Seven phases from the first scan to recurring governance — for the customers you actually have, on Business Premium, who are not buying E5.
Your customer cannot safely turn Copilot on until the plumbing is fixed. That is true, and it is why you keep losing the deal.
Start with The Copilot Readiness & Governance Engagement — the same seven phases as gates, checklists, decision tables and effort bands, and the version to work from when you are scoping, quoting or standing up Purview. This page is where its figures come from: the reasoning in full, the evidence and its weaknesses, the practice-building material and the workshop run of show. Read it once; deliver from the other one.
There is a version of this meeting that every partner has had. The customer asks about Copilot. You explain, correctly, that before they turn it on you need to look at permissions, data classification, DLP and retention. You are technically right about every word of it. And you watch the energy leave the room.
The usual diagnosis is that the customer is not mature enough, or that they will learn the hard way. Both are comfortable and neither is useful. Here is the more uncomfortable reading, and it is the reason this session exists.
Leading with governance is the responsible opening. You are protecting the customer from an outcome they cannot see coming. If they will not engage with the prerequisite work, the deal was never real.
A list of reasons they cannot have the thing they asked for. You have converted a demand conversation into a compliance conversation, and you did it before establishing that anything is wrong.
Watch the order carefully, because it is the whole problem. The customer arrived with demand. You replaced it with an obligation. Nothing in that exchange established that their tenant actually has a problem — you asserted a general truth about Copilot and asked them to fund a project on the strength of it.
In most stalled Copilot deals, the governance objection was raised by the partner, not the customer. Ask any room of partners who has had a Copilot conversation stall on “we need to sort our data out first,” and most hands go up. Ask whose customer said it and whose partner said it for them, and the room gets quiet. That second question is the session.
The first failure is the one above — leading with the plumbing. The second is more recent and it is spreading fast among partners who have actually done their homework.
A partner reads up on Copilot readiness, discovers that Microsoft’s oversharing toolkit requires an enterprise license base their customer does not have, and concludes the customer must move to E5. They put a number in front of a 78-person business that roughly doubles its Microsoft bill, and the conversation ends there.
Opens with governance. Kills the demand before establishing that anything is wrong. Loses on sequence.
Finds the licensing constraint, believes it means E5, and quotes accordingly. Loses on a conclusion that is wrong.
Both end the same deal. The second one is worse, because the partner walks away believing they did the responsible thing. Section 2 is the correction, and it is deliberately the next thing you read.
This is not an argument for skipping the work. The work is real, the risk is real, and section 9 will show you a licensing wall that makes the standard approach to it fail outright. It is an argument about sequence and about who is carrying the burden of proof.
It assumes you have not really turned Purview on. Perhaps you enabled a label once in a demo tenant. It assumes you have never sat four people from a customer's business down in a room and walked them to a decision about how their documents should be classified. It assumes that when you have quoted this work, you guessed, and that the guess was probably too low or too high by a factor that would embarrass you if you saw the real numbers.
That is not a criticism. It describes most of the channel, including partners who are excellent at everything else. This work sits at an awkward intersection — too advisory for a technician, too technical for a vCIO, and until recently too expensive to tool for a sub-100-seat customer. What follows is written for that reader specifically, which means it explains things a Purview specialist would find obvious and refuses to hand-wave things a salesperson would rather not read.
It is not the shadow AI conversation. That one is already written up in the Shadow AI Assessment Guide — how to open with discovery rather than product, what SMBs actually have running, Microsoft's discovery model, the thirty-app enterprise onboarding matrix, and how to read Partner Center propensity signals into a weekly call list. This guide starts where that one ends: the scan came back, the findings are real, and now somebody has to fix the tenant and get paid for it.
It is also not the post-deployment usage story. Once Copilot is live and you need to prove it is working, that is the Copilot Adoption Audit.
Everything after this section is detail. If you read nothing else, read this page.
Your customer is on Business Premium. They are not buying E5. They do not need to.
Across the 25–300 seat market the answer is almost always Microsoft 365 Business Premium, often mixed with Business Standard on the seats nobody got around to upgrading. That is the normal case, not the failure case, and this guide is written for it.
It matters because Business Premium was sold, correctly, as a complete small-business security stack — Entra ID P1, Defender for Business, Intune, Defender for Office. It is a good SKU and it did the job it was bought for. Copilot did not make it inadequate. Copilot added one requirement that nobody was scoping for in 2023.
Sensitivity labels, DLP, retention, insider risk, audit, and the controls that keep labeled content out of Copilot — all of it, through the Purview Suite for Business Premium add-on.
There is no gap here. Do not let anyone tell your customer they need E5 for this.
SharePoint Advanced Management — the oversharing toolkit. Data Access Governance reports, Everyone Except External Users insights, Restricted Content Discovery, site access reviews.
Microsoft requires an Office 365 or Microsoft 365 E-SKU base for it. Business Premium and Business Standard are not on the list, and buying Copilot does not change that. Full detail and the verbatim requirement in section 9.
That is the entire gap. One toolkit, one requirement. Everything else in this guide is reachable on the licenses your customer already owns.
Every option below is documented, buyable today, and produces a defensible engagement. They differ in cost, in effort, and in what they leave you unable to do — so the risks are stated with each one rather than buried.
The SharePoint admin center exposes sharing settings, site permissions and sharing reports. The SharePoint Online PowerShell module enumerates permissions across the estate. Free tooling covers the configuration baseline. This is a complete, legitimate delivery path and it is where most partners should start.
Risk: the output is raw rather than client-ready, so you supply the judgment and the report. There is no continuous monitoring, so you are re-running work rather than watching for drift. Effort grows with site count, and past roughly 100 seats or a handful of customers the consultant hours stop being cheaper than a tool.
Some platforms read Microsoft's security and activity feeds rather than depending on SharePoint Advanced Management, so they run on a Business Premium tenant with no Microsoft license change at all. That is an architectural difference, not a loophole. It is also the only option here that gives you continuous drift monitoring, which is what the recurring fee in section 12 is actually for.
Risk: seat minimums can price out your smallest tenants, and pricing in this category is largely unpublished, so you are quoting against a number you have to go and get. Label-enforcement features generally still inherit Microsoft's E5 requirement, and no platform replaces Restricted Content Discovery.
Microsoft's own documented path. On an Office 365 or Microsoft 365 E-SKU base, a single assigned Copilot license unlocks the whole SharePoint Advanced Management toolset — the governance reports, Restricted Content Discovery, site access reviews. If the customer is heading to E3 anyway, or genuinely needs Restricted Content Discovery, this is the right answer and not a defeat.
Risk: it is the most expensive option per seat, and it does not solve the other half — E3 does not carry the control that keeps labeled content out of Copilot, which still needs the Purview Suite family. Confirm the exact entitlement in writing with Microsoft licensing or your distributor before you quote it, including how it applies in a mixed-SKU tenant. Microsoft states the requirement at organization level and does not publish a partial-adoption scenario, so this is a question to ask, not one to assume.
Start with option 1. It costs nothing, it proves you can deliver the engagement, and the findings are the same findings. Move to option 2 once you have enough customers that re-running manual work is the bottleneck — roughly ten, per section 13. Reach for option 3 when the customer specifically needs Restricted Content Discovery, or is moving to an enterprise SKU for reasons that have nothing to do with you.
What you should not do is present an enterprise upgrade as the only way through. It is one of three, and it is the one your customer is least likely to accept.
Partners consistently do not know that Microsoft publishes SMB-scale guidance for exactly this, and citing it removes the suspicion that the whole conversation is a partner upsell. Five things Microsoft says, in Microsoft's own words, that you should be repeating.
| Microsoft says | Why it matters to you |
|---|---|
| Contain, remediate, then un-contain | Apply interim protections, fix the permissions, then remove the interim protections. Partners routinely skip the third step and leave the customer paying for a Copilot that cannot see their own content. Section 8.3. |
| Start from the default label set | Microsoft auto-creates Personal, Public, General, Confidential and Highly Confidential for eligible customers. Cut that down rather than designing from a blank page. |
| Keep it to 5×5 | “Effectiveness is noticeably reduced when users have more than five main labels or more than five sublabels per main label.” At this size, four top-level labels is plenty. Section 10.3. |
| DLP in audit mode first | Three documented stages — simulation, then policy tips, then enforcement. Enforcing on day one produces the false-positive flood that retires the control permanently. |
| Fabrikam | Microsoft publishes an 18-person startup DLP persona with a prescribed approach. It is the closest thing to official SMB guidance that exists and almost nobody in the channel has seen it. Section 10.5. |
| At a 78-seat customer | Figure | Detail in |
|---|---|---|
| Assessment | ~$100 per seat Range | Section 18.2 |
| Remediation — roughly 2× the assessment | $160–$240 per seat Model | Section 18.3 |
| Remediation effort at 50 seats | 40–60 hours over 30 days Range — not the 200–400 the channel repeats | Section 17 |
| Ongoing governance | Nobody publishes a price. You set the reference. | Section 12 |
“You are on Business Premium, and that was the right call — it is a genuinely good security stack and it did the job you bought it for. Copilot adds one requirement nobody was scoping for when you bought it, which is knowing who can see what across your SharePoint.
The good news is that the data protection side is a ten-dollar add-on, and Microsoft is running it at half price alongside Copilot until the end of the year. Nobody is asking you to move to E5.
The permissions side needs one extra piece, and there are three ways to get it — one of which costs about as much as three licenses. Let me find out which one applies to you before either of us assumes it is expensive.”
One: open with the governance work and watch the demand evaporate before anything has been established. Section 1.
Two: discover the SharePoint Advanced Management requirement, conclude the customer has to buy E5, and quote a number that ends the conversation. That conclusion is wrong, and this section is the reason.
Every guide in this category opens with a statistic designed to frighten a business owner. Most of those statistics come from companies selling the remedy, and a prospect with a search engine can work that out in ten minutes. So this section does something less satisfying and more durable: it separates what is actually documented from what is merely repeated, and it tells you which arguments survive a skeptical room.
In January 2026, Microsoft 365 Copilot Chat began returning summaries derived from content in users' Drafts and Sent Items — including messages carrying confidentiality sensitivity labels and covered by DLP policies specifically configured to exclude them from Copilot processing.
| Microsoft tracking ID | CW1226324 |
|---|---|
| First reported by customers | 21 January 2026 |
| Fix rollout | Began early February 2026; remediation still incomplete mid-February |
| Approximate exposure window | Four weeks |
| Content categories involved | Legal memos, business agreements, government correspondence, protected health information |
| Named affected organization | UK National Health Service, tracked internally as INC46740412. NHS stated patient information was not exposed. |
| Microsoft's position | That users only accessed information they were already authorized to see |
| Number of tenants affected | Not disclosed |
Read Microsoft's response again, because it is the reason this incident matters more than any statistic in this guide. Users only accessed information they were already authorized to see. That is the exact sentence your prospect will say to you when you raise oversharing. Here it is being said by Microsoft, about an incident in which a customer had configured labels and DLP correctly and the control plane bypassed both anyway.
It does not prove Copilot is unsafe. It proves something more useful and more sellable: the control plane is new, it changes monthly, and neither Microsoft nor the customer had independent visibility into whether the controls were doing what they were configured to do.
That is an argument for a monitored, recurring governance service. It is not an argument for a one-time cleanup project, and a partner who uses it to sell one has misread it.
Do not let CW1226324 compress in retelling into “Copilot leaked NHS patient data.” The NHS explicitly said it did not. If you overstate this in a room and someone looks it up, you lose the entire section along with your credibility on everything after it.
Here is the finding that most competing material will not tell you.
There is no published, named-company case study of Microsoft 365 Copilot surfacing HR or salary data to the wrong employee. Not one that survives a search. The stories circulate constantly in the channel and they are almost certainly happening, but companies do not publish “we bought AI and it embarrassed us,” and no breach-notification regime compels them to.
The corollary is equally important: there is also no enforcement action anywhere — no GDPR fine, no FTC action, no ICO reprimand — against a company for an AI-assistant oversharing incident. If you imply otherwise you are inventing regulatory risk, and the customer's lawyer will find out.
What you can cite is a corpus of a different shape: vendor-side product failures like CW1226324, and security research disclosed and patched before anyone exploited it. Both are real. Neither is a customer scandal. Argue from mechanism, and use the incidents to show the mechanism is not hypothetical.
Lasso Security found 20,580 repositories across 16,290 organizations — including Microsoft, Google, Intel, PayPal and IBM — still reachable through Copilot after being made private, because a search cache retained them. Disclosed Nov 2024, addressed Jan 2025.
PromptArmor demonstrated exfiltration of private-channel Slack data via an instruction planted in a public channel and ingested into the AI's index. The attacker never needed access to the private channel. MITRE ATLAS AML.CS0035.
Radware's ShadowLeak was the first service-side zero-click prompt injection — the whole chain executes inside the AI vendor's cloud, leaving no artifact on the endpoint or the network. EDR and network monitoring are blind to this class of event by construction.
Exhibit A is the one to use with a non-technical owner, because the principle is intuitive and it transfers directly to Microsoft 365: once an index has seen something, taking away access to the original does not take it out of the index. That is precisely why Restricted Content Discovery requires a reindex rather than taking effect instantly.
The zero-click Copilot vulnerabilities — EchoLeak (CVE-2025-32711, CVSS 9.3, disclosed June 2025) and CoSnitch (CVE-2026-24301, disclosed December 2025, patched August 2026) — belong in a technical conversation and nowhere near a business owner. Every one of them was responsibly disclosed and patched with no confirmed exploitation in the wild. Cite them for mechanism; never imply harm occurred. CoSnitch has one genuinely SMB-relevant angle: it affected Copilot Personal, which is exactly the shadow-AI pattern a readiness assessment is supposed to find.
Varonis scanned roughly 1,000 real environments covering about ten billion files. The number worth quoting from it is not the frightening one.
Lead with one in ten. It is modest, it is checkable, and the customer will recognize it as true about themselves before you finish the sentence. The 99% figure is worse rhetoric precisely because it is unbelievable — a number that high reads as marketing, and it invites the prospect to discount everything else you say.
“802,000 at-risk files per organization.” Widely presented as current. It traces to a 2022 report. Date it 2022 or drop it.
“150–300 overshared SharePoint sites per tenant.” No published methodology anywhere, and it describes enterprise tenants regardless. A 78-seat firm does not have 300 sites, which makes this actively misleading in an SMB room.
There is also no credible statistic for how much stale or redundant data sits in a typical SMB SharePoint estate. Argue that one from the customer's own reports, not from a number.
Everything above is defensive — it stops you from being wrong. This is the part that wins.
Forrester's commissioned Total Economic Impact study of Microsoft 365 Copilot interviewed sixteen decision-makers across twelve organizations and surveyed 367 people with Copilot experience. The headline ROI figures are enterprise-composite and you should not use them with a 78-seat customer. One finding transfers completely.
70% of the organizations Forrester surveyed ran data security projects before deploying Copilot.
That reframing does more commercial work than every incident on this page combined, because it converts governance from a tax into a success factor. It also happens to be true, which means it survives being checked.
“I am not going to tell you Copilot is dangerous, because mostly it isn't. What I will tell you is that when Forrester looked at the companies who got the returns Microsoft advertises, seven in ten had done a data security project first. That is the difference between the deployments that worked and the ones that quietly stalled. I would rather put you in the first group, and it is cheaper to do that now than to unpick it later.”
A guide that only presents risk is a guide the customer stops trusting the moment they read something balanced. Two pieces of honesty you should carry into every meeting.
Most deployments proceed without an incident. The absence of published customer scandals cuts both ways. If Copilot were routinely producing HR disasters across tens of thousands of tenants, some would have surfaced through employment tribunals or trade press by now. The dominant observed customer-side outcome is delay and friction, not breach.
The pilot-to-scale statistics are contested and you can get caught. Gartner-derived material puts the share of organizations moving past pilot in the single digits. A Morgan Stanley and RSM survey reports 79% of enterprises deployed with half past pilot. Those cannot both describe the same population. If you quote the pessimistic figure to a prospect who read the optimistic one, you have lost. What is not contested is that governance work is a common cause of delay — roughly two-thirds of surveyed IT leaders reported that information governance and security risks consumed significant time and resources during deployment. Argue that, and leave the decimal points alone.
Timing is the difference between a governance conversation that lands and one that sounds like an upsell. The rule is simple: you want an external party to have already asked the customer a question they cannot answer. Then you are helping them answer it rather than manufacturing a reason to care.
Ranked by how often they actually apply to a business under 100 people, and by how hard a deadline they carry.
It is annual, it is sector-agnostic, it is headcount-agnostic, it has a hard date, and it has a named signer who is personally uncomfortable attesting to something they do not know. Nothing else in this list has all five properties.
What changed, and why almost nobody in the channel has noticed yet: the standard-forms body introduced generative-AI exclusion endorsements for commercial general liability — CG 40 47, CG 40 48 and CG 35 08 — effective 1 January 2026, and carriers began attaching them at renewal. Cyber policies remain the more stable source of AI coverage for now, but carriers are adding AI sublimits, reported at around a tenth of policy limit in some cases. Some carriers are writing affirmative AI coverage deliberately and pricing it against documented governance.
Before 2026, most organizations were covered for AI losses by silence rather than by grant. That silence is being written out of policies right now, quietly, at renewal.
“Pull out your last general liability and cyber renewal endorsements. Not the policy — the endorsements. Do you have a generative AI exclusion on there? Most companies acquired one this year without being told. And if your cyber policy now carries an AI sublimit, I would want to know what it is before your staff put another client document into a chatbot.”
The customer can verify this themselves in ten minutes, which is exactly what makes it powerful. You are not asking them to believe you.
There is no published, adjudicated insurance claim denial attributable to AI use. The exclusions are only months old. Argue the underwriting shift — which is documented and verifiable — and do not imply that anyone has been denied a claim yet, because as far as the public record shows, nobody has.
| Trigger | Who it actually covers | Why it forces the conversation |
|---|---|---|
| FTC Safeguards Rule | Accountants, tax preparers, auto dealers arranging finance, mortgage brokers, and insurance brokers under GLBA | Requires a written risk assessment and a designated qualified individual. Note the trap: the fewer-than-5,000-consumers exemption removes exactly the written risk assessment you were planning to sell. Check the count first. |
| CMMC Phase 1 | Defense contractors and subcontractors handling federal contract information | In force since 10 November 2025; self-assessment gates contract award. The sharpest deadline available, applying to a narrow slice of the channel. |
| ABA Formal Opinion 512 and 35+ state bars | Law firms of any size | Issued 29 July 2024. Creates a professional-conduct obligation around confidentiality when using generative AI. For a small firm this is the partner's license, which concentrates attention. |
| Illinois HB 3773 | Any employer with Illinois staff | Effective 1 January 2026. Reaches employers who have never thought of themselves as regulated. |
| HIPAA's existing risk-analysis duty | Covered entities and business associates | Already in force — you do not need the proposed Security Rule update, which now targets 2027. Benefits administration drags ordinary companies into business-associate status more often than they realize. |
This is the highest-credibility paragraph in the guide. Most partner marketing overstates regulatory applicability to small business, and sophisticated buyers know it. Being the partner who narrows the claim is worth more than any statistic.
| Commonly cited | The actual position as of August 2026 |
|---|---|
| EU AI Act | Enforcement provisions apply from 2 August 2026 with penalties up to €35M or 7% of global turnover — but high-risk obligations were pushed to December 2027 and August 2028. An SMB using Copilot is a deployer, not a provider, and carries far lighter obligations than most partner decks imply. |
| Colorado AI Act | SB 24-205 was repealed and replaced. The replacement takes effect 1 January 2027. Any partner material still citing a February 2026 Colorado deadline is citing a law that no longer exists. |
| California ADMT rules | 1 January 2027, and gated behind CCPA applicability thresholds that most sub-100-seat businesses do not meet. |
| ISO/IEC 42001 | A genuine and useful frame — see section 12 — but it is a voluntary standard, not a legal obligation. Audit and implementation costs put certification out of reach for most SMBs. Use the structure; do not sell the certificate by default. |
When a customer says “I read the EU AI Act is going to hit us,” the winning answer is “probably not, and here is why.” You have just demonstrated you are not fear-selling, which makes the one lever that does apply to them — almost always the insurance renewal — land with far more weight.
An enterprise client sends your customer a security questionnaire. It now contains AI questions: do you have a written AI acceptable use policy, do you record training completion, have you performed a dated AI risk assessment, do you audit tool usage. Your customer cannot answer any of them, the questionnaire is blocking a contract renewal, and they need it back this week.
That is the highest-urgency, highest-margin entry point available, and it arrives without warning. Build the questionnaire-response artifact once and it becomes a repeatable rapid-response offer rather than a scramble. It is also the cleanest possible qualification signal: someone with buying power already cares.
This is a long document. Before you wade into it, here is the finished thing — one complete engagement, start to finish, on a customer that looks like most of your book.
Around 80 employees. Roughly two-thirds on Microsoft 365 Business Premium, the rest on Business Standard because nobody got around to it. SharePoint was migrated off a file server a few years ago and the folder structure still mirrors the old drive. Purview has never been configured. Their cyber insurance renews in 90 days, and a carrier questionnaire just arrived with AI questions on it that nobody can answer.
They are not buying E5. They were never going to buy E5.
A conversation about the insurance renewal and the questionnaire, then an automated tenant scan. It comes back with a site count, an exposure count, and a list of anonymous links. That is not the deliverable — it is what lets you quote accurately instead of guessing. Phase 1 in detail.
Purview Suite attached at $10 per user per month MS list, half price alongside Copilot, which covers the entire data-protection half. Then the one real decision: which of three supported options covers the permissions half. No E5 in the conversation at any point. Phase 2 in detail.
Find what is actually exposed, sort it against three gates, and produce a costed remediation plan with a named list of sites. Findings readout to the owner. Everything that is not a gate gets explicitly deferred — that is what keeps this a four-week engagement instead of a six-month program. Phase 3 in detail.
Replace the organization-wide grants, expire the anonymous links, remove the leavers and stale guests, break inheritance where it should never have been inherited. In one typical engagement a single misconfigured share accounted for about 80% of the high-priority work. Phase 4 in detail.
A 90-minute classification workshop with four people from the business produces a signed page of policy intent statements. Four labels get published, DLP goes into audit mode. Then you wait, because Microsoft's propagation timers are not negotiable. Phase 5 in detail.
Copilot on for a pilot group. Any interim containment applied in week 3 comes back off — the step partners forget, and the one that decides whether the customer thinks the product works. Phase 6 in detail.
A monthly drift report, a quarterly review, and an annual reassessment timed to the insurance renewal so the fee always has an external reason to exist. Phase 7 in detail.
| Phase | Elapsed | Partner hours | Tools used | What the customer gets |
|---|---|---|---|---|
| 1 | 90 minutes | 1.5 | Automated tenant scan; free config baseline tooling | A site count, an exposure count, and a fixed-price proposal that is not a guess |
| 2 | One meeting | 2–3 | Microsoft 365 admin center; a licensing decision table | Purview Suite attached; a chosen route for the permissions half |
| 3 | 1–2 weeks | 20–35 | Native SharePoint reports and PowerShell, or a governance platform | Findings report, three gates identified, costed remediation plan, deferral list |
| 4 | 3–4 weeks | 40–70 | SharePoint admin center, PowerShell, platform bulk-remediation | Permissions actually fixed, against a named list of sites |
| 5 | Parallel | 15–25 | Microsoft Purview | Four labels published, DLP in audit mode, signed policy intent statements |
| 6 | 1 week | 6–10 | Microsoft 365 admin center; Copilot Dashboard | Copilot live for a pilot group, containment removed, adoption handoff |
| 7 | Ongoing | ~5 / month | Governance platform or scripted re-runs | Monthly drift report, quarterly review, annual reassessment |
Not six months. Not 400 hours. The enterprise numbers circulating in the channel describe tenants with 200+ SharePoint sites — an 80-seat business has around 30. If you have been quoting this work from enterprise literature, you have been pricing yourself out of deals you should be winning. Section 17 is the arithmetic.
Every figure above is a model composed from the sourced inputs in section 18, shown so you can rebuild it against your own cost base rather than copy it. The point is not the numbers. The point is the shape: a project that pays for the practice, and a recurring line that compounds across the book.
Not blocked, not deferred pending a governance program. The demand that started the conversation actually got served.
The carrier's AI questions have documented answers, with a dated risk assessment behind them, in time for the renewal.
A $10 add-on and, at most, a handful of extra seats. Their Microsoft bill did not double and nobody had to justify an E5 migration.
The permissions do not silently drift back, and when Microsoft changes the control plane underneath them — which it does — someone notices.
Sections 6 through 12 are those seven phases, one per section, with what has to be done and why it has to be done in that order.
Sections 13 through 15 are the supporting decisions — which tools, which vendor, who on your team delivers it. Sections 16 through 18 are the money in full. Section 19 is how you turn one engagement into a practice, and section 20 runs the workshop.
Ninety minutes, no charge, and it is the most commercially important phase in the engagement — not because of what it finds, but because of what it lets you quote.
Distribution has been packaging and part-funding automated readiness scans since 2026, several of them at no cost to the partner. You cannot charge for something a distributor is giving away, and trying to will lose you the deal on price before you have said anything interesting.
Give it away deliberately. It costs you 60–90 minutes of platform time and it does one job nothing else does.
Remediation effort scales with sites, libraries and distinct permission structures — not with headcount. But seat count is the only number the buyer knows when they ask you for a price.
Quote from a site inventory, not from a headcount. The scan is what converts one into the other, and it is why a partner who skips it either over-quotes and loses, or under-quotes and eats the difference.
| Signal | What it tells you |
|---|---|
| Number of SharePoint sites and libraries | The scoping variable. Under about 30 sites this is a small engagement; past 60 it is a different quote. |
| Sites shared organization-wide | Gate 1 exposure. Often concentrated in one or two sites that came from a file-server migration. |
| Live anonymous links | Fast, visible, cheap to fix — your week-one credibility win. |
| Disabled accounts still holding grants, and stale guests | Gate 2. Cheapest finding in the engagement and the one a regulator would ask about first. |
| Whether Purview has ever been configured | Almost always no. Determines whether Phase 5 is a stand-up or a tune-up. |
| The license mix | Business Standard versus Business Premium versus anything else. Sets up the Phase 2 conversation entirely. |
Six questions. If you cannot get satisfying answers to the first three, this is not a deal yet — it is an education conversation, and you should treat it as one rather than writing a proposal.
It is tempting — you can see an anonymous link, you have the access, it takes thirty seconds. Do not. The moment you remediate for free you have taught the customer that remediation is free, and you have also lost your own before-and-after evidence.
Equally: do not present findings as findings yet. A raw scan output handed over without judgment is a report anyone could have run, and it is the thing most likely to walk to a cheaper competitor. The scan produces a scope. The assessment produces findings, and the assessment is billed.
“I ran the scan. You have 31 SharePoint sites, and four of them are shared with everybody in the company — including the one your old file server turned into. There are nine anonymous links still live, two of them older than the staff who created them.
I am not going to tell you what is in those sites yet, because I do not know and neither do you. That is the assessment, it is fixed price, it takes two weeks, and if you go ahead with the fixes afterward I credit the whole fee against them. Before your insurance renewal, this is the cheapest week you will spend all year.”
Nobody in this market is buying E5. Assume that as the starting condition rather than the objection, and the licensing conversation becomes short and winnable.
Partners lose it by presenting a feature matrix. The customer does not want to know what E5 includes. They want to know what to buy on Monday, and whether you are about to double their bill. This section is built as decisions, not comparisons.
The reflexive channel pitch is “you need to upgrade to E5.” A Business Premium customer hears that as double my Microsoft bill, and the deal stalls. It has also been wrong since September 2025, when Microsoft started selling the governance stack as add-ons scoped specifically to Business Premium.
| Component | Price | Notes |
|---|---|---|
| Microsoft 365 Business Premium (base) | $22 /user/mo Range | Held at this price through the July 2026 adjustments. Reseller-corroborated rather than read off a Microsoft page. |
| Purview Suite for Business Premium | $10 /user/mo MS list | Microsoft's words: “$10.00 user/month, paid yearly”, “Maximum of 300 seats”, “Requires a Microsoft 365 Business Premium subscription” |
| Defender + Purview Suites combined | $15 /user/mo Range | Widely and consistently reported; not read off a Microsoft page in this research |
| = the SMB governance stack | ~$37 /user/mo Model | Business Premium plus both suites |
| Microsoft 365 E5, for comparison | $60 /user/mo Range | Rose from $57 on 1 July 2026 |
50% off Purview Suite for Business Premium when purchased with Microsoft 365 Copilot, available 1 December 2025 through 31 December 2026 MS list. Microsoft's own page frames it around smooth AI rollout. Distribution is running first-year promotions alongside it, several expiring on the same date, and funded deployment services are available on top — see section 15.5.
Verify current terms with your TD SYNNEX rep before quoting. Promotions move.
Microsoft's own DLP documentation marks “restrict Copilot from processing files and emails” as unavailable on Business Premium and unavailable on E3. Only the E5 family and the Purview Suite line carry it.
A customer who buys E3 specifically to govern Copilot has bought the wrong thing. They have cleared the SharePoint Advanced Management base requirement — which is genuinely useful and may be the whole reason to do it — but they have not bought the ability to keep labeled content out of Copilot. Be explicit about which problem the E3 step-up solves, because it solves exactly one of the two.
The capability is not there on the base SKU. With the Purview Suite add-on attached it is in scope — Microsoft lists “policy-based controls for AI experiences and Copilot interactions” among the suite's capabilities.
Promise this on base Business Premium and you will be discovered at configuration time, in front of the customer, by a support engineer.
Microsoft's published capability list for the Business Premium suite: automated data classification, labeling and protection; sensitive data discovery and data mapping; DLP across apps, devices and cloud services; automated retention, deletion and records management; insider risk analytics with adaptive protection; advanced eDiscovery with legal hold; enhanced audit logging with extended retention; policy-based controls for AI experiences and Copilot interactions; communication compliance; Compliance Manager. Plus message encryption, Customer Lockbox, Customer Key, information barriers and privileged access management.
Microsoft's page does not use the term “DSPM for AI” anywhere. Third-party summaries say it is included; Microsoft's own phrasing is “policy-based controls for AI experiences.” The Purview service description has no DSPM section at all, and DSPM for AI has itself been superseded by a newer unified experience.
Do not tell a customer DSPM for AI is included in the Business Premium Purview Suite until you have seen it in their tenant. Describe the capability, confirm the product surface in configuration. This is the single most likely place to make a confident wrong claim.
This is the table to have open when a customer asks what they need to buy. Read it as: everything green is reachable on what most SMBs already own.
| Capability | Business Premium alone |
BP + Purview Suite |
Microsoft 365 E3 |
What decides it |
|---|---|---|---|---|
| Sensitivity labels, published and applied manually | Yes | Yes | Yes | Included broadly |
| DLP for email and documents | Yes | Yes | Yes | Base entitlement |
| DLP extended to Teams chat and endpoints | No | Yes | No | Purview Suite |
| Keep labeled content out of Copilot | No | Yes | No | The mis-sale in 7.2. E3 does not carry this. |
| Insider risk, communication compliance, Audit Premium | No | Yes | No | Purview Suite |
| Auto-labeling of files and emails | No | Confirm | No | Microsoft names E5-family; suite inclusion unconfirmed — Q2 |
| Conditional Access, guest and leaver cleanup | Yes | Yes | Yes | Entra ID P1, in Business Premium |
| Shadow AI discovery (full CASB) | No | Confirm | No | Defender Suite — Q3 |
| Governance reports, EEEU insights, site access reviews | No | No | Yes* | SharePoint Advanced Management. Needs an E-SKU base plus one assigned Copilot license. |
| Restricted Content Discovery | No | No | Yes* | Same. The only capability with no substitute — see 9.5 for the alternative approach. |
* Requires at least one Microsoft Copilot license assigned in the tenant, on top of the E-SKU base.
Business Premium plus the Purview Suite covers everything in the data-protection column. That is most of Copilot readiness, and it is a $10 add-on.
The last two rows are the only genuine gap, they are both SharePoint Advanced Management, and section 2.3 gives you three supported ways to cover them — two of which require no license change at all.
| If the customer needs… | Buy | Because |
|---|---|---|
| Labels, DLP, insider risk, Copilot interaction controls, audit retention | Business Premium + Purview Suite | $10/user/mo, 300-seat cap, half price alongside Copilot through 31 Dec 2026 |
| Shadow AI discovery and full CASB | + Defender Suite (combined $15) | Business Premium has no CASB. Verify that the suite carries full Defender for Cloud Apps before promising discovery. |
| DAG reports, EEEU insights, Restricted Content Discovery, site access reviews | An E-SKU base — or a third-party platform | The wall in section 9. No Business Premium add-on reaches SharePoint Advanced Management. |
| Auto-labeling of files and emails | E5 family Verify | Microsoft states the symptom for “E3 or Business Premium” explicitly. Whether the Purview Suite lifts it is unconfirmed — test before scoping. |
| Copilot itself, under 300 seats | Copilot Business SKUs | Sequencing trap: you cannot upgrade to an Enterprise plan from Business Standard or Premium with Copilot Business until commitment end. A growing customer can be stuck for up to a year. Decide before attaching. |
| Security Copilot | Do not sell it here | Provisioned capacity is priced per hour and the included-capacity model is E5/E7 only. Not an SMB motion. |
These are delegated-administration constraints, and they will surprise you mid-engagement rather than at scoping.
While you are there: the Purview role model will bite you at least once. Viewing file contents in simulation results requires the Data Classification Content Viewer role, which Global Admin does not hold by default, and turning a policy from ready to on requires Compliance Administrator or Compliance Data Administrator. Without them the button is simply greyed out with no explanation. Assign both before you start rather than losing a day to each.
This is the section the guide exists for. Partners over-scope this work because nobody has ever told them what is optional. The bridge separates the two or three things that must be true before Copilot is enabled from the much longer list of things that can safely follow it.
Everything in Purview and SharePoint governance is useful. Almost none of it is a gate. These three are.
Specifically: no site or library containing regulated, financial, HR or client-confidential content is shared with an organization-wide group, an Everyone Except External Users grant, or a live anonymous link.
Why it gates: Copilot inherits the permission model exactly. Every one of these becomes queryable in natural language on day one. This is the finding that produces the incident nobody publishes.
Disabled accounts still holding grants, guest accounts from finished projects, and shared mailboxes with lingering access. Cheap to fix, fast to verify, and the single most defensible item on the list — regulators fine for this even without AI in the picture.
Why it gates: it is the cheapest credibility you will ever buy, and it makes the whole engagement look competent in week one.
A named person — on the customer side — who decides what happens when a control blocks legitimate work. Not a policy document. A person, with a decision route and a response time.
Why it gates: this is the one partners skip, and it is the one that kills engagements in month two. Without it, the first false positive escalates to the managing partner and your controls get switched off by someone who outranks everybody who understands them.
All of the following are genuinely valuable and none of them should stop a Copilot rollout. Sequencing them after enablement is not negligence; it is the difference between a four-week engagement and a stalled six-month one.
| Work | Timing | Why it can wait |
|---|---|---|
| A complete sensitivity label taxonomy applied across the estate | After | Four labels published and a default set is enough to start. Full coverage is a program, not a prerequisite. |
| Auto-labeling policies | After | Requires simulation cycles and, on most SMB SKUs, a license you have not sold yet. See section 10. |
| DLP in enforcement mode | After | Microsoft's own documented rollout is audit first, then policy tips, then enforce. Enforcing on day one produces the false-positive flood that retires the control. |
| Retention and records management | After | A lifecycle program with its own business case. Unrelated to whether Copilot is safe today. |
| Custom sensitive information types and trainable classifiers | Much later, if ever | At 25–300 seats these are almost always out of scope. Built-in types cover the realistic cases. |
| Insider risk management and communication compliance | After | Real capabilities that need a mature customer and a reason. Selling them at gate stage makes you sound like you are inventing scope. |
| Cleaning up redundant and obsolete data | After | Improves answer quality and cuts storage. It is a follow-on project with its own economics, not a gate. |
Microsoft's own deployment blueprint prescribes a three-move pattern that most partners execute two-thirds of.
Restricted Content Discovery on the worst sites, plus DLP scoped to keep labeled content out of Copilot processing. This buys time without waiting for a full permissions cleanup. Both carry license prerequisites that most SMB tenants do not meet — see sections 6 and 7.
Break inheritance where it should never have been inherited, replace organization-wide grants with scoped groups, expire anonymous links, remove leavers and stale guests.
Once the permissions are right, take the containment off so Copilot can see the content it legitimately should.
Partners contain, remediate, and then leave the containment in place because nothing forces them to remove it and removing it feels like a risk. The customer is now paying full price for a Copilot that cannot see their own content, concludes the product is useless, and does not renew.
This is the most common way a technically successful engagement produces a commercially failed one. Put move 3 in the statement of work as a dated, billable milestone so somebody is accountable for it.
| What the assessment finds | The control that answers it | Position | On Business Premium? | Note |
|---|---|---|---|---|
| Site shared with Everyone Except External Users | Replace grant with a scoped group; break inheritance | Gate 1 | Fixable finding it needs a route from §2.3 | Usually the single largest share of high-priority remediation |
| Live anonymous sharing links | Expire links; tighten tenant default link type | Gate 1 | Yes native admin center | Fast, high-visibility win |
| Disabled accounts retaining grants | Offboarding cleanup; access review | Gate 2 | Yes Entra P1 | Regulators fine for this without AI involved |
| Stale guest accounts | Guest expiry / removal | Gate 2 | Yes Entra P1 | Included in Business Premium |
| No owner for blocked-work decisions | Named exception owner + route + response time | Gate 3 | Yes no license involved | Not a technical control. Still a gate. |
| Sites with sensitive content and no label | Publish four labels; manual labeling at container level | After | Yes Purview Suite | Containers before files |
| Sensitive content leaving via chat or email | DLP, audit mode first | After | Yes Purview Suite | Audit → policy tips → enforce |
| Automatic labeling at scale | Auto-labeling policies | After | Verify gated above base SKU | Confirm before scoping — §21.2 |
| Content Copilot should never ground on | Restricted Content Discovery | Interim only | Needs a route | Must be removed after remediation. Needs a Copilot license assigned and an eligible base SKU. |
| Who can reach what, across the estate | Permission and exposure reporting | Gate 1 | Needs a route — §2.3 | The one genuine gap. Option 1, 2 or 3. |
| Personal AI accounts in use | Sanctioned tenant AI + conditional access | Parallel track | Yes | See the Shadow AI Assessment Guide |
| Redundant and obsolete data degrading answers | Lifecycle and archival | Follow-on | Yes Purview Suite | Sell on storage cost, not risk |
| Permissions drifting back after cleanup | Continuous drift monitoring | Recurring | Third party | This is the MRR. See section 12. |
Almost everything on this list is reachable on the licenses your customer already owns. One row is not — permission and exposure reporting across the estate — and it is the row Gate 1 depends on. That single row is what section 2.3's three options exist to solve, and what section 9 documents.
Scoping an engagement without knowing which route the customer is on is how partners end up quoting an E5 upgrade they never needed to quote.
“There are three things that have to be true before we turn this on. Everything else on this list is real work that makes the product better, and none of it has to happen first. I would rather get you to value in four weeks and keep improving than sell you a six-month program you will cancel in month three.”
Gate 1 is the hard one. It is also where the standard channel playbook needs adjusting for this market — for a documented reason most partners have not yet run into.
Section 2 already gave you the answer. This section is the evidence behind it, so that when a customer or a competitor challenges you on it, you can show them the page.
Microsoft's statement is accurate. Copilot does not grant access to anything a user could not already open. Partners repeat it as reassurance, and customers repeat it back as an objection. Both are making the same error.
Access control. Whether a user is permitted to open a file. Copilot changes nothing here and never has.
Exposure. Whether a user will ever find the file. For thirty years the answer was no — nobody browses to /Company/Shared/Old HR/2019. Natural language search removed that friction entirely.
The salary spreadsheet sitting in the customer's main SharePoint site has typically been readable by every member of staff since the file server was migrated. Nobody found it, because finding it required knowing it existed and where it lived. Ask Copilot “what do our senior account managers earn,” and the friction that was doing all the actual protection is gone.
Restricted Content Discovery exists. Microsoft built a feature whose entire purpose is to stop Copilot surfacing content that users are already permitted to open. If “they technically had access” were a sufficient answer, that feature would have no reason to exist.
SharePoint Advanced Management is the answer to Gate 1. It is comprehensive and it is genuinely good.
| Capability | What it gives you |
|---|---|
| Data Access Governance reports | Permission state across sites, OneDrive and files; site permissions for a given user; sensitivity label snapshot; sharing links activity |
| Everyone Except External Users insights | Top items and groups shared with EEEU in the last 28 days, and which policies apply to those sites. Directly answers Gate 1. |
| Restricted Content Discovery | Prevents high-risk sites and files surfacing in Copilot and agent experiences — the interim protection in move 1 |
| Restricted Access Control | Limits site access to specific groups |
| Site access reviews | Delegates review of DAG findings to site owners rather than making the MSP guess |
| Site ownership policies, attestations, inactive site policies | The lifecycle half — who owns this, is it still needed |
| Agent access insights | How agents interact with SharePoint and OneDrive content |
Microsoft's prerequisites page for SharePoint Advanced Management states the base requirement in one short list. Read it carefully.
Microsoft 365 base subscription. Your organization must have one of the following base licenses:
— Office 365 E3, E5, or A5
— Microsoft 365 E1, E3, E5, or A5
— Microsoft 365 GCC, GCC-High, or DoD Microsoft Learn, Prerequisites for SharePoint Advanced Management — page dated 30 June 2026, updated 18 August 2026, verified 28 August 2026
The Copilot unlock — one assigned Microsoft Copilot license anywhere in the tenant — is a second, additional condition. It is not a substitute for the base requirement. Microsoft's page presents them as two sequential gates and both have to be cleared.
A tenant running a mix of Business Premium and Business Standard clears neither today. Three supported options fix that, and the cheapest one costs nothing beyond your own time.
The sequence most of the channel is running goes: buy one Copilot seat, unlock SharePoint Advanced Management, run the DAG reports, find the oversharing, remediate it, then roll Copilot out properly. On an E3 or E5 tenant that works exactly as advertised.
On a Business Premium tenant it needs one extra step first, because every item in the table above sits behind the base-SKU requirement — the DAG reports, the EEEU insights, Restricted Content Discovery, the site access reviews. The work does not change. The way you reach the tooling does.
Older partner material says “you need E5 for oversharing tooling.” That is out of date — one Copilot license does unlock the full SAM feature set, and E5 is not required.
Newer partner material has over-corrected to “SAM is included with Copilot, the E5 objection is dead.” That is true only on an E-SKU base, and it is being repeated at SMB customers where it is simply false.
Both statements are true of different customers. For an E3 or E5 tenant, one Copilot seat unlocks everything and nobody needs E5. For a Business Premium tenant — most of the SMB market — it is unreachable at any Copilot seat count. Getting this wrong in either direction mis-scopes the engagement before it starts.
These are the same three options as section 2.3, with the delivery detail attached. All three are documented and buyable. None of them is an E5 upgrade, and none of them depends on a licensing behavior this guide has not verified.
The SharePoint admin center exposes sharing settings, site-level permissions and sharing reports. The SharePoint Online PowerShell module enumerates permissions. Free tools cover the configuration baseline — see section 13.
What you give up: raw output rather than a client-ready report, no continuous monitoring, and effort that grows with site count. Workable comfortably at 80 seats, painful at 300.
Some governance platforms read Microsoft's security and activity feeds directly, so they work on a Business Premium tenant unchanged. That is the strongest reason for a partner in this market to look outside the Microsoft stack, and it is what makes the recurring service in section 12 deliverable at a margin.
What you give up: seat minimums at the small end, pricing you have to go and obtain, and label-enforcement features that still inherit Microsoft's E5 requirement. Section 14 is the full assessment.
Microsoft's documented path, and the only one that delivers Restricted Content Discovery. On an eligible E-SKU base a single assigned Copilot license unlocks the full toolset.
Before you quote it: get the entitlement confirmed in writing by Microsoft licensing or your distributor, including how it behaves in a mixed-SKU tenant. Microsoft states the requirement at organization level and publishes no partial-adoption guidance, so treat it as a question for the licensing desk rather than an assumption to build a proposal on.
Tempting because it is fast, and because the owner will suggest it. It is also the one path where you carry the consequence: you enabled it, and the salary spreadsheet surfaces in week two.
The counter is not a lecture. It is Gate 1 as a two-day job. Find the organization-wide grants, fix the worst handful, then enable. You are not refusing him; you are giving him a shorter path than he expected.
Restricted Content Discovery is Microsoft's interim containment — it hides high-risk sites from Copilot while you fix the permissions underneath. It needs an assigned Copilot license and an eligible base subscription, so on Business Premium it is simply not on the table.
The supported alternative gets you the same outcome by a different route: remediate first, then scope the pilot to what you have cleaned. Enable Copilot for a small pilot group whose work sits in sites you have already remediated, rather than enabling the tenant and hiding the rest. It is slower to reach everybody and it is completely defensible, which the alternative is not.
It also removes the un-containment step in section 11.1 entirely — the step partners most often forget.
“Microsoft built a proper set of tools for exactly this problem. There is one catch, and I would rather you hear it from me than find it in a support ticket: on your current plan those particular tools are not switched on, and buying Copilot does not switch them on either.
Before you brace for a big number — this is not an E5 conversation. There are three ways to solve it. One of them costs you nothing and costs me more time, one is a small monthly tool, and one is a licensing change you would only make if you wanted it anyway. I will tell you which I would pick for you and why.”
The data protection half of Copilot readiness is fully reachable on the licenses your customer already owns, through a $10 add-on that is half price alongside Copilot until the end of 2026. The permissions half is deliverable by any of the three options above. Neither half requires E5, and a partner who tells a Business Premium customer otherwise has cost them money and cost themselves the deal.
This section is for the partner who has never really turned Purview on. It is deliberately specific, because the reason partners underprice this work is that they have never seen it written down.
Before anything else, one setting. Get it wrong and the fix is manual, per-file, and humiliating.
Until this is on, SharePoint and OneDrive “can't process encrypted files, which means that coauthoring, eDiscovery, data loss prevention, search, and other collaborative features won't work for these files.”
The trap: labels applied before the setting is enabled are never recognized. Microsoft's remedy is to “download these files and then upload them to their original location.” On a tenant with any volume that is not a remediation, it is a punishment.
Takes about 15 minutes to take effect. There is no reason to ever do this second.
Purview is not slow to configure. It is slow to propagate, and the waits are documented, non-negotiable, and almost never in a partner's schedule.
| What you are waiting for | Documented wait |
|---|---|
| Label and label policy changes to propagate | 24 hours (24–48 for group-membership-dependent configuration) |
| Editing an already-published label | Up to 24 hours |
| Microsoft's own safe-publish pattern: pilot users → verify → widen | 1 hour, then “wait at least a day” before widening |
| A newly created auto-labeling policy is locked | ~24 hours greyed out while the backend provisions |
| Auto-labeling simulation run | Up to 12 hours, and you will run two or three |
| Co-authoring tenant setting replication | 24 hours |
| DSPM for AI reports showing any data | At least a day (Microsoft states this twice on the same page) |
| Newly added policy location before first crawl | 24 hours before troubleshooting missing labels |
| Reindexing after a bulk label change, 100+ sites | Up to several days |
| Container label deletion, SharePoint sites | 48–72 hours, during which users may be unable to open previously protected content |
A minimal, clean, single-tenant stand-up — one auto-labeling policy, one DLP policy, nothing custom — carries a floor of roughly six to ten elapsed working days of pure waiting, before a single hour of consulting, workshop, tuning or user communication.
Any project plan that does not contain those waits as explicit calendar items is wrong on day one. This is the single most common reason a four-week engagement becomes a nine-week one, and the partner absorbs the difference.
This is the part partners skip, and skipping it is why taxonomies fail. It is not a configuration session. It is ninety minutes in a room with people who do not work in IT.
Microsoft's stakeholder list for DLP planning runs to seven roles. At this size it collapses to four: the owner or managing partner, whoever owns finance, whoever owns HR, and the person who actually knows where the files are. That last one is usually the part-time IT person who ran the migration, and they are the most important person in the room. Ninety minutes.
Microsoft publishes an unusually direct answer:
Real-world deployments show that effectiveness is noticeably reduced when users have more than five main labels or more than five sublabels per main label. Microsoft Learn, Learn about sensitivity labels — page dated 15 April 2026
Restated in Microsoft's deployment blueprint as a rule: keep the list to 5×5 wherever possible. Practitioners working in SMB go tighter still, at three to five.
Four top-level labels. Sublabels only under Confidential. Start from Microsoft's own default set — Personal, Public, General, Confidential, Highly Confidential — rather than a blank page, and cut it down rather than building up.
Anything more is the partner performing thoroughness at the customer's expense. A fifteen-label taxonomy does not produce careful classification; it produces users picking whatever is least likely to interrupt them.
Microsoft's naming guidance is worth following literally: use terms that make sense to your users, always test names and tooltips with the people who have to apply them, and avoid mixing Confidential, Restricted and Internal together — users cannot reliably distinguish them.
“What is this organization's tolerance for leakage?”
Microsoft's own worked example: a legal team demands zero leakage of card numbers, while internal auditors must legitimately share exactly that data with external auditors. The resolution is not a technical control. It is an explicit, business-signed statement of what level is acceptable.
Ask that question and the room stops treating this as an IT decision, which is the entire purpose of holding the workshop.
Not a label list. Microsoft's policy intent statement: “You should be able to summarize, in a single statement, the business intent for every policy you have.” Microsoft's own example:
We're a U.S. based organization, and we need to detect Office documents that contain sensitive health care information covered by HIPAA that are stored in OneDrive/SharePoint and to protect against that information being shared in Teams chat and channel messages and restrict everyone from sharing them with unauthorized third parties.Microsoft Learn, Data loss prevention policy design
Every clause maps to a configuration decision: what to monitor, how to scope, where to monitor, which conditions, which actions. A page of these, signed by the customer, is the deliverable of the workshop — and it is the artifact that makes the engagement defensible when somebody asks eighteen months later why a policy exists.
Three of these change what a file is. They are senior-consultant decisions and they should never be made by whoever happens to be in the portal.
Deleting an encrypting label archives its protection template, and you can then never create a new label with the same name. Deleted labels show as GUIDs in content and activity explorer. Deleting a label applied to a SharePoint document strips label and encryption on download — but the same document stored outside SharePoint stays encrypted forever. Two different outcomes for one action.
Microsoft's own blueprint hedges its recommended default with “note: encryption of labels can be implemented later” and ships a dedicated \Internal exception sublabel “for situations where encryption is impacting daily operations.” That is Microsoft telling you it breaks things.
Ship labels without encryption first. Add encryption as a separate, separately-communicated change.
Microsoft: “After you enable co-authoring... you can't disable this setting in the Microsoft Purview portal. This action is supported only by using PowerShell.”
Worse, it changes where labeling metadata is stored. Microsoft warns not to enable it if you use any app, script or tool that reads or writes labeling metadata in the old location. Turn it back off and “this labeling information for unencrypted Word, Excel, and PowerPoint files will be lost.” Documented breakage includes Exchange mail flow rules keyed on labels failing to encrypt, or encrypting when they should not.
This is the trap most likely to burn a partner who “just turned everything on.” SMB tenants are precisely where undocumented scripts and third-party add-ins live. Inventory first.
Order is not cosmetic; it is semantic. It determines what counts as downgrading, it resolves auto-labeling conflicts, and — the one that matters here — Copilot surfaces the highest-priority label. Copilot Chat displays it; content Copilot generates from multiple sources inherits it.
Get the order wrong and Copilot tells your customer's staff the wrong thing about the sensitivity of their own documents, with authority, in a chat window. Reordering later means re-reasoning about every policy that depends on it.
Microsoft prescribes three stages and gives a duration for none of them, because the exit criterion is judgment, not a clock.
Assess impact through the reports. Nobody is interrupted. Use this stage to test your own review and remediation workflow, not just the policy.
Begin teaching users. Link to the customer's own policy page. Explicitly ask users to report false positives. Move here only “once you have confidence that the results of applying the policies match what the stakeholders had in mind.”
And keep monitoring. Most partners never arrive here, which is its own failure — a permanent diagnostic state that looks like compliance and protects nothing.
Buried in the DLP planning documentation is Fabrikam — Microsoft's own worked persona for an 18-person startup. It is the closest thing to official small-business DLP guidance that exists, and its prescribed approach is refreshingly short:
use the default Teams DLP policy; make SharePoint restricted by default; block external sharing; deploy to Windows devices; and block non-OneDrive cloud storage.
That is the whole recommendation. Five moves, no custom classifiers, no taxonomy project. Cite it by name when a customer asks whether you are over-engineering — being able to say “this is Microsoft's own guidance for a company your size” ends that objection faster than any argument of your own.
Microsoft also publishes its own split of why organizations do this at all: roughly 85% regulatory and compliance protection, 15% intellectual property protection. Useful for keeping the conversation on the ground the customer actually cares about.
Users route around policy tips within days, and every subsequent recommendation you make is pre-discredited. The mitigation is structural, not clever: run audit-first, ask for false-positive reports, and have the leakage-tolerance conversation before writing rules rather than after.
Four documented behaviors that get misdiagnosed as bugs, and one of them will embarrass you publicly.
Custom sensitive information types and custom trainable classifiers are almost always out of scope at 25–300 seats. Built-in types and pre-trained classifiers cover the realistic cases. If you do go there, know that Microsoft Support will not help you write regular expressions — their documentation says so explicitly — that custom classifiers are English-only and cannot be retrained (you delete and start over), and that a new sensitive information type does not retroactively light up existing content without a recrawl.
Price custom classification as its own opt-in workstream or refuse it. Folding it into a fixed-fee readiness engagement is how partners lose money on this work.
The shortest phase and the one most often fumbled. Everything up to here was preparation; this is where the customer finds out whether any of it worked.
If you applied interim protections in Phase 4 — restricting what Copilot can surface while the permissions were being fixed — this is where they come off. Microsoft's own pattern is three moves, and this is move three.
Partners contain, remediate, and then leave the containment in place, because nothing forces them to remove it and removing it feels like a risk.
The customer is now paying full price for a Copilot that cannot see their own content. They conclude the product is useless. They do not renew, and they are not wrong to reach that conclusion from the evidence in front of them.
This is the most common way a technically successful engagement produces a commercially failed one. Make somebody accountable for it by name and by date.
Five to ten people, and the selection matters more than the size.
| Include | Why |
|---|---|
| The person who asked for Copilot | Usually the owner. They funded this and they need to see it work first. |
| The heaviest existing AI user | They are already using something on a personal account. Give them a sanctioned alternative and they become your loudest advocate; leave them out and they stay a shadow-AI problem. |
| Somebody from finance or HR | They work with the most sensitive content, so they are the fastest way to find out whether the labeling and DLP work in practice rather than in simulation. |
| The part-time IT person | They have to support this. They should not meet it for the first time when a user complains. |
| One skeptic | Deliberately. A pilot group of enthusiasts tells you nothing you can act on. |
Governance and adoption fail independently. A perfectly remediated tenant that nobody uses still loses the customer, and it will look like your fault because you are the one who was there.
Phase 6 is where you name that risk to the customer and price the answer: role-based enablement at $50–$100 per user Range, which at 80 seats is a natural second project of comparable size to the assessment. Section 19.3 covers the follow-on ladder.
“It is on, it is clean, and the containment we put up in week three is down — so it can see everything it is supposed to see and nothing it is not.
Here is the part I want to be straight with you about. Everything we just did makes Copilot safe. None of it makes anyone use it. The deployments that stall do not stall for security reasons — they stall around month three because the enthusiasm wore off and nobody changed how they actually work. That is a different piece of work, it is not expensive, and I would rather sell it to you now than watch the licenses go quiet.”
Interim containment removed and verified · pilot group live and using it · the exception path exercised at least once for real · a dated first governance report scheduled · the adoption conversation had, and either sold or explicitly declined in writing.
That last one matters. If the customer declines adoption support, you want that on the record before month three.
Kaseya's 2026 State of the MSP survey, with over a thousand respondents, contains two numbers that sit five percentage points and one enormous business opportunity apart.
A 35-point gap between what clients are asking for and what partners are being paid for. The same survey found MSPs whose typical client spends over $25,000 a year Survey collapsed from 75% to 41% in twelve months, and the share of unprofitable MSPs doubled to 10%.
Security is already monetized. Governance and AI are not. That is the arbitrage this entire guide describes.
No SMB-focused partner publishes a price for ongoing AI governance as a distinct managed service.
That is a strategic finding rather than a research gap. You set the reference price rather than matching one. It also means the two derivations below are the closest thing to a benchmark that exists, and neither is strong enough to lean on.
| Derivation | Lands at | Weakness |
|---|---|---|
| 0.5 FTE for governance at 1,000+ Copilot users, scaled naively to 60 seats → ~5 hours a month at $150–$250/hr | $750–$1,250 /mo Model | The 0.5 FTE input is unverified and linear scaling is generous |
| vCISO “core advisory” band from an MSP-focused vendor benchmark | $1,000–$1,500 /mo Range | Vendor-published, unaudited, and describes a broader service |
Two very different routes landing near $1,000 a month for a small tenant is worth noting. It is not worth presenting as a benchmark, and the guide will not pretend otherwise.
Section 13.2 established why: per-tenant tooling minimums mean a 60-seat customer can cost the same to tool as a 100-seat one. A pure per-user price on a small tenant buys revenue at negative margin.
“$X per user per month, minimum $Y per month.”
That is the same structure your tool vendors use on you, it is defensible when a customer asks why a 40-seat site costs nearly what a 70-seat one does, and it protects you at exactly the customer size where this work is hardest to make profitable.
The recurring fee has to answer one question every renewal: we already cleaned it up, why am I still paying you? Three answers, in order of persuasiveness.
Permissions do not stay fixed. New sites get created, staff share links to get work done, a project spins up a Team with the wrong default. Continuous monitoring catches it, and platform tooling can alert or auto-revert as often as every two hours. You report what drifted and what you reverted. That is the invoice.
This is what CW1226324 proves. Microsoft shipped a change that bypassed correctly configured labels and DLP for four weeks. Nobody — not Microsoft, not the customer — had independent visibility into whether the controls were working. Somebody has to be watching, and it is not going to be the customer's part-time IT person.
The cyber renewal is annual. The carrier questionnaire is annual. The enterprise client's security review is annual. Tie the reassessment cadence to those dates and the recurring fee has an external justification that is not you.
Microsoft's own practice is a useful precedent worth quoting: it re-attests its own containers on a six-monthly cycle. A company with Microsoft's resources does not treat this as one-time work.
The report is the product. Everything below is obtainable from tooling the customer already has or that you already run.
| Metric | Source | Why it belongs in the report |
|---|---|---|
| Anonymous links, count over time | Governance platform, or SPO PowerShell | Trends down after remediation and creeps back up. The clearest proof drift is real. |
| External user access, count over time | Same | Guest sprawl is continuous and invisible without reporting |
| Shadow users — access via nested groups | Same | The finding customers find most surprising, every time |
| Organization-wide grants introduced this period | Same | Directly maps to Gate 1 |
| Leavers and stale guests removed | Entra access reviews | Gate 2. Cheap, visible, and the item a regulator would ask about |
| Label coverage on sites holding sensitive content | Purview | Progress on the work that is not a gate but does compound |
| DLP matches, and false positives reported by users | Purview | Report the false positives. It proves you are tuning rather than accumulating noise, and it keeps the exception path alive |
| Secure Score delta | Microsoft 365 | Imperfect, but the customer's board understands a number that goes up |
| Copilot license utilization | Admin center | Ties governance to the spend it protects, and surfaces reclaimable seats |
If your report only ever says everything is fine, you are teaching the customer they do not need you. Report what changed, what you fixed, and what you decided not to fix and why. Three items of judgment beat forty green checkmarks, and judgment is the thing that cannot be bought from a distributor for $3,000.
The strongest recurring-revenue mechanic in the SMB channel is to tie the service to an external standard, so the renewal conversation is about maintaining a position rather than about your fee. One published SMB rate card sells maturity levels of a security framework as the tiers themselves — the level is the product, and the framework does the selling.
For this motion the credible anchors are the cyber insurance questionnaire (universal, annual, and already on their desk), the carrier or enterprise-client security review, and — where the customer genuinely wants it — ISO/IEC 42001 as a structure. Use 42001's shape: an AI system inventory, a risk register, named use-case owners, and an incident protocol. Do not default to selling the certification. Audit and implementation costs put it out of reach for most businesses this size, and offering the structure without the certificate is both cheaper for them and more honest.
The first assessment a partner runs usually has to cost near zero to deliver, because it is being run to win the work. The good news is that a genuinely credible baseline is free.
| Tool | Cost | What it does in this engagement |
|---|---|---|
| ScubaGear (CISA) | Free | Secure-configuration baseline assessment for M365. Produces HTML, JSON and CSV output that is close to client-presentable as-is. Start here. |
| Maester | Free | Repeatable security-as-code tests. Turns a one-time assessment into something you can re-run monthly — which is the mechanical basis of the recurring service. |
| Monkey365 | Free | CIS and Entra misconfiguration review |
| Microsoft365DSC | Free | Configuration baseline capture and drift detection |
| SharePoint Online PowerShell | Free | Permission enumeration. On a Business Premium tenant with no SharePoint Advanced Management, this is your Gate 1 evidence. Raw output; you supply the report. |
| Microsoft 365 Lighthouse | Free with CSP | The multi-tenant floor. Entra ID P1 is included in Business Premium, so most customers qualify. |
These cover configuration baseline extremely well and permission exposure only adequately. Nothing free gives you a ranked, click-to-remediate view of who can reach what across the estate. You will assemble that from PowerShell output and your own judgment, which is exactly the labor a platform is sold to remove.
The instinct is to compare features. The better question is about the unit of purchase, because that is what actually determines whether a tool works in this market.
Per-user pricing with a floor punishes small tenants. Syskit Point bills a minimum of 100 users even for a 60-user tenant, on annual terms only. At its governance tier that is roughly $300 a month of cost Range for one small customer before you have earned anything.
Published seat minimums across the category: AvePoint's own list 500 users, Syskit and Rencore 100, Nudge Security a flat monthly fee, Orchestry Starter and ManageEngine none.
Consequence for your pricing: the recurring offer needs a floor price, not a pure per-user rate. Structure it as “$X per user per month, minimum $Y per month” — the same structure the tool vendors use on you. A partner who prices purely per-user on a 40-seat customer is buying revenue at negative margin.
| Tool | Role in this motion | Multi-tenant | Pricing model | Realistic under 100 seats? |
|---|---|---|---|---|
| Free stack (ScubaGear, Maester, Monkey365, DSC, PowerShell) | Configuration baseline, drift, permission enumeration | Scripted | Free | Yes — and it is where nearly everyone should start |
| AvePoint Insights + Policies | Exposure discovery, bulk remediation, continuous drift enforcement. No Microsoft E-SKU dependency. | Yes (Elements, separately) | Per user; published list carries a 500-user minimum | Get a written quote at your seat count — see section 14 |
| Syskit Point | Governance reporting and access review | Not marketed for MSP | Per user per year, published; 100-user billing minimum | Marginal — the minimum is the problem |
| ShareGate Protect | Governance risk assessment, tenant-wide visibility | Limited | Single per-user price, no minimums; partner pricing exists but is unpublished | Yes |
| Orchestry | Workspace lifecycle and provisioning governance | Yes | Flat per tenant, unlimited users at the Starter tier | Yes — the pricing unit fits this market best |
| ManageEngine M365 Manager Plus | Reporting and auditing | Partial | Per tenant, banded — cheapest commercial reporting by a wide margin | Yes |
| CoreView | Multi-tenant governance and delegation | Yes | Unpublished; access reviews, SharePoint control, auditing and delegation are paid add-ons | No — enterprise-shaped |
| Varonis | Deep data security posture; publishes a free Copilot readiness assessment | No MSP console | Unpublished, enterprise | No — but the free assessment is a legitimate door-opener |
| Rencore | Governance console explicitly built for multi-tenant MSP delivery | Yes, explicitly | Unpublished; 100-user minimum | Get a quote — the MSP positioning is the strongest in the category |
| Nudge Security | SaaS and shadow AI discovery | Yes | Flat monthly | Yes at the low end |
| Compliance Scorecard | The GRC half — policy, attestation, AI governance module | MSP-native | Flat monthly, MSP-priced | Yes |
| CIPP | Multi-tenant delivery chassis | Yes | Low monthly self-hosted or hosted | Yes — but it holds delegated admin into every tenant. Document that risk deliberately. |
At one or two customers, scripts win. The license cost of any platform exceeds the consultant hours it saves.
At roughly ten or more customers, a platform wins — not because it finds more, but because it makes findings comparable across tenants and turns your report into a product rather than a document. That is also the point at which the recurring service becomes deliverable at a margin.
Match the pricing unit to the shape of your book, not to the feature list. If your customers average 60 seats, a per-tenant price beats a per-user price with a 100-seat floor every time.
AvePoint gets its own section for a specific technical reason rather than a commercial one: its discovery product does not inherit the base-SKU wall from section 9. For a Business Premium tenant that is not a feature advantage, it is an availability advantage, and it is the strongest argument for looking outside the Microsoft stack in this market.
What follows is even-handed. The weaknesses are stated as plainly as the strengths, because a partner audience discounts a guide that reads as single-vendor — and because you will be in a room with people who have read Microsoft's documentation.
AvePoint's website, price lists, documentation and marketplace listings use different names for the same product. This is a practical quoting hazard, so start with the translation.
| Marketing name (website) | SKU name (price lists, docs, quotes) |
|---|---|
| Data & Security Insights | Insights for Microsoft 365 |
| Policy Enforcement & Drift Control | Policies for Microsoft 365 |
| Records & Information Lifecycle Management | AvePoint Opus (its AI classification engine is called Maestro) |
| Access & Power Platform Governance | AvePoint EnPower |
| Adoption & Usage Analytics | AvePoint tyGraph |
| License & Cost Management | AvePoint Cense |
| Data Owner Engagement | AvePoint MyHub |
| Agentic AI Governance | AgentPulse Command Center |
| MSP multi-tenant platform | AvePoint Elements |
Three dependencies that are not on any slide and will change a quote:
Insights + Policies for a Copilot readiness engagement. Add MyHub when you want the customer's own site owners doing attestation rather than your engineer guessing. Everything else in the portfolio is a separate business case.
This table is the reason this section exists. Engagement stage on the left, the specific product and the specific report on the right.
| Stage | Product | The specific feature | What you actually get |
|---|---|---|---|
| Pre-sales — the door-opener | Insights (free trial) | Risk Assessment Report | An out-of-the-box, exportable PDF. AvePoint designs it explicitly as “a benchmark to track progress over time” — which is why the second run is your recurring hook, not just your first deliverable. |
| Pre-sales — the AI angle | AgentPulse | Automated agent discovery and inventory | “You have 41 agents nobody inventoried.” Only lands where Copilot is already on. |
| Discovery — permissions baseline | Insights | Risk Analysis → Workspaces Reports, then Detailed Records Reports | Workspace-level then item-level exposure. A full inventory, not a 28-day delta. |
| Discovery — “who can see this?” | Insights | Search Center — object-based or user-based search | “Show me everything this one user can reach.” The most demo-able screen in the platform. Run this one live. |
| Discovery — broad-access exposure | Insights | Exposure Report, configured in Risk Definition Administration | External sharing and “broad access groups.” You tune what counts as exposure. See the caveat below. |
| Discovery — hidden access paths | Insights | Shadow Users and Groups Access Report | Access granted through nested groups or direct grants the site owner cannot see. Consistently one of the most surprising findings for a customer. |
| Discovery — links | Insights | Shared Links report | Anonymous, company-wide and specific-people links, with full history rather than a 28-day window |
| Discovery — data quality | Opus | Discovery & Analysis, delivered as Power BI reports; File Share Discovery for on-premises | Redundant and obsolete data. Improves Copilot answer quality rather than security. Sell on storage cost. |
| Findings readout | Insights | Risk Assessment Report + dashboard | The readout deck largely writes itself. Opus data can be exported to SharePoint for Power BI so you can brand it rather than screenshot AvePoint's UI. |
| Remediation — bulk | Insights | Risk Remediation, in-report bulk actions | Expire, remove or edit permissions for external users, shadow users and anonymous links. Expiry is what native tooling handles worst. |
| Remediation — the upsell bridge | Insights → Policies | Intelligent Remediation | Proposes the rule that would have prevented the finding. This is the moment the customer understands why one-time cleanup is not enough. |
| Remediation — owner-led | MyHub | Recertification and attestation, including OneDrive cleanup | Pushes the decision to the site owner. Substitutes for SAM site access reviews, which a Business Premium tenant cannot have. |
| Ongoing — drift | Policies | Violations Report; Remove Shadow Users, External Sharing Settings, Direct Sharing Prevention | Alert or auto-revert as often as every two hours. There is no Microsoft equivalent at any SKU. This is the mechanical basis of your recurring fee. |
| Ongoing — tenant hygiene | Policies | Ghost User Detection, Remove Inactive Guest Users | The two the customer notices immediately, and both map to Gate 2. |
| Copilot enablement — licensing | Cense | License allocation and budget reporting | “Which twelve people should get a Copilot license” and who is burning pay-as-you-go AI credits. |
| Post-deployment — the QBR | Insights | Time-based dashboards for anonymous links, external user access and shadow users; risk score over time | Those three metrics are your quarterly scorecard. Lift them directly. |
| Post-deployment — agent sprawl | Insights | Agent Reports under Risk Analysis | High-risk, inactive or ownerless agents — a cheaper path to basic agent hygiene than buying AgentPulse. |
| Multi-tenant delivery | Elements | Permission Simulation; CIS Level 2 baselines; sensitivity label management | The portfolio layer. Contains no AI or Copilot governance as of the June 2026 release. |
Insights covers the permission and exposure reporting that section 8's map flags as the one genuine gap, with no Microsoft license change. Policies adds continuous drift enforcement Microsoft does not offer at any SKU.
Three Policies rules — all of them label-enforcement — require Microsoft 365 E5. AvePoint did not route around Microsoft's label wall. Nobody has.
There is no AvePoint equivalent to Restricted Content Discovery. AvePoint's position is that you should fix the permission rather than hide the content from search — arguably the better engineering answer, and definitely the slower one. If you need interim containment while remediation runs, that is an enterprise-SKU conversation — or, more practically at this size, a reason to scope the pilot to remediated sites instead. See section 9.5.
It consumes Microsoft's security, activity and compliance feeds rather than crawling content, so it runs on a Business Premium tenant. For the discovery half of Gate 1 it substitutes for SharePoint Advanced Management — with deeper history than SAM's 28-day sharing-activity window.
Policies adds continuous drift enforcement that Microsoft does not offer at any SKU.
Four documented dependencies, from AvePoint's own documentation:
Business Premium includes Entra P1, so the guest rule works. The three E5 rules do not. All three are label-enforcement rules. AvePoint has not built around Microsoft's E5 label wall; it inherits it.
There is also no AvePoint equivalent to Restricted Content Discovery. AvePoint's position is that you should fix the permission rather than hide the content from search. That is arguably the better engineering answer and it is definitely the slower one, which matters when you need an interim protection this week.
There is a genuine self-serve 30-day free trial, confirmed in two AvePoint product brochures and in its public framework listings. Its deliverable is the Risk Assessment Report. That is your assessment engine and your readout in one artifact, and because the report is designed to be re-run as a benchmark, the second run is the recurring hook.
Pair it with free ScubaGear and Maester output for the configuration-baseline half that Insights does not touch, and you have a complete first engagement at near-zero license cost.
There is no free AvePoint readiness scan. Varonis gives one away; AvePoint gives a time-limited trial and gated eBooks. That is a weaker door-opener and you should know it going in.
The substantive documentation is behind a login. Navigation trees and overview pages are public; the report specifics, the full Policies rule catalog and the entire Elements guide are not. You cannot pre-qualify AvePoint against a specific client requirement without a sales conversation, which is a real evaluation cost.
Pricing is the least transparent in the category. Competitors publish per-user-per-year rates and flat per-tenant prices. AvePoint publishes a Request Pricing button.
| Source | Stated minimum |
|---|---|
| AvePoint's own published price list | 500 users on nearly every SKU; 12-month minimum term |
| Elements (the MSP platform) | No minimum published — no pricing published at all |
| Distribution, including TD SYNNEX StreamOne | Behind partner authentication |
AvePoint publishes no US pricing for Insights, Policies or Elements — anywhere. Not a rate card, not a starting-from figure, not a tier. That is a finding rather than a hole in this research, and it has a practical consequence: you cannot build a repeatable SMB offer around a product you cannot price without a sales call. Get a written quote at your actual seat count through TD SYNNEX before you design an offer around it.
Treat AvePoint as unconfirmed below 100 seats and demonstrably viable above 500 — a commercial question to settle with a written quote, not a technical one.
The arguments that the minimum is negotiable are real but circumstantial: AvePoint's 2025 partner program explicitly rewards “smaller but highly committed partners”, and partner-generated revenue reached 58% of its recurring business in early 2026. A 500-seat floor sits awkwardly against both.
But no public source confirms that buying through distribution removes it, and AvePoint's own flagship readiness engagement is scoped around scan envelopes no 78-seat customer will ever approach. The ask is portfolio aggregation — committing 500+ seats across many small tenants rather than one. Put it to your TD SYNNEX rep and get the answer in writing.
License reach. Insights works on Business Premium; SAM does not. In this market that is decisive.
History depth. Continuous inventory versus SAM's 28-day sharing-activity window.
Continuous enforcement. Alert-or-revert every two hours has no Microsoft equivalent at any SKU.
Archival granularity. Site, document, list and library level, versus SAM's site-only.
Breadth. Backup, migration, records, licensing, analytics and agent governance from one vendor, across Google, Salesforce, AWS and Box as well as Microsoft.
Price transparency is the worst in a category where competitors publish rate cards.
Seat minimums are the harshest documented — 500 against Syskit and Rencore's 100 and Orchestry's none.
Portfolio sprawl is a delivery cost. Ten products with a cross-dependency graph, against Syskit doing the core job in three tiers of one product. Training two engineers on that is real money.
The MSP console and the governance products are separate. Elements has no AI or Copilot governance and, on public evidence, does not surface Insights or Policies findings across tenants. Rencore explicitly markets that; AvePoint has not claimed it.
AvePoint's published comparison presents SharePoint Advanced Management as 28-day-only and admin-led. That understates SAM as of August 2026 — permission state reports give a current-state snapshot, site access reviews are a delegation model, and Restricted Content Discovery and site policy comparison both exist.
Anyone in the room who has read Microsoft's documentation will correct you, and you will lose the section. Make the argument on license reach, which is true, verifiable and sufficient on its own.
AvePoint will be at these workshops. These are ordered by commercial value; the first four change whether this section reads as a recommendation or a “when you grow into it.”
And if not — can a partner aggregate seats across a portfolio of small tenants to meet it? Get this one in writing.
Specifically: are Microsoft sensitive information types, sensitivity labels and the activity feed available at that SKU, or is the risk-prioritization signal degraded? Section 14.4's central claim rests on this.
Anchor the conversation on the published bundled framework rate rather than opening blind.
AvePoint publishes that buying Baseline, Workspace or User Management unlocks Risk, Change and Marketplace at no extra cost. So which of the three is the entry purchase?
The name appears in distribution catalogs and nowhere on AvePoint's own product index. Does it bundle Insights and Policies?
Or is it configured through the “large groups” exposure definition? Ask them to show you the screen. Microsoft names EEEU explicitly; AvePoint's public material does not.
“Percentage of sites labeled” or “unlabeled sites containing PII” — or is label data only used as a prioritization input?
And can Elements surface Insights and Policies findings across tenants, or does governance stay a per-tenant login? Can the Elements Graph API feed our QBR reporting?
The cheapest, highest-value ask in the room, and there is no reason for them to say no.
Can a partner run sequential 30-day trials across a pipeline of prospects without friction? That is the difference between a demo and a repeatable land motion.
In an enterprise systems integrator these are five people. In a partner serving 25–300 seat customers they are one and a half. Naming them separately still matters, because it tells you which hat you are failing to wear.
| Role | What they own here |
|---|---|
| Modern Work / M365 architect | The tenant. Enabling labels for SharePoint and OneDrive, auditing, sharing defaults, licensing. The pre-work nobody bills for. A generalist — and that is the trap, because a generalist treats Purview as another admin center. |
| Purview / information protection specialist | Labels, DLP, retention, the AI-services controls. Microsoft's own description of this role is half technical and half stakeholder facilitation. The facilitation half is what partners skip. |
| Security consultant / SecOps | Defender, shadow AI discovery, incident response. A different skill from the above — detection and response rather than classification and policy. |
| vCISO / governance advisor | The conversation, not the console. Runs the classification workshop, chairs the risk decisions, signs the attestation, holds the quarterly review. This is the role that carries the recurring revenue. |
| Adoption / change manager | User communications, labeling training, the false-positive feedback loop. Note that Microsoft retired the Adoption and Change Management specialization — the work did not go away, only the badge did. |
The classification workshop gets run as a configuration session. The engineer asks which folders are sensitive, writes down the answers, and builds a taxonomy nobody in the business actually agreed to. Six weeks later Finance cannot email the auditor, nobody knows who decides, and the labels come off.
The workshop is a facilitation job that ends in configuration, not a configuration job with people watching.
SC-400 retired on 30 May 2025 — the certification and its renewal assessment. It is still being recommended in partner enablement material and by well-meaning people who have not checked.
The replacement is SC-401, Information Security Administrator, whose skills were refreshed on 28 July 2026 and which now carries an explicit “Protect data used by AI services” objective covering exactly the readiness work this guide describes.
| Credential | Status | Relevance |
|---|---|---|
| SC-401 Information Security Administrator | Live | The single most on-target credential for this motion. Information protection, DLP and retention, plus protecting data used by AI services. A partner with nobody holding SC-401 has nobody credentialed for the work they are selling. |
| SC-200 Security Operations Analyst | Live | The shadow AI discovery and response half. Its 2026 refresh added AI agents and Copilots to the familiarity list. |
| SC-300 Identity and Access Administrator | Live | Identity governance and access reviews — Gate 2 territory. |
| SC-100 Cybersecurity Architect | Live | Expert level. The closest thing to a vCISO credential Microsoft offers. |
| Applied Skills APL-5003 | Live | A hands-on lab: build a custom sensitive information type, publish a label, create an auto-labeling policy, create a DLP policy. Cheaper and faster proof of capability than a certification. Note the 72-hour cooldown between attempts. |
| SC-400 | Retired | 30 May 2025. Superseded by SC-401. |
| MS-102 M365 Administrator | Retiring | 30 November 2026. Do not start a junior on it now unless they can sit it first. It was also removed from the Copilot specialization requirements in July 2026, so it no longer earns program credit either. |
Two things worth knowing for practice economics. Microsoft publishes no exam price to an unauthenticated visitor — every figure circulating is third-party, so confirm at booking. And renewal is annual, free, and by online assessment rather than a re-sit, which means the ongoing cost of a certified bench is time once a year at no exam fee. That is a far better story than most partners tell themselves.
| Configuration | Works? | Notes |
|---|---|---|
| One generalist M365 admin | No | Will build a taxonomy nobody agreed to and discover the problem in week six. |
| One genuine senior who does both halves | Yes, with a ceiling | Works to about 75 seats. Requires someone who can chair a room of business owners and write a DLP rule. These people exist and are rare. They do not scale past roughly two concurrent engagements. |
| One senior plus one technician | Yes | This is the answer. It is also the shape that lets you charge properly for the senior's time instead of averaging it away. |
| Plus fractional adoption and communications | Yes | The only shape that survives a mandatory-labeling rollout. The comms person can be borrowed rather than hired. |
The junior may touch anything reversible. The senior signs anything that changes what a file is.
That puts encryption on a label, the co-authoring switch, label order, and the move from DLP audit mode to enforcement on the senior's desk — and puts building labels to an agreed taxonomy, running simulations, triaging false positives and capturing evidence on the junior's. It is a clean line, it maps exactly to the irreversible decisions in section 10, and it is defensible to a customer asking why two people are on the call.
Nobody publishes a rate card for SMB-channel Purview work. Rather than invent one, here is the arithmetic, with its inputs visible.
| Input | Figure | What it actually is |
|---|---|---|
| M365 consultant salary, 75th percentile | $130,000 /yr Range | Aggregated job-postings data. A salary, not a bill rate. |
| → base hourly | ~$65 /hr Model | Arithmetic |
| → fully loaded at 1.3–1.4× burden | ~$85–$91 /hr Model | Conventional burden multiplier |
| → recoverable cost at 65% utilization | ~$130–$140 /hr Model | The number that matters |
| What it costs to rent a cybersecurity engineer | $130–$195 /hr Range | Staffing agency bill rate. A hard floor — you cannot bill less than you buy. |
A partner billing under roughly $150 an hour for senior Purview work is not making money on it. The channel band sits somewhere around $150–$275 Model — above the freelance band and well below the global-integrator band — but no published source isolates this work, so treat that as a bounded inference and not a benchmark.
Do not quote a day rate. Nothing credible is published, and everything shaped like one on the open web is a lead magnet.
Distributor-funded deployment offers now price a baseline Purview stand-up — data lifecycle review, sensitivity labeling policies, baseline classification, and DLP policies aligned to Microsoft best practice — at around $3,000 Range, usually with a small seat minimum attached.
Sit with that number, because it is uncomfortable and useful. The configuration layer of this work has a public price, and it is a few thousand dollars. If your quote is $30,000, you need a clear story about the other $27,000 — and if you do not have one, your quote is wrong.
You can outsource the build and the tooling. You cannot outsource the taxonomy decision, the exception path, or the quarterly review — and those three are where the margin and the recurring revenue live.
A partner who subcontracts everything has bought a $3,000 deployment and sold a $3,000 deployment.
Three independent sources in the SMB channel — a governance ISV, an MSP-focused readiness platform, and a multi-tenant management vendor — describe the same five-stage ladder in the same order. They agree because they are all describing the offer their tooling enables, which is a real limitation. It is still useful: an MSP building this ladder is building the offer the channel's tooling is designed to support.
Automated tenant scan, findings list, no judgment applied. The output is raw — a site count, an exposure count, a list of anonymous links.
Scorecard, three to five stakeholder interviews, a debrief, prioritized findings. No remediation plan costed.
Oversharing report, costed remediation plan, pilot design, draft policy, roadmap. This is the tier that converts.
Actually fix it. Break inheritance, replace organization-wide grants, expire links, remove leavers, publish labels, stand up DLP in audit mode.
Drift monitoring, periodic reassessment, quarterly review, attestation reporting. The only tier that compounds.
Distribution changed the economics of tier 0 during 2026. MSP-focused Copilot readiness capabilities are now packaged on a per-tenant, per-month basis with volume discounts, and TD SYNNEX packages an AvePoint-powered readiness assessment as a partner-deliverable service — a full scan of Teams, SharePoint, OneDrive, Exchange and Groups, a risk assessment, a readiness report with a prioritized remediation roadmap, and a business review session — with a stated turnaround inside five weeks and a co-investment commercial model that may be partly or fully funded depending on partner status.
The scan is not defensible as a revenue line. You are competing against a funded distributor offer, and you will lose that on price every time.
The judgment, the roadmap and the remediation are defensible. Give the scan away deliberately rather than losing it slowly — it costs you 60–90 minutes of platform time and it does a job nothing else does, which is the subject of the next section.
Not lead generation. Scoping. Section 17 explains why the scan's real product is a site count, and why quoting without one is how partners lose money on this work.
If you take one commercial fact from this guide, take this one.
A widely circulated practitioner critique of MSP readiness assessments puts real remediation at 200–400 hours. Enterprise consultancies quote permissions remediation before a Copilot rollout at $50,000–$400,000 over 60–180 days Range. Both figures are honest. Both describe mid-market and enterprise tenants. And partners are quoting SMB work from them.
One SMB MSP publishes an hour-level phase plan against a stated seat count — which almost nobody does, and which makes it the most useful duration source available for this market.
| Week | Phase | Work | IT hours |
|---|---|---|---|
| 1 | Inventory | Permission reports, overshared-site export, anonymous-link reports | 8–12 |
| 2 | Classify and triage | Apply sensitivity labels; sort findings into four buckets, critical to low | 12–16 |
| 3 | Remediate | Break inheritance, replace group shares, expire links, implement policies | 16–24 |
| 4 | Lock and pilot | Enable tenant-wide policies, apply containment where needed, pilot with five users | 4–8 |
| Total | At a 50-user tenant | 40–60 hours over 30 calendar days Range |
Supporting field data from the same source: a 65-user firm's inventory phase took 9 hours; and in one engagement a single “Everyone Except External Users” misconfiguration accounted for roughly 80% of all high-priority remediation. That second figure is worth remembering — it means the work is usually concentrated, not diffuse, and finding the concentration is most of the job.
At 50 seats, this is 40 to 60 hours. Not 200 to 400.
The 200–400 hour figure is explicitly framed around “permission inheritance across 200+ sites.” A 50-seat firm does not have 200 sites. A typical one has around 30, and well over half the content usually sits in one of them.
Quote from a site inventory, not from a headcount. Effort scales with sites, libraries and the number of distinct permission structures — not with the number of people.
But seat count is the only thing the buyer knows when they ask for a price. That is precisely what the free scan is for: it produces the site count that determines the quote. This is the clean commercial justification for a free tier that the distributors are commoditizing anyway.
This is extrapolated, not published. It is built from the 50-seat figures above and a practitioner convention of scoping governance reviews to 10–25 high-risk or inactive sites. Nobody publishes it. Use it as a planning heuristic and replace it with your own delivery data as soon as you have three engagements behind you.
| Seats | Typical sites | Assessment hours | Remediation hours | Elapsed, total |
|---|---|---|---|---|
| 25–50 | 10–30 | 15–25 | 30–50 | 3–4 weeks |
| 50–100 | 25–60 | 20–35 | 40–70 | 4–6 weeks |
| 100–300 | 60–150 | 30–50 | 80–160 | 6–10 weeks |
Model — every row above is a construction from the sourced 50-seat figures.
The hours above are work. Section 10.2 established a floor of six to ten elapsed working days of pure propagation waiting. Those are not the same thing and they do not overlap neatly — the label propagation wait in week two blocks the auto-labeling simulation in week three.
Put the waits in the plan as named calendar items. A customer who understands on day one why week three is quiet does not lose confidence in week three.
Most pricing guidance in this category launders vendor list prices into benchmarks. Three things you should know about the evidence before you use any number on this page.
One published price is tied to a stated seat count: $5,000 for a Copilot readiness assessment at 50 users Range — $100 per seat. Two other published bands converge on $5,000–$15,000 for SMB independently, which is weak corroboration but is what exists.
At 78 seats that anchors around $7,800 Model, and the honest way to quote it is from the site count the free scan produced, not the headcount.
Nobody in the SMB channel publishes a remediation rate card. That is a real gap, and the fix is not to invent one but to build it from two things that are published, and to show your working.
| Input | Figure | Source type |
|---|---|---|
| Remediation effort, 50-seat tenant | 40–60 hours | Range Published, hour-level, seat-count-stated |
| MSP project services rate | $150–$250 /hr | Range Published MSP pricing guidance |
| → Remediation, 50 seats | $6,000–$15,000 | Model Multiplication, nothing more |
| → Sensible fixed-fee landing zone | $8,000–$12,000 | Model |
| → Per seat | $160–$240 | Model |
Assessment at roughly $100 per seat, remediation at roughly $160–$240 per seat — a ratio of about 1.6–2.4×. The one vendor band that covers both implies 2.7–3×. Same family.
“Remediation is roughly twice the assessment” is defensible ground, and it is a sentence you can say in a room without a spreadsheet.
| Stage | Price | Structure |
|---|---|---|
| Scan | $0 Model | 90 minutes. Produces the site count that scopes everything below. |
| Full assessment | $7,800 Model | Fixed fee at $100/seat. Credited in full against remediation if they proceed within 60 days. |
| Remediation | $14,000 Model | Fixed fee, scoped to a named list of sites from the assessment. Roughly 2× the assessment, consistent with 78 seats and ~30 sites. |
| Ongoing governance | $1,400 /mo Model | Floor-priced, not pure per-user. See section 12. |
| Year one | ~$30,600 Model | Assessment credited, so $14,000 project plus 12 months recurring |
| Recurring thereafter | $16,800 /yr Model | The number that matters |
Every figure in that table is a model, not a quote. It is composed from the sourced inputs above and shown so you can rebuild it against your own cost base rather than copy it.
Crediting the assessment fee against the remediation project does three things at once, and it is the single best packaging device available in this motion.
Someone who will not pay for an assessment will not pay for remediation. Charging for it filters, and the credit removes the reason to object.
A free report goes to a cheaper remediator. A credited report is money already committed to you.
Review billed separately from remediation, with the customer's decisions documented before any cleanup begins. That boundary is what stops an assessment quietly becoming an unpaid Purview deployment.
“You are just selling us more stuff.” It is fair, it is common, and there is a specific and unusually strong answer.
“Fair. So let me show you the part of this that pays for itself. Assessments at your size routinely find 10 to 30% of license spend Range going to the wrong place — people with the wrong SKU, seats assigned to leavers, duplicated add-ons. On your bill that is real money, every month, and it does not stop unless somebody looks.
I would rather find that first and put it against the cost of this work than ask you to fund it out of fear of something that might not happen.”
That answer works because it is checkable, because it reframes you as someone reducing their spend rather than increasing it, and because it is usually true. It also sets up the licensing conversation in section 7 as an optimization rather than an upsell.
There is one non-negotiable, and it is the same one the Customer Zero Starter Kit argues for everywhere else on this site.
Before you quote this work, complete it in your own tenant. Publish four labels. Watch the 24-hour propagation actually take 24 hours. Run an auto-labeling simulation and discover it fired 300 activity alerts because you did not scope the alert policy first. Break something with an encrypting label and find out what it costs to unbreak.
Every hour of that is an hour you will not lose in front of a customer, and it converts the numbers in section 17 from something you read into something you know.
Beyond that: one person holding SC-401, one person who can chair a room of business owners, and a written decision about who signs the irreversible changes in section 10.4. That is the floor. It is lower than most partners assume and higher than most partners currently clear.
The threshold is repeatability, and it has a specific shape. The first engagement costs you 60–80 hours because everything is new. The third costs 40 because you have a scan procedure, a report template, a workshop agenda and a scope boundary. The difference between those two numbers is the entire margin.
At roughly ten customers, three things change together: platform tooling starts to pay for itself (section 13.3), findings become comparable across tenants so your report becomes a product, and the recurring revenue is enough to carry a dedicated person. Below ten, this is a service the senior consultant does between other work. Above it, it is a practice.
The margin target worth holding yourself to: best-in-class MSPs run around 19%+ adjusted EBITDA Survey, against a median closer to 9%. Governance work delivered repeatably sits comfortably in the top band. Delivered ad hoc, it sits below the median, because the senior consultant's hours are the most expensive thing you own.
This is the part partners undersell. The governance engagement is not the end of a sale; it is the qualification event for four more. Only SMB-scale numbers appear below — the enterprise figures circulating for all of these are irrelevant here and actively misleading.
The natural second project, and the one that protects the first. Governance and adoption fail independently — a perfectly remediated tenant that nobody uses still loses the customer at month three, and it will look like your fault.
Once the data estate is trustworthy, agents become buildable. Stay in the basic-integration tier: prebuilt connectors, straightforward authentication, read-mostly data.
Now with three independent forcing functions rather than one: the insurance underwriting shift, the enterprise client questionnaire, and the EU regime for anyone with European exposure.
The redundant-data cleanup you deliberately deferred in section 8.2. Sell it on storage cost, not risk — cost avoidance is a materially easier conversation with a 78-person business than another security argument.
Copilot Studio runs on a credit model — roughly $200 a month for 25,000 credits, or pay-as-you-go per credit Range. Consumption is not uniform: a classic answer costs 1 credit, a generative answer 2, an agent action 5, and grounding in Microsoft Graph costs 10.
Graph grounding is the one that touches tenant content, which means any agent built on the data estate you just cleaned up will hit it constantly. Budget 10–20% headroom, 30% for chained agent calls, and put consumption in the customer's name rather than absorbing it into a fixed fee.
Everything in this guide is dated, and some of it will be wrong within two quarters — Microsoft moved SharePoint Advanced Management's entitlement, retired a certification and blocked a containment feature inside eighteen months. The correction usually shows up in the community weeks before it shows up in a partner deck.
These are the places that were load-bearing in researching this guide, and they are worth a standing half-hour a week.
| Where | What it is good for |
|---|---|
Microsoft Learn release notes and ms.date stamps | The single most reliable signal in this whole field. Every Learn page carries a date; when a page you depend on moves, something changed. Bookmark the SharePoint Advanced Management prerequisites page and the Purview sensitivity-label page specifically — both moved during this research. |
| Microsoft Tech Community — Purview, SharePoint and Copilot blogs | Where feature changes and deprecations get announced before they reach documentation, and where the comment threads tell you what broke for other people. |
| The Purview and information-protection MVPs | A small, identifiable group publishes almost all of the useful field detail in this space — label taxonomy design, oversharing remediation at real scale, what the deployment blueprints leave out. Their write-ups are consistently months ahead of channel material. |
| The SMB and MSP practitioner community | The most candid source on what this work actually costs to deliver and what customers actually pay. It is also where the delivery post-mortems live — the engagements that went wrong, which nobody publishes as a case study. |
| Practitioner blogs from working consultants | Where you find hour-level effort breakdowns against stated seat counts, which is the number this guide had the hardest time sourcing. Section 17 rests on exactly one such source. |
| Vendor release notes — including AvePoint's | Read them for capability changes rather than marketing. The gap between what a platform claimed last year and what it ships this quarter is where your assessment either gains or loses a feature. |
The honest gap in this guide, stated in section 21.3, is that no independent dataset exists for what this work costs or what it finds in a 25–300 seat tenant. Every prevalence statistic in circulation comes from a vendor selling remediation, sampled from enterprise tenants.
Ten engagements in, with your own anonymized findings written down — sites per seat, share of exposure concentrated in one site, hours per remediation — you will own the only real dataset in the channel. That is worth more than any benchmark you could borrow, and it is the thing worth contributing back.
The tier ladder, the partner capability score and the certification roadmap are covered in The Path to Frontier Partner. What follows is only what is specific to this motion.
| Do this first | Why |
|---|---|
| Fix your CPOR hygiene | It is free, it is administrative, and it is worth real points. Association thresholds for customer-success metrics are materially lower than the transacting equivalents for identical points — and usage growth only counts from the date of association, so pre-existing usage is worth nothing. Claim on every workload you influence, today. This is days of work for a meaningful score movement. |
| Pursue Solutions Partner for Security via the SMB path | Microsoft scores both the enterprise and SMB paths and takes the higher. The SMB skilling column is the unlock, and one person can hold more than one of the qualifying certifications. The threshold only has to be cleared on a single day inside a rolling six-month window — most small partners believe they must sustain it, and they do not. |
| Get onto Security Immersion Briefings | Since January 2026 the execution cap was removed, resellers can deliver and claim, and the stated focus is Defender and Purview for Business Premium customers at 50–300 licenses. That is precisely this guide's customer. Uncapped, repeatable, and claimable — ask your partner development manager what a briefing pays, because the amount is not published. |
| Sell the Purview play while Microsoft funds it | 50% off Purview Suite for Business Premium alongside Copilot, through 31 December 2026 MS list. Microsoft is funding control-before-scale directly and the window closes. |
| Defer or skip | Why |
|---|---|
| Defer the specializations | They now require partner-funded third-party audits on a two-year cycle, validating a documented repeatable delivery process rather than skills. Build the methodology and the evidence pack first — this guide is most of the methodology. Note also that only three security specializations earn benefits; a fourth earns nothing. |
| Skip FastTrack | Its seat floor sits above most of this market. That gap is your business. |
| Skip marketplace listings and MACC | Services-only partners are excluded from the marketplace rewards economics, and SMB customers do not hold consumption commitments. |
| Skip customer investment funds and Copilot vouchers | Eligibility rules exclude CSP customers and set seat minimums far above this segment. |
Every FY27 incentive rate circulating in the channel comes from documents behind partner sign-in. This guide names mechanisms and deliberately names no rates. If a number matters to your business case, get it from Partner Center yourself — a secondhand incentive rate is the fastest way to build a plan on a figure that was never real.
This section is for whoever facilitates this material as a workshop session — Control Before Scale: Assess, Govern and Earn Trust on a Customer Zero agenda. Everything below is an extract of material already in this guide — nothing is authored twice, and every figure the room sees has a section number behind it.
The session's premise is that partners lose this conversation by leading with the plumbing. A session that teaches the plumbing in the order partners already fail with it will reproduce the failure in the room. So the running order inverts the usual one: the customer and the failure first, the sequence second, the economics third, and the controls last, as reference.
No statistics. Two show-of-hands questions.
“Who has had a Copilot conversation stall on ‘we need to sort our data out first’?” Most hands.
“Now keep your hand up only if the customer said it.” Most hands go down. That silence is the session.
One-page profile of a composite 80-seat customer on mixed Business Standard and Business Premium, distributed face down and turned over on cue. Facts only, no findings. The room needs to recognize this customer from their own book before they are told what is wrong with it.
One question: what is the first thing you sell them, and what does it cost?
Capture answers verbatim before commenting. The spread is the teaching material — some sell an assessment, some sell Copilot seats, some sell a security project, some say “I'd fix the SharePoint first.” Do not correct any answer. Stop 3 does that structurally.
Three gates and nothing else. Then what is not a gate, which is the part that changes how they scope. Then the containment pattern and the move-3 trap.
Close the segment on the licensing constraint: read Microsoft's base-SKU list aloud, let the room notice Business Premium is not on it — and then immediately give them the three options. Do not leave them sitting in the problem. The room's takeaway must be “this is solvable for the price of three licenses,” not “my customers all need E5.”
A decision table, not a feature matrix. The $37-against-$60 comparison, the two mis-sales, and the promotion that expires on 31 December 2026.
This is where a vendor slot belongs, if there is one — six minutes, on the question the room has just asked itself: how do I actually find and fix this on a Business Premium tenant? See 17.4.
Each table produces three numbers for the composite customer — assessment, remediation, monthly — and one sentence of justification for each.
The spread across the room is always wide, and the wide spread is the lesson: everyone is guessing, and whoever guesses lowest sets the market for the rest. Then show the researched ranges and the delivery-cost side, so tables can see which of their own numbers were unprofitable.
It is the highest-value nine minutes in the session and the first thing a running-late facilitator sacrifices. If it genuinely will not fit, the session is a webinar and should be billed as one.
If competitors are in the room and price discussion is a concern, run the exercise against delivery cost and margin rather than price. It teaches the same lesson — most of the room is under-costing the senior's hours — without anyone comparing rate cards.
The 48%-against-13% gap. The finding that nobody has published a price for this yet, so they are setting the reference rather than matching one. The floor-price structure and why a pure per-user rate loses money at 40 seats.
Facilitator plays the owner. Three objections only — the ones that actually end deals:
“Our last MSP reviewed us and said we were fine.” — attack the date, never the predecessor.
“Why am I paying monthly for a one-time cleanup?” — drift, and the control plane changing underneath them.
“Microsoft says Copilot respects permissions, so we're covered.” — access control is not exposure.
The softer objections live in the Shadow AI Assessment Guide and are the leave-behind, not the room.
One action, written on the handout, with a date: run the assessment on your own tenant. Not a reading list. Not a follow-up call. One thing, dated.
| Slot | Cut | Protect |
|---|---|---|
| 60 min | Exercise A becomes a 3-minute poll; objections cut to one; the recurring layer compressed to the two headline numbers | Stop 3 and Stop 5 survive intact. Everything else is negotiable. |
| 120 min | — | Add a live walkthrough of the actual portal paths from §10, and a second objection round with roles reversed — the room sells, the facilitator objects. |
| Theater-style, 100+ | Both table exercises become polls | Be honest that this is a materially weaker session. If the room cannot sit at tables, Stop 5 should become a facilitator-led walkthrough of one worked quote rather than a poll. |
| Self-serve | The whole room | This guide, with the exercises rewritten as self-assessment prompts |
A vendor in the room is an asset if the session places them and a liability if it does not. The rule: the vendor answers a question the session has already made the room ask.
That moment is inside Stop 4, immediately after the licensing constraint lands and the room asks how to find and fix permission sprawl on a Business Premium tenant without three weeks of PowerShell. The question is real, the native answer is genuinely partial at this seat count, and a demo lands as relief rather than as an interruption.
| Set with the vendor beforehand | Why |
|---|---|
| Six minutes, inside Stop 4, on the stated question | Not a corporate overview. The room has a specific question and a specific attention span. |
| Multi-tenant support and price per seat disclosed in the room | Sub-100-seat economics are the room's actual objection. A vendor who will not address them should not present. |
| The session names the free and native path first | Credibility with a partner audience depends on §13 being honest that scripts work at one customer and platforms earn their place at ten. |
| No exclusivity in the written guide | The page carries a comparison table. The room carries whoever showed up. |
A session on a technical journey fails when the facilitator cannot answer the third follow-up. The floor:
| ID | Artifact | Extract of |
|---|---|---|
| E-1 | Customer profile — one page, printed | §5 |
| E-2 | Pricing and scoping worksheet | §17.4, §18 |
| E-3 | The vendor question list | §14.8 |
| E-4 | Classification workshop agenda — four people, ninety minutes, output is signed intent statements | §10.3 |
| E-5 | The 30-day card | §19.1 |
This section exists because the rest of the guide argues that honesty about evidence is a commercial differentiator. It would be strange not to apply that here.
Every item below circulates in partner material. Each is wrong, stale, or unverifiable, and using any of them will cost you credibility with a buyer who checks.
| Claim in circulation | The problem |
|---|---|
| “802,000 at-risk files per organization” | Presented as current; traces to a 2022 report. Date it or drop it. |
| “150–300 overshared SharePoint sites per tenant” | No published methodology, and it describes enterprise tenants. Actively misleading in an SMB room. |
| “99% of organizations have sensitive data exposed to AI” | Real vendor research, but too high to be believed. Use the 1-in-10 labeled files figure instead. |
| The Gartner pilot-progression percentage | Two sample sizes and two different percentages circulate for what is presented as one finding, and a competing survey reports the opposite. Cite the governance-delay pairing, not the decimal. |
| “Get your team SC-400” | Retired 30 May 2025. The replacement is SC-401. |
| “Enable Restricted SharePoint Search while we review permissions” | New enablement was blocked on 31 July 2026. Microsoft directs you to Restricted Content Discovery. Any playbook opening with this step is unexecutable. |
| “SAM is included with Copilot, so the E5 objection is dead” | True only on an E-SKU base. See §9.4. This over-correction is now as common as the error it replaced. |
| “The EU AI Act will hit your business next year” | High-risk obligations moved to 2027–2028, and an SMB using Copilot is a deployer, not a provider. |
| “Colorado's AI Act takes effect in February 2026” | That law was repealed and replaced. The replacement takes effect 1 January 2027. |
| Any FY27 Microsoft incentive rate | All sit behind partner sign-in. Name mechanisms; get rates from Partner Center yourself. |
| “MaestroBridge” as an AvePoint product | No such product exists. Maestro is the classification engine inside Opus. |
| A published SANS AI acceptable use policy template | Could not be found. Do not cite one. |
Three claims this guide deliberately does not make, because no primary source settles them. Each one is a question for a licensing desk, a distributor or a vendor — get the answer in writing and it stops being a risk.
It is tempting to buy a seat, watch what lights up in the portal, and build a recommendation on the result. Do not. Portal behavior is not an entitlement, it changes without notice, and a customer who is audited will be measured against the licensing terms rather than against what worked in your tenant last quarter. Ask the people who can answer authoritatively, and quote from their answer.
Microsoft states it at organization level — “Your organization must have one of the following base licenses” — and publishes no guidance on tenants that hold a mix. Ask Microsoft licensing or your distributor how it is measured and licensed before you build a proposal on it.
Microsoft's add-on page says “policy-based controls for AI experiences” and never uses the term DSPM; the Purview service description has no DSPM section. Both capabilities are described in general language rather than named.
Corroborated by community and reseller sources, not by a Microsoft page read in this research. If it does, $15 per user per month is the price of shadow AI discovery for an SMB, which changes the recommendation in §13.
A fourth question belongs to a vendor rather than to Microsoft: whether AvePoint Insights runs at full fidelity on a Business Premium tenant, given its risk prioritization draws on Microsoft sensitive information types and the activity feed. No AvePoint statement exists either way, and §14.5's central claim rests on it. It is question 2 on the list in §14.9.
The MSP practitioner forums could not be reached. The pricing evidence here rests on published surveys and partner rate cards, not on invoices. No community-reported figure was invented to fill the gap — but it means the numbers in §18 are weaker than they look, and your own delivery data should override them the moment you have three engagements behind you.
No SMB-specific prevalence data exists at all. Every oversharing statistic in circulation comes from a vendor selling remediation, sampled from enterprise tenants. If you want a defensible number for 25–300 seat businesses, start recording your own anonymized engagement findings. Ten engagements in, you will own the only real dataset in the channel.
The customer does not need to be frightened into this. Seven in ten of the organizations that got the returns Microsoft advertises did the data security work first. You are not selling insurance against a disaster that may never arrive. You are selling the precondition that separated the deployments that worked from the ones that quietly stalled — and you are selling it to a business that is going to buy Copilot either way.