Copilot Playbook
Copilot Readiness & Governance Engagement
Updated August 28, 2026
Engagement Guide · Seven Phases, Priced and Staffed

The Copilot Readiness & Governance Engagement

Seven phases from the first scan to recurring governance — for the customers you actually have, on Business Premium, who are not buying E5. The decisions, gates, effort bands and prices, in the order you need them.

Prepared by Ken Lince — Sr. Director, Cloud Engineering, TD SYNNEX

How to use this

Sections 2 through 8 are the seven phases in delivery order — each one states what you do, what you do not do, how long it takes and what it produces. Sections 9 through 13 are the reference material you reach for mid-engagement: tooling, vendor, staffing, price, and the claims that will cost you credibility if you repeat them. Nothing here is argued. Where you want the reasoning, the evidence and its weaknesses, the long-form background reference carries all of it, section by section.


1 · The Answer, On One Page

Your customer is on Business Premium and is not buying E5. Everything below assumes that as the starting condition.

The data-protection half

Fully reachable on Business Premium. Labels, DLP, retention, insider risk, audit, and the control that keeps labeled content out of Copilot — all through the Purview Suite for Business Premium add-on at $10 per user per month.

The permissions half

One gap, and only one. SharePoint Advanced Management requires an Office 365 or Microsoft 365 E-SKU base. Business Premium and Business Standard are not on Microsoft's list, and buying Copilot does not change that.

The three routes across it

None of them is E5. Deliver natively on Business Premium at zero license cost; use a governance platform that does not depend on SharePoint Advanced Management; or move the base to an enterprise SKU. Section 5.

$10
Purview Suite for Business Premium, per user per month MS list
300-seat cap · half price alongside Copilot through 31 Dec 2026
3
Gates that must be true before enablement
Everything else on the list can follow
40–60
Remediation hours at 50 seats over 30 days Range
Not the 200–400 the channel repeats
~7 wks
Scan to live, governed pilot
85–145 partner hours end to end Model

1.1 · The two ways partners lose this deal

Failure one — sequence

Opening with the governance work. The customer arrived with demand; you replaced it with an obligation before establishing that anything was wrong in their tenant. Establish the problem, then sell the fix.

Failure two — conclusion

Finding the SharePoint Advanced Management requirement and quoting E5. That conclusion is wrong. It is one of three routes and the one the customer is least likely to accept.

1.2 · The seven phases at a glance

PhaseElapsedPartner hoursToolsWhat the customer gets
1 · Qualify and scope90 minutes1.5Automated tenant scan; free config baseline toolingA site count, an exposure count, and a fixed-price proposal that is not a guess
2 · Licensing decisionOne meeting2–3M365 admin center; the decision table in 3.2Purview Suite attached; a chosen route for the permissions half
3 · Assessment1–2 weeks20–35Native SharePoint reports and PowerShell, or a governance platformFindings report, three gates identified, costed remediation plan, deferral list
4 · Remediation3–4 weeks40–70SharePoint admin center, PowerShell, platform bulk remediationPermissions fixed against a named list of sites
5 · Purview stand-upParallel15–25Microsoft PurviewFour labels published, DLP in audit mode, signed policy intent statements
6 · Enable and pilot1 week6–10M365 admin center; Copilot DashboardCopilot live for a pilot group, containment removed, adoption handoff
7 · Ongoing governanceOngoing~5 / monthGovernance platform or scripted re-runsMonthly drift report, quarterly review, annual reassessment
MS list published Microsoft price or documented entitlement Survey named survey with a stated sample Range community-reported, multiple independent sources Model composed from cited inputs — a construction, not a citation
↑ Contents

2 · Phase 1 · Qualify and Scope

P1Qualify and scope90 min · 1.5 hrs · $0
Purpose
Produce the site count that scopes the quote. Not lead generation — scoping. Effort scales with sites, libraries and distinct permission structures, and seat count is the only number the buyer knows.
Do
  • Run the automated tenant scan — 60–90 minutes of platform time, given away deliberately.
  • Run ScubaGear and Maester for the configuration baseline.
  • Ask the six questions below.
Do not
  • Fix anything. Remediating for free teaches the customer that remediation is free, and destroys your before-and-after evidence.
  • Present findings. A raw scan handed over without judgment is a report anyone could run — and the thing most likely to walk to a cheaper competitor. The scan produces a scope; the assessment produces findings, and the assessment is billed.
Output
A site and library count · a one-page exposure summary of counts, not detail · a fixed-price assessment proposal, credited against remediation · an honest go / no-go.

2.1 · The six qualifying questions

If the first three do not produce satisfying answers, this is an education conversation, not a deal. Treat it as one rather than writing a proposal.

  1. “When does your cyber insurance renew, and can I see last time's endorsements?” The strongest lever in this market. Generative-AI exclusion endorsements — CG 40 47, CG 40 48, CG 35 08 — took effect 1 January 2026 and carriers are attaching them at renewal. The customer can verify all of it in ten minutes, which is what makes it work.
  2. “Has anyone sent you a security questionnaire with AI questions on it?” If yes: a deadline, and a sponsor who already cares. Highest-urgency, highest-margin entry point available.
  3. “Who decides when a control blocks someone's work?” If the honest answer is nobody, that is Gate 3 — a bigger finding than anything technical.
  4. “Where did your SharePoint come from?” A file-server migration predicts the shape of the exposure almost perfectly.
  5. “Has anyone here bought AI tools on a personal card?” Usually yes, and usually the person asking. See the Shadow AI Assessment Guide.
  6. “What made you ask about Copilot now?” Tells you whether you are selling to demand or manufacturing it.

2.2 · What the scan is looking for

SignalWhat it tells you
Number of SharePoint sites and librariesThe scoping variable. Under ~30 sites is a small engagement; past 60 is a different quote.
Sites shared organization-wideGate 1 exposure. Usually concentrated in one or two sites that came off a file server.
Live anonymous linksFast, visible, cheap to fix — the week-one credibility win.
Disabled accounts holding grants, stale guestsGate 2. Cheapest finding in the engagement, and the one a regulator asks about first.
Whether Purview has ever been configuredAlmost always no. Decides whether Phase 5 is a stand-up or a tune-up.
The license mixBusiness Standard vs Business Premium vs anything else. Sets up Phase 2 entirely.
Closing Phase 1

“You have 31 SharePoint sites, and four of them are shared with everybody in the company — including the one your old file server turned into. Nine anonymous links are still live, two of them older than the staff who created them.

I am not going to tell you what is in those sites yet, because I do not know and neither do you. That is the assessment. It is fixed price, it takes two weeks, and if you go ahead with the fixes afterward I credit the whole fee against them.”

↑ Contents

3 · Phase 2 · The Licensing Decision

Decisions, not a feature matrix. The customer wants to know what to buy on Monday and whether you are about to double their bill.

3.1 · The prices

ComponentPriceNotes
Microsoft 365 Business Premium (base)$22 /user/mo RangeHeld at this price through the July 2026 adjustments. Reseller-corroborated.
Purview Suite for Business Premium$10 /user/mo MS listMicrosoft's words: “$10.00 user/month, paid yearly”, “Maximum of 300 seats”, “Requires a Microsoft 365 Business Premium subscription”
Defender + Purview Suites combined$15 /user/mo RangeWidely and consistently reported; not read off a Microsoft page in this research.
= the SMB governance stack~$37 /user/mo ModelBusiness Premium plus both suites
Microsoft 365 E5, for comparison$60 /user/mo RangeRose from $57 on 1 July 2026
Microsoft is funding this motion, and it expires

50% off Purview Suite for Business Premium when purchased with Microsoft 365 Copilot, 1 December 2025 through 31 December 2026 MS list. Distribution is running first-year promotions alongside it, several expiring on the same date. Verify current terms with your TD SYNNEX rep before quoting.

3.2 · The decision table

If the customer needs…BuyBecause
Labels, DLP, insider risk, Copilot interaction controls, audit retentionBusiness Premium + Purview Suite$10/user/mo, 300-seat cap, half price alongside Copilot through 31 Dec 2026
Shadow AI discovery and full CASB+ Defender Suite (combined $15)Business Premium has no CASB. Verify the suite carries full Defender for Cloud Apps before promising discovery.
DAG reports, EEEU insights, Restricted Content Discovery, site access reviewsAn E-SKU base — or a third-party platformThe wall in section 5. No Business Premium add-on reaches SharePoint Advanced Management.
Auto-labeling of files and emailsE5 family VerifyMicrosoft states the symptom for “E3 or Business Premium” explicitly. Whether the Purview Suite lifts it is unconfirmed — test before scoping.
Copilot itself, under 300 seatsCopilot Business SKUsSequencing trap: you cannot upgrade to an Enterprise plan from Business Standard or Premium with Copilot Business until commitment end. A growing customer can be stuck for up to a year. Decide before attaching.
Security CopilotDo not sell it hereProvisioned capacity is priced per hour; the included-capacity model is E5/E7 only. Not an SMB motion.

3.3 · What each combination gets you

CapabilityBusiness Premium aloneBP + Purview SuiteMicrosoft 365 E3What decides it
Sensitivity labels, published and applied manuallyYesYesYesIncluded broadly
DLP for email and documentsYesYesYesBase entitlement
DLP extended to Teams chat and endpointsNoYesNoPurview Suite
Keep labeled content out of CopilotNoYesNoThe mis-sale in 3.4. E3 does not carry this.
Insider risk, communication compliance, Audit PremiumNoYesNoPurview Suite
Auto-labeling of files and emailsNoConfirmNoMicrosoft names E5-family; suite inclusion unconfirmed — 13.2 Q2
Conditional Access, guest and leaver cleanupYesYesYesEntra ID P1, in Business Premium
Shadow AI discovery (full CASB)NoConfirmNoDefender Suite — 13.2 Q3
Governance reports, EEEU insights, site access reviewsNoNoYes*SharePoint Advanced Management. Needs an E-SKU base plus one assigned Copilot license.
Restricted Content DiscoveryNoNoYes*Same. The only capability with no substitute — see 5.3.

* Requires at least one Microsoft Copilot license assigned in the tenant, on top of the E-SKU base.

3.4 · The two mis-sales

Mis-sale 1

E3 as the compliance step-up

Microsoft's DLP documentation marks “restrict Copilot from processing files and emails” as unavailable on Business Premium and unavailable on E3. Only the E5 family and the Purview Suite line carry it.

E3 clears the SharePoint Advanced Management base requirement — which may be the whole reason to do it — but it does not buy the ability to keep labeled content out of Copilot. Be explicit about which of the two problems it solves.

Mis-sale 2

Label-based Copilot exclusion on bare Business Premium

The capability is not on the base SKU. With the Purview Suite attached it is in scope — Microsoft lists “policy-based controls for AI experiences and Copilot interactions” among the suite's capabilities.

Promise it on base Business Premium and you will be discovered at configuration time, in front of the customer, by a support engineer.

3.5 · Put these in the engagement letter

  1. Content Explorer is not supported over GDAP. If your assessment method depends on it, your delegated access will not carry you.
  2. Purview audit access requires your engineer to be a guest user in the customer tenant. The customer must create, approve and later remove that account. Put creation in prerequisites and removal in the closeout.
  3. Assign the Purview roles before you start. Viewing file contents in simulation results needs Data Classification Content Viewer, which Global Admin does not hold by default. Turning a policy from ready to on needs Compliance Administrator or Compliance Data Administrator. Without them the button is greyed out with no explanation — a lost day each.
↑ Contents

4 · Phase 3 · Assessment — The Three Gates

P3The assessment1–2 weeks · 20–35 hrs
Purpose
Separate the two or three things that must be true before Copilot is enabled from the much longer list that can safely follow it.
Do
Enumerate exposure · sort every finding against the three gates · cost the remediation against a named list of sites · readout to the owner · write the deferral list down explicitly.
Do not
Scope anything in 4.2 as a prerequisite. That is what turns a four-week engagement into a stalled six-month program.
Output
Findings report · three gates identified · costed remediation plan · a written, agreed deferral list.

4.1 · The three gates, and nothing else

Gate 1 Must be true before enablement

Nothing sensitive is reachable by “everyone”

No site or library holding regulated, financial, HR or client-confidential content is shared with an organization-wide group, an Everyone Except External Users grant, or a live anonymous link.

Why it gates: Copilot inherits the permission model exactly. Every one of these becomes queryable in natural language on day one.

Gate 2 Must be true before enablement

Leavers and guests are actually gone

Disabled accounts still holding grants, guest accounts from finished projects, shared mailboxes with lingering access.

Why it gates: cheapest credibility you will ever buy, and regulators fine for this without AI in the picture.

Gate 3 Must be true before enablement

Somebody owns the exception path

A named person on the customer side who decides what happens when a control blocks legitimate work. Not a policy document — a person, with a decision route and a response time.

Why it gates: the one partners skip, and the one that kills engagements in month two. Without it the first false positive escalates to the managing partner and your controls get switched off by someone who outranks everybody who understands them.

4.2 · What is not a gate — defer these, in writing

WorkTimingWhy it can wait
A complete sensitivity label taxonomy across the estateAfterFour labels and a default set is enough to start. Full coverage is a program, not a prerequisite.
Auto-labeling policiesAfterNeeds simulation cycles and, on most SMB SKUs, a license you have not sold.
DLP in enforcement modeAfterMicrosoft's documented rollout is audit, then policy tips, then enforce.
Retention and records managementAfterA lifecycle program with its own business case.
Custom sensitive information types and trainable classifiersMuch later, if everAlmost always out of scope at 25–300 seats. Built-in types cover the realistic cases.
Insider risk and communication complianceAfterReal capabilities that need a mature customer and a reason. Selling them at gate stage sounds like inventing scope.
Cleaning up redundant and obsolete dataAfterA follow-on project with its own economics. Sell it on storage cost, not risk.

4.3 · Finding → control → gate

What the assessment findsThe control that answers itPositionOn Business Premium?Note
Site shared with Everyone Except External UsersReplace grant with a scoped group; break inheritanceGate 1Fixable — needs a route from 5.2Usually the single largest share of high-priority remediation
Live anonymous sharing linksExpire links; tighten tenant default link typeGate 1Yes — native admin centerFast, high-visibility win
Disabled accounts retaining grantsOffboarding cleanup; access reviewGate 2Yes — Entra P1Regulators fine for this without AI involved
Stale guest accountsGuest expiry / removalGate 2Yes — Entra P1Included in Business Premium
No owner for blocked-work decisionsNamed exception owner + route + response timeGate 3Yes — no license involvedNot a technical control. Still a gate.
Sites with sensitive content and no labelPublish four labels; manual labeling at container levelAfterYes — Purview SuiteContainers before files
Sensitive content leaving via chat or emailDLP, audit mode firstAfterYes — Purview SuiteAudit → policy tips → enforce
Automatic labeling at scaleAuto-labeling policiesAfterVerify — gated above base SKUConfirm before scoping — 13.2
Content Copilot should never ground onRestricted Content DiscoveryInterim onlyNeeds a routeMust be removed after remediation. Needs an eligible base SKU and an assigned Copilot license.
Who can reach what, across the estatePermission and exposure reportingGate 1Needs a route — 5.2The one genuine gap. Route 1, 2 or 3.
Personal AI accounts in useSanctioned tenant AI + conditional accessParallelYesSee the Shadow AI Assessment Guide
Redundant and obsolete data degrading answersLifecycle and archivalFollow-onYes — Purview SuiteSell on storage cost, not risk
Permissions drifting back after cleanupContinuous drift monitoringRecurringThird partyThis is the MRR. Section 8.
Read the fourth column before you scope

Almost everything on that list is reachable on the licenses your customer already owns. One row is not — permission and exposure reporting across the estate — and it is the row Gate 1 depends on. Scoping without knowing which route the customer is on is how partners end up quoting an E5 upgrade they never needed to quote.

↑ Contents

5 · Phase 4 · Permissions Remediation

P4Remediation3–4 weeks · 40–70 hrs
Do
Replace organization-wide grants with scoped groups · break inheritance where it should never have been inherited · expire anonymous links · remove leavers and stale guests.
Expect
Concentration, not diffusion. In one documented engagement a single misconfigured “Everyone Except External Users” share accounted for roughly 80% of all high-priority remediation. Finding the concentration is most of the job.
Output
Permissions fixed against the named site list from Phase 3, with before-and-after evidence.

5.1 · The constraint, in Microsoft's own words

Microsoft 365 base subscription. Your organization must have one of the following base licenses: Office 365 E3, E5, or A5; Microsoft 365 E1, E3, E5, or A5; Microsoft 365 GCC, GCC-High, or DoD. Microsoft Learn, Prerequisites for SharePoint Advanced Management — page dated 30 June 2026, updated 18 August 2026, verified 28 August 2026
Read this twice

Microsoft 365 Business Premium is not on that list. Neither is Business Standard.

The Copilot unlock — one assigned Microsoft Copilot license anywhere in the tenant — is a second, additional condition, not a substitute for the base requirement. Both gates have to be cleared.

The channel is currently wrong in both directions. Older material says “you need E5 for oversharing tooling” — out of date; one Copilot license does unlock the full SAM feature set. Newer material has over-corrected to “SAM is included with Copilot, the E5 objection is dead” — true only on an E-SKU base, and false at most SMB customers.

5.2 · The three routes across the gap

1
Deliver it natively on Business Premium

SharePoint admin center for sharing settings, site permissions and sharing reports. SharePoint Online PowerShell to enumerate permissions across the estate. Free tooling covers the configuration baseline. This is where most partners should start.

What you give up: raw output rather than a client-ready report, no continuous monitoring, effort that grows with site count. Comfortable at 80 seats, painful at 300.

License cost $0Best for your first engagementsDetail Section 9
2
A governance platform that does not depend on SharePoint Advanced Management

Some platforms read Microsoft's security and activity feeds rather than depending on SAM, so they run on a Business Premium tenant with no Microsoft license change. That is an architectural difference, not a loophole — and it is the only route that gives you continuous drift monitoring, which is what the recurring fee in section 8 is actually for.

What you give up: seat minimums can price out the smallest tenants, pricing is largely unpublished so you quote against a number you have to obtain, and label-enforcement features generally still inherit Microsoft's E5 requirement.

License change noneBest for a book of customersDetail Section 10
3
Move the base to an enterprise SKU

Microsoft's documented path, and the only route that delivers Restricted Content Discovery. On an eligible E-SKU base a single assigned Copilot license unlocks the full toolset.

Before you quote it: get the entitlement confirmed in writing by Microsoft licensing or your distributor, including how it behaves in a mixed-SKU tenant. Microsoft states the requirement at organization level and publishes no partial-adoption guidance. It also does not solve the other half — E3 does not carry the control that keeps labeled content out of Copilot.

Cost highest per seatBest for customers who need RCDDetail Section 3
The one to refuse — turn it on and deal with it later

Tempting, and the owner will suggest it. It is also the one path where you carry the consequence: you enabled it, and the salary spreadsheet surfaces in week two.

The counter is not a lecture — it is Gate 1 as a two-day job. Find the organization-wide grants, fix the worst handful, then enable. You are giving them a shorter path than they expected, not refusing them.

5.3 · Contain, remediate, un-contain

MOVE 1

Contain

Restricted Content Discovery on the worst sites, plus DLP scoped to keep labeled content out of Copilot processing. Both carry license prerequisites most SMB tenants do not meet.

MOVE 2

Remediate

Actually fix the permissions. Break inheritance, replace organization-wide grants, expire links, remove leavers and guests.

MOVE 3

Un-contain

Take the containment off so Copilot can see the content it legitimately should. Put this in the SOW as a dated, billable milestone.

The trap

Move 3 never happens

Partners contain, remediate, then leave the containment in place because nothing forces them to remove it and removing it feels like a risk. The customer is now paying full price for a Copilot that cannot see their own content, concludes the product is useless, and does not renew. This is the most common way a technically successful engagement produces a commercially failed one.

If you cannot use Restricted Content Discovery — scope the pilot instead

RCD needs an assigned Copilot license and an eligible base subscription, so on Business Premium it is not on the table. The supported alternative reaches the same outcome by a different route: remediate first, then scope the pilot to what you have cleaned. Enable Copilot for a small pilot group whose work sits in already-remediated sites, rather than enabling the tenant and hiding the rest. Slower to reach everybody, completely defensible — and it removes the un-containment step entirely.

↑ Contents

6 · Phase 5 · Purview Stand-Up

P5Purview from zeroparallel to P4 · 15–25 hrs
Output
Four labels published · DLP in audit mode · a signed page of policy intent statements.
Sequence
Step 0 → classification workshop → publish four labels → DLP simulation → wait. The waits in 6.2 are calendar items, not slack.

6.1 · Step 0 — do this before anyone labels anything

Step 0 There is no reason to ever do this second

Enable sensitivity labels for Office files in SharePoint and OneDrive

Set-SPOTenant -EnableAIPIntegration $true

Until this is on, SharePoint and OneDrive “can't process encrypted files, which means that coauthoring, eDiscovery, data loss prevention, search, and other collaborative features won't work for these files.”

The trap: labels applied before the setting is enabled are never recognized. Microsoft's remedy is to “download these files and then upload them to their original location.” On any volume that is a punishment, not a remediation. Takes ~15 minutes to take effect. Microsoft Learn

6.2 · The calendar floor — put these in the plan by name

What you are waiting forDocumented wait
Label and label policy changes to propagate24 hours (24–48 where group membership is involved)
Editing an already-published labelUp to 24 hours
Microsoft's safe-publish pattern: pilot users → verify → widen1 hour, then “wait at least a day” before widening
A newly created auto-labeling policy is locked~24 hours greyed out while the backend provisions
Auto-labeling simulation runUp to 12 hours — and you will run two or three
Co-authoring tenant setting replication24 hours
Newly added policy location before first crawl24 hours before troubleshooting missing labels
Reindexing after a bulk label change, 100+ sitesUp to several days
Container label deletion, SharePoint sites48–72 hours, during which users may be unable to open previously protected content
The number that breaks project plans

A minimal, clean, single-tenant stand-up — one auto-labeling policy, one DLP policy, nothing custom — carries a floor of roughly six to ten elapsed working days of pure waiting, before a single hour of consulting, workshop, tuning or user communication. This is the single most common reason a four-week engagement becomes a nine-week one, and the partner absorbs the difference.

6.3 · The classification workshop — 90 minutes, four people

Who is in the room

The owner or managing partner · whoever owns finance · whoever owns HR · the person who actually knows where the files are — usually the part-time IT person who ran the migration, and the most important person present.

How many labels

Four top-level labels. Sublabels only under Confidential. Start from Microsoft's default set — Personal, Public, General, Confidential, Highly Confidential — and cut down rather than build up. Microsoft: effectiveness drops noticeably past five main labels or five sublabels each.

The question that does the work

“What is this organization's tolerance for leakage?” Microsoft names this one directly. Asking it stops the room treating classification as an IT decision, which is the entire purpose of holding the workshop.

What it must produce

Not a label list — policy intent statements, signed. Microsoft: “You should be able to summarize, in a single statement, the business intent for every policy you have.” Every clause maps to a configuration decision, and the signed page is what makes the engagement defensible eighteen months later.

Follow Microsoft's naming guidance literally: use terms that make sense to your users, test names and tooltips with the people who have to apply them, and do not mix Confidential, Restricted and Internal — users cannot reliably distinguish them. A fifteen-label taxonomy does not produce careful classification; it produces users picking whatever is least likely to interrupt them.

6.4 · The three decisions that cannot be undone

These are senior-consultant decisions. They should never be made by whoever happens to be in the portal.

Irreversible — 1

Encryption on a label

Deleting an encrypting label archives its protection template, and you can never create a new label with the same name. Deleted labels show as GUIDs in content and activity explorer. Deleting a label applied to a SharePoint document strips label and encryption on download — but the same document stored outside SharePoint stays encrypted forever.

Rule: ship labels without encryption first. Add encryption as a separate, separately-communicated change. Microsoft's own blueprint hedges its default with “encryption of labels can be implemented later” and ships an \Internal exception sublabel for when encryption impacts daily operations.

Irreversible — 2

Co-authoring for files with sensitivity labels

Microsoft: “After you enable co-authoring… you can't disable this setting in the Microsoft Purview portal. This action is supported only by using PowerShell.” It also changes where labeling metadata is stored; turn it back off and “this labeling information for unencrypted Word, Excel, and PowerPoint files will be lost.”

Rule: inventory scripts, add-ins and mail flow rules that read or write labeling metadata before enabling. SMB tenants are precisely where undocumented scripts live. Microsoft Learn

Irreversible in effect — 3

Label order and priority

Order is semantic, not cosmetic. It defines what counts as downgrading, it resolves auto-labeling conflicts, and Copilot surfaces the highest-priority label — Copilot Chat displays it, and content generated from multiple sources inherits it.

Rule: get the order right at publish. Reordering later means re-reasoning about every policy that depends on it.

6.5 · DLP — the only rollout pattern that works

STAGE 1

Simulation, no policy tips

Assess impact through the reports. Nobody is interrupted. Use this stage to test your own review and remediation workflow, not just the policy.

STAGE 2

Simulation with notifications and tips

Begin teaching users. Link the customer's own policy page. Explicitly ask users to report false positives. Move here only once results match what the stakeholders had in mind.

STAGE 3

Full enforcement

And keep monitoring. Most partners never arrive here — a permanent diagnostic state that looks like compliance and protects nothing.

Cite Fabrikam when a customer asks whether you are over-engineering

Microsoft's DLP planning documentation carries a worked persona for an 18-person startup. The whole prescribed approach: use the default Teams DLP policy; make SharePoint restricted by default; block external sharing; deploy to Windows devices; block non-OneDrive cloud storage. Five moves, no custom classifiers, no taxonomy project. Being able to say “this is Microsoft's own guidance for a company your size” ends that objection faster than any argument of your own. Microsoft Learn

6.6 · Simulation gotchas — check these before your first run

  1. Simulation still generates activity alerts. Microsoft's advice is to temporarily scope or disable the alert policy for the simulation window. Do this before the run, not after you have mailed the customer's security contact four hundred alerts.
  2. Simulation shows one policy's result. Conflicts between multiple policies only resolve when all of them run, so a simulation can be honestly, confidently wrong.
  3. Exchange simulation is not reproducible — it evaluates mail sent and received during the run.
  4. Simulation matches more than activation acts on. On activation the service only re-evaluates files whose state recently changed. Forcing a full pass needs on-demand classification.
Leave out at this size

Custom sensitive information types and custom trainable classifiers are almost always out of scope at 25–300 seats. Microsoft Support will not help you write regular expressions — their documentation says so. Custom classifiers are English-only and cannot be retrained; you delete and start over. A new sensitive information type does not retroactively light up existing content without a recrawl. Price custom classification as its own opt-in workstream, or refuse it.

↑ Contents

7 · Phase 6 · Enable, Pilot, Un-Contain

P6Enable and pilot1 week · 6–10 hrs
Do first
Remove the interim containment applied in Phase 4, and verify it. Dated, billable milestone — not a tidy-up.
Then
Enable Copilot for five to ten people (7.1) · watch the four signals in 7.2 · run the exception path for real at least once · have the adoption conversation.
Exit
Containment removed and verified · pilot live and in use · exception path exercised · first governance report dated and scheduled · adoption support sold or explicitly declined in writing.

7.1 · The pilot group — five to ten people

IncludeWhy
The person who asked for CopilotUsually the owner. They funded this and they need to see it work first.
The heaviest existing AI userAlready using something on a personal account. Give them a sanctioned alternative and they become your loudest advocate; leave them out and they stay a shadow-AI problem.
Somebody from finance or HRWorks with the most sensitive content — the fastest way to find out whether labeling and DLP work in practice rather than in simulation.
The part-time IT personThey have to support this. They should not meet it for the first time when a user complains.
One skepticDeliberately. A pilot group of enthusiasts tells you nothing you can act on.

7.2 · What to watch in week one

  1. Anything surfacing that surprises someone. The single most valuable signal in the engagement. One “wait, how did it find that?” means Phase 4 missed something.
  2. DLP policy tips firing on legitimate work. Expected, and the reason DLP is still in audit mode. Route every one through the Gate 3 exception owner, so the path gets exercised while the stakes are low.
  3. Labels applied wrongly, or not at all. Usually a naming problem, not a training problem. If two labels are being confused, rename one.
  4. People quietly not using it. The quietest failure and the one that kills the renewal in month three. Ask directly — usage reports will not tell you why.
Hand off to adoption, and price it now

Governance and adoption fail independently. A perfectly remediated tenant that nobody uses still loses the customer, and it will look like your fault because you were the one who was there. Price role-based enablement at $50–$100 per user Range — at 78 seats a natural second project of comparable size to the assessment. Then see the Copilot Adoption Audit for proving it worked.

↑ Contents

8 · Phase 7 · Ongoing Governance

The only tier that compounds, and the only one nobody has published a price for.

48%
of MSPs name AI as their clients' number-one need Survey
Kaseya 2026 State of the MSP, n>1,000
13%
earn meaningful revenue from AI or automation services
Same survey — a 35-point gap
8%
have regulatory compliance and reporting in their top three revenue lines
Security is already monetized. Governance is not.

8.1 · How to structure the fee

The shape

“$X per user per month, minimum $Y per month.” Per-tenant tooling minimums mean a 60-seat customer can cost the same to tool as a 100-seat one, so a pure per-user rate on a small tenant buys revenue at negative margin. This is the same structure your tool vendors use on you, and it is defensible when a customer asks why a 40-seat site costs nearly what a 70-seat one does.

Two independent derivations — a naive FTE scale-down and a vCISO advisory band — both land near $1,000 a month for a small tenant Model. Worth noting; not worth presenting as a benchmark. Nobody publishes a price for this, which means you set the reference rather than match one.

8.2 · Three answers to “why am I still paying you?”

01

Drift is real and measurable

New sites, links shared to get work done, a project Team with the wrong default. Platform tooling can alert or auto-revert as often as every two hours. You report what drifted and what you reverted. That is the invoice.

02

The control plane changes underneath them

In January 2026 Microsoft shipped a change (tracking ID CW1226324) that returned Copilot Chat summaries derived from Drafts and Sent Items, including content carrying confidentiality labels and covered by DLP policies configured to exclude it. Roughly four weeks; fix rollout began early February. Nobody — not Microsoft, not the customer — had independent visibility into whether the controls were working. The strongest argument you have.

03

Somebody external keeps asking

The cyber renewal is annual. The carrier questionnaire is annual. The enterprise client's security review is annual. Co-term the reassessment to those dates and the fee has a justification that is not you.

Handle CW1226324 with precision

It is a label-scope failure, not a permissions failure

The NHS was named as affected and explicitly stated patient information was not exposed. Do not let it compress in retelling into “Copilot leaked NHS patient data.” If you overstate it and someone looks it up, you lose the argument and your credibility on everything after it. It is an argument for a monitored, recurring service — not for a one-time cleanup.

8.3 · What you report, monthly

MetricSourceWhy it belongs in the report
Anonymous links, count over timeGovernance platform, or SPO PowerShellTrends down after remediation and creeps back up. The clearest proof drift is real.
External user access, count over timeSameGuest sprawl is continuous and invisible without reporting
Shadow users — access via nested groupsSameThe finding customers find most surprising, every time
Organization-wide grants introduced this periodSameDirectly maps to Gate 1
Leavers and stale guests removedEntra access reviewsGate 2. Cheap, visible, and the item a regulator would ask about
Label coverage on sites holding sensitive contentPurviewProgress on the work that is not a gate but does compound
DLP matches, and false positives reported by usersPurviewReport the false positives. It proves you are tuning rather than accumulating noise.
Secure Score deltaMicrosoft 365Imperfect, but the customer's board understands a number that goes up
Copilot license utilizationAdmin centerTies governance to the spend it protects, and surfaces reclaimable seats
The reporting trap

A green dashboard every month reads as “nothing is happening”

If your report only ever says everything is fine, you are teaching the customer they do not need you. Report what changed, what you fixed, and what you decided not to fix and why. Three items of judgment beat forty green checkmarks.

Anchor it to something external

The cyber insurance questionnaire is universal, annual, and already on their desk — use it. Where a customer genuinely wants a framework, use ISO/IEC 42001's shape: an AI system inventory, a risk register, named use-case owners, an incident protocol. Do not default to selling the certification; audit and implementation costs put it out of reach for most businesses this size, and offering the structure without the certificate is cheaper for them and more honest. Microsoft's own practice is a useful precedent: it re-attests its own containers on a six-monthly cycle.

↑ Contents

9 · Tooling

Your first assessment has to cost near zero to deliver, because you are running it to win the work. A credible baseline is free.

9.1 · The free toolkit

ToolWhat it does in this engagement
ScubaGear (CISA)Secure-configuration baseline for M365. HTML, JSON and CSV output that is close to client-presentable as-is. Start here.
MaesterRepeatable security-as-code tests. Turns a one-time assessment into something you re-run monthly — the mechanical basis of the recurring service.
Monkey365CIS and Entra misconfiguration review
Microsoft365DSCConfiguration baseline capture and drift detection
SharePoint Online PowerShellPermission enumeration. On a Business Premium tenant with no SharePoint Advanced Management, this is your Gate 1 evidence. Raw output; you supply the report.
Microsoft 365 LighthouseThe multi-tenant floor, free with CSP. Entra ID P1 is in Business Premium, so most customers qualify.
The honest limitation

These cover configuration baseline extremely well and permission exposure only adequately. Nothing free gives you a ranked, click-to-remediate view of who can reach what across the estate. You assemble that from PowerShell output and your own judgment — which is exactly the labor a platform is sold to remove.

9.2 · The build-versus-buy line

At one or two customers

Scripts win. The license cost of any platform exceeds the consultant hours it saves.

At roughly ten or more

A platform wins — not because it finds more, but because it makes findings comparable across tenants and turns your report into a product rather than a document. That is also the point at which the recurring service becomes deliverable at a margin.

Match the pricing unit to the shape of your book, not to the feature list. If your customers average 60 seats, a per-tenant price beats a per-user price with a 100-seat floor every time. Published seat minimums across the category: Syskit and Rencore 100, Nudge Security a flat monthly fee, Orchestry Starter and ManageEngine none. Syskit Point bills a minimum of 100 users even on a 60-user tenant, on annual terms — at its governance tier roughly $300 a month of cost Range for one small customer before you have earned anything.

9.3 · The comparison

ToolRole in this motionMulti-tenantPricing modelRealistic under 100 seats?
Free stack (ScubaGear, Maester, Monkey365, DSC, PowerShell)Configuration baseline, drift, permission enumerationScriptedFreeYes — and where nearly everyone should start
AvePoint Insights + PoliciesExposure discovery, bulk remediation, continuous drift enforcement. No Microsoft E-SKU dependency.Yes (Elements, separately)Per user; published list carries a 500-user minimumGet a written quote at your seat count — section 10
Syskit PointGovernance reporting and access reviewNot marketed for MSPPer user per year, published; 100-user billing minimumMarginal — the minimum is the problem
ShareGate ProtectGovernance risk assessment, tenant-wide visibilityLimitedSingle per-user price, no minimums; partner pricing unpublishedYes
OrchestryWorkspace lifecycle and provisioning governanceYesFlat per tenant, unlimited users at StarterYes — the pricing unit fits this market best
ManageEngine M365 Manager PlusReporting and auditingPartialPer tenant, bandedYes — cheapest commercial reporting by a wide margin
CoreViewMulti-tenant governance and delegationYesUnpublished; access reviews, SharePoint control, auditing and delegation are paid add-onsNo — enterprise-shaped
VaronisDeep data security posture; publishes a free Copilot readiness assessmentNo MSP consoleUnpublished, enterpriseNo — but the free assessment is a legitimate door-opener
RencoreGovernance console explicitly built for multi-tenant MSP deliveryYes, explicitlyUnpublished; 100-user minimumGet a quote
Nudge SecuritySaaS and shadow AI discoveryYesFlat monthlyYes at the low end
Compliance ScorecardThe GRC half — policy, attestation, AI governance moduleMSP-nativeFlat monthly, MSP-pricedYes
CIPPMulti-tenant delivery chassisYesLow monthly, self-hosted or hostedYes — but it holds delegated admin into every tenant. Document that risk deliberately.
↑ Contents

10 · AvePoint — What To Use, When

AvePoint gets its own section for a technical reason: Insights does not inherit the base-SKU wall from section 5. On a Business Premium tenant that is not a feature advantage — it is an availability advantage, and it is the strongest reason in this market to look outside the Microsoft stack.

10.1 · Name translation, before you quote

Website, price lists and marketplace listings use different names for the same product. Work from the right-hand column.

Marketing name (website)SKU name (price lists, docs, quotes)
Data & Security InsightsInsights for Microsoft 365
Policy Enforcement & Drift ControlPolicies for Microsoft 365
Records & Information Lifecycle ManagementAvePoint Opus (classification engine: Maestro)
Access & Power Platform GovernanceAvePoint EnPower
Adoption & Usage AnalyticsAvePoint tyGraph
License & Cost ManagementAvePoint Cense
Data Owner EngagementAvePoint MyHub
Agentic AI GovernanceAgentPulse Command Center
MSP multi-tenant platformAvePoint Elements
The minimum viable stack, and three dependencies that change a quote

Insights + Policies for a Copilot readiness engagement. Add MyHub when you want the customer's own site owners doing attestation rather than your engineer guessing. Everything else in the portfolio is a separate business case.

Policies needs Cense for its two license-reclamation rules · Policies needs Insights for Intelligent Remediation, the loop that makes either worth buying · Opus tiers stack: Analysis → Action → Archive.

10.2 · Engagement stage → product → the specific feature

StageProductThe specific featureWhat you actually get
Pre-sales — the door-openerInsights (30-day trial)Risk Assessment ReportAn out-of-the-box, exportable PDF. AvePoint designs it explicitly as “a benchmark to track progress over time” — which is why the second run is your recurring hook, not just your first deliverable.
Pre-sales — the AI angleAgentPulseAutomated agent discovery and inventory“You have 41 agents nobody inventoried.” Only lands where Copilot is already on.
Discovery — permissions baselineInsightsRisk Analysis → Workspaces Reports, then Detailed Records ReportsWorkspace-level then item-level exposure. A full inventory, not a 28-day delta.
Discovery — “who can see this?”InsightsSearch Center — object-based or user-based search“Show me everything this one user can reach.” The most demo-able screen in the platform. Run this one live.
Discovery — broad-access exposureInsightsExposure Report, configured in Risk Definition AdministrationExternal sharing and broad access groups. You tune what counts as exposure — confirm where EEEU surfaces (10.5).
Discovery — hidden access pathsInsightsShadow Users and Groups Access ReportAccess granted through nested groups or direct grants the site owner cannot see. Consistently one of the most surprising findings for a customer.
Discovery — linksInsightsShared Links reportAnonymous, company-wide and specific-people links, with full history rather than a 28-day window
Discovery — data qualityOpusDiscovery & Analysis as Power BI reports; File Share Discovery for on-premisesRedundant and obsolete data. Improves Copilot answer quality rather than security — sell on storage cost.
Findings readoutInsightsRisk Assessment Report + dashboardThe readout deck largely writes itself. Opus data exports to SharePoint for Power BI so you can brand it rather than screenshot a vendor UI.
Remediation — bulkInsightsRisk Remediation, in-report bulk actionsExpire, remove or edit permissions for external users, shadow users and anonymous links. Expiry is what native tooling handles worst.
Remediation — the upsell bridgeInsights → PoliciesIntelligent RemediationProposes the rule that would have prevented the finding. This is the moment the customer understands why one-time cleanup is not enough.
Remediation — owner-ledMyHubRecertification and attestation, including OneDrive cleanupPushes the decision to the site owner. Substitutes for SAM site access reviews, which a Business Premium tenant cannot have.
Ongoing — driftPoliciesViolations Report; Remove Shadow Users, External Sharing Settings, Direct Sharing PreventionAlert or auto-revert as often as every two hours. There is no Microsoft equivalent at any SKU. This is the mechanical basis of your recurring fee.
Ongoing — tenant hygienePoliciesGhost User Detection, Remove Inactive Guest UsersThe two the customer notices immediately, and both map to Gate 2.
Copilot enablement — licensingCenseLicense allocation and budget reporting“Which twelve people should get a Copilot license”, and who is burning pay-as-you-go AI credits.
Post-deployment — the QBRInsightsTime-based dashboards for anonymous links, external user access and shadow users; risk score over timeThose three metrics are your quarterly scorecard. Lift them directly into the report in 8.3.
Post-deployment — agent sprawlInsightsAgent Reports under Risk AnalysisHigh-risk, inactive or ownerless agents — a cheaper path to basic agent hygiene than buying AgentPulse.
Multi-tenant deliveryElementsPermission Simulation; CIS Level 2 baselines; sensitivity label managementThe portfolio layer. As of the June 2026 release it does not carry AI or Copilot governance — confirm the current roadmap (10.5).

10.3 · What it covers, and what still needs a Microsoft license

Covered on Business Premium

Discovery and drift, with no Microsoft license change

Insights consumes Microsoft's security, activity and compliance feeds rather than crawling content, so it runs on Business Premium unchanged. For the discovery half of Gate 1 it substitutes for SharePoint Advanced Management — with deeper history than SAM's 28-day sharing-activity window.

Policies adds continuous drift enforcement that Microsoft does not offer at any SKU. Together they cover the one genuine gap in the map at 4.3.

Scope around these

Three Policies rules require Microsoft 365 E5

From AvePoint's own documentation: Content Sensitivity Label Enforcement, Site Sensitivity Label Enforcement, and Content Creation and Upload Restriction all require E5. Inactive Guest User Detection requires Entra ID P1 — which Business Premium includes, so that rule works.

All three E5 rules are label-enforcement rules. That is Microsoft's licensing wall, not a vendor gap; no platform in this category has routed around it. Scope label enforcement to Purview, and use Policies for the permission and drift work it does reach.

One capability with no equivalent anywhere

There is no AvePoint equivalent to Restricted Content Discovery. AvePoint's position is that you should fix the permission rather than hide the content from search — arguably the better engineering answer, and definitely the slower one. If you need interim containment while remediation runs, that is an enterprise-SKU conversation, or more practically at this size a reason to scope the pilot to remediated sites. See 5.3.

10.4 · The land motion, and the commercials

The land motion

A genuine self-serve 30-day free trial, whose deliverable is the Risk Assessment Report — your assessment engine and your readout in one artifact. Pair it with free ScubaGear and Maester output for the configuration-baseline half Insights does not touch, and you have a complete first engagement at near-zero license cost.

The commercial question to settle

AvePoint's published price list carries a 500-user minimum on nearly every SKU with a 12-month minimum term, and no US pricing is published for Insights, Policies or Elements. Distribution pricing sits behind partner authentication. Get a written quote at your actual seat count through TD SYNNEX before you design an offer around it.

The ask that makes it work at SMB

Portfolio aggregation — committing 500+ seats across many small tenants rather than one. AvePoint's 2025 partner program explicitly rewards smaller but highly committed partners, and partner-generated revenue reached 58% of its recurring business in early 2026, so the conversation is a reasonable one to have. Put it to your rep and get the answer in writing.

10.5 · Five questions to settle before you build an offer

AvePoint will be in the room at these workshops. These are scoping questions, in the order that changes your quote.

  1. Does buying through distribution change the 500-user minimum on Insights and Policies — and can we aggregate seats across a portfolio of small tenants to meet it? Get this in writing. It decides whether AvePoint appears in an SMB practice at all.
  2. What is the per-seat price at 75, 150 and 300 seats, in our currency, at our tier? And what is Elements priced at, on what unit, with what minimum — and is there an NFR tier?
  3. Does Insights run at full fidelity on a Business Premium tenant? Specifically: are Microsoft sensitive information types, sensitivity labels and the activity feed available at that SKU, or is the risk-prioritization signal degraded? The claim in 10.3 rests on this.
  4. In the Exposure Report, where does “Everyone Except External Users” surface? As a first-class named exposure type, or through the broad-access-groups definition? Ask them to show you the screen — this is the single most common oversharing pattern and you need to know exactly where it appears. While you are there: is there a sensitivity-label coverage report (“percentage of sites labeled”), or is label data only a prioritization input?
  5. When does agent governance reach the Elements console, can Elements surface Insights and Policies findings across tenants, and can the Elements Graph API feed our QBR reporting? This determines whether the motion scales across a book of customers. And ask for AvePoint Learn documentation logins for your engineers — the cheapest, highest-value ask in the room.
Where AvePoint is genuinely strongest in this market

License reach — Insights works on Business Premium; SAM does not, and in this market that is decisive. History depth — continuous inventory versus a 28-day sharing-activity window. Continuous enforcement — alert-or-revert every two hours, with no Microsoft equivalent at any SKU. Archival granularity — site, document, list and library level. Breadth — backup, migration, records, licensing, analytics and agent governance from one vendor, across Google, Salesforce, AWS and Box as well as Microsoft.

Make the argument on license reach. It is true, it is verifiable, and it is sufficient on its own — you do not need a comparison table to win it, and a room that has read Microsoft's SharePoint Advanced Management documentation will hold you to the detail.

↑ Contents

11 · Staffing, Effort and Price

11.1 · Who delivers it

ConfigurationWorks?Notes
One generalist M365 admin NoWill build a taxonomy nobody agreed to and discover the problem in week six.
One genuine senior who does both halvesYes, with a ceilingWorks to about 75 seats. Needs someone who can chair a room of business owners and write a DLP rule. Does not scale past ~two concurrent engagements.
One senior plus one technician YesThis is the answer. It is also the shape that lets you charge properly for the senior's time instead of averaging it away.
Plus fractional adoption and communicationsYesThe only shape that survives a mandatory-labeling rollout. The comms person can be borrowed rather than hired.
The split is decisions versus execution, not hard versus easy

The junior may touch anything reversible. The senior signs anything that changes what a file is.

Senior: encryption on a label, the co-authoring switch, label order, and the move from DLP audit mode to enforcement. Junior: building labels to an agreed taxonomy, running simulations, triaging false positives, capturing evidence. It maps exactly to the irreversible decisions in 6.4, and it is defensible to a customer asking why two people are on the call.

The most common staffing failure

Putting the M365 architect in the vCISO's chair

The classification workshop gets run as a configuration session. The engineer asks which folders are sensitive, writes down the answers, and builds a taxonomy nobody in the business agreed to. Six weeks later Finance cannot email the auditor, nobody knows who decides, and the labels come off. The workshop is a facilitation job that ends in configuration, not a configuration job with people watching.

Stop telling people to get SC-400

SC-400 retired on 30 May 2025 — the certification and its renewal assessment. The replacement is SC-401 Information Security Administrator, refreshed 28 July 2026, which now carries an explicit “Protect data used by AI services” objective covering exactly this work. Supporting: SC-200 for the shadow-AI discovery half, SC-300 for Gate 2 identity work, SC-100 as the closest thing to a vCISO credential. Applied Skills APL-5003 is a hands-on lab — cheaper and faster proof of capability than a certification, with a 72-hour cooldown between attempts. MS-102 retires 30 November 2026 and no longer earns Copilot specialization credit; do not start a junior on it.

11.2 · Effort by seat band

Read this table with the caveat attached

The 50-seat row is published, hour-level, against a stated seat count. Everything else is extrapolated from it plus a practitioner convention of scoping governance reviews to 10–25 high-risk or inactive sites. Use it as a planning heuristic and replace it with your own delivery data after three engagements.

SeatsTypical sitesAssessment hoursRemediation hoursElapsed, total
25–5010–3015–2530–503–4 weeks
50–10025–6020–3540–704–6 weeks
100–30060–15030–5080–1606–10 weeks

Model — rows 1 and 3 are constructions from the sourced 50-seat figures.

The number that loses deals

The 200–400 hour figure circulating in the channel is explicitly framed around “permission inheritance across 200+ sites.” A 50-seat firm does not have 200 sites — a typical one has around 30, and well over half the content usually sits in one of them. At 50 seats this is 40 to 60 hours over 30 calendar days. A partner who scopes SMB work from enterprise literature prices themselves out of every deal they quote.

Quote from a site inventory, not from a headcount. And do not forget the waiting — the six to ten elapsed days in 6.2 are not the same as the hours above and do not overlap neatly. Put them in the plan as named calendar items; a customer who understands on day one why week three is quiet does not lose confidence in week three.

11.3 · What it costs you to deliver

InputFigureWhat it actually is
M365 consultant salary, 75th percentile$130,000 /yr RangeAggregated job-postings data. A salary, not a bill rate.
→ base hourly~$65 /hr ModelArithmetic
→ fully loaded at 1.3–1.4× burden~$85–$91 /hr ModelConventional burden multiplier
→ recoverable cost at 65% utilization~$130–$140 /hr ModelThe number that matters
Cost to rent a cybersecurity engineer$130–$195 /hr RangeStaffing agency bill rate. A hard floor — you cannot bill less than you buy.

A partner billing under roughly $150 an hour for senior Purview work is not making money on it. The channel band sits somewhere around $150–$275 Model, but no published source isolates this work — treat that as a bounded inference, not a benchmark. Do not quote a day rate; nothing credible is published, and everything shaped like one on the open web is a lead magnet.

What you can and cannot subcontract

Distributor-funded deployment offers price a baseline Purview stand-up — data lifecycle review, labeling policies, baseline classification, DLP aligned to Microsoft best practice — at around $3,000 Range. Sit with that number: the configuration layer of this work has a public price, and it is a few thousand dollars. If your quote is $30,000 you need a clear story about the other $27,000.

You can outsource the build and the tooling. You cannot outsource the taxonomy decision, the exception path, or the quarterly review — and those three are where the margin and the recurring revenue live.

11.4 · The tier ladder and what to charge

TierWhat it isPriceElapsed
0 · ScanAutomated tenant scan, findings list, no judgment applied$0 — give it away deliberately60–90 min
1 · Light assessmentScorecard, 3–5 stakeholder interviews, debrief, prioritized findings. No costed remediation plan.$1,500–$3,000 Range1–2 weeks
2 · Full assessmentOversharing report, costed remediation plan, pilot design, draft policy, roadmap. The tier that converts.$3,000–$15,000 Range · anchor $100/seat2–4 weeks
3 · Remediation projectBreak inheritance, replace grants, expire links, remove leavers, publish labels, DLP in audit mode$6,000–$15,000 at 50 seats Model40–60 hrs / 30 days
4 · Ongoing governanceDrift monitoring, reassessment, quarterly review, attestation reporting. The only tier that compounds.Floor-priced — section 8Monthly + quarterly

The scan is not defensible as a revenue line. Distribution packages funded readiness assessments on a per-tenant, per-month basis, and TD SYNNEX packages an AvePoint-powered readiness assessment as a partner-deliverable service with turnaround inside five weeks and a co-investment model that may be partly or fully funded depending on partner status. You will lose tier 0 on price every time. The judgment, the roadmap and the remediation are what is defensible.

11.5 · A worked engagement at 78 seats

StagePriceStructure
Scan$090 minutes. Produces the site count that scopes everything below.
Full assessment$7,800 ModelFixed fee at $100/seat. Credited in full against remediation if they proceed within 60 days.
Remediation$14,000 ModelFixed fee, scoped to a named list of sites. Roughly 2× the assessment — a ratio you can say in a room without a spreadsheet.
Ongoing governance$1,400 /mo ModelFloor-priced, not pure per-user.
Year one~$30,600 ModelAssessment credited, so $14,000 project plus 12 months recurring
Recurring thereafter$16,800 /yr ModelThe number that matters

Every figure there is a model, not a quote — composed from the sourced inputs above and shown so you can rebuild it against your own cost base rather than copy it. The evidence and its weaknesses are set out in section 18 of the full guide.

Credit the assessment. Always.

It qualifies the buyer — someone who will not pay for an assessment will not pay for remediation; charging filters, and the credit removes the reason to object. It stops the report walking — a free report goes to a cheaper remediator; a credited report is money already committed to you. It keeps the scopes separate — review billed separately from remediation, with the customer's decisions documented before any cleanup begins. That boundary is what stops an assessment quietly becoming an unpaid Purview deployment.

↑ Contents

12 · Language — Lines and Objections

12.1 · The whole licensing conversation, in six sentences

Say this early

“You are on Business Premium, and that was the right call — it is a genuinely good security stack and it did the job you bought it for. Copilot adds one requirement nobody was scoping for when you bought it, which is knowing who can see what across your SharePoint.

The good news is that the data protection side is a ten-dollar add-on, and Microsoft is running it at half price alongside Copilot until the end of the year. Nobody is asking you to move to E5.

The permissions side needs one extra piece, and there are three ways to get it — one of which costs about as much as three licenses. Let me find out which one applies to you before either of us assumes it is expensive.”

12.2 · The argument that actually wins

Use this instead of a scary statistic

“I am not going to tell you Copilot is dangerous, because mostly it isn't. What I will tell you is that when Forrester looked at the companies who got the returns Microsoft advertises, seven in ten had done a data security project first. That is the difference between the deployments that worked and the ones that quietly stalled. I would rather put you in the first group, and it is cheaper to do that now than to unpick it later.”

That reframing converts governance from a tax into a success factor, and it survives being checked. The source is Forrester's commissioned Total Economic Impact study — sixteen decision-makers across twelve organizations plus 367 surveyed users. Use the 70% finding; do not use the headline ROI figures, which are an enterprise composite.

12.3 · The three objections that actually end deals

ObjectionThe answer
“Our last MSP reviewed us and said we were fine.”Attack the date, never the predecessor. Permissions drift, and the AI control plane did not exist when that review was written.
“Why am I paying monthly for a one-time cleanup?”Drift, and the control plane changing underneath them. The three answers in 8.2, in that order.
“Microsoft says Copilot respects permissions, so we're covered.”The statement is accurate and it is about access control — whether a user is permitted to open a file. It says nothing about exposure — whether they will ever find it. Nobody browses to /Company/Shared/Old HR/2019; natural language search removed that friction entirely. The proof the distinction is real: Restricted Content Discovery exists. Microsoft built a feature whose entire purpose is to stop Copilot surfacing content users are already permitted to open.
“You are just selling us more stuff.”“Fair. Assessments at your size routinely find 10 to 30% of license spend Range going to the wrong place — wrong SKUs, seats assigned to leavers, duplicated add-ons. I would rather find that first and put it against the cost of this work than ask you to fund it out of fear of something that might not happen.” Checkable, and it reframes you as reducing their spend.

12.4 · The timing levers, ranked

TriggerWho it coversWhy it forces the conversation
Cyber insurance renewalEveryoneAnnual, sector-agnostic, headcount-agnostic, hard date, named signer. Nothing else has all five. Generative-AI exclusion endorsements took effect 1 January 2026 and carriers are adding AI sublimits. Limit: there is no published, adjudicated claim denial attributable to AI use — argue the underwriting shift, not a denial.
An enterprise client's security questionnaireAnyone with an enterprise customerArrives without warning, blocks a contract renewal, and needs answering this week. Highest urgency and margin available. Build the response artifact once.
FTC Safeguards RuleAccountants, tax preparers, auto dealers arranging finance, mortgage and insurance brokers under GLBAWritten risk assessment and a designated qualified individual. Trap: the fewer-than-5,000-consumers exemption removes exactly the assessment you were planning to sell. Check the count first.
CMMC Phase 1Defense contractors and subcontractorsIn force since 10 November 2025; self-assessment gates contract award. Sharpest deadline available, narrow slice of the channel.
ABA Formal Opinion 512 and 35+ state barsLaw firms of any sizeIssued 29 July 2024. For a small firm this is the partner's license, which concentrates attention.
Illinois HB 3773Any employer with Illinois staffEffective 1 January 2026. Reaches employers who have never thought of themselves as regulated.
HIPAA's existing risk-analysis dutyCovered entities and business associatesAlready in force. Benefits administration drags ordinary companies into business-associate status more often than they realize.
Narrowing the claim wins you the deal

Most partner marketing overstates regulatory applicability to small business, and sophisticated buyers know it. EU AI Act: enforcement provisions apply from 2 August 2026, but high-risk obligations moved to December 2027 and August 2028, and an SMB using Copilot is a deployer, not a provider. Colorado: SB 24-205 was repealed and replaced; the replacement takes effect 1 January 2027. California ADMT: 1 January 2027, gated behind CCPA thresholds most sub-100-seat businesses do not meet. When a customer says “I read the EU AI Act is going to hit us,” the winning answer is “probably not, and here is why.”

↑ Contents

13 · Claims Discipline

13.1 · Do not repeat these

Claim in circulationThe problem
“802,000 at-risk files per organization”Presented as current; traces to a 2022 report. Date it or drop it.
“150–300 overshared SharePoint sites per tenant”No published methodology, and it describes enterprise tenants. Actively misleading in an SMB room.
“99% of organizations have sensitive data exposed to AI”Real vendor research, but too high to be believed. Use the 1-in-10-had-any-labeled-files figure instead — modest, checkable, and the customer recognizes it as true about themselves before you finish the sentence.
The Gartner pilot-progression percentageTwo sample sizes and two percentages circulate for one finding, and a competing survey reports the opposite. Cite the governance-delay pairing — roughly two-thirds of IT leaders reported governance and security consumed significant time — not the decimal.
“Get your team SC-400”Retired 30 May 2025. The replacement is SC-401.
“Enable Restricted SharePoint Search while we review permissions”New enablement was blocked on 31 July 2026. Microsoft directs you to Restricted Content Discovery. Any playbook opening with this step is unexecutable.
“SAM is included with Copilot, so the E5 objection is dead”True only on an E-SKU base. This over-correction is now as common as the error it replaced. Section 5.1.
“The EU AI Act will hit your business next year”High-risk obligations moved to 2027–2028, and an SMB using Copilot is a deployer, not a provider.
“Colorado's AI Act takes effect in February 2026”Repealed and replaced. The replacement takes effect 1 January 2027.
Any FY27 Microsoft incentive rateAll sit behind partner sign-in. Name mechanisms; get rates from Partner Center yourself.
“MaestroBridge” as an AvePoint productNo such product exists. Maestro is the classification engine inside Opus.
A published SANS AI acceptable use policy templateCould not be found. Do not cite one.
Any claim that a company was fined or sanctioned for AI oversharingThere is no enforcement action anywhere — no GDPR fine, no FTC action, no ICO reprimand. Inventing regulatory risk is how you lose a customer's lawyer. There is also no published, named-company case study of Copilot surfacing HR or salary data to the wrong employee. Argue from mechanism.

13.2 · Confirm these before you quote

Three claims this guide deliberately does not make, because no primary source settles them. Each is a question for a licensing desk or a distributor — get the answer in writing and it stops being a risk. Do not settle them by buying a seat and watching the portal: portal behavior is not an entitlement, it changes without notice, and an audited customer is measured against licensing terms rather than against what worked in your tenant last quarter.

Q1

How does SharePoint Advanced Management's base requirement apply in a mixed-SKU tenant?

Microsoft states it at organization level and publishes no guidance for tenants holding a mix. Ask: Microsoft licensing desk or TD SYNNEX · affects route 3 in 5.2.

Q2

Does the Purview Suite for Business Premium include auto-labeling and the DSPM for AI surface?

Microsoft's page says “policy-based controls for AI experiences” and never uses the term DSPM; the Purview service description has no DSPM section. Highest risk of a confident wrong claim in the whole motion — describe the capability, confirm the product surface in configuration. Ask: Microsoft licensing desk.

Q3

Does the Defender Suite for Business Premium carry full Defender for Cloud Apps?

Corroborated by community and reseller sources, not by a Microsoft page. If it does, $15 per user per month is the price of shadow AI discovery for an SMB. Ask: Microsoft licensing desk or TD SYNNEX.

Q4

Does AvePoint Insights run at full fidelity on Business Premium?

Its risk prioritization draws on Microsoft sensitive information types and the activity feed. Ask: AvePoint · question 3 in 10.5.

13.3 · Be fair, or lose the room

Say this before someone else does

Most deployments proceed without an incident. If Copilot were routinely producing HR disasters across tens of thousands of tenants, some would have surfaced through employment tribunals or trade press. The dominant observed customer-side outcome is delay and friction, not breach.

What you can safely cite

Vendor-side product failures like CW1226324, and security research disclosed and patched before exploitation. EchoLeak (CVE-2025-32711) and CoSnitch (CVE-2026-24301) belong in a technical conversation and nowhere near a business owner. Cite them for mechanism; never imply harm occurred.

The mechanism argument for a non-technical owner

The index remembers what you revoked. Lasso Security found 20,580 repositories across 16,290 organizations still reachable through Copilot after being made private, because a search cache retained them. The principle transfers directly to Microsoft 365 — and it is precisely why Restricted Content Discovery requires a reindex rather than taking effect instantly.

↑ Contents

14 · Related Guides

14.1 · Run it on yourself first

The one non-negotiable

Before you quote this work, complete it in your own tenant. Publish four labels. Watch the 24-hour propagation actually take 24 hours. Run an auto-labeling simulation and discover it fired 300 activity alerts because you did not scope the alert policy first. Break something with an encrypting label and find out what it costs to unbreak.

Every hour of that is an hour you will not lose in front of a customer, and it converts the numbers in section 11 from something you read into something you know. Beyond that the floor is low: one person holding SC-401, one person who can chair a room of business owners, and a written decision about who signs the irreversible changes in 6.4.

14.2 · Where this sits

The customer does not need to be frightened into this. Seven in ten of the organizations that got the returns Microsoft advertises did the data security work first.

You are selling the precondition that separated the deployments that worked from the ones that quietly stalled — to a business that is going to buy Copilot either way.
↑ Contents