful and more sellable: the control plane is new, it changes monthly, and neither Microsoft nor the customer had independent visibility into whether the controls were doing what they were configured to do.

That is an argument for a monitored, recurring governance service. It is not an argument for a one-time cleanup project, and a partner who uses it to sell one has misread it.

Handle with precision

This is a label-scope failure, not a permissions failure

Do not let CW1226324 compress in retelling into “Copilot leaked NHS patient data.” The NHS explicitly said it did not. If you overstate this in a room and someone looks it up, you lose the entire section along with your credibility on everything after it.

3.2 · The gap you must be honest about

Here is the finding that most competing material will not tell you.

Say this out loud before someone else says it to you

There is no published, named-company case study of Microsoft 365 Copilot surfacing HR or salary data to the wrong employee. Not one that survives a search. The stories circulate constantly in the channel and they are almost certainly happening, but companies do not publish “we bought AI and it embarrassed us,” and no breach-notification regime compels them to.

The corollary is equally important: there is also no enforcement action anywhere — no GDPR fine, no FTC action, no ICO reprimand — against a company for an AI-assistant oversharing incident. If you imply otherwise you are inventing regulatory risk, and the customer's lawyer will find out.

What you can cite is a corpus of a different shape: vendor-side product failures like CW1226324, and security research disclosed and patched before anyone exploited it. Both are real. Neither is a customer scandal. Argue from mechanism, and use the incidents to show the mechanism is not hypothetical.

3.3 · The mechanism arguments that hold up

EXHIBIT A

The index remembers what you revoked

Lasso Security found 20,580 repositories across 16,290 organizations — including Microsoft, Google, Intel, PayPal and IBM — still reachable through Copilot after being made private, because a search cache retained them. Disclosed Nov 2024, addressed Jan 2025.

EXHIBIT B

Permission hygiene does not close the boundary

PromptArmor demonstrated exfiltration of private-channel Slack data via an instruction planted in a public channel and ingested into the AI's index. The attacker never needed access to the private channel. MITRE ATLAS AML.CS0035.

EXHIBIT C

Your existing stack cannot see it

Radware's ShadowLeak was the first service-side zero-click prompt injection — the whole chain executes inside the AI vendor's cloud, leaving no artifact on the endpoint or the network. EDR and network monitoring are blind to this class of event by construction.

Exhibit A is the one to use with a non-technical owner, because the principle is intuitive and it transfers directly to Microsoft 365: once an index has seen something, taking away access to the original does not take it out of the index. That is precisely why Restricted Content Discovery requires a reindex rather than taking effect instantly.

The zero-click Copilot vulnerabilities — EchoLeak (CVE-2025-32711, CVSS 9.3, disclosed June 2025) and CoSnitch (CVE-2026-24301, disclosed December 2025, patched August 2026) — belong in a technical conversation and nowhere near a business owner. Every one of them was responsibly disclosed and patched with no confirmed exploitation in the wild. Cite them for mechanism; never imply harm occurred. CoSnitch has one genuinely SMB-relevant angle: it affected Copilot Personal, which is exactly the shadow-AI pattern a readiness assessment is supposed to find.

3.4 · Prevalence — the modest number beats the terrifying one

Varonis scanned roughly 1,000 real environments covering about ten billion files. The number worth quoting from it is not the frightening one.

1 in 10
of organizations had any labeled files at all
Varonis, 2025 State of Data Security — vendor research
66%
had cloud data exposed to anonymous users
Same sample. Vendor research.
88%
had stale but still-enabled ghost user accounts
Same sample. Vendor research.
99%
had sensitive data “easily surfaceable by AI” — do not use this one
Too high to be believed. It costs you the room.

Lead with one in ten. It is modest, it is checkable, and the customer will recognize it as true about themselves before you finish the sentence. The 99% figure is worse rhetoric precisely because it is unbelievable — a number that high reads as marketing, and it invites the prospect to discount everything else you say.

Two numbers circulating in partner decks that you should stop using

“802,000 at-risk files per organization.” Widely presented as current. It traces to a 2022 report. Date it 2022 or drop it.

“150–300 overshared SharePoint sites per tenant.” No published methodology anywhere, and it describes enterprise tenants regardless. A 78-seat firm does not have 300 sites, which makes this actively misleading in an SMB room.

There is also no credible statistic for how much stale or redundant data sits in a typical SMB SharePoint estate. Argue that one from the customer's own reports, not from a number.

3.5 · The argument that actually works

Everything above is defensive — it stops you from being wrong. This is the part that wins.

Forrester's commissioned Total Economic Impact study of Microsoft 365 Copilot interviewed sixteen decision-makers across twelve organizations and surveyed 367 people with Copilot experience. The headline ROI figures are enterprise-composite and you should not use them with a 78-seat customer. One finding transfers completely.

70% of the organizations Forrester surveyed ran data security projects before deploying Copilot.

The reference deployments that produced the returns Microsoft advertises are overwhelmingly the ones that did this work first. You are not selling protection from a disaster that might not happen. You are selling the precondition that the successful deployments had and the stalled ones did not.

That reframing does more commercial work than every incident on this page combined, because it converts governance from a tax into a success factor. It also happens to be true, which means it survives being checked.

The version to say out loud

“I am not going to tell you Copilot is dangerous, because mostly it isn't. What I will tell you is that when Forrester looked at the companies who got the returns Microsoft advertises, seven in ten had done a data security project first. That is the difference between the deployments that worked and the ones that quietly stalled. I would rather put you in the first group, and it is cheaper to do that now than to unpick it later.”

3.6 · Be fair, or lose the room

A guide that only presents risk is a guide the customer stops trusting the moment they read something balanced. Two pieces of honesty you should carry into every meeting.

Most deployments proceed without an incident. The absence of published customer scandals cuts both ways. If Copilot were routinely producing HR disasters across tens of thousands of tenants, some would have surfaced through employment tribunals or trade press by now. The dominant observed customer-side outcome is delay and friction, not breach.

The pilot-to-scale statistics are contested and you can get caught. Gartner-derived material puts the share of organizations moving past pilot in the single digits. A Morgan Stanley and RSM survey reports 79% of enterprises deployed with half past pilot. Those cannot both describe the same population. If you quote the pessimistic figure to a prospect who read the optimistic one, you have lost. What is not contested is that governance work is a common cause of delay — roughly two-thirds of surveyed IT leaders reported that information governance and security risks consumed significant time and resources during deployment. Argue that, and leave the decimal points alone.

↑ Back to Table of Contents

4 · When This Conversation Happens

Timing is the difference between a governance conversation that lands and one that sounds like an upsell. The rule is simple: you want an external party to have already asked the customer a question they cannot answer. Then you are helping them answer it rather than manufacturing a reason to care.

Ranked by how often they actually apply to a business under 100 people, and by how hard a deadline they carry.

4.1 · Cyber insurance renewal — the strongest lever, and the least used

It is annual, it is sector-agnostic, it is headcount-agnostic, it has a hard date, and it has a named signer who is personally uncomfortable attesting to something they do not know. Nothing else in this list has all five properties.

What changed, and why almost nobody in the channel has noticed yet: the standard-forms body introduced generative-AI exclusion endorsements for commercial general liability — CG 40 47, CG 40 48 and CG 35 08 — effective 1 January 2026, and carriers began attaching them at renewal. Cyber policies remain the more stable source of AI coverage for now, but carriers are adding AI sublimits, reported at around a tenth of policy limit in some cases. Some carriers are writing affirmative AI coverage deliberately and pricing it against documented governance.

Before 2026, most organizations were covered for AI losses by silence rather than by grant. That silence is being written out of policies right now, quietly, at renewal.

The discovery question that does the work

“Pull out your last general liability and cyber renewal endorsements. Not the policy — the endorsements. Do you have a generative AI exclusion on there? Most companies acquired one this year without being told. And if your cyber policy now carries an AI sublimit, I would want to know what it is before your staff put another client document into a chatbot.”

The customer can verify this themselves in ten minutes, which is exactly what makes it powerful. You are not asking them to believe you.

The limit of this argument

There is no published, adjudicated insurance claim denial attributable to AI use. The exclusions are only months old. Argue the underwriting shift — which is documented and verifiable — and do not imply that anyone has been denied a claim yet, because as far as the public record shows, nobody has.

4.2 · The sector rules that genuinely apply

TriggerWho it actually coversWhy it forces the conversation
FTC Safeguards RuleAccountants, tax preparers, auto dealers arranging finance, mortgage brokers, and insurance brokers under GLBARequires a written risk assessment and a designated qualified individual. Note the trap: the fewer-than-5,000-consumers exemption removes exactly the written risk assessment you were planning to sell. Check the count first.
CMMC Phase 1Defense contractors and subcontractors handling federal contract informationIn force since 10 November 2025; self-assessment gates contract award. The sharpest deadline available, applying to a narrow slice of the channel.
ABA Formal Opinion 512 and 35+ state barsLaw firms of any sizeIssued 29 July 2024. Creates a professional-conduct obligation around confidentiality when using generative AI. For a small firm this is the partner's license, which concentrates attention.
Illinois HB 3773Any employer with Illinois staffEffective 1 January 2026. Reaches employers who have never thought of themselves as regulated.
HIPAA's existing risk-analysis dutyCovered entities and business associatesAlready in force — you do not need the proposed Security Rule update, which now targets 2027. Benefits administration drags ordinary companies into business-associate status more often than they realize.

4.3 · What does not apply, and why saying so wins you the deal

This is the highest-credibility paragraph in the guide. Most partner marketing overstates regulatory applicability to small business, and sophisticated buyers know it. Being the partner who narrows the claim is worth more than any statistic.

Commonly citedThe actual position as of August 2026
EU AI ActEnforcement provisions apply from 2 August 2026 with penalties up to €35M or 7% of global turnover — but high-risk obligations were pushed to December 2027 and August 2028. An SMB using Copilot is a deployer, not a provider, and carries far lighter obligations than most partner decks imply.
Colorado AI ActSB 24-205 was repealed and replaced. The replacement takes effect 1 January 2027. Any partner material still citing a February 2026 Colorado deadline is citing a law that no longer exists.
California ADMT rules1 January 2027, and gated behind CCPA applicability thresholds that most sub-100-seat businesses do not meet.
ISO/IEC 42001A genuine and useful frame — see section 12 — but it is a voluntary standard, not a legal obligation. Audit and implementation costs put certification out of reach for most SMBs. Use the structure; do not sell the certificate by default.
The move

When a customer says “I read the EU AI Act is going to hit us,” the winning answer is “probably not, and here is why.” You have just demonstrated you are not fear-selling, which makes the one lever that does apply to them — almost always the insurance renewal — land with far more weight.

4.4 · The trigger nobody plans for

An enterprise client sends your customer a security questionnaire. It now contains AI questions: do you have a written AI acceptable use policy, do you record training completion, have you performed a dated AI risk assessment, do you audit tool usage. Your customer cannot answer any of them, the questionnaire is blocking a contract renewal, and they need it back this week.

That is the highest-urgency, highest-margin entry point available, and it arrives without warning. Build the questionnaire-response artifact once and it becomes a repeatable rapid-response offer rather than a scramble. It is also the cleanest possible qualification signal: someone with buying power already cares.

↑ Back to Table of Contents

5 · What Success Looks Like

This is a long document. Before you wade into it, here is the finished thing — one complete engagement, start to finish, on a customer that looks like most of your book.

The customer

Around 80 employees. Roughly two-thirds on Microsoft 365 Business Premium, the rest on Business Standard because nobody got around to it. SharePoint was migrated off a file server a few years ago and the folder structure still mirrors the old drive. Purview has never been configured. Their cyber insurance renews in 90 days, and a carrier questionnaire just arrived with AI questions on it that nobody can answer.

They are not buying E5. They were never going to buy E5.

5.1 · The engagement, week by week

Week 0 — Phase 1

Qualify and scope · 90 minutes, free

A conversation about the insurance renewal and the questionnaire, then an automated tenant scan. It comes back with a site count, an exposure count, and a list of anonymous links. That is not the deliverable — it is what lets you quote accurately instead of guessing. Phase 1 in detail.

Week 1 — Phase 2

The licensing decision · one meeting

Purview Suite attached at $10 per user per month MS list, half price alongside Copilot, which covers the entire data-protection half. Then the one real decision: which of three supported options covers the permissions half. No E5 in the conversation at any point. Phase 2 in detail.

Weeks 1–2 — Phase 3

The assessment · 20–35 partner hours

Find what is actually exposed, sort it against three gates, and produce a costed remediation plan with a named list of sites. Findings readout to the owner. Everything that is not a gate gets explicitly deferred — that is what keeps this a four-week engagement instead of a six-month program. Phase 3 in detail.

Weeks 3–6 — Phase 4

Remediation · 40–70 partner hours

Replace the organization-wide grants, expire the anonymous links, remove the leavers and stale guests, break inheritance where it should never have been inherited. In one typical engagement a single misconfigured share accounted for about 80% of the high-priority work. Phase 4 in detail.

Weeks 3–6, in parallel — Phase 5

Purview stand-up · a workshop and a wait

A 90-minute classification workshop with four people from the business produces a signed page of policy intent statements. Four labels get published, DLP goes into audit mode. Then you wait, because Microsoft's propagation timers are not negotiable. Phase 5 in detail.

Week 7 — Phase 6

Enable, pilot, and un-contain

Copilot on for a pilot group. Any interim containment applied in week 3 comes back off — the step partners forget, and the one that decides whether the customer thinks the product works. Phase 6 in detail.

Month 3 onward — Phase 7

Ongoing governance · the part that compounds

A monthly drift report, a quarterly review, and an annual reassessment timed to the insurance renewal so the fee always has an external reason to exist. Phase 7 in detail.

5.2 · The same thing as a table

PhaseElapsedPartner hoursTools usedWhat the customer gets
190 minutes1.5Automated tenant scan; free config baseline toolingA site count, an exposure count, and a fixed-price proposal that is not a guess
2One meeting2–3Microsoft 365 admin center; a licensing decision tablePurview Suite attached; a chosen route for the permissions half
31–2 weeks20–35Native SharePoint reports and PowerShell, or a governance platformFindings report, three gates identified, costed remediation plan, deferral list
43–4 weeks40–70SharePoint admin center, PowerShell, platform bulk-remediationPermissions actually fixed, against a named list of sites
5Parallel15–25Microsoft PurviewFour labels published, DLP in audit mode, signed policy intent statements
61 week6–10Microsoft 365 admin center; Copilot DashboardCopilot live for a pilot group, containment removed, adoption handoff
7Ongoing~5 / monthGovernance platform or scripted re-runsMonthly drift report, quarterly review, annual reassessment
Total: about seven weeks and 85–145 partner hours to a live, governed Copilot pilot

Not six months. Not 400 hours. The enterprise numbers circulating in the channel describe tenants with 200+ SharePoint sites — an 80-seat business has around 30. If you have been quoting this work from enterprise literature, you have been pricing yourself out of deals you should be winning. Section 17 is the arithmetic.

5.3 · What it was worth

$7,800
Assessment, at roughly $100 per seat Range
Credited in full against remediation
$14,000
Remediation, fixed fee against a named site list Model
Roughly 2× the assessment
$1,400
Per month, ongoing governance Model
Floor-priced, not pure per-user
$16,800
Recurring, every year after Model
Year one lands near $30,600

Every figure above is a model composed from the sourced inputs in section 18, shown so you can rebuild it against your own cost base rather than copy it. The point is not the numbers. The point is the shape: a project that pays for the practice, and a recurring line that compounds across the book.

5.4 · And what the customer got

OUTCOME 1

Copilot, live, in seven weeks

Not blocked, not deferred pending a governance program. The demand that started the conversation actually got served.

OUTCOME 2

The questionnaire answered

The carrier's AI questions have documented answers, with a dated risk assessment behind them, in time for the renewal.

OUTCOME 3

No license upheaval

A $10 add-on and, at most, a handful of extra seats. Their Microsoft bill did not double and nobody had to justify an E5 migration.

OUTCOME 4

Somebody is watching it

The permissions do not silently drift back, and when Microsoft changes the control plane underneath them — which it does — someone notices.

How to read the rest of this guide

Sections 6 through 12 are those seven phases, one per section, with what has to be done and why it has to be done in that order.

Sections 13 through 15 are the supporting decisions — which tools, which vendor, who on your team delivers it. Sections 16 through 18 are the money in full. Section 19 is how you turn one engagement into a practice, and section 20 runs the workshop.

↑ Back to Table of Contents

6 · Phase 1 · Qualify and Scope

Ninety minutes, no charge, and it is the most commercially important phase in the engagement — not because of what it finds, but because of what it lets you quote.

6.1 · Why the scan is free

Distribution has been packaging and part-funding automated readiness scans since 2026, several of them at no cost to the partner. You cannot charge for something a distributor is giving away, and trying to will lose you the deal on price before you have said anything interesting.

Give it away deliberately. It costs you 60–90 minutes of platform time and it does one job nothing else does.

The point This is the whole reason Phase 1 exists

The scan's real product is a site count

Remediation effort scales with sites, libraries and distinct permission structures — not with headcount. But seat count is the only number the buyer knows when they ask you for a price.

Quote from a site inventory, not from a headcount. The scan is what converts one into the other, and it is why a partner who skips it either over-quotes and loses, or under-quotes and eats the difference.

6.2 · What you are looking for

SignalWhat it tells you
Number of SharePoint sites and librariesThe scoping variable. Under about 30 sites this is a small engagement; past 60 it is a different quote.
Sites shared organization-wideGate 1 exposure. Often concentrated in one or two sites that came from a file-server migration.
Live anonymous linksFast, visible, cheap to fix — your week-one credibility win.
Disabled accounts still holding grants, and stale guestsGate 2. Cheapest finding in the engagement and the one a regulator would ask about first.
Whether Purview has ever been configuredAlmost always no. Determines whether Phase 5 is a stand-up or a tune-up.
The license mixBusiness Standard versus Business Premium versus anything else. Sets up the Phase 2 conversation entirely.

6.3 · The qualifying questions

Six questions. If you cannot get satisfying answers to the first three, this is not a deal yet — it is an education conversation, and you should treat it as one rather than writing a proposal.

  1. “When does your cyber insurance renew, and can I see the endorsements from last time?” The strongest lever in this market, and the customer can verify everything you say about it in ten minutes.
  2. “Has anyone sent you a security questionnaire with AI questions on it?” If yes, you have a deadline and a sponsor who already cares.
  3. “Who decides when a control blocks someone's work?” If the honest answer is nobody, that is Gate 3 and it is a bigger finding than anything technical.
  4. “Where did your SharePoint come from?” A file-server migration predicts the shape of the exposure almost perfectly.
  5. “Has anyone here bought AI tools on a personal card?” Usually yes, and usually the person asking. See the Shadow AI Assessment Guide.
  6. “What made you ask about Copilot now?” The answer tells you whether you are selling to demand or manufacturing it.

6.4 · What you do not do yet

The Phase 1 trap

Do not start fixing things during the scan

It is tempting — you can see an anonymous link, you have the access, it takes thirty seconds. Do not. The moment you remediate for free you have taught the customer that remediation is free, and you have also lost your own before-and-after evidence.

Equally: do not present findings as findings yet. A raw scan output handed over without judgment is a report anyone could have run, and it is the thing most likely to walk to a cheaper competitor. The scan produces a scope. The assessment produces findings, and the assessment is billed.

6.5 · What Phase 1 produces

Closing Phase 1

“I ran the scan. You have 31 SharePoint sites, and four of them are shared with everybody in the company — including the one your old file server turned into. There are nine anonymous links still live, two of them older than the staff who created them.

I am not going to tell you what is in those sites yet, because I do not know and neither do you. That is the assessment, it is fixed price, it takes two weeks, and if you go ahead with the fixes afterward I credit the whole fee against them. Before your insurance renewal, this is the cheapest week you will spend all year.”

↑ Back to Table of Contents

7 · Phase 2 · The Licensing Path

Nobody in this market is buying E5. Assume that as the starting condition rather than the objection, and the licensing conversation becomes short and winnable.

Partners lose it by presenting a feature matrix. The customer does not want to know what E5 includes. They want to know what to buy on Monday, and whether you are about to double their bill. This section is built as decisions, not comparisons.

MS list published Microsoft price or documented entitlement Survey named survey with a stated sample Range community-reported, multiple independent sources Model composed here from cited inputs — a construction, not a citation

7.1 · The number that changes the conversation

The reflexive channel pitch is “you need to upgrade to E5.” A Business Premium customer hears that as double my Microsoft bill, and the deal stalls. It has also been wrong since September 2025, when Microsoft started selling the governance stack as add-ons scoped specifically to Business Premium.

ComponentPriceNotes
Microsoft 365 Business Premium (base)$22 /user/mo RangeHeld at this price through the July 2026 adjustments. Reseller-corroborated rather than read off a Microsoft page.
Purview Suite for Business Premium$10 /user/mo MS listMicrosoft's words: “$10.00 user/month, paid yearly”, “Maximum of 300 seats”, “Requires a Microsoft 365 Business Premium subscription”
Defender + Purview Suites combined$15 /user/mo RangeWidely and consistently reported; not read off a Microsoft page in this research
= the SMB governance stack~$37 /user/mo ModelBusiness Premium plus both suites
Microsoft 365 E5, for comparison$60 /user/mo RangeRose from $57 on 1 July 2026
Microsoft is funding this motion directly, and it expires

50% off Purview Suite for Business Premium when purchased with Microsoft 365 Copilot, available 1 December 2025 through 31 December 2026 MS list. Microsoft's own page frames it around smooth AI rollout. Distribution is running first-year promotions alongside it, several expiring on the same date, and funded deployment services are available on top — see section 15.5.

Verify current terms with your TD SYNNEX rep before quoting. Promotions move.

7.2 · The two mis-sales

Mis-sale 1

E3 is not the compliance step-up customers think it is

Microsoft's own DLP documentation marks “restrict Copilot from processing files and emails” as unavailable on Business Premium and unavailable on E3. Only the E5 family and the Purview Suite line carry it.

A customer who buys E3 specifically to govern Copilot has bought the wrong thing. They have cleared the SharePoint Advanced Management base requirement — which is genuinely useful and may be the whole reason to do it — but they have not bought the ability to keep labeled content out of Copilot. Be explicit about which problem the E3 step-up solves, because it solves exactly one of the two.

Mis-sale 2

Selling label-based Copilot exclusion on bare Business Premium

The capability is not there on the base SKU. With the Purview Suite add-on attached it is in scope — Microsoft lists “policy-based controls for AI experiences and Copilot interactions” among the suite's capabilities.

Promise this on base Business Premium and you will be discovered at configuration time, in front of the customer, by a support engineer.

7.3 · What the Purview Suite actually includes

Microsoft's published capability list for the Business Premium suite: automated data classification, labeling and protection; sensitive data discovery and data mapping; DLP across apps, devices and cloud services; automated retention, deletion and records management; insider risk analytics with adaptive protection; advanced eDiscovery with legal hold; enhanced audit logging with extended retention; policy-based controls for AI experiences and Copilot interactions; communication compliance; Compliance Manager. Plus message encryption, Customer Lockbox, Customer Key, information barriers and privileged access management.

One thing to be careful about naming

Microsoft's page does not use the term “DSPM for AI” anywhere. Third-party summaries say it is included; Microsoft's own phrasing is “policy-based controls for AI experiences.” The Purview service description has no DSPM section at all, and DSPM for AI has itself been superseded by a newer unified experience.

Do not tell a customer DSPM for AI is included in the Business Premium Purview Suite until you have seen it in their tenant. Describe the capability, confirm the product surface in configuration. This is the single most likely place to make a confident wrong claim.

7.4 · What each combination actually gets you

This is the table to have open when a customer asks what they need to buy. Read it as: everything green is reachable on what most SMBs already own.

Capability Business
Premium alone
BP +
Purview Suite
Microsoft 365
E3
What decides it
Sensitivity labels, published and applied manuallyYesYesYesIncluded broadly
DLP for email and documentsYesYesYesBase entitlement
DLP extended to Teams chat and endpointsNoYesNoPurview Suite
Keep labeled content out of CopilotNoYesNoThe mis-sale in 7.2. E3 does not carry this.
Insider risk, communication compliance, Audit PremiumNoYesNoPurview Suite
Auto-labeling of files and emailsNoConfirmNoMicrosoft names E5-family; suite inclusion unconfirmed — Q2
Conditional Access, guest and leaver cleanupYesYesYesEntra ID P1, in Business Premium
Shadow AI discovery (full CASB)NoConfirmNoDefender Suite — Q3
Governance reports, EEEU insights, site access reviewsNoNoYes*SharePoint Advanced Management. Needs an E-SKU base plus one assigned Copilot license.
Restricted Content DiscoveryNoNoYes*Same. The only capability with no substitute — see 9.5 for the alternative approach.

* Requires at least one Microsoft Copilot license assigned in the tenant, on top of the E-SKU base.

The two-line summary

Business Premium plus the Purview Suite covers everything in the data-protection column. That is most of Copilot readiness, and it is a $10 add-on.

The last two rows are the only genuine gap, they are both SharePoint Advanced Management, and section 2.3 gives you three supported ways to cover them — two of which require no license change at all.

7.5 · The decision table

If the customer needs…BuyBecause
Labels, DLP, insider risk, Copilot interaction controls, audit retentionBusiness Premium + Purview Suite$10/user/mo, 300-seat cap, half price alongside Copilot through 31 Dec 2026
Shadow AI discovery and full CASB+ Defender Suite (combined $15)Business Premium has no CASB. Verify that the suite carries full Defender for Cloud Apps before promising discovery.
DAG reports, EEEU insights, Restricted Content Discovery, site access reviewsAn E-SKU base — or a third-party platformThe wall in section 9. No Business Premium add-on reaches SharePoint Advanced Management.
Auto-labeling of files and emailsE5 family VerifyMicrosoft states the symptom for “E3 or Business Premium” explicitly. Whether the Purview Suite lifts it is unconfirmed — test before scoping.
Copilot itself, under 300 seatsCopilot Business SKUsSequencing trap: you cannot upgrade to an Enterprise plan from Business Standard or Premium with Copilot Business until commitment end. A growing customer can be stuck for up to a year. Decide before attaching.
Security CopilotDo not sell it hereProvisioned capacity is priced per hour and the included-capacity model is E5/E7 only. Not an SMB motion.

7.6 · Two things that belong in the engagement letter

These are delegated-administration constraints, and they will surprise you mid-engagement rather than at scoping.

While you are there: the Purview role model will bite you at least once. Viewing file contents in simulation results requires the Data Classification Content Viewer role, which Global Admin does not hold by default, and turning a policy from ready to on requires Compliance Administrator or Compliance Data Administrator. Without them the button is simply greyed out with no explanation. Assign both before you start rather than losing a day to each.

↑ Back to Table of Contents

8 · Phase 3 · The Assessment — Finding to Control to Gate

This is the section the guide exists for. Partners over-scope this work because nobody has ever told them what is optional. The bridge separates the two or three things that must be true before Copilot is enabled from the much longer list of things that can safely follow it.

8.1 · The three gates, and nothing else

Everything in Purview and SharePoint governance is useful. Almost none of it is a gate. These three are.

Gate 1 Must be true before enablement

Nothing sensitive is reachable by “everyone”

Specifically: no site or library containing regulated, financial, HR or client-confidential content is shared with an organization-wide group, an Everyone Except External Users grant, or a live anonymous link.

Why it gates: Copilot inherits the permission model exactly. Every one of these becomes queryable in natural language on day one. This is the finding that produces the incident nobody publishes.

Gate 2 Must be true before enablement

Leavers and guests are actually gone

Disabled accounts still holding grants, guest accounts from finished projects, and shared mailboxes with lingering access. Cheap to fix, fast to verify, and the single most defensible item on the list — regulators fine for this even without AI in the picture.

Why it gates: it is the cheapest credibility you will ever buy, and it makes the whole engagement look competent in week one.

Gate 3 Must be true before enablement

Somebody owns the exception path

A named person — on the customer side — who decides what happens when a control blocks legitimate work. Not a policy document. A person, with a decision route and a response time.

Why it gates: this is the one partners skip, and it is the one that kills engagements in month two. Without it, the first false positive escalates to the managing partner and your controls get switched off by someone who outranks everybody who understands them.

8.2 · What is not a gate

All of the following are genuinely valuable and none of them should stop a Copilot rollout. Sequencing them after enablement is not negligence; it is the difference between a four-week engagement and a stalled six-month one.

WorkTimingWhy it can wait
A complete sensitivity label taxonomy applied across the estateAfterFour labels published and a default set is enough to start. Full coverage is a program, not a prerequisite.
Auto-labeling policiesAfterRequires simulation cycles and, on most SMB SKUs, a license you have not sold yet. See section 10.
DLP in enforcement modeAfterMicrosoft's own documented rollout is audit first, then policy tips, then enforce. Enforcing on day one produces the false-positive flood that retires the control.
Retention and records managementAfterA lifecycle program with its own business case. Unrelated to whether Copilot is safe today.
Custom sensitive information types and trainable classifiersMuch later, if everAt 25–300 seats these are almost always out of scope. Built-in types cover the realistic cases.
Insider risk management and communication complianceAfterReal capabilities that need a mature customer and a reason. Selling them at gate stage makes you sound like you are inventing scope.
Cleaning up redundant and obsolete dataAfterImproves answer quality and cuts storage. It is a follow-on project with its own economics, not a gate.

8.3 · The interim-protection pattern, and the step everyone skips

Microsoft's own deployment blueprint prescribes a three-move pattern that most partners execute two-thirds of.

Move 1 — Contain

Apply interim protections

Restricted Content Discovery on the worst sites, plus DLP scoped to keep labeled content out of Copilot processing. This buys time without waiting for a full permissions cleanup. Both carry license prerequisites that most SMB tenants do not meet — see sections 6 and 7.

Move 2 — Remediate

Actually fix the permissions

Break inheritance where it should never have been inherited, replace organization-wide grants with scoped groups, expire anonymous links, remove leavers and stale guests.

Move 3 — Un-contain

Remove the interim protections

Once the permissions are right, take the containment off so Copilot can see the content it legitimately should.

The trap

Move 3 never happens

Partners contain, remediate, and then leave the containment in place because nothing forces them to remove it and removing it feels like a risk. The customer is now paying full price for a Copilot that cannot see their own content, concludes the product is useless, and does not renew.

This is the most common way a technically successful engagement produces a commercially failed one. Put move 3 in the statement of work as a dated, billable milestone so somebody is accountable for it.

8.4 · The map

What the assessment findsThe control that answers itPositionOn Business Premium?Note
Site shared with Everyone Except External UsersReplace grant with a scoped group; break inheritanceGate 1Fixable finding it needs a route from §2.3Usually the single largest share of high-priority remediation
Live anonymous sharing linksExpire links; tighten tenant default link typeGate 1Yes native admin centerFast, high-visibility win
Disabled accounts retaining grantsOffboarding cleanup; access reviewGate 2Yes Entra P1Regulators fine for this without AI involved
Stale guest accountsGuest expiry / removalGate 2Yes Entra P1Included in Business Premium
No owner for blocked-work decisionsNamed exception owner + route + response timeGate 3Yes no license involvedNot a technical control. Still a gate.
Sites with sensitive content and no labelPublish four labels; manual labeling at container levelAfterYes Purview SuiteContainers before files
Sensitive content leaving via chat or emailDLP, audit mode firstAfterYes Purview SuiteAudit → policy tips → enforce
Automatic labeling at scaleAuto-labeling policiesAfterVerify gated above base SKUConfirm before scoping — §21.2
Content Copilot should never ground onRestricted Content DiscoveryInterim onlyNeeds a routeMust be removed after remediation. Needs a Copilot license assigned and an eligible base SKU.
Who can reach what, across the estatePermission and exposure reportingGate 1Needs a route§2.3The one genuine gap. Option 1, 2 or 3.
Personal AI accounts in useSanctioned tenant AI + conditional accessParallel trackYesSee the Shadow AI Assessment Guide
Redundant and obsolete data degrading answersLifecycle and archivalFollow-onYes Purview SuiteSell on storage cost, not risk
Permissions drifting back after cleanupContinuous drift monitoringRecurringThird partyThis is the MRR. See section 12.
Read the fourth column before you scope

Almost everything on this list is reachable on the licenses your customer already owns. One row is not — permission and exposure reporting across the estate — and it is the row Gate 1 depends on. That single row is what section 2.3's three options exist to solve, and what section 9 documents.

Scoping an engagement without knowing which route the customer is on is how partners end up quoting an E5 upgrade they never needed to quote.

The line to take into the room

“There are three things that have to be true before we turn this on. Everything else on this list is real work that makes the product better, and none of it has to happen first. I would rather get you to value in four weeks and keep improving than sell you a six-month program you will cancel in month three.”

↑ Back to Table of Contents

9 · Phase 4 · Remediation — The Permissions Work

Gate 1 is the hard one. It is also where the standard channel playbook needs adjusting for this market — for a documented reason most partners have not yet run into.

Section 2 already gave you the answer. This section is the evidence behind it, so that when a customer or a competitor challenges you on it, you can show them the page.

9.1 · Why “Copilot respects existing permissions” is true and is not a defense

Microsoft's statement is accurate. Copilot does not grant access to anything a user could not already open. Partners repeat it as reassurance, and customers repeat it back as an objection. Both are making the same error.

What the statement describes

Access control. Whether a user is permitted to open a file. Copilot changes nothing here and never has.

What it says nothing about

Exposure. Whether a user will ever find the file. For thirty years the answer was no — nobody browses to /Company/Shared/Old HR/2019. Natural language search removed that friction entirely.

The salary spreadsheet sitting in the customer's main SharePoint site has typically been readable by every member of staff since the file server was migrated. Nobody found it, because finding it required knowing it existed and where it lived. Ask Copilot “what do our senior account managers earn,” and the friction that was doing all the actual protection is gone.

The proof that this distinction is real

Restricted Content Discovery exists. Microsoft built a feature whose entire purpose is to stop Copilot surfacing content that users are already permitted to open. If “they technically had access” were a sufficient answer, that feature would have no reason to exist.

9.2 · The toolkit Microsoft built for exactly this

SharePoint Advanced Management is the answer to Gate 1. It is comprehensive and it is genuinely good.

CapabilityWhat it gives you
Data Access Governance reportsPermission state across sites, OneDrive and files; site permissions for a given user; sensitivity label snapshot; sharing links activity
Everyone Except External Users insightsTop items and groups shared with EEEU in the last 28 days, and which policies apply to those sites. Directly answers Gate 1.
Restricted Content DiscoveryPrevents high-risk sites and files surfacing in Copilot and agent experiences — the interim protection in move 1
Restricted Access ControlLimits site access to specific groups
Site access reviewsDelegates review of DAG findings to site owners rather than making the MSP guess
Site ownership policies, attestations, inactive site policiesThe lifecycle half — who owns this, is it still needed
Agent access insightsHow agents interact with SharePoint and OneDrive content

9.3 · The constraint, in Microsoft’s own words

Microsoft's prerequisites page for SharePoint Advanced Management states the base requirement in one short list. Read it carefully.

Microsoft 365 base subscription. Your organization must have one of the following base licenses:
— Office 365 E3, E5, or A5
— Microsoft 365 E1, E3, E5, or A5
— Microsoft 365 GCC, GCC-High, or DoD Microsoft Learn, Prerequisites for SharePoint Advanced Management — page dated 30 June 2026, updated 18 August 2026, verified 28 August 2026
The point Read this twice

Microsoft 365 Business Premium is not on that list. Neither is Business Standard.

The Copilot unlock — one assigned Microsoft Copilot license anywhere in the tenant — is a second, additional condition. It is not a substitute for the base requirement. Microsoft's page presents them as two sequential gates and both have to be cleared.

A tenant running a mix of Business Premium and Business Standard clears neither today. Three supported options fix that, and the cheapest one costs nothing beyond your own time.

9.4 · What it changes about the standard playbook

The sequence most of the channel is running goes: buy one Copilot seat, unlock SharePoint Advanced Management, run the DAG reports, find the oversharing, remediate it, then roll Copilot out properly. On an E3 or E5 tenant that works exactly as advertised.

On a Business Premium tenant it needs one extra step first, because every item in the table above sits behind the base-SKU requirement — the DAG reports, the EEEU insights, Restricted Content Discovery, the site access reviews. The work does not change. The way you reach the tooling does.

The channel is currently wrong about this in both directions

Older partner material says “you need E5 for oversharing tooling.” That is out of date — one Copilot license does unlock the full SAM feature set, and E5 is not required.

Newer partner material has over-corrected to “SAM is included with Copilot, the E5 objection is dead.” That is true only on an E-SKU base, and it is being repeated at SMB customers where it is simply false.

Both statements are true of different customers. For an E3 or E5 tenant, one Copilot seat unlocks everything and nobody needs E5. For a Business Premium tenant — most of the SMB market — it is unreachable at any Copilot seat count. Getting this wrong in either direction mis-scopes the engagement before it starts.

9.5 · The three supported ways through

These are the same three options as section 2.3, with the delivery detail attached. All three are documented and buyable. None of them is an E5 upgrade, and none of them depends on a licensing behavior this guide has not verified.

Option 1 — start here

Native reports, PowerShell, and free tooling

The SharePoint admin center exposes sharing settings, site-level permissions and sharing reports. The SharePoint Online PowerShell module enumerates permissions. Free tools cover the configuration baseline — see section 13.

What you give up: raw output rather than a client-ready report, no continuous monitoring, and effort that grows with site count. Workable comfortably at 80 seats, painful at 300.

Option 2 — at portfolio scale

A platform that does not depend on SharePoint Advanced Management

Some governance platforms read Microsoft's security and activity feeds directly, so they work on a Business Premium tenant unchanged. That is the strongest reason for a partner in this market to look outside the Microsoft stack, and it is what makes the recurring service in section 12 deliverable at a margin.

What you give up: seat minimums at the small end, pricing you have to go and obtain, and label-enforcement features that still inherit Microsoft's E5 requirement. Section 14 is the full assessment.

Option 3 — when the customer needs it

Move the base to an enterprise SKU

Microsoft's documented path, and the only one that delivers Restricted Content Discovery. On an eligible E-SKU base a single assigned Copilot license unlocks the full toolset.

Before you quote it: get the entitlement confirmed in writing by Microsoft licensing or your distributor, including how it behaves in a mixed-SKU tenant. Microsoft states the requirement at organization level and publishes no partial-adoption guidance, so treat it as a question for the licensing desk rather than an assumption to build a proposal on.

The one to refuse

Turn Copilot on and deal with it later

Tempting because it is fast, and because the owner will suggest it. It is also the one path where you carry the consequence: you enabled it, and the salary spreadsheet surfaces in week two.

The counter is not a lecture. It is Gate 1 as a two-day job. Find the organization-wide grants, fix the worst handful, then enable. You are not refusing him; you are giving him a shorter path than he expected.

If you cannot use Restricted Content Discovery, scope the pilot instead

Restricted Content Discovery is Microsoft's interim containment — it hides high-risk sites from Copilot while you fix the permissions underneath. It needs an assigned Copilot license and an eligible base subscription, so on Business Premium it is simply not on the table.

The supported alternative gets you the same outcome by a different route: remediate first, then scope the pilot to what you have cleaned. Enable Copilot for a small pilot group whose work sits in sites you have already remediated, rather than enabling the tenant and hiding the rest. It is slower to reach everybody and it is completely defensible, which the alternative is not.

It also removes the un-containment step in section 11.1 entirely — the step partners most often forget.

Explaining the constraint without sounding like an upsell

“Microsoft built a proper set of tools for exactly this problem. There is one catch, and I would rather you hear it from me than find it in a support ticket: on your current plan those particular tools are not switched on, and buying Copilot does not switch them on either.

Before you brace for a big number — this is not an E5 conversation. There are three ways to solve it. One of them costs you nothing and costs me more time, one is a small monthly tool, and one is a licensing change you would only make if you wanted it anyway. I will tell you which I would pick for you and why.”

Where this lands

The data protection half of Copilot readiness is fully reachable on the licenses your customer already owns, through a $10 add-on that is half price alongside Copilot until the end of 2026. The permissions half is deliverable by any of the three options above. Neither half requires E5, and a partner who tells a Business Premium customer otherwise has cost them money and cost themselves the deal.

↑ Back to Table of Contents

10 · Phase 5 · Purview From Zero

This section is for the partner who has never really turned Purview on. It is deliberately specific, because the reason partners underprice this work is that they have never seen it written down.

10.1 · The order that cannot be reversed

Before anything else, one setting. Get it wrong and the fix is manual, per-file, and humiliating.

Step 0 Do this before anyone labels anything

Enable sensitivity labels for Office files in SharePoint and OneDrive

Set-SPOTenant -EnableAIPIntegration $true

Until this is on, SharePoint and OneDrive “can't process encrypted files, which means that coauthoring, eDiscovery, data loss prevention, search, and other collaborative features won't work for these files.”

The trap: labels applied before the setting is enabled are never recognized. Microsoft's remedy is to “download these files and then upload them to their original location.” On a tenant with any volume that is not a remediation, it is a punishment.

Takes about 15 minutes to take effect. There is no reason to ever do this second.

10.2 · The calendar floor nobody puts in a project plan

Purview is not slow to configure. It is slow to propagate, and the waits are documented, non-negotiable, and almost never in a partner's schedule.

What you are waiting forDocumented wait
Label and label policy changes to propagate24 hours (24–48 for group-membership-dependent configuration)
Editing an already-published labelUp to 24 hours
Microsoft's own safe-publish pattern: pilot users → verify → widen1 hour, then “wait at least a day” before widening
A newly created auto-labeling policy is locked~24 hours greyed out while the backend provisions
Auto-labeling simulation runUp to 12 hours, and you will run two or three
Co-authoring tenant setting replication24 hours
DSPM for AI reports showing any dataAt least a day (Microsoft states this twice on the same page)
Newly added policy location before first crawl24 hours before troubleshooting missing labels
Reindexing after a bulk label change, 100+ sitesUp to several days
Container label deletion, SharePoint sites48–72 hours, during which users may be unable to open previously protected content
Add only the unavoidable waits

A minimal, clean, single-tenant stand-up — one auto-labeling policy, one DLP policy, nothing custom — carries a floor of roughly six to ten elapsed working days of pure waiting, before a single hour of consulting, workshop, tuning or user communication.

Any project plan that does not contain those waits as explicit calendar items is wrong on day one. This is the single most common reason a four-week engagement becomes a nine-week one, and the partner absorbs the difference.

10.3 · The classification workshop

This is the part partners skip, and skipping it is why taxonomies fail. It is not a configuration session. It is ninety minutes in a room with people who do not work in IT.

Who is actually in it

Microsoft's stakeholder list for DLP planning runs to seven roles. At this size it collapses to four: the owner or managing partner, whoever owns finance, whoever owns HR, and the person who actually knows where the files are. That last one is usually the part-time IT person who ran the migration, and they are the most important person in the room. Ninety minutes.

How many labels

Microsoft publishes an unusually direct answer:

Real-world deployments show that effectiveness is noticeably reduced when users have more than five main labels or more than five sublabels per main label. Microsoft Learn, Learn about sensitivity labels — page dated 15 April 2026

Restated in Microsoft's deployment blueprint as a rule: keep the list to 5×5 wherever possible. Practitioners working in SMB go tighter still, at three to five.

The position to take at 25–300 seats

Four top-level labels. Sublabels only under Confidential. Start from Microsoft's own default set — Personal, Public, General, Confidential, Highly Confidential — rather than a blank page, and cut it down rather than building up.

Anything more is the partner performing thoroughness at the customer's expense. A fifteen-label taxonomy does not produce careful classification; it produces users picking whatever is least likely to interrupt them.

Microsoft's naming guidance is worth following literally: use terms that make sense to your users, always test names and tooltips with the people who have to apply them, and avoid mixing Confidential, Restricted and Internal together — users cannot reliably distinguish them.

The question that does the work

Microsoft names this one directly, and it is the hinge of the whole session

What is this organization's tolerance for leakage?

Microsoft's own worked example: a legal team demands zero leakage of card numbers, while internal auditors must legitimately share exactly that data with external auditors. The resolution is not a technical control. It is an explicit, business-signed statement of what level is acceptable.

Ask that question and the room stops treating this as an IT decision, which is the entire purpose of holding the workshop.

What the workshop must produce

Not a label list. Microsoft's policy intent statement: “You should be able to summarize, in a single statement, the business intent for every policy you have.” Microsoft's own example:

We're a U.S. based organization, and we need to detect Office documents that contain sensitive health care information covered by HIPAA that are stored in OneDrive/SharePoint and to protect against that information being shared in Teams chat and channel messages and restrict everyone from sharing them with unauthorized third parties.Microsoft Learn, Data loss prevention policy design

Every clause maps to a configuration decision: what to monitor, how to scope, where to monitor, which conditions, which actions. A page of these, signed by the customer, is the deliverable of the workshop — and it is the artifact that makes the engagement defensible when somebody asks eighteen months later why a policy exists.

10.4 · The decisions that cannot be undone

Three of these change what a file is. They are senior-consultant decisions and they should never be made by whoever happens to be in the portal.

Irreversible — 1

Encryption on a label

Deleting an encrypting label archives its protection template, and you can then never create a new label with the same name. Deleted labels show as GUIDs in content and activity explorer. Deleting a label applied to a SharePoint document strips label and encryption on download — but the same document stored outside SharePoint stays encrypted forever. Two different outcomes for one action.

Microsoft's own blueprint hedges its recommended default with “note: encryption of labels can be implemented later” and ships a dedicated \Internal exception sublabel “for situations where encryption is impacting daily operations.” That is Microsoft telling you it breaks things.

Ship labels without encryption first. Add encryption as a separate, separately-communicated change.

Irreversible — 2

Co-authoring for files with sensitivity labels

Microsoft: “After you enable co-authoring... you can't disable this setting in the Microsoft Purview portal. This action is supported only by using PowerShell.”

Worse, it changes where labeling metadata is stored. Microsoft warns not to enable it if you use any app, script or tool that reads or writes labeling metadata in the old location. Turn it back off and “this labeling information for unencrypted Word, Excel, and PowerPoint files will be lost.” Documented breakage includes Exchange mail flow rules keyed on labels failing to encrypt, or encrypting when they should not.

This is the trap most likely to burn a partner who “just turned everything on.” SMB tenants are precisely where undocumented scripts and third-party add-ins live. Inventory first.

Irreversible in effect — 3

Label order and priority

Order is not cosmetic; it is semantic. It determines what counts as downgrading, it resolves auto-labeling conflicts, and — the one that matters here — Copilot surfaces the highest-priority label. Copilot Chat displays it; content Copilot generates from multiple sources inherits it.

Get the order wrong and Copilot tells your customer's staff the wrong thing about the sensitivity of their own documents, with authority, in a chat window. Reordering later means re-reasoning about every policy that depends on it.

10.5 · DLP, and the only rollout pattern that works

Microsoft prescribes three stages and gives a duration for none of them, because the exit criterion is judgment, not a clock.

Stage 1

Simulation, no policy tips

Assess impact through the reports. Nobody is interrupted. Use this stage to test your own review and remediation workflow, not just the policy.

Stage 2

Simulation with notifications and policy tips

Begin teaching users. Link to the customer's own policy page. Explicitly ask users to report false positives. Move here only “once you have confidence that the results of applying the policies match what the stakeholders had in mind.”

Stage 3

Full enforcement

And keep monitoring. Most partners never arrive here, which is its own failure — a permanent diagnostic state that looks like compliance and protects nothing.

Microsoft publishes SMB DLP guidance and almost nobody has read it

Buried in the DLP planning documentation is Fabrikam — Microsoft's own worked persona for an 18-person startup. It is the closest thing to official small-business DLP guidance that exists, and its prescribed approach is refreshingly short:

use the default Teams DLP policy; make SharePoint restricted by default; block external sharing; deploy to Windows devices; and block non-OneDrive cloud storage.

That is the whole recommendation. Five moves, no custom classifiers, no taxonomy project. Cite it by name when a customer asks whether you are over-engineering — being able to say “this is Microsoft's own guidance for a company your size” ends that objection faster than any argument of your own.

Microsoft also publishes its own split of why organizations do this at all: roughly 85% regulatory and compliance protection, 15% intellectual property protection. Useful for keeping the conversation on the ground the customer actually cares about.

The trust trap

A false-positive flood does not annoy users — it retires the control

Users route around policy tips within days, and every subsequent recommendation you make is pre-discredited. The mitigation is structural, not clever: run audit-first, ask for false-positive reports, and have the leakage-tolerance conversation before writing rules rather than after.

10.6 · Simulation is not a silent dry run

Four documented behaviors that get misdiagnosed as bugs, and one of them will embarrass you publicly.

10.7 · What to leave out at this size

Custom sensitive information types and custom trainable classifiers are almost always out of scope at 25–300 seats. Built-in types and pre-trained classifiers cover the realistic cases. If you do go there, know that Microsoft Support will not help you write regular expressions — their documentation says so explicitly — that custom classifiers are English-only and cannot be retrained (you delete and start over), and that a new sensitive information type does not retroactively light up existing content without a recrawl.

Price custom classification as its own opt-in workstream or refuse it. Folding it into a fixed-fee readiness engagement is how partners lose money on this work.

↑ Back to Table of Contents

11 · Phase 6 · Enable, Pilot, and Un-Contain

The shortest phase and the one most often fumbled. Everything up to here was preparation; this is where the customer finds out whether any of it worked.

11.1 · Take the containment back off

If you applied interim protections in Phase 4 — restricting what Copilot can surface while the permissions were being fixed — this is where they come off. Microsoft's own pattern is three moves, and this is move three.

Mandatory Put this in the statement of work

Un-containment is a dated, billable milestone. Not a tidy-up.

Partners contain, remediate, and then leave the containment in place, because nothing forces them to remove it and removing it feels like a risk.

The customer is now paying full price for a Copilot that cannot see their own content. They conclude the product is useless. They do not renew, and they are not wrong to reach that conclusion from the evidence in front of them.

This is the most common way a technically successful engagement produces a commercially failed one. Make somebody accountable for it by name and by date.

11.2 · Choosing the pilot group

Five to ten people, and the selection matters more than the size.

IncludeWhy
The person who asked for CopilotUsually the owner. They funded this and they need to see it work first.
The heaviest existing AI userThey are already using something on a personal account. Give them a sanctioned alternative and they become your loudest advocate; leave them out and they stay a shadow-AI problem.
Somebody from finance or HRThey work with the most sensitive content, so they are the fastest way to find out whether the labeling and DLP work in practice rather than in simulation.
The part-time IT personThey have to support this. They should not meet it for the first time when a user complains.
One skepticDeliberately. A pilot group of enthusiasts tells you nothing you can act on.

11.3 · What to watch in the first week

11.4 · Hand off to adoption, and say so out loud

Governance and adoption fail independently. A perfectly remediated tenant that nobody uses still loses the customer, and it will look like your fault because you are the one who was there.

Phase 6 is where you name that risk to the customer and price the answer: role-based enablement at $50–$100 per user Range, which at 80 seats is a natural second project of comparable size to the assessment. Section 19.3 covers the follow-on ladder.

The handover conversation

“It is on, it is clean, and the containment we put up in week three is down — so it can see everything it is supposed to see and nothing it is not.

Here is the part I want to be straight with you about. Everything we just did makes Copilot safe. None of it makes anyone use it. The deployments that stall do not stall for security reasons — they stall around month three because the enthusiasm wore off and nobody changed how they actually work. That is a different piece of work, it is not expensive, and I would rather sell it to you now than watch the licenses go quiet.”

Phase 6 exit criteria

Interim containment removed and verified · pilot group live and using it · the exception path exercised at least once for real · a dated first governance report scheduled · the adoption conversation had, and either sold or explicitly declined in writing.

That last one matters. If the customer declines adoption support, you want that on the record before month three.

↑ Back to Table of Contents

12 · Phase 7 · Ongoing Governance

12.1 · The gap that is the whole opportunity

Kaseya's 2026 State of the MSP survey, with over a thousand respondents, contains two numbers that sit five percentage points and one enormous business opportunity apart.

48%
of MSPs name AI as their clients' number-one need
Kaseya 2026 State of the MSP, n>1,000 Survey
13%
earn meaningful revenue from AI or automation services
Same survey Survey
8%
have regulatory compliance and reporting as a top-three revenue line
Same survey Survey
52%
have security in their top three, and 71% grew it year over year
Same survey Survey

A 35-point gap between what clients are asking for and what partners are being paid for. The same survey found MSPs whose typical client spends over $25,000 a year Survey collapsed from 75% to 41% in twelve months, and the share of unprofitable MSPs doubled to 10%.

Security is already monetized. Governance and AI are not. That is the arbitrage this entire guide describes.

12.2 · Nobody has set the price yet

No SMB-focused partner publishes a price for ongoing AI governance as a distinct managed service.

Not one that survives a search. The recurring layer today is either absorbed into an existing managed-services tier, sold as vCISO advisory, or not sold at all. A partner productizing this is not undercutting a market — there isn't one yet.

That is a strategic finding rather than a research gap. You set the reference price rather than matching one. It also means the two derivations below are the closest thing to a benchmark that exists, and neither is strong enough to lean on.

DerivationLands atWeakness
0.5 FTE for governance at 1,000+ Copilot users, scaled naively to 60 seats → ~5 hours a month at $150–$250/hr$750–$1,250 /mo ModelThe 0.5 FTE input is unverified and linear scaling is generous
vCISO “core advisory” band from an MSP-focused vendor benchmark$1,000–$1,500 /mo RangeVendor-published, unaudited, and describes a broader service

Two very different routes landing near $1,000 a month for a small tenant is worth noting. It is not worth presenting as a benchmark, and the guide will not pretend otherwise.

12.3 · Structure it with a floor, not a per-user rate

Section 13.2 established why: per-tenant tooling minimums mean a 60-seat customer can cost the same to tool as a 100-seat one. A pure per-user price on a small tenant buys revenue at negative margin.

The shape

“$X per user per month, minimum $Y per month.”

That is the same structure your tool vendors use on you, it is defensible when a customer asks why a 40-seat site costs nearly what a 70-seat one does, and it protects you at exactly the customer size where this work is hardest to make profitable.

12.4 · What the customer is actually buying

The recurring fee has to answer one question every renewal: we already cleaned it up, why am I still paying you? Three answers, in order of persuasiveness.

1
Drift is real and it is measurable

Permissions do not stay fixed. New sites get created, staff share links to get work done, a project spins up a Team with the wrong default. Continuous monitoring catches it, and platform tooling can alert or auto-revert as often as every two hours. You report what drifted and what you reverted. That is the invoice.

Evidence your own monthly report
2
The control plane changes underneath them

This is what CW1226324 proves. Microsoft shipped a change that bypassed correctly configured labels and DLP for four weeks. Nobody — not Microsoft, not the customer — had independent visibility into whether the controls were working. Somebody has to be watching, and it is not going to be the customer's part-time IT person.

The single strongest argument you have
3
Somebody external keeps asking

The cyber renewal is annual. The carrier questionnaire is annual. The enterprise client's security review is annual. Tie the reassessment cadence to those dates and the recurring fee has an external justification that is not you.

Co-term with the M365 renewal and the insurance date

Microsoft's own practice is a useful precedent worth quoting: it re-attests its own containers on a six-monthly cycle. A company with Microsoft's resources does not treat this as one-time work.

12.5 · What you report, monthly

The report is the product. Everything below is obtainable from tooling the customer already has or that you already run.

MetricSourceWhy it belongs in the report
Anonymous links, count over timeGovernance platform, or SPO PowerShellTrends down after remediation and creeps back up. The clearest proof drift is real.
External user access, count over timeSameGuest sprawl is continuous and invisible without reporting
Shadow users — access via nested groupsSameThe finding customers find most surprising, every time
Organization-wide grants introduced this periodSameDirectly maps to Gate 1
Leavers and stale guests removedEntra access reviewsGate 2. Cheap, visible, and the item a regulator would ask about
Label coverage on sites holding sensitive contentPurviewProgress on the work that is not a gate but does compound
DLP matches, and false positives reported by usersPurviewReport the false positives. It proves you are tuning rather than accumulating noise, and it keeps the exception path alive
Secure Score deltaMicrosoft 365Imperfect, but the customer's board understands a number that goes up
Copilot license utilizationAdmin centerTies governance to the spend it protects, and surfaces reclaimable seats
The reporting trap

A green dashboard every month reads as “nothing is happening”

If your report only ever says everything is fine, you are teaching the customer they do not need you. Report what changed, what you fixed, and what you decided not to fix and why. Three items of judgment beat forty green checkmarks, and judgment is the thing that cannot be bought from a distributor for $3,000.

12.6 · Anchor it to a framework so the customer has a reason that is not you

The strongest recurring-revenue mechanic in the SMB channel is to tie the service to an external standard, so the renewal conversation is about maintaining a position rather than about your fee. One published SMB rate card sells maturity levels of a security framework as the tiers themselves — the level is the product, and the framework does the selling.

For this motion the credible anchors are the cyber insurance questionnaire (universal, annual, and already on their desk), the carrier or enterprise-client security review, and — where the customer genuinely wants it — ISO/IEC 42001 as a structure. Use 42001's shape: an AI system inventory, a risk register, named use-case owners, and an incident protocol. Do not default to selling the certification. Audit and implementation costs put it out of reach for most businesses this size, and offering the structure without the certificate is both cheaper for them and more honest.

↑ Back to Table of Contents

13 · The Tooling Floor — Free, Native, Bought

The first assessment a partner runs usually has to cost near zero to deliver, because it is being run to win the work. The good news is that a genuinely credible baseline is free.

13.1 · The free toolkit

ToolCostWhat it does in this engagement
ScubaGear (CISA)FreeSecure-configuration baseline assessment for M365. Produces HTML, JSON and CSV output that is close to client-presentable as-is. Start here.
MaesterFreeRepeatable security-as-code tests. Turns a one-time assessment into something you can re-run monthly — which is the mechanical basis of the recurring service.
Monkey365FreeCIS and Entra misconfiguration review
Microsoft365DSCFreeConfiguration baseline capture and drift detection
SharePoint Online PowerShellFreePermission enumeration. On a Business Premium tenant with no SharePoint Advanced Management, this is your Gate 1 evidence. Raw output; you supply the report.
Microsoft 365 LighthouseFree with CSPThe multi-tenant floor. Entra ID P1 is included in Business Premium, so most customers qualify.
The honest limitation

These cover configuration baseline extremely well and permission exposure only adequately. Nothing free gives you a ranked, click-to-remediate view of who can reach what across the estate. You will assemble that from PowerShell output and your own judgment, which is exactly the labor a platform is sold to remove.

13.2 · The build-versus-buy line

The instinct is to compare features. The better question is about the unit of purchase, because that is what actually determines whether a tool works in this market.

The economics that catch partners out

Per-user pricing with a floor punishes small tenants. Syskit Point bills a minimum of 100 users even for a 60-user tenant, on annual terms only. At its governance tier that is roughly $300 a month of cost Range for one small customer before you have earned anything.

Published seat minimums across the category: AvePoint's own list 500 users, Syskit and Rencore 100, Nudge Security a flat monthly fee, Orchestry Starter and ManageEngine none.

Consequence for your pricing: the recurring offer needs a floor price, not a pure per-user rate. Structure it as “$X per user per month, minimum $Y per month” — the same structure the tool vendors use on you. A partner who prices purely per-user on a 40-seat customer is buying revenue at negative margin.

13.3 · The comparison

ToolRole in this motionMulti-tenantPricing modelRealistic under 100 seats?
Free stack (ScubaGear, Maester, Monkey365, DSC, PowerShell)Configuration baseline, drift, permission enumerationScriptedFreeYes — and it is where nearly everyone should start
AvePoint Insights + PoliciesExposure discovery, bulk remediation, continuous drift enforcement. No Microsoft E-SKU dependency.Yes (Elements, separately)Per user; published list carries a 500-user minimumGet a written quote at your seat count — see section 14
Syskit PointGovernance reporting and access reviewNot marketed for MSPPer user per year, published; 100-user billing minimumMarginal — the minimum is the problem
ShareGate ProtectGovernance risk assessment, tenant-wide visibilityLimitedSingle per-user price, no minimums; partner pricing exists but is unpublishedYes
OrchestryWorkspace lifecycle and provisioning governanceYesFlat per tenant, unlimited users at the Starter tierYes — the pricing unit fits this market best
ManageEngine M365 Manager PlusReporting and auditingPartialPer tenant, banded — cheapest commercial reporting by a wide marginYes
CoreViewMulti-tenant governance and delegationYesUnpublished; access reviews, SharePoint control, auditing and delegation are paid add-onsNo — enterprise-shaped
VaronisDeep data security posture; publishes a free Copilot readiness assessmentNo MSP consoleUnpublished, enterpriseNo — but the free assessment is a legitimate door-opener
RencoreGovernance console explicitly built for multi-tenant MSP deliveryYes, explicitlyUnpublished; 100-user minimumGet a quote — the MSP positioning is the strongest in the category
Nudge SecuritySaaS and shadow AI discoveryYesFlat monthlyYes at the low end
Compliance ScorecardThe GRC half — policy, attestation, AI governance moduleMSP-nativeFlat monthly, MSP-pricedYes
CIPPMulti-tenant delivery chassisYesLow monthly self-hosted or hostedYes — but it holds delegated admin into every tenant. Document that risk deliberately.
The threshold

At one or two customers, scripts win. The license cost of any platform exceeds the consultant hours it saves.

At roughly ten or more customers, a platform wins — not because it finds more, but because it makes findings comparable across tenants and turns your report into a product rather than a document. That is also the point at which the recurring service becomes deliverable at a margin.

Match the pricing unit to the shape of your book, not to the feature list. If your customers average 60 seats, a per-tenant price beats a per-user price with a 100-seat floor every time.

↑ Back to Table of Contents

14 · AvePoint — What To Use, And When

AvePoint gets its own section for a specific technical reason rather than a commercial one: its discovery product does not inherit the base-SKU wall from section 9. For a Business Premium tenant that is not a feature advantage, it is an availability advantage, and it is the strongest argument for looking outside the Microsoft stack in this market.

What follows is even-handed. The weaknesses are stated as plainly as the strengths, because a partner audience discounts a guide that reads as single-vendor — and because you will be in a room with people who have read Microsoft's documentation.

14.1 · The name problem, first

AvePoint's website, price lists, documentation and marketplace listings use different names for the same product. This is a practical quoting hazard, so start with the translation.

Marketing name (website)SKU name (price lists, docs, quotes)
Data & Security InsightsInsights for Microsoft 365
Policy Enforcement & Drift ControlPolicies for Microsoft 365
Records & Information Lifecycle ManagementAvePoint Opus (its AI classification engine is called Maestro)
Access & Power Platform GovernanceAvePoint EnPower
Adoption & Usage AnalyticsAvePoint tyGraph
License & Cost ManagementAvePoint Cense
Data Owner EngagementAvePoint MyHub
Agentic AI GovernanceAgentPulse Command Center
MSP multi-tenant platformAvePoint Elements

14.2 · The dependency graph, before you quote

Three dependencies that are not on any slide and will change a quote:

The minimum viable stack

Insights + Policies for a Copilot readiness engagement. Add MyHub when you want the customer's own site owners doing attestation rather than your engineer guessing. Everything else in the portfolio is a separate business case.

14.3 · When to use what

This table is the reason this section exists. Engagement stage on the left, the specific product and the specific report on the right.

StageProductThe specific featureWhat you actually get
Pre-sales — the door-openerInsights (free trial)Risk Assessment ReportAn out-of-the-box, exportable PDF. AvePoint designs it explicitly as “a benchmark to track progress over time” — which is why the second run is your recurring hook, not just your first deliverable.
Pre-sales — the AI angleAgentPulseAutomated agent discovery and inventory“You have 41 agents nobody inventoried.” Only lands where Copilot is already on.
Discovery — permissions baselineInsightsRisk Analysis → Workspaces Reports, then Detailed Records ReportsWorkspace-level then item-level exposure. A full inventory, not a 28-day delta.
Discovery — “who can see this?”InsightsSearch Center — object-based or user-based search“Show me everything this one user can reach.” The most demo-able screen in the platform. Run this one live.
Discovery — broad-access exposureInsightsExposure Report, configured in Risk Definition AdministrationExternal sharing and “broad access groups.” You tune what counts as exposure. See the caveat below.
Discovery — hidden access pathsInsightsShadow Users and Groups Access ReportAccess granted through nested groups or direct grants the site owner cannot see. Consistently one of the most surprising findings for a customer.
Discovery — linksInsightsShared Links reportAnonymous, company-wide and specific-people links, with full history rather than a 28-day window
Discovery — data qualityOpusDiscovery & Analysis, delivered as Power BI reports; File Share Discovery for on-premisesRedundant and obsolete data. Improves Copilot answer quality rather than security. Sell on storage cost.
Findings readoutInsightsRisk Assessment Report + dashboardThe readout deck largely writes itself. Opus data can be exported to SharePoint for Power BI so you can brand it rather than screenshot AvePoint's UI.
Remediation — bulkInsightsRisk Remediation, in-report bulk actionsExpire, remove or edit permissions for external users, shadow users and anonymous links. Expiry is what native tooling handles worst.
Remediation — the upsell bridgeInsights → PoliciesIntelligent RemediationProposes the rule that would have prevented the finding. This is the moment the customer understands why one-time cleanup is not enough.
Remediation — owner-ledMyHubRecertification and attestation, including OneDrive cleanupPushes the decision to the site owner. Substitutes for SAM site access reviews, which a Business Premium tenant cannot have.
Ongoing — driftPoliciesViolations Report; Remove Shadow Users, External Sharing Settings, Direct Sharing PreventionAlert or auto-revert as often as every two hours. There is no Microsoft equivalent at any SKU. This is the mechanical basis of your recurring fee.
Ongoing — tenant hygienePoliciesGhost User Detection, Remove Inactive Guest UsersThe two the customer notices immediately, and both map to Gate 2.
Copilot enablement — licensingCenseLicense allocation and budget reporting“Which twelve people should get a Copilot license” and who is burning pay-as-you-go AI credits.
Post-deployment — the QBRInsightsTime-based dashboards for anonymous links, external user access and shadow users; risk score over timeThose three metrics are your quarterly scorecard. Lift them directly.
Post-deployment — agent sprawlInsightsAgent Reports under Risk AnalysisHigh-risk, inactive or ownerless agents — a cheaper path to basic agent hygiene than buying AgentPulse.
Multi-tenant deliveryElementsPermission Simulation; CIS Level 2 baselines; sensitivity label managementThe portfolio layer. Contains no AI or Copilot governance as of the June 2026 release.

14.4 · Does AvePoint fill the gap? The three-line answer

Yes — for the gap that matters

Discovery and drift, on Business Premium, unchanged

Insights covers the permission and exposure reporting that section 8's map flags as the one genuine gap, with no Microsoft license change. Policies adds continuous drift enforcement Microsoft does not offer at any SKU.

No — for label enforcement

It inherits the same E5 requirement

Three Policies rules — all of them label-enforcement — require Microsoft 365 E5. AvePoint did not route around Microsoft's label wall. Nobody has.

And one thing it does not replace at all

There is no AvePoint equivalent to Restricted Content Discovery. AvePoint's position is that you should fix the permission rather than hide the content from search — arguably the better engineering answer, and definitely the slower one. If you need interim containment while remediation runs, that is an enterprise-SKU conversation — or, more practically at this size, a reason to scope the pilot to remediated sites instead. See section 9.5.

14.5 · The license story, both halves

The good half

Insights has no documented Microsoft E-SKU dependency

It consumes Microsoft's security, activity and compliance feeds rather than crawling content, so it runs on a Business Premium tenant. For the discovery half of Gate 1 it substitutes for SharePoint Advanced Management — with deeper history than SAM's 28-day sharing-activity window.

Policies adds continuous drift enforcement that Microsoft does not offer at any SKU.

The half nobody mentions

Policies inherits Microsoft's E5 label wall

Four documented dependencies, from AvePoint's own documentation:

Business Premium includes Entra P1, so the guest rule works. The three E5 rules do not. All three are label-enforcement rules. AvePoint has not built around Microsoft's E5 label wall; it inherits it.

There is also no AvePoint equivalent to Restricted Content Discovery. AvePoint's position is that you should fix the permission rather than hide the content from search. That is arguably the better engineering answer and it is definitely the slower one, which matters when you need an interim protection this week.

14.6 · The land motion

There is a genuine self-serve 30-day free trial, confirmed in two AvePoint product brochures and in its public framework listings. Its deliverable is the Risk Assessment Report. That is your assessment engine and your readout in one artifact, and because the report is designed to be re-run as a benchmark, the second run is the recurring hook.

Pair it with free ScubaGear and Maester output for the configuration-baseline half that Insights does not touch, and you have a complete first engagement at near-zero license cost.

Three weaknesses to state before a customer finds them

There is no free AvePoint readiness scan. Varonis gives one away; AvePoint gives a time-limited trial and gated eBooks. That is a weaker door-opener and you should know it going in.

The substantive documentation is behind a login. Navigation trees and overview pages are public; the report specifics, the full Policies rule catalog and the entire Elements guide are not. You cannot pre-qualify AvePoint against a specific client requirement without a sales conversation, which is a real evaluation cost.

Pricing is the least transparent in the category. Competitors publish per-user-per-year rates and flat per-tenant prices. AvePoint publishes a Request Pricing button.

14.7 · The minimum, and whether it prices out a sub-100-seat customer

SourceStated minimum
AvePoint's own published price list500 users on nearly every SKU; 12-month minimum term
Elements (the MSP platform)No minimum published — no pricing published at all
Distribution, including TD SYNNEX StreamOneBehind partner authentication

AvePoint publishes no US pricing for Insights, Policies or Elements — anywhere. Not a rate card, not a starting-from figure, not a tier. That is a finding rather than a hole in this research, and it has a practical consequence: you cannot build a repeatable SMB offer around a product you cannot price without a sales call. Get a written quote at your actual seat count through TD SYNNEX before you design an offer around it.

The position to take until somebody gets a written quote

Treat AvePoint as unconfirmed below 100 seats and demonstrably viable above 500 — a commercial question to settle with a written quote, not a technical one.

The arguments that the minimum is negotiable are real but circumstantial: AvePoint's 2025 partner program explicitly rewards “smaller but highly committed partners”, and partner-generated revenue reached 58% of its recurring business in early 2026. A 500-seat floor sits awkwardly against both.

But no public source confirms that buying through distribution removes it, and AvePoint's own flagship readiness engagement is scoped around scan envelopes no 78-seat customer will ever approach. The ask is portfolio aggregation — committing 500+ seats across many small tenants rather than one. Put it to your TD SYNNEX rep and get the answer in writing.

14.8 · Where AvePoint genuinely wins, and where it does not

Genuinely stronger

License reach. Insights works on Business Premium; SAM does not. In this market that is decisive.

History depth. Continuous inventory versus SAM's 28-day sharing-activity window.

Continuous enforcement. Alert-or-revert every two hours has no Microsoft equivalent at any SKU.

Archival granularity. Site, document, list and library level, versus SAM's site-only.

Breadth. Backup, migration, records, licensing, analytics and agent governance from one vendor, across Google, Salesforce, AWS and Box as well as Microsoft.

Genuinely weaker

Price transparency is the worst in a category where competitors publish rate cards.

Seat minimums are the harshest documented — 500 against Syskit and Rencore's 100 and Orchestry's none.

Portfolio sprawl is a delivery cost. Ten products with a cross-dependency graph, against Syskit doing the core job in three tiers of one product. Training two engineers on that is real money.

The MSP console and the governance products are separate. Elements has no AI or Copilot governance and, on public evidence, does not surface Insights or Policies findings across tenants. Rencore explicitly markets that; AvePoint has not claimed it.

Credibility warning

Do not repeat AvePoint's own SAM comparison uncritically

AvePoint's published comparison presents SharePoint Advanced Management as 28-day-only and admin-led. That understates SAM as of August 2026 — permission state reports give a current-state snapshot, site access reviews are a delegation model, and Restricted Content Discovery and site policy comparison both exist.

Anyone in the room who has read Microsoft's documentation will correct you, and you will lose the section. Make the argument on license reach, which is true, verifiable and sufficient on its own.

14.9 · The questions to ask in the room

AvePoint will be at these workshops. These are ordered by commercial value; the first four change whether this section reads as a recommendation or a “when you grow into it.”

01

Does buying through distribution remove the 500-user minimum on Policies and Insights?

And if not — can a partner aggregate seats across a portfolio of small tenants to meet it? Get this one in writing.

Decides whether AvePoint appears in an SMB practice at all
02

Does Insights function at full fidelity on a Business Premium tenant?

Specifically: are Microsoft sensitive information types, sensitivity labels and the activity feed available at that SKU, or is the risk-prioritization signal degraded? Section 14.4's central claim rests on this.

No AvePoint statement exists either way
03

What is the per-seat price at 75, 150 and 300 seats, in our currency, at our tier?

Anchor the conversation on the published bundled framework rate rather than opening blind.

Nothing current is published outside one 2024 UK framework
04

What is Elements priced at, on what unit, with what minimum — and is there a free or NFR tier?

AvePoint publishes that buying Baseline, Workspace or User Management unlocks Risk, Change and Marketplace at no extra cost. So which of the three is the entry purchase?

No Elements pricing exists publicly in any form
05

What is “AvePoint Control Suite”?

The name appears in distribution catalogs and nowhere on AvePoint's own product index. Does it bundle Insights and Policies?

A name mismatch that will confuse a quote
06

In the Exposure Report, is “Everyone Except External Users” a first-class named exposure type?

Or is it configured through the “large groups” exposure definition? Ask them to show you the screen. Microsoft names EEEU explicitly; AvePoint's public material does not.

This is the single most common oversharing pattern — you need to know exactly where it surfaces
07

Is there a sensitivity-label coverage report?

“Percentage of sites labeled” or “unlabeled sites containing PII” — or is label data only used as a prioritization input?

Not publicly named; would change how you scope §8
08

When does agent governance reach the multi-tenant Elements console?

And can Elements surface Insights and Policies findings across tenants, or does governance stay a per-tenant login? Can the Elements Graph API feed our QBR reporting?

Determines whether this scales across a book of customers
09

Can we have AvePoint Learn documentation logins for our engineers, today?

The cheapest, highest-value ask in the room, and there is no reason for them to say no.

Removes the evaluation blocker in §10.5
10

What NFR licenses do we get, at which tier — and what is the trial's real user and data allowance?

Can a partner run sequential 30-day trials across a pipeline of prospects without friction? That is the difference between a demo and a repeatable land motion.

Partner tier names, thresholds and margins are all unpublished
↑ Back to Table of Contents

15 · Who Delivers This

15.1 · Five roles, and how few people they collapse into

In an enterprise systems integrator these are five people. In a partner serving 25–300 seat customers they are one and a half. Naming them separately still matters, because it tells you which hat you are failing to wear.

RoleWhat they own here
Modern Work / M365 architectThe tenant. Enabling labels for SharePoint and OneDrive, auditing, sharing defaults, licensing. The pre-work nobody bills for. A generalist — and that is the trap, because a generalist treats Purview as another admin center.
Purview / information protection specialistLabels, DLP, retention, the AI-services controls. Microsoft's own description of this role is half technical and half stakeholder facilitation. The facilitation half is what partners skip.
Security consultant / SecOpsDefender, shadow AI discovery, incident response. A different skill from the above — detection and response rather than classification and policy.
vCISO / governance advisorThe conversation, not the console. Runs the classification workshop, chairs the risk decisions, signs the attestation, holds the quarterly review. This is the role that carries the recurring revenue.
Adoption / change managerUser communications, labeling training, the false-positive feedback loop. Note that Microsoft retired the Adoption and Change Management specialization — the work did not go away, only the badge did.
The most common staffing failure

Putting the M365 architect in the vCISO's chair

The classification workshop gets run as a configuration session. The engineer asks which folders are sensitive, writes down the answers, and builds a taxonomy nobody in the business actually agreed to. Six weeks later Finance cannot email the auditor, nobody knows who decides, and the labels come off.

The workshop is a facilitation job that ends in configuration, not a configuration job with people watching.

15.2 · Certifications — and the advice that is now wrong

Stop telling people to get SC-400

SC-400 retired on 30 May 2025 — the certification and its renewal assessment. It is still being recommended in partner enablement material and by well-meaning people who have not checked.

The replacement is SC-401, Information Security Administrator, whose skills were refreshed on 28 July 2026 and which now carries an explicit “Protect data used by AI services” objective covering exactly the readiness work this guide describes.

CredentialStatusRelevance
SC-401 Information Security AdministratorLiveThe single most on-target credential for this motion. Information protection, DLP and retention, plus protecting data used by AI services. A partner with nobody holding SC-401 has nobody credentialed for the work they are selling.
SC-200 Security Operations AnalystLiveThe shadow AI discovery and response half. Its 2026 refresh added AI agents and Copilots to the familiarity list.
SC-300 Identity and Access AdministratorLiveIdentity governance and access reviews — Gate 2 territory.
SC-100 Cybersecurity ArchitectLiveExpert level. The closest thing to a vCISO credential Microsoft offers.
Applied Skills APL-5003LiveA hands-on lab: build a custom sensitive information type, publish a label, create an auto-labeling policy, create a DLP policy. Cheaper and faster proof of capability than a certification. Note the 72-hour cooldown between attempts.
SC-400Retired30 May 2025. Superseded by SC-401.
MS-102 M365 AdministratorRetiring30 November 2026. Do not start a junior on it now unless they can sit it first. It was also removed from the Copilot specialization requirements in July 2026, so it no longer earns program credit either.

Two things worth knowing for practice economics. Microsoft publishes no exam price to an unauthenticated visitor — every figure circulating is third-party, so confirm at booking. And renewal is annual, free, and by online assessment rather than a re-sit, which means the ongoing cost of a certified bench is time once a year at no exam fee. That is a far better story than most partners tell themselves.

15.3 · The minimum viable team

ConfigurationWorks?Notes
One generalist M365 adminNoWill build a taxonomy nobody agreed to and discover the problem in week six.
One genuine senior who does both halvesYes, with a ceilingWorks to about 75 seats. Requires someone who can chair a room of business owners and write a DLP rule. These people exist and are rare. They do not scale past roughly two concurrent engagements.
One senior plus one technicianYesThis is the answer. It is also the shape that lets you charge properly for the senior's time instead of averaging it away.
Plus fractional adoption and communicationsYesThe only shape that survives a mandatory-labeling rollout. The comms person can be borrowed rather than hired.
The split is decisions versus execution, not hard versus easy

The junior may touch anything reversible. The senior signs anything that changes what a file is.

That puts encryption on a label, the co-authoring switch, label order, and the move from DLP audit mode to enforcement on the senior's desk — and puts building labels to an agreed taxonomy, running simulations, triaging false positives and capturing evidence on the junior's. It is a clean line, it maps exactly to the irreversible decisions in section 10, and it is defensible to a customer asking why two people are on the call.

15.4 · What it costs you to deliver

Nobody publishes a rate card for SMB-channel Purview work. Rather than invent one, here is the arithmetic, with its inputs visible.

InputFigureWhat it actually is
M365 consultant salary, 75th percentile$130,000 /yr RangeAggregated job-postings data. A salary, not a bill rate.
→ base hourly~$65 /hr ModelArithmetic
→ fully loaded at 1.3–1.4× burden~$85–$91 /hr ModelConventional burden multiplier
→ recoverable cost at 65% utilization~$130–$140 /hr ModelThe number that matters
What it costs to rent a cybersecurity engineer$130–$195 /hr RangeStaffing agency bill rate. A hard floor — you cannot bill less than you buy.
The conclusion, stated as an inference rather than a rate card

A partner billing under roughly $150 an hour for senior Purview work is not making money on it. The channel band sits somewhere around $150–$275 Model — above the freelance band and well below the global-integrator band — but no published source isolates this work, so treat that as a bounded inference and not a benchmark.

Do not quote a day rate. Nothing credible is published, and everything shaped like one on the open web is a lead magnet.

15.5 · What you can and cannot subcontract

Distributor-funded deployment offers now price a baseline Purview stand-up — data lifecycle review, sensitivity labeling policies, baseline classification, and DLP policies aligned to Microsoft best practice — at around $3,000 Range, usually with a small seat minimum attached.

Sit with that number, because it is uncomfortable and useful. The configuration layer of this work has a public price, and it is a few thousand dollars. If your quote is $30,000, you need a clear story about the other $27,000 — and if you do not have one, your quote is wrong.

The rule

You can outsource the build and the tooling. You cannot outsource the taxonomy decision, the exception path, or the quarterly review — and those three are where the margin and the recurring revenue live.

A partner who subcontracts everything has bought a $3,000 deployment and sold a $3,000 deployment.

↑ Back to Table of Contents

16 · The Tier Ladder

Three independent sources in the SMB channel — a governance ISV, an MSP-focused readiness platform, and a multi-tenant management vendor — describe the same five-stage ladder in the same order. They agree because they are all describing the offer their tooling enables, which is a real limitation. It is still useful: an MSP building this ladder is building the offer the channel's tooling is designed to support.

0
Scan

Automated tenant scan, findings list, no judgment applied. The output is raw — a site count, an exposure count, a list of anonymous links.

Price $0 RangePlatform time 60–90 minPurpose qualify and scope
1
Light assessment

Scorecard, three to five stakeholder interviews, a debrief, prioritized findings. No remediation plan costed.

Price $1,500–$3,000 RangeElapsed 1–2 weeks
2
Full assessment

Oversharing report, costed remediation plan, pilot design, draft policy, roadmap. This is the tier that converts.

Price $3,000–$15,000 RangeAnchor $5,000 at 50 seats = $100/seat RangeElapsed 2–4 weeks
3
Remediation project

Actually fix it. Break inheritance, replace organization-wide grants, expire links, remove leavers, publish labels, stand up DLP in audit mode.

Price $6,000–$15,000 at 50 seats ModelEffort 40–60 hours over 30 days Range
4
Ongoing governance

Drift monitoring, periodic reassessment, quarterly review, attestation reporting. The only tier that compounds.

Price see section 12 — nobody publishes oneCadence monthly and quarterly

16.1 · The scan tier is being commoditized, and that is fine

Distribution changed the economics of tier 0 during 2026. MSP-focused Copilot readiness capabilities are now packaged on a per-tenant, per-month basis with volume discounts, and TD SYNNEX packages an AvePoint-powered readiness assessment as a partner-deliverable service — a full scan of Teams, SharePoint, OneDrive, Exchange and Groups, a risk assessment, a readiness report with a prioritized remediation roadmap, and a business review session — with a stated turnaround inside five weeks and a co-investment commercial model that may be partly or fully funded depending on partner status.

What this means for your pricing

The scan is not defensible as a revenue line. You are competing against a funded distributor offer, and you will lose that on price every time.

The judgment, the roadmap and the remediation are defensible. Give the scan away deliberately rather than losing it slowly — it costs you 60–90 minutes of platform time and it does a job nothing else does, which is the subject of the next section.

16.2 · What the free scan is actually for

Not lead generation. Scoping. Section 17 explains why the scan's real product is a site count, and why quoting without one is how partners lose money on this work.

↑ Back to Table of Contents

17 · Duration and Effort — The Number That Loses Deals

If you take one commercial fact from this guide, take this one.

17.1 · The number the channel repeats

A widely circulated practitioner critique of MSP readiness assessments puts real remediation at 200–400 hours. Enterprise consultancies quote permissions remediation before a Copilot rollout at $50,000–$400,000 over 60–180 days Range. Both figures are honest. Both describe mid-market and enterprise tenants. And partners are quoting SMB work from them.

17.2 · The number that is actually true at this size

One SMB MSP publishes an hour-level phase plan against a stated seat count — which almost nobody does, and which makes it the most useful duration source available for this market.

WeekPhaseWorkIT hours
1InventoryPermission reports, overshared-site export, anonymous-link reports8–12
2Classify and triageApply sensitivity labels; sort findings into four buckets, critical to low12–16
3RemediateBreak inheritance, replace group shares, expire links, implement policies16–24
4Lock and pilotEnable tenant-wide policies, apply containment where needed, pilot with five users4–8
TotalAt a 50-user tenant40–60 hours over 30 calendar days Range

Supporting field data from the same source: a 65-user firm's inventory phase took 9 hours; and in one engagement a single “Everyone Except External Users” misconfiguration accounted for roughly 80% of all high-priority remediation. That second figure is worth remembering — it means the work is usually concentrated, not diffuse, and finding the concentration is most of the job.

At 50 seats, this is 40 to 60 hours. Not 200 to 400.

A partner who scopes an SMB engagement from enterprise literature will price themselves out of every deal they quote — and will assume the work is unaffordable for exactly the customers who most need it.

17.3 · Reconciling the two — the variable is sites, not seats

The 200–400 hour figure is explicitly framed around “permission inheritance across 200+ sites.” A 50-seat firm does not have 200 sites. A typical one has around 30, and well over half the content usually sits in one of them.

The scoping rule

Quote from a site inventory, not from a headcount. Effort scales with sites, libraries and the number of distinct permission structures — not with the number of people.

But seat count is the only thing the buyer knows when they ask for a price. That is precisely what the free scan is for: it produces the site count that determines the quote. This is the clean commercial justification for a free tier that the distributors are commoditizing anyway.

17.4 · A scoping heuristic

Read this table with the caveat attached

This is extrapolated, not published. It is built from the 50-seat figures above and a practitioner convention of scoping governance reviews to 10–25 high-risk or inactive sites. Nobody publishes it. Use it as a planning heuristic and replace it with your own delivery data as soon as you have three engagements behind you.

SeatsTypical sitesAssessment hoursRemediation hoursElapsed, total
25–5010–3015–2530–503–4 weeks
50–10025–6020–3540–704–6 weeks
100–30060–15030–5080–1606–10 weeks

Model — every row above is a construction from the sourced 50-seat figures.

17.5 · Do not forget the waiting

The hours above are work. Section 10.2 established a floor of six to ten elapsed working days of pure propagation waiting. Those are not the same thing and they do not overlap neatly — the label propagation wait in week two blocks the auto-labeling simulation in week three.

Put the waits in the plan as named calendar items. A customer who understands on day one why week three is quiet does not lose confidence in week three.

↑ Back to Table of Contents

18 · What To Charge

MS list published Microsoft price Survey named survey, stated sample Range community-reported, multiple sources Model constructed here from cited inputs

18.1 · The honesty this section is built on

Most pricing guidance in this category launders vendor list prices into benchmarks. Three things you should know about the evidence before you use any number on this page.

18.2 · The assessment

One published price is tied to a stated seat count: $5,000 for a Copilot readiness assessment at 50 users Range$100 per seat. Two other published bands converge on $5,000–$15,000 for SMB independently, which is weak corroboration but is what exists.

At 78 seats that anchors around $7,800 Model, and the honest way to quote it is from the site count the free scan produced, not the headcount.

18.3 · The remediation — and the derivation you should show

Nobody in the SMB channel publishes a remediation rate card. That is a real gap, and the fix is not to invent one but to build it from two things that are published, and to show your working.

InputFigureSource type
Remediation effort, 50-seat tenant40–60 hoursRange Published, hour-level, seat-count-stated
MSP project services rate$150–$250 /hrRange Published MSP pricing guidance
Remediation, 50 seats$6,000–$15,000Model Multiplication, nothing more
→ Sensible fixed-fee landing zone$8,000–$12,000Model
→ Per seat$160–$240Model
The ratio that makes this quotable

Assessment at roughly $100 per seat, remediation at roughly $160–$240 per seat — a ratio of about 1.6–2.4×. The one vendor band that covers both implies 2.7–3×. Same family.

“Remediation is roughly twice the assessment” is defensible ground, and it is a sentence you can say in a room without a spreadsheet.

18.4 · A worked engagement, priced

StagePriceStructure
Scan$0 Model90 minutes. Produces the site count that scopes everything below.
Full assessment$7,800 ModelFixed fee at $100/seat. Credited in full against remediation if they proceed within 60 days.
Remediation$14,000 ModelFixed fee, scoped to a named list of sites from the assessment. Roughly 2× the assessment, consistent with 78 seats and ~30 sites.
Ongoing governance$1,400 /mo ModelFloor-priced, not pure per-user. See section 12.
Year one~$30,600 ModelAssessment credited, so $14,000 project plus 12 months recurring
Recurring thereafter$16,800 /yr ModelThe number that matters

Every figure in that table is a model, not a quote. It is composed from the sourced inputs above and shown so you can rebuild it against your own cost base rather than copy it.

18.5 · Credit the assessment. Always.

Crediting the assessment fee against the remediation project does three things at once, and it is the single best packaging device available in this motion.

EFFECT 1

It qualifies the buyer

Someone who will not pay for an assessment will not pay for remediation. Charging for it filters, and the credit removes the reason to object.

EFFECT 2

It stops the report walking

A free report goes to a cheaper remediator. A credited report is money already committed to you.

EFFECT 3

It keeps the scopes separate

Review billed separately from remediation, with the customer's decisions documented before any cleanup begins. That boundary is what stops an assessment quietly becoming an unpaid Purview deployment.

18.6 · The objection this section exists to answer

“You are just selling us more stuff.” It is fair, it is common, and there is a specific and unusually strong answer.

The self-funding argument

“Fair. So let me show you the part of this that pays for itself. Assessments at your size routinely find 10 to 30% of license spend Range going to the wrong place — people with the wrong SKU, seats assigned to leavers, duplicated add-ons. On your bill that is real money, every month, and it does not stop unless somebody looks.

I would rather find that first and put it against the cost of this work than ask you to fund it out of fear of something that might not happen.”

That answer works because it is checkable, because it reframes you as someone reducing their spend rather than increasing it, and because it is usually true. It also sets up the licensing conversation in section 7 as an optimization rather than an upsell.

↑ Back to Table of Contents

19 · Building the Practice, and What Comes Next

19.1 · The skills floor

There is one non-negotiable, and it is the same one the Customer Zero Starter Kit argues for everywhere else on this site.

Run it on yourself first

Before you quote this work, complete it in your own tenant. Publish four labels. Watch the 24-hour propagation actually take 24 hours. Run an auto-labeling simulation and discover it fired 300 activity alerts because you did not scope the alert policy first. Break something with an encrypting label and find out what it costs to unbreak.

Every hour of that is an hour you will not lose in front of a customer, and it converts the numbers in section 17 from something you read into something you know.

Beyond that: one person holding SC-401, one person who can chair a room of business owners, and a written decision about who signs the irreversible changes in section 10.4. That is the floor. It is lower than most partners assume and higher than most partners currently clear.

19.2 · When this becomes a practice rather than a project

The threshold is repeatability, and it has a specific shape. The first engagement costs you 60–80 hours because everything is new. The third costs 40 because you have a scan procedure, a report template, a workshop agenda and a scope boundary. The difference between those two numbers is the entire margin.

At roughly ten customers, three things change together: platform tooling starts to pay for itself (section 13.3), findings become comparable across tenants so your report becomes a product, and the recurring revenue is enough to carry a dedicated person. Below ten, this is a service the senior consultant does between other work. Above it, it is a practice.

The margin target worth holding yourself to: best-in-class MSPs run around 19%+ adjusted EBITDA Survey, against a median closer to 9%. Governance work delivered repeatably sits comfortably in the top band. Delivered ad hoc, it sits below the median, because the senior consultant's hours are the most expensive thing you own.

19.3 · What the conversation opens next

This is the part partners undersell. The governance engagement is not the end of a sale; it is the qualification event for four more. Only SMB-scale numbers appear below — the enterprise figures circulating for all of these are irrelevant here and actively misleading.

1
Adoption and change management

The natural second project, and the one that protects the first. Governance and adoption fail independently — a perfectly remediated tenant that nobody uses still loses the customer at month three, and it will look like your fault.

Price $50–$100 /user RangeAt 78 seats ~$3,900–$7,800 ModelTrigger day 30 of the pilot
2
Agent development

Once the data estate is trustworthy, agents become buildable. Stay in the basic-integration tier: prebuilt connectors, straightforward authentication, read-mostly data.

Price $5,000–$20,000 RangeRule design fixed-fee, integration time-and-materials
3
Compliance and certification support

Now with three independent forcing functions rather than one: the insurance underwriting shift, the enterprise client questionnaire, and the EU regime for anyone with European exposure.

Gap analysis $5,000–$15,000 RangePolicy development $2,000–$5,000 per framework Range
4
Data lifecycle and records

The redundant-data cleanup you deliberately deferred in section 8.2. Sell it on storage cost, not risk — cost avoidance is a materially easier conversation with a 78-person business than another security argument.

Price $3,000–$8,000 per pass Range — weakest evidence of the four
Quote this, do not absorb it

Agent runtime consumption

Copilot Studio runs on a credit model — roughly $200 a month for 25,000 credits, or pay-as-you-go per credit Range. Consumption is not uniform: a classic answer costs 1 credit, a generative answer 2, an agent action 5, and grounding in Microsoft Graph costs 10.

Graph grounding is the one that touches tenant content, which means any agent built on the data estate you just cleaned up will hit it constantly. Budget 10–20% headroom, 30% for chained agent calls, and put consumption in the customer's name rather than absorbing it into a fixed fee.

19.4 · Where to see what the channel is actually doing

Everything in this guide is dated, and some of it will be wrong within two quarters — Microsoft moved SharePoint Advanced Management's entitlement, retired a certification and blocked a containment feature inside eighteen months. The correction usually shows up in the community weeks before it shows up in a partner deck.

These are the places that were load-bearing in researching this guide, and they are worth a standing half-hour a week.

WhereWhat it is good for
Microsoft Learn release notes and ms.date stampsThe single most reliable signal in this whole field. Every Learn page carries a date; when a page you depend on moves, something changed. Bookmark the SharePoint Advanced Management prerequisites page and the Purview sensitivity-label page specifically — both moved during this research.
Microsoft Tech Community — Purview, SharePoint and Copilot blogsWhere feature changes and deprecations get announced before they reach documentation, and where the comment threads tell you what broke for other people.
The Purview and information-protection MVPsA small, identifiable group publishes almost all of the useful field detail in this space — label taxonomy design, oversharing remediation at real scale, what the deployment blueprints leave out. Their write-ups are consistently months ahead of channel material.
The SMB and MSP practitioner communityThe most candid source on what this work actually costs to deliver and what customers actually pay. It is also where the delivery post-mortems live — the engagements that went wrong, which nobody publishes as a case study.
Practitioner blogs from working consultantsWhere you find hour-level effort breakdowns against stated seat counts, which is the number this guide had the hardest time sourcing. Section 17 rests on exactly one such source.
Vendor release notes — including AvePoint'sRead them for capability changes rather than marketing. The gap between what a platform claimed last year and what it ships this quarter is where your assessment either gains or loses a feature.
Bring something back

The honest gap in this guide, stated in section 21.3, is that no independent dataset exists for what this work costs or what it finds in a 25–300 seat tenant. Every prevalence statistic in circulation comes from a vendor selling remediation, sampled from enterprise tenants.

Ten engagements in, with your own anonymized findings written down — sites per seat, share of exposure concentrated in one site, hours per remediation — you will own the only real dataset in the channel. That is worth more than any benchmark you could borrow, and it is the thing worth contributing back.

19.5 · How this ties to the Microsoft partner program

The tier ladder, the partner capability score and the certification roadmap are covered in The Path to Frontier Partner. What follows is only what is specific to this motion.

Do this firstWhy
Fix your CPOR hygieneIt is free, it is administrative, and it is worth real points. Association thresholds for customer-success metrics are materially lower than the transacting equivalents for identical points — and usage growth only counts from the date of association, so pre-existing usage is worth nothing. Claim on every workload you influence, today. This is days of work for a meaningful score movement.
Pursue Solutions Partner for Security via the SMB pathMicrosoft scores both the enterprise and SMB paths and takes the higher. The SMB skilling column is the unlock, and one person can hold more than one of the qualifying certifications. The threshold only has to be cleared on a single day inside a rolling six-month window — most small partners believe they must sustain it, and they do not.
Get onto Security Immersion BriefingsSince January 2026 the execution cap was removed, resellers can deliver and claim, and the stated focus is Defender and Purview for Business Premium customers at 50–300 licenses. That is precisely this guide's customer. Uncapped, repeatable, and claimable — ask your partner development manager what a briefing pays, because the amount is not published.
Sell the Purview play while Microsoft funds it50% off Purview Suite for Business Premium alongside Copilot, through 31 December 2026 MS list. Microsoft is funding control-before-scale directly and the window closes.
Defer or skipWhy
Defer the specializationsThey now require partner-funded third-party audits on a two-year cycle, validating a documented repeatable delivery process rather than skills. Build the methodology and the evidence pack first — this guide is most of the methodology. Note also that only three security specializations earn benefits; a fourth earns nothing.
Skip FastTrackIts seat floor sits above most of this market. That gap is your business.
Skip marketplace listings and MACCServices-only partners are excluded from the marketplace rewards economics, and SMB customers do not hold consumption commitments.
Skip customer investment funds and Copilot vouchersEligibility rules exclude CSP customers and set seat minimums far above this segment.
On incentive rates specifically

Every FY27 incentive rate circulating in the channel comes from documents behind partner sign-in. This guide names mechanisms and deliberately names no rates. If a number matters to your business case, get it from Partner Center yourself — a secondhand incentive rate is the fastest way to build a plan on a figure that was never real.

↑ Back to Table of Contents

20 · Running the Session

This section is for whoever facilitates this material as a workshop session — Control Before Scale: Assess, Govern and Earn Trust on a Customer Zero agenda. Everything below is an extract of material already in this guide — nothing is authored twice, and every figure the room sees has a section number behind it.

20.1 · The design principle

The session's premise is that partners lose this conversation by leading with the plumbing. A session that teaches the plumbing in the order partners already fail with it will reproduce the failure in the room. So the running order inverts the usual one: the customer and the failure first, the sequence second, the economics third, and the controls last, as reference.

20.2 · Run of show — 90 minutes

000–5 minThe cold openFacilitator

No statistics. Two show-of-hands questions.

“Who has had a Copilot conversation stall on ‘we need to sort our data out first’?” Most hands.

“Now keep your hand up only if the customer said it.” Most hands go down. That silence is the session.

They leave with: the failure named in their own experience, before any content. Source: §1
015–15 minMeet the customerFacilitator + handout

One-page profile of a composite 80-seat customer on mixed Business Standard and Business Premium, distributed face down and turned over on cue. Facts only, no findings. The room needs to recognize this customer from their own book before they are told what is wrong with it.

They leave with: a 78-seat customer they recognize. Source: §5 — handout E-1
0215–30 minExercise A — where do you start?Tables · 8 min + 7 report

One question: what is the first thing you sell them, and what does it cost?

Capture answers verbatim before commenting. The spread is the teaching material — some sell an assessment, some sell Copilot seats, some sell a security project, some say “I'd fix the SharePoint first.” Do not correct any answer. Stop 3 does that structurally.

They leave with: their own instinct surfaced and on the wall, where the next segment can act on it
0330–45 minThe bridge — and the constraintFacilitator · the spine

Three gates and nothing else. Then what is not a gate, which is the part that changes how they scope. Then the containment pattern and the move-3 trap.

Close the segment on the licensing constraint: read Microsoft's base-SKU list aloud, let the room notice Business Premium is not on it — and then immediately give them the three options. Do not leave them sitting in the problem. The room's takeaway must be “this is solvable for the price of three licenses,” not “my customers all need E5.”

They leave with: the one diagram they photograph. Source: §8 and §9
0445–55 minThe licensing decisionFacilitator + table

A decision table, not a feature matrix. The $37-against-$60 comparison, the two mis-sales, and the promotion that expires on 31 December 2026.

This is where a vendor slot belongs, if there is one — six minutes, on the question the room has just asked itself: how do I actually find and fix this on a Business Premium tenant? See 17.4.

They leave with: an answer to “can they even buy it?” Source: §7, §14
0555–70 minExercise B — price the engagementTables · 9 min + 6 report

Each table produces three numbers for the composite customer — assessment, remediation, monthly — and one sentence of justification for each.

The spread across the room is always wide, and the wide spread is the lesson: everyone is guessing, and whoever guesses lowest sets the market for the rest. Then show the researched ranges and the delivery-cost side, so tables can see which of their own numbers were unprofitable.

They leave with: a number they wrote down and defended out loud. Source: §17, §18 — worksheet E-2
Do not cut Exercise B for time

It is the highest-value nine minutes in the session and the first thing a running-late facilitator sacrifices. If it genuinely will not fit, the session is a webinar and should be billed as one.

If competitors are in the room and price discussion is a concern, run the exercise against delivery cost and margin rather than price. It teaches the same lesson — most of the room is under-costing the senior's hours — without anyone comparing rate cards.

0670–80 minThe recurring layerFacilitator

The 48%-against-13% gap. The finding that nobody has published a price for this yet, so they are setting the reference rather than matching one. The floor-price structure and why a pure per-user rate loses money at 40 seats.

They leave with: the practice model, not the project. Source: §12
0780–88 minObjections, liveFacilitator versus the room

Facilitator plays the owner. Three objections only — the ones that actually end deals:

“Our last MSP reviewed us and said we were fine.” — attack the date, never the predecessor.
“Why am I paying monthly for a one-time cleanup?” — drift, and the control plane changing underneath them.
“Microsoft says Copilot respects permissions, so we're covered.” — access control is not exposure.

The softer objections live in the Shadow AI Assessment Guide and are the leave-behind, not the room.

They leave with: the three that matter, answered out loud. Source: §5.3, §9.1, §12.4
0888–90 minThe 30-day closeFacilitator

One action, written on the handout, with a date: run the assessment on your own tenant. Not a reading list. Not a follow-up call. One thing, dated.

They leave with: a commitment. Source: §19.1 — card E-5

20.3 · Variants

SlotCutProtect
60 minExercise A becomes a 3-minute poll; objections cut to one; the recurring layer compressed to the two headline numbersStop 3 and Stop 5 survive intact. Everything else is negotiable.
120 minAdd a live walkthrough of the actual portal paths from §10, and a second objection round with roles reversed — the room sells, the facilitator objects.
Theater-style, 100+Both table exercises become pollsBe honest that this is a materially weaker session. If the room cannot sit at tables, Stop 5 should become a facilitator-led walkthrough of one worked quote rather than a poll.
Self-serveThe whole roomThis guide, with the exercises rewritten as self-assessment prompts

20.4 · Where a vendor fits

A vendor in the room is an asset if the session places them and a liability if it does not. The rule: the vendor answers a question the session has already made the room ask.

That moment is inside Stop 4, immediately after the licensing constraint lands and the room asks how to find and fix permission sprawl on a Business Premium tenant without three weeks of PowerShell. The question is real, the native answer is genuinely partial at this seat count, and a demo lands as relief rather than as an interruption.

Set with the vendor beforehandWhy
Six minutes, inside Stop 4, on the stated questionNot a corporate overview. The room has a specific question and a specific attention span.
Multi-tenant support and price per seat disclosed in the roomSub-100-seat economics are the room's actual objection. A vendor who will not address them should not present.
The session names the free and native path firstCredibility with a partner audience depends on §13 being honest that scripts work at one customer and platforms earn their place at ten.
No exclusivity in the written guideThe page carries a comparison table. The room carries whoever showed up.

20.5 · What the facilitator must be able to do

A session on a technical journey fails when the facilitator cannot answer the third follow-up. The floor:

20.6 · Materials

IDArtifactExtract of
E-1Customer profile — one page, printed§5
E-2Pricing and scoping worksheet§17.4, §18
E-3The vendor question list§14.8
E-4Classification workshop agenda — four people, ninety minutes, output is signed intent statements§10.3
E-5The 30-day card§19.1
↑ Back to Table of Contents

21 · Sources, and What We Could Not Verify

This section exists because the rest of the guide argues that honesty about evidence is a commercial differentiator. It would be strange not to apply that here.

21.1 · Do not repeat these

Every item below circulates in partner material. Each is wrong, stale, or unverifiable, and using any of them will cost you credibility with a buyer who checks.

Claim in circulationThe problem
“802,000 at-risk files per organization”Presented as current; traces to a 2022 report. Date it or drop it.
“150–300 overshared SharePoint sites per tenant”No published methodology, and it describes enterprise tenants. Actively misleading in an SMB room.
“99% of organizations have sensitive data exposed to AI”Real vendor research, but too high to be believed. Use the 1-in-10 labeled files figure instead.
The Gartner pilot-progression percentageTwo sample sizes and two different percentages circulate for what is presented as one finding, and a competing survey reports the opposite. Cite the governance-delay pairing, not the decimal.
“Get your team SC-400”Retired 30 May 2025. The replacement is SC-401.
“Enable Restricted SharePoint Search while we review permissions”New enablement was blocked on 31 July 2026. Microsoft directs you to Restricted Content Discovery. Any playbook opening with this step is unexecutable.
“SAM is included with Copilot, so the E5 objection is dead”True only on an E-SKU base. See §9.4. This over-correction is now as common as the error it replaced.
“The EU AI Act will hit your business next year”High-risk obligations moved to 2027–2028, and an SMB using Copilot is a deployer, not a provider.
“Colorado's AI Act takes effect in February 2026”That law was repealed and replaced. The replacement takes effect 1 January 2027.
Any FY27 Microsoft incentive rateAll sit behind partner sign-in. Name mechanisms; get rates from Partner Center yourself.
“MaestroBridge” as an AvePoint productNo such product exists. Maestro is the classification engine inside Opus.
A published SANS AI acceptable use policy templateCould not be found. Do not cite one.

21.2 · Confirm these before you quote

Three claims this guide deliberately does not make, because no primary source settles them. Each one is a question for a licensing desk, a distributor or a vendor — get the answer in writing and it stops being a risk.

Why these are questions and not experiments

It is tempting to buy a seat, watch what lights up in the portal, and build a recommendation on the result. Do not. Portal behavior is not an entitlement, it changes without notice, and a customer who is audited will be measured against the licensing terms rather than against what worked in your tenant last quarter. Ask the people who can answer authoritatively, and quote from their answer.

Q1

How does SharePoint Advanced Management's base-subscription requirement apply in a mixed-SKU tenant?

Microsoft states it at organization level — “Your organization must have one of the following base licenses” — and publishes no guidance on tenants that hold a mix. Ask Microsoft licensing or your distributor how it is measured and licensed before you build a proposal on it.

Ask: Microsoft licensing desk or TD SYNNEX · affects §2.3 option 3
Q2

Does the Purview Suite for Business Premium include auto-labeling and the DSPM for AI surface?

Microsoft's add-on page says “policy-based controls for AI experiences” and never uses the term DSPM; the Purview service description has no DSPM section. Both capabilities are described in general language rather than named.

Ask: Microsoft licensing desk · affects §7.3 and §10 · highest risk of a wrong claim
Q3

Does the Defender Suite for Business Premium carry full Defender for Cloud Apps?

Corroborated by community and reseller sources, not by a Microsoft page read in this research. If it does, $15 per user per month is the price of shadow AI discovery for an SMB, which changes the recommendation in §13.

Ask: Microsoft licensing desk or TD SYNNEX

A fourth question belongs to a vendor rather than to Microsoft: whether AvePoint Insights runs at full fidelity on a Business Premium tenant, given its risk prioritization draws on Microsoft sensitive information types and the activity feed. No AvePoint statement exists either way, and §14.5's central claim rests on it. It is question 2 on the list in §14.9.

21.3 · What this guide could not research

Two gaps you should know about before you rely on section 18

The MSP practitioner forums could not be reached. The pricing evidence here rests on published surveys and partner rate cards, not on invoices. No community-reported figure was invented to fill the gap — but it means the numbers in §18 are weaker than they look, and your own delivery data should override them the moment you have three engagements behind you.

No SMB-specific prevalence data exists at all. Every oversharing statistic in circulation comes from a vendor selling remediation, sampled from enterprise tenants. If you want a defensible number for 25–300 seat businesses, start recording your own anonymized engagement findings. Ten engagements in, you will own the only real dataset in the channel.

21.4 · Primary sources worth reading yourself

21.5 · Related guides on this site

If you take one thing

The customer does not need to be frightened into this. Seven in ten of the organizations that got the returns Microsoft advertises did the data security work first. You are not selling insurance against a disaster that may never arrive. You are selling the precondition that separated the deployments that worked from the ones that quietly stalled — and you are selling it to a business that is going to buy Copilot either way.

↑ Back to Table of Contents