Seven phases from the first scan to recurring governance — for the customers you actually have, on Business Premium, who are not buying E5. The decisions, gates, effort bands and prices, in the order you need them.
Sections 2 through 8 are the seven phases in delivery order — each one states what you do, what you do not do, how long it takes and what it produces. Sections 9 through 13 are the reference material you reach for mid-engagement: tooling, vendor, staffing, price, and the claims that will cost you credibility if you repeat them. Nothing here is argued. Where you want the reasoning, the evidence and its weaknesses, the long-form background reference carries all of it, section by section.
Your customer is on Business Premium and is not buying E5. Everything below assumes that as the starting condition.
Fully reachable on Business Premium. Labels, DLP, retention, insider risk, audit, and the control that keeps labeled content out of Copilot — all through the Purview Suite for Business Premium add-on at $10 per user per month.
One gap, and only one. SharePoint Advanced Management requires an Office 365 or Microsoft 365 E-SKU base. Business Premium and Business Standard are not on Microsoft's list, and buying Copilot does not change that.
None of them is E5. Deliver natively on Business Premium at zero license cost; use a governance platform that does not depend on SharePoint Advanced Management; or move the base to an enterprise SKU. Section 5.
Opening with the governance work. The customer arrived with demand; you replaced it with an obligation before establishing that anything was wrong in their tenant. Establish the problem, then sell the fix.
Finding the SharePoint Advanced Management requirement and quoting E5. That conclusion is wrong. It is one of three routes and the one the customer is least likely to accept.
| Phase | Elapsed | Partner hours | Tools | What the customer gets |
|---|---|---|---|---|
| 1 · Qualify and scope | 90 minutes | 1.5 | Automated tenant scan; free config baseline tooling | A site count, an exposure count, and a fixed-price proposal that is not a guess |
| 2 · Licensing decision | One meeting | 2–3 | M365 admin center; the decision table in 3.2 | Purview Suite attached; a chosen route for the permissions half |
| 3 · Assessment | 1–2 weeks | 20–35 | Native SharePoint reports and PowerShell, or a governance platform | Findings report, three gates identified, costed remediation plan, deferral list |
| 4 · Remediation | 3–4 weeks | 40–70 | SharePoint admin center, PowerShell, platform bulk remediation | Permissions fixed against a named list of sites |
| 5 · Purview stand-up | Parallel | 15–25 | Microsoft Purview | Four labels published, DLP in audit mode, signed policy intent statements |
| 6 · Enable and pilot | 1 week | 6–10 | M365 admin center; Copilot Dashboard | Copilot live for a pilot group, containment removed, adoption handoff |
| 7 · Ongoing governance | Ongoing | ~5 / month | Governance platform or scripted re-runs | Monthly drift report, quarterly review, annual reassessment |
If the first three do not produce satisfying answers, this is an education conversation, not a deal. Treat it as one rather than writing a proposal.
| Signal | What it tells you |
|---|---|
| Number of SharePoint sites and libraries | The scoping variable. Under ~30 sites is a small engagement; past 60 is a different quote. |
| Sites shared organization-wide | Gate 1 exposure. Usually concentrated in one or two sites that came off a file server. |
| Live anonymous links | Fast, visible, cheap to fix — the week-one credibility win. |
| Disabled accounts holding grants, stale guests | Gate 2. Cheapest finding in the engagement, and the one a regulator asks about first. |
| Whether Purview has ever been configured | Almost always no. Decides whether Phase 5 is a stand-up or a tune-up. |
| The license mix | Business Standard vs Business Premium vs anything else. Sets up Phase 2 entirely. |
“You have 31 SharePoint sites, and four of them are shared with everybody in the company — including the one your old file server turned into. Nine anonymous links are still live, two of them older than the staff who created them.
I am not going to tell you what is in those sites yet, because I do not know and neither do you. That is the assessment. It is fixed price, it takes two weeks, and if you go ahead with the fixes afterward I credit the whole fee against them.”
Decisions, not a feature matrix. The customer wants to know what to buy on Monday and whether you are about to double their bill.
| Component | Price | Notes |
|---|---|---|
| Microsoft 365 Business Premium (base) | $22 /user/mo Range | Held at this price through the July 2026 adjustments. Reseller-corroborated. |
| Purview Suite for Business Premium | $10 /user/mo MS list | Microsoft's words: “$10.00 user/month, paid yearly”, “Maximum of 300 seats”, “Requires a Microsoft 365 Business Premium subscription” |
| Defender + Purview Suites combined | $15 /user/mo Range | Widely and consistently reported; not read off a Microsoft page in this research. |
| = the SMB governance stack | ~$37 /user/mo Model | Business Premium plus both suites |
| Microsoft 365 E5, for comparison | $60 /user/mo Range | Rose from $57 on 1 July 2026 |
50% off Purview Suite for Business Premium when purchased with Microsoft 365 Copilot, 1 December 2025 through 31 December 2026 MS list. Distribution is running first-year promotions alongside it, several expiring on the same date. Verify current terms with your TD SYNNEX rep before quoting.
| If the customer needs… | Buy | Because |
|---|---|---|
| Labels, DLP, insider risk, Copilot interaction controls, audit retention | Business Premium + Purview Suite | $10/user/mo, 300-seat cap, half price alongside Copilot through 31 Dec 2026 |
| Shadow AI discovery and full CASB | + Defender Suite (combined $15) | Business Premium has no CASB. Verify the suite carries full Defender for Cloud Apps before promising discovery. |
| DAG reports, EEEU insights, Restricted Content Discovery, site access reviews | An E-SKU base — or a third-party platform | The wall in section 5. No Business Premium add-on reaches SharePoint Advanced Management. |
| Auto-labeling of files and emails | E5 family Verify | Microsoft states the symptom for “E3 or Business Premium” explicitly. Whether the Purview Suite lifts it is unconfirmed — test before scoping. |
| Copilot itself, under 300 seats | Copilot Business SKUs | Sequencing trap: you cannot upgrade to an Enterprise plan from Business Standard or Premium with Copilot Business until commitment end. A growing customer can be stuck for up to a year. Decide before attaching. |
| Security Copilot | Do not sell it here | Provisioned capacity is priced per hour; the included-capacity model is E5/E7 only. Not an SMB motion. |
| Capability | Business Premium alone | BP + Purview Suite | Microsoft 365 E3 | What decides it |
|---|---|---|---|---|
| Sensitivity labels, published and applied manually | Yes | Yes | Yes | Included broadly |
| DLP for email and documents | Yes | Yes | Yes | Base entitlement |
| DLP extended to Teams chat and endpoints | No | Yes | No | Purview Suite |
| Keep labeled content out of Copilot | No | Yes | No | The mis-sale in 3.4. E3 does not carry this. |
| Insider risk, communication compliance, Audit Premium | No | Yes | No | Purview Suite |
| Auto-labeling of files and emails | No | Confirm | No | Microsoft names E5-family; suite inclusion unconfirmed — 13.2 Q2 |
| Conditional Access, guest and leaver cleanup | Yes | Yes | Yes | Entra ID P1, in Business Premium |
| Shadow AI discovery (full CASB) | No | Confirm | No | Defender Suite — 13.2 Q3 |
| Governance reports, EEEU insights, site access reviews | No | No | Yes* | SharePoint Advanced Management. Needs an E-SKU base plus one assigned Copilot license. |
| Restricted Content Discovery | No | No | Yes* | Same. The only capability with no substitute — see 5.3. |
* Requires at least one Microsoft Copilot license assigned in the tenant, on top of the E-SKU base.
Microsoft's DLP documentation marks “restrict Copilot from processing files and emails” as unavailable on Business Premium and unavailable on E3. Only the E5 family and the Purview Suite line carry it.
E3 clears the SharePoint Advanced Management base requirement — which may be the whole reason to do it — but it does not buy the ability to keep labeled content out of Copilot. Be explicit about which of the two problems it solves.
The capability is not on the base SKU. With the Purview Suite attached it is in scope — Microsoft lists “policy-based controls for AI experiences and Copilot interactions” among the suite's capabilities.
Promise it on base Business Premium and you will be discovered at configuration time, in front of the customer, by a support engineer.
No site or library holding regulated, financial, HR or client-confidential content is shared with an organization-wide group, an Everyone Except External Users grant, or a live anonymous link.
Why it gates: Copilot inherits the permission model exactly. Every one of these becomes queryable in natural language on day one.
Disabled accounts still holding grants, guest accounts from finished projects, shared mailboxes with lingering access.
Why it gates: cheapest credibility you will ever buy, and regulators fine for this without AI in the picture.
A named person on the customer side who decides what happens when a control blocks legitimate work. Not a policy document — a person, with a decision route and a response time.
Why it gates: the one partners skip, and the one that kills engagements in month two. Without it the first false positive escalates to the managing partner and your controls get switched off by someone who outranks everybody who understands them.
| Work | Timing | Why it can wait |
|---|---|---|
| A complete sensitivity label taxonomy across the estate | After | Four labels and a default set is enough to start. Full coverage is a program, not a prerequisite. |
| Auto-labeling policies | After | Needs simulation cycles and, on most SMB SKUs, a license you have not sold. |
| DLP in enforcement mode | After | Microsoft's documented rollout is audit, then policy tips, then enforce. |
| Retention and records management | After | A lifecycle program with its own business case. |
| Custom sensitive information types and trainable classifiers | Much later, if ever | Almost always out of scope at 25–300 seats. Built-in types cover the realistic cases. |
| Insider risk and communication compliance | After | Real capabilities that need a mature customer and a reason. Selling them at gate stage sounds like inventing scope. |
| Cleaning up redundant and obsolete data | After | A follow-on project with its own economics. Sell it on storage cost, not risk. |
| What the assessment finds | The control that answers it | Position | On Business Premium? | Note |
|---|---|---|---|---|
| Site shared with Everyone Except External Users | Replace grant with a scoped group; break inheritance | Gate 1 | Fixable — needs a route from 5.2 | Usually the single largest share of high-priority remediation |
| Live anonymous sharing links | Expire links; tighten tenant default link type | Gate 1 | Yes — native admin center | Fast, high-visibility win |
| Disabled accounts retaining grants | Offboarding cleanup; access review | Gate 2 | Yes — Entra P1 | Regulators fine for this without AI involved |
| Stale guest accounts | Guest expiry / removal | Gate 2 | Yes — Entra P1 | Included in Business Premium |
| No owner for blocked-work decisions | Named exception owner + route + response time | Gate 3 | Yes — no license involved | Not a technical control. Still a gate. |
| Sites with sensitive content and no label | Publish four labels; manual labeling at container level | After | Yes — Purview Suite | Containers before files |
| Sensitive content leaving via chat or email | DLP, audit mode first | After | Yes — Purview Suite | Audit → policy tips → enforce |
| Automatic labeling at scale | Auto-labeling policies | After | Verify — gated above base SKU | Confirm before scoping — 13.2 |
| Content Copilot should never ground on | Restricted Content Discovery | Interim only | Needs a route | Must be removed after remediation. Needs an eligible base SKU and an assigned Copilot license. |
| Who can reach what, across the estate | Permission and exposure reporting | Gate 1 | Needs a route — 5.2 | The one genuine gap. Route 1, 2 or 3. |
| Personal AI accounts in use | Sanctioned tenant AI + conditional access | Parallel | Yes | See the Shadow AI Assessment Guide |
| Redundant and obsolete data degrading answers | Lifecycle and archival | Follow-on | Yes — Purview Suite | Sell on storage cost, not risk |
| Permissions drifting back after cleanup | Continuous drift monitoring | Recurring | Third party | This is the MRR. Section 8. |
Almost everything on that list is reachable on the licenses your customer already owns. One row is not — permission and exposure reporting across the estate — and it is the row Gate 1 depends on. Scoping without knowing which route the customer is on is how partners end up quoting an E5 upgrade they never needed to quote.
Microsoft 365 base subscription. Your organization must have one of the following base licenses: Office 365 E3, E5, or A5; Microsoft 365 E1, E3, E5, or A5; Microsoft 365 GCC, GCC-High, or DoD. Microsoft Learn, Prerequisites for SharePoint Advanced Management — page dated 30 June 2026, updated 18 August 2026, verified 28 August 2026
The Copilot unlock — one assigned Microsoft Copilot license anywhere in the tenant — is a second, additional condition, not a substitute for the base requirement. Both gates have to be cleared.
The channel is currently wrong in both directions. Older material says “you need E5 for oversharing tooling” — out of date; one Copilot license does unlock the full SAM feature set. Newer material has over-corrected to “SAM is included with Copilot, the E5 objection is dead” — true only on an E-SKU base, and false at most SMB customers.
SharePoint admin center for sharing settings, site permissions and sharing reports. SharePoint Online PowerShell to enumerate permissions across the estate. Free tooling covers the configuration baseline. This is where most partners should start.
What you give up: raw output rather than a client-ready report, no continuous monitoring, effort that grows with site count. Comfortable at 80 seats, painful at 300.
Some platforms read Microsoft's security and activity feeds rather than depending on SAM, so they run on a Business Premium tenant with no Microsoft license change. That is an architectural difference, not a loophole — and it is the only route that gives you continuous drift monitoring, which is what the recurring fee in section 8 is actually for.
What you give up: seat minimums can price out the smallest tenants, pricing is largely unpublished so you quote against a number you have to obtain, and label-enforcement features generally still inherit Microsoft's E5 requirement.
Microsoft's documented path, and the only route that delivers Restricted Content Discovery. On an eligible E-SKU base a single assigned Copilot license unlocks the full toolset.
Before you quote it: get the entitlement confirmed in writing by Microsoft licensing or your distributor, including how it behaves in a mixed-SKU tenant. Microsoft states the requirement at organization level and publishes no partial-adoption guidance. It also does not solve the other half — E3 does not carry the control that keeps labeled content out of Copilot.
Tempting, and the owner will suggest it. It is also the one path where you carry the consequence: you enabled it, and the salary spreadsheet surfaces in week two.
The counter is not a lecture — it is Gate 1 as a two-day job. Find the organization-wide grants, fix the worst handful, then enable. You are giving them a shorter path than they expected, not refusing them.
Restricted Content Discovery on the worst sites, plus DLP scoped to keep labeled content out of Copilot processing. Both carry license prerequisites most SMB tenants do not meet.
Actually fix the permissions. Break inheritance, replace organization-wide grants, expire links, remove leavers and guests.
Take the containment off so Copilot can see the content it legitimately should. Put this in the SOW as a dated, billable milestone.
Partners contain, remediate, then leave the containment in place because nothing forces them to remove it and removing it feels like a risk. The customer is now paying full price for a Copilot that cannot see their own content, concludes the product is useless, and does not renew. This is the most common way a technically successful engagement produces a commercially failed one.
RCD needs an assigned Copilot license and an eligible base subscription, so on Business Premium it is not on the table. The supported alternative reaches the same outcome by a different route: remediate first, then scope the pilot to what you have cleaned. Enable Copilot for a small pilot group whose work sits in already-remediated sites, rather than enabling the tenant and hiding the rest. Slower to reach everybody, completely defensible — and it removes the un-containment step entirely.
Until this is on, SharePoint and OneDrive “can't process encrypted files, which means that coauthoring, eDiscovery, data loss prevention, search, and other collaborative features won't work for these files.”
The trap: labels applied before the setting is enabled are never recognized. Microsoft's remedy is to “download these files and then upload them to their original location.” On any volume that is a punishment, not a remediation. Takes ~15 minutes to take effect. Microsoft Learn
| What you are waiting for | Documented wait |
|---|---|
| Label and label policy changes to propagate | 24 hours (24–48 where group membership is involved) |
| Editing an already-published label | Up to 24 hours |
| Microsoft's safe-publish pattern: pilot users → verify → widen | 1 hour, then “wait at least a day” before widening |
| A newly created auto-labeling policy is locked | ~24 hours greyed out while the backend provisions |
| Auto-labeling simulation run | Up to 12 hours — and you will run two or three |
| Co-authoring tenant setting replication | 24 hours |
| Newly added policy location before first crawl | 24 hours before troubleshooting missing labels |
| Reindexing after a bulk label change, 100+ sites | Up to several days |
| Container label deletion, SharePoint sites | 48–72 hours, during which users may be unable to open previously protected content |
A minimal, clean, single-tenant stand-up — one auto-labeling policy, one DLP policy, nothing custom — carries a floor of roughly six to ten elapsed working days of pure waiting, before a single hour of consulting, workshop, tuning or user communication. This is the single most common reason a four-week engagement becomes a nine-week one, and the partner absorbs the difference.
The owner or managing partner · whoever owns finance · whoever owns HR · the person who actually knows where the files are — usually the part-time IT person who ran the migration, and the most important person present.
Four top-level labels. Sublabels only under Confidential. Start from Microsoft's default set — Personal, Public, General, Confidential, Highly Confidential — and cut down rather than build up. Microsoft: effectiveness drops noticeably past five main labels or five sublabels each.
“What is this organization's tolerance for leakage?” Microsoft names this one directly. Asking it stops the room treating classification as an IT decision, which is the entire purpose of holding the workshop.
Not a label list — policy intent statements, signed. Microsoft: “You should be able to summarize, in a single statement, the business intent for every policy you have.” Every clause maps to a configuration decision, and the signed page is what makes the engagement defensible eighteen months later.
Follow Microsoft's naming guidance literally: use terms that make sense to your users, test names and tooltips with the people who have to apply them, and do not mix Confidential, Restricted and Internal — users cannot reliably distinguish them. A fifteen-label taxonomy does not produce careful classification; it produces users picking whatever is least likely to interrupt them.
These are senior-consultant decisions. They should never be made by whoever happens to be in the portal.
Deleting an encrypting label archives its protection template, and you can never create a new label with the same name. Deleted labels show as GUIDs in content and activity explorer. Deleting a label applied to a SharePoint document strips label and encryption on download — but the same document stored outside SharePoint stays encrypted forever.
Rule: ship labels without encryption first. Add encryption as a separate, separately-communicated change. Microsoft's own blueprint hedges its default with “encryption of labels can be implemented later” and ships an \Internal exception sublabel for when encryption impacts daily operations.
Microsoft: “After you enable co-authoring… you can't disable this setting in the Microsoft Purview portal. This action is supported only by using PowerShell.” It also changes where labeling metadata is stored; turn it back off and “this labeling information for unencrypted Word, Excel, and PowerPoint files will be lost.”
Rule: inventory scripts, add-ins and mail flow rules that read or write labeling metadata before enabling. SMB tenants are precisely where undocumented scripts live. Microsoft Learn
Order is semantic, not cosmetic. It defines what counts as downgrading, it resolves auto-labeling conflicts, and Copilot surfaces the highest-priority label — Copilot Chat displays it, and content generated from multiple sources inherits it.
Rule: get the order right at publish. Reordering later means re-reasoning about every policy that depends on it.
Assess impact through the reports. Nobody is interrupted. Use this stage to test your own review and remediation workflow, not just the policy.
Begin teaching users. Link the customer's own policy page. Explicitly ask users to report false positives. Move here only once results match what the stakeholders had in mind.
And keep monitoring. Most partners never arrive here — a permanent diagnostic state that looks like compliance and protects nothing.
Microsoft's DLP planning documentation carries a worked persona for an 18-person startup. The whole prescribed approach: use the default Teams DLP policy; make SharePoint restricted by default; block external sharing; deploy to Windows devices; block non-OneDrive cloud storage. Five moves, no custom classifiers, no taxonomy project. Being able to say “this is Microsoft's own guidance for a company your size” ends that objection faster than any argument of your own. Microsoft Learn
Custom sensitive information types and custom trainable classifiers are almost always out of scope at 25–300 seats. Microsoft Support will not help you write regular expressions — their documentation says so. Custom classifiers are English-only and cannot be retrained; you delete and start over. A new sensitive information type does not retroactively light up existing content without a recrawl. Price custom classification as its own opt-in workstream, or refuse it.
| Include | Why |
|---|---|
| The person who asked for Copilot | Usually the owner. They funded this and they need to see it work first. |
| The heaviest existing AI user | Already using something on a personal account. Give them a sanctioned alternative and they become your loudest advocate; leave them out and they stay a shadow-AI problem. |
| Somebody from finance or HR | Works with the most sensitive content — the fastest way to find out whether labeling and DLP work in practice rather than in simulation. |
| The part-time IT person | They have to support this. They should not meet it for the first time when a user complains. |
| One skeptic | Deliberately. A pilot group of enthusiasts tells you nothing you can act on. |
Governance and adoption fail independently. A perfectly remediated tenant that nobody uses still loses the customer, and it will look like your fault because you were the one who was there. Price role-based enablement at $50–$100 per user Range — at 78 seats a natural second project of comparable size to the assessment. Then see the Copilot Adoption Audit for proving it worked.
The only tier that compounds, and the only one nobody has published a price for.
“$X per user per month, minimum $Y per month.” Per-tenant tooling minimums mean a 60-seat customer can cost the same to tool as a 100-seat one, so a pure per-user rate on a small tenant buys revenue at negative margin. This is the same structure your tool vendors use on you, and it is defensible when a customer asks why a 40-seat site costs nearly what a 70-seat one does.
Two independent derivations — a naive FTE scale-down and a vCISO advisory band — both land near $1,000 a month for a small tenant Model. Worth noting; not worth presenting as a benchmark. Nobody publishes a price for this, which means you set the reference rather than match one.
New sites, links shared to get work done, a project Team with the wrong default. Platform tooling can alert or auto-revert as often as every two hours. You report what drifted and what you reverted. That is the invoice.
In January 2026 Microsoft shipped a change (tracking ID CW1226324) that returned Copilot Chat summaries derived from Drafts and Sent Items, including content carrying confidentiality labels and covered by DLP policies configured to exclude it. Roughly four weeks; fix rollout began early February. Nobody — not Microsoft, not the customer — had independent visibility into whether the controls were working. The strongest argument you have.
The cyber renewal is annual. The carrier questionnaire is annual. The enterprise client's security review is annual. Co-term the reassessment to those dates and the fee has a justification that is not you.
The NHS was named as affected and explicitly stated patient information was not exposed. Do not let it compress in retelling into “Copilot leaked NHS patient data.” If you overstate it and someone looks it up, you lose the argument and your credibility on everything after it. It is an argument for a monitored, recurring service — not for a one-time cleanup.
| Metric | Source | Why it belongs in the report |
|---|---|---|
| Anonymous links, count over time | Governance platform, or SPO PowerShell | Trends down after remediation and creeps back up. The clearest proof drift is real. |
| External user access, count over time | Same | Guest sprawl is continuous and invisible without reporting |
| Shadow users — access via nested groups | Same | The finding customers find most surprising, every time |
| Organization-wide grants introduced this period | Same | Directly maps to Gate 1 |
| Leavers and stale guests removed | Entra access reviews | Gate 2. Cheap, visible, and the item a regulator would ask about |
| Label coverage on sites holding sensitive content | Purview | Progress on the work that is not a gate but does compound |
| DLP matches, and false positives reported by users | Purview | Report the false positives. It proves you are tuning rather than accumulating noise. |
| Secure Score delta | Microsoft 365 | Imperfect, but the customer's board understands a number that goes up |
| Copilot license utilization | Admin center | Ties governance to the spend it protects, and surfaces reclaimable seats |
If your report only ever says everything is fine, you are teaching the customer they do not need you. Report what changed, what you fixed, and what you decided not to fix and why. Three items of judgment beat forty green checkmarks.
The cyber insurance questionnaire is universal, annual, and already on their desk — use it. Where a customer genuinely wants a framework, use ISO/IEC 42001's shape: an AI system inventory, a risk register, named use-case owners, an incident protocol. Do not default to selling the certification; audit and implementation costs put it out of reach for most businesses this size, and offering the structure without the certificate is cheaper for them and more honest. Microsoft's own practice is a useful precedent: it re-attests its own containers on a six-monthly cycle.
Your first assessment has to cost near zero to deliver, because you are running it to win the work. A credible baseline is free.
| Tool | What it does in this engagement |
|---|---|
| ScubaGear (CISA) | Secure-configuration baseline for M365. HTML, JSON and CSV output that is close to client-presentable as-is. Start here. |
| Maester | Repeatable security-as-code tests. Turns a one-time assessment into something you re-run monthly — the mechanical basis of the recurring service. |
| Monkey365 | CIS and Entra misconfiguration review |
| Microsoft365DSC | Configuration baseline capture and drift detection |
| SharePoint Online PowerShell | Permission enumeration. On a Business Premium tenant with no SharePoint Advanced Management, this is your Gate 1 evidence. Raw output; you supply the report. |
| Microsoft 365 Lighthouse | The multi-tenant floor, free with CSP. Entra ID P1 is in Business Premium, so most customers qualify. |
These cover configuration baseline extremely well and permission exposure only adequately. Nothing free gives you a ranked, click-to-remediate view of who can reach what across the estate. You assemble that from PowerShell output and your own judgment — which is exactly the labor a platform is sold to remove.
Scripts win. The license cost of any platform exceeds the consultant hours it saves.
A platform wins — not because it finds more, but because it makes findings comparable across tenants and turns your report into a product rather than a document. That is also the point at which the recurring service becomes deliverable at a margin.
Match the pricing unit to the shape of your book, not to the feature list. If your customers average 60 seats, a per-tenant price beats a per-user price with a 100-seat floor every time. Published seat minimums across the category: Syskit and Rencore 100, Nudge Security a flat monthly fee, Orchestry Starter and ManageEngine none. Syskit Point bills a minimum of 100 users even on a 60-user tenant, on annual terms — at its governance tier roughly $300 a month of cost Range for one small customer before you have earned anything.
| Tool | Role in this motion | Multi-tenant | Pricing model | Realistic under 100 seats? |
|---|---|---|---|---|
| Free stack (ScubaGear, Maester, Monkey365, DSC, PowerShell) | Configuration baseline, drift, permission enumeration | Scripted | Free | Yes — and where nearly everyone should start |
| AvePoint Insights + Policies | Exposure discovery, bulk remediation, continuous drift enforcement. No Microsoft E-SKU dependency. | Yes (Elements, separately) | Per user; published list carries a 500-user minimum | Get a written quote at your seat count — section 10 |
| Syskit Point | Governance reporting and access review | Not marketed for MSP | Per user per year, published; 100-user billing minimum | Marginal — the minimum is the problem |
| ShareGate Protect | Governance risk assessment, tenant-wide visibility | Limited | Single per-user price, no minimums; partner pricing unpublished | Yes |
| Orchestry | Workspace lifecycle and provisioning governance | Yes | Flat per tenant, unlimited users at Starter | Yes — the pricing unit fits this market best |
| ManageEngine M365 Manager Plus | Reporting and auditing | Partial | Per tenant, banded | Yes — cheapest commercial reporting by a wide margin |
| CoreView | Multi-tenant governance and delegation | Yes | Unpublished; access reviews, SharePoint control, auditing and delegation are paid add-ons | No — enterprise-shaped |
| Varonis | Deep data security posture; publishes a free Copilot readiness assessment | No MSP console | Unpublished, enterprise | No — but the free assessment is a legitimate door-opener |
| Rencore | Governance console explicitly built for multi-tenant MSP delivery | Yes, explicitly | Unpublished; 100-user minimum | Get a quote |
| Nudge Security | SaaS and shadow AI discovery | Yes | Flat monthly | Yes at the low end |
| Compliance Scorecard | The GRC half — policy, attestation, AI governance module | MSP-native | Flat monthly, MSP-priced | Yes |
| CIPP | Multi-tenant delivery chassis | Yes | Low monthly, self-hosted or hosted | Yes — but it holds delegated admin into every tenant. Document that risk deliberately. |
AvePoint gets its own section for a technical reason: Insights does not inherit the base-SKU wall from section 5. On a Business Premium tenant that is not a feature advantage — it is an availability advantage, and it is the strongest reason in this market to look outside the Microsoft stack.
Website, price lists and marketplace listings use different names for the same product. Work from the right-hand column.
| Marketing name (website) | SKU name (price lists, docs, quotes) |
|---|---|
| Data & Security Insights | Insights for Microsoft 365 |
| Policy Enforcement & Drift Control | Policies for Microsoft 365 |
| Records & Information Lifecycle Management | AvePoint Opus (classification engine: Maestro) |
| Access & Power Platform Governance | AvePoint EnPower |
| Adoption & Usage Analytics | AvePoint tyGraph |
| License & Cost Management | AvePoint Cense |
| Data Owner Engagement | AvePoint MyHub |
| Agentic AI Governance | AgentPulse Command Center |
| MSP multi-tenant platform | AvePoint Elements |
Insights + Policies for a Copilot readiness engagement. Add MyHub when you want the customer's own site owners doing attestation rather than your engineer guessing. Everything else in the portfolio is a separate business case.
Policies needs Cense for its two license-reclamation rules · Policies needs Insights for Intelligent Remediation, the loop that makes either worth buying · Opus tiers stack: Analysis → Action → Archive.
| Stage | Product | The specific feature | What you actually get |
|---|---|---|---|
| Pre-sales — the door-opener | Insights (30-day trial) | Risk Assessment Report | An out-of-the-box, exportable PDF. AvePoint designs it explicitly as “a benchmark to track progress over time” — which is why the second run is your recurring hook, not just your first deliverable. |
| Pre-sales — the AI angle | AgentPulse | Automated agent discovery and inventory | “You have 41 agents nobody inventoried.” Only lands where Copilot is already on. |
| Discovery — permissions baseline | Insights | Risk Analysis → Workspaces Reports, then Detailed Records Reports | Workspace-level then item-level exposure. A full inventory, not a 28-day delta. |
| Discovery — “who can see this?” | Insights | Search Center — object-based or user-based search | “Show me everything this one user can reach.” The most demo-able screen in the platform. Run this one live. |
| Discovery — broad-access exposure | Insights | Exposure Report, configured in Risk Definition Administration | External sharing and broad access groups. You tune what counts as exposure — confirm where EEEU surfaces (10.5). |
| Discovery — hidden access paths | Insights | Shadow Users and Groups Access Report | Access granted through nested groups or direct grants the site owner cannot see. Consistently one of the most surprising findings for a customer. |
| Discovery — links | Insights | Shared Links report | Anonymous, company-wide and specific-people links, with full history rather than a 28-day window |
| Discovery — data quality | Opus | Discovery & Analysis as Power BI reports; File Share Discovery for on-premises | Redundant and obsolete data. Improves Copilot answer quality rather than security — sell on storage cost. |
| Findings readout | Insights | Risk Assessment Report + dashboard | The readout deck largely writes itself. Opus data exports to SharePoint for Power BI so you can brand it rather than screenshot a vendor UI. |
| Remediation — bulk | Insights | Risk Remediation, in-report bulk actions | Expire, remove or edit permissions for external users, shadow users and anonymous links. Expiry is what native tooling handles worst. |
| Remediation — the upsell bridge | Insights → Policies | Intelligent Remediation | Proposes the rule that would have prevented the finding. This is the moment the customer understands why one-time cleanup is not enough. |
| Remediation — owner-led | MyHub | Recertification and attestation, including OneDrive cleanup | Pushes the decision to the site owner. Substitutes for SAM site access reviews, which a Business Premium tenant cannot have. |
| Ongoing — drift | Policies | Violations Report; Remove Shadow Users, External Sharing Settings, Direct Sharing Prevention | Alert or auto-revert as often as every two hours. There is no Microsoft equivalent at any SKU. This is the mechanical basis of your recurring fee. |
| Ongoing — tenant hygiene | Policies | Ghost User Detection, Remove Inactive Guest Users | The two the customer notices immediately, and both map to Gate 2. |
| Copilot enablement — licensing | Cense | License allocation and budget reporting | “Which twelve people should get a Copilot license”, and who is burning pay-as-you-go AI credits. |
| Post-deployment — the QBR | Insights | Time-based dashboards for anonymous links, external user access and shadow users; risk score over time | Those three metrics are your quarterly scorecard. Lift them directly into the report in 8.3. |
| Post-deployment — agent sprawl | Insights | Agent Reports under Risk Analysis | High-risk, inactive or ownerless agents — a cheaper path to basic agent hygiene than buying AgentPulse. |
| Multi-tenant delivery | Elements | Permission Simulation; CIS Level 2 baselines; sensitivity label management | The portfolio layer. As of the June 2026 release it does not carry AI or Copilot governance — confirm the current roadmap (10.5). |
Insights consumes Microsoft's security, activity and compliance feeds rather than crawling content, so it runs on Business Premium unchanged. For the discovery half of Gate 1 it substitutes for SharePoint Advanced Management — with deeper history than SAM's 28-day sharing-activity window.
Policies adds continuous drift enforcement that Microsoft does not offer at any SKU. Together they cover the one genuine gap in the map at 4.3.
From AvePoint's own documentation: Content Sensitivity Label Enforcement, Site Sensitivity Label Enforcement, and Content Creation and Upload Restriction all require E5. Inactive Guest User Detection requires Entra ID P1 — which Business Premium includes, so that rule works.
All three E5 rules are label-enforcement rules. That is Microsoft's licensing wall, not a vendor gap; no platform in this category has routed around it. Scope label enforcement to Purview, and use Policies for the permission and drift work it does reach.
There is no AvePoint equivalent to Restricted Content Discovery. AvePoint's position is that you should fix the permission rather than hide the content from search — arguably the better engineering answer, and definitely the slower one. If you need interim containment while remediation runs, that is an enterprise-SKU conversation, or more practically at this size a reason to scope the pilot to remediated sites. See 5.3.
A genuine self-serve 30-day free trial, whose deliverable is the Risk Assessment Report — your assessment engine and your readout in one artifact. Pair it with free ScubaGear and Maester output for the configuration-baseline half Insights does not touch, and you have a complete first engagement at near-zero license cost.
AvePoint's published price list carries a 500-user minimum on nearly every SKU with a 12-month minimum term, and no US pricing is published for Insights, Policies or Elements. Distribution pricing sits behind partner authentication. Get a written quote at your actual seat count through TD SYNNEX before you design an offer around it.
Portfolio aggregation — committing 500+ seats across many small tenants rather than one. AvePoint's 2025 partner program explicitly rewards smaller but highly committed partners, and partner-generated revenue reached 58% of its recurring business in early 2026, so the conversation is a reasonable one to have. Put it to your rep and get the answer in writing.
AvePoint will be in the room at these workshops. These are scoping questions, in the order that changes your quote.
License reach — Insights works on Business Premium; SAM does not, and in this market that is decisive. History depth — continuous inventory versus a 28-day sharing-activity window. Continuous enforcement — alert-or-revert every two hours, with no Microsoft equivalent at any SKU. Archival granularity — site, document, list and library level. Breadth — backup, migration, records, licensing, analytics and agent governance from one vendor, across Google, Salesforce, AWS and Box as well as Microsoft.
Make the argument on license reach. It is true, it is verifiable, and it is sufficient on its own — you do not need a comparison table to win it, and a room that has read Microsoft's SharePoint Advanced Management documentation will hold you to the detail.
| Configuration | Works? | Notes |
|---|---|---|
| One generalist M365 admin | ✗ No | Will build a taxonomy nobody agreed to and discover the problem in week six. |
| One genuine senior who does both halves | Yes, with a ceiling | Works to about 75 seats. Needs someone who can chair a room of business owners and write a DLP rule. Does not scale past ~two concurrent engagements. |
| One senior plus one technician | ✓ Yes | This is the answer. It is also the shape that lets you charge properly for the senior's time instead of averaging it away. |
| Plus fractional adoption and communications | Yes | The only shape that survives a mandatory-labeling rollout. The comms person can be borrowed rather than hired. |
The junior may touch anything reversible. The senior signs anything that changes what a file is.
Senior: encryption on a label, the co-authoring switch, label order, and the move from DLP audit mode to enforcement. Junior: building labels to an agreed taxonomy, running simulations, triaging false positives, capturing evidence. It maps exactly to the irreversible decisions in 6.4, and it is defensible to a customer asking why two people are on the call.
The classification workshop gets run as a configuration session. The engineer asks which folders are sensitive, writes down the answers, and builds a taxonomy nobody in the business agreed to. Six weeks later Finance cannot email the auditor, nobody knows who decides, and the labels come off. The workshop is a facilitation job that ends in configuration, not a configuration job with people watching.
SC-400 retired on 30 May 2025 — the certification and its renewal assessment. The replacement is SC-401 Information Security Administrator, refreshed 28 July 2026, which now carries an explicit “Protect data used by AI services” objective covering exactly this work. Supporting: SC-200 for the shadow-AI discovery half, SC-300 for Gate 2 identity work, SC-100 as the closest thing to a vCISO credential. Applied Skills APL-5003 is a hands-on lab — cheaper and faster proof of capability than a certification, with a 72-hour cooldown between attempts. MS-102 retires 30 November 2026 and no longer earns Copilot specialization credit; do not start a junior on it.
The 50-seat row is published, hour-level, against a stated seat count. Everything else is extrapolated from it plus a practitioner convention of scoping governance reviews to 10–25 high-risk or inactive sites. Use it as a planning heuristic and replace it with your own delivery data after three engagements.
| Seats | Typical sites | Assessment hours | Remediation hours | Elapsed, total |
|---|---|---|---|---|
| 25–50 | 10–30 | 15–25 | 30–50 | 3–4 weeks |
| 50–100 | 25–60 | 20–35 | 40–70 | 4–6 weeks |
| 100–300 | 60–150 | 30–50 | 80–160 | 6–10 weeks |
Model — rows 1 and 3 are constructions from the sourced 50-seat figures.
The 200–400 hour figure circulating in the channel is explicitly framed around “permission inheritance across 200+ sites.” A 50-seat firm does not have 200 sites — a typical one has around 30, and well over half the content usually sits in one of them. At 50 seats this is 40 to 60 hours over 30 calendar days. A partner who scopes SMB work from enterprise literature prices themselves out of every deal they quote.
Quote from a site inventory, not from a headcount. And do not forget the waiting — the six to ten elapsed days in 6.2 are not the same as the hours above and do not overlap neatly. Put them in the plan as named calendar items; a customer who understands on day one why week three is quiet does not lose confidence in week three.
| Input | Figure | What it actually is |
|---|---|---|
| M365 consultant salary, 75th percentile | $130,000 /yr Range | Aggregated job-postings data. A salary, not a bill rate. |
| → base hourly | ~$65 /hr Model | Arithmetic |
| → fully loaded at 1.3–1.4× burden | ~$85–$91 /hr Model | Conventional burden multiplier |
| → recoverable cost at 65% utilization | ~$130–$140 /hr Model | The number that matters |
| Cost to rent a cybersecurity engineer | $130–$195 /hr Range | Staffing agency bill rate. A hard floor — you cannot bill less than you buy. |
A partner billing under roughly $150 an hour for senior Purview work is not making money on it. The channel band sits somewhere around $150–$275 Model, but no published source isolates this work — treat that as a bounded inference, not a benchmark. Do not quote a day rate; nothing credible is published, and everything shaped like one on the open web is a lead magnet.
Distributor-funded deployment offers price a baseline Purview stand-up — data lifecycle review, labeling policies, baseline classification, DLP aligned to Microsoft best practice — at around $3,000 Range. Sit with that number: the configuration layer of this work has a public price, and it is a few thousand dollars. If your quote is $30,000 you need a clear story about the other $27,000.
You can outsource the build and the tooling. You cannot outsource the taxonomy decision, the exception path, or the quarterly review — and those three are where the margin and the recurring revenue live.
| Tier | What it is | Price | Elapsed |
|---|---|---|---|
| 0 · Scan | Automated tenant scan, findings list, no judgment applied | $0 — give it away deliberately | 60–90 min |
| 1 · Light assessment | Scorecard, 3–5 stakeholder interviews, debrief, prioritized findings. No costed remediation plan. | $1,500–$3,000 Range | 1–2 weeks |
| 2 · Full assessment | Oversharing report, costed remediation plan, pilot design, draft policy, roadmap. The tier that converts. | $3,000–$15,000 Range · anchor $100/seat | 2–4 weeks |
| 3 · Remediation project | Break inheritance, replace grants, expire links, remove leavers, publish labels, DLP in audit mode | $6,000–$15,000 at 50 seats Model | 40–60 hrs / 30 days |
| 4 · Ongoing governance | Drift monitoring, reassessment, quarterly review, attestation reporting. The only tier that compounds. | Floor-priced — section 8 | Monthly + quarterly |
The scan is not defensible as a revenue line. Distribution packages funded readiness assessments on a per-tenant, per-month basis, and TD SYNNEX packages an AvePoint-powered readiness assessment as a partner-deliverable service with turnaround inside five weeks and a co-investment model that may be partly or fully funded depending on partner status. You will lose tier 0 on price every time. The judgment, the roadmap and the remediation are what is defensible.
| Stage | Price | Structure |
|---|---|---|
| Scan | $0 | 90 minutes. Produces the site count that scopes everything below. |
| Full assessment | $7,800 Model | Fixed fee at $100/seat. Credited in full against remediation if they proceed within 60 days. |
| Remediation | $14,000 Model | Fixed fee, scoped to a named list of sites. Roughly 2× the assessment — a ratio you can say in a room without a spreadsheet. |
| Ongoing governance | $1,400 /mo Model | Floor-priced, not pure per-user. |
| Year one | ~$30,600 Model | Assessment credited, so $14,000 project plus 12 months recurring |
| Recurring thereafter | $16,800 /yr Model | The number that matters |
Every figure there is a model, not a quote — composed from the sourced inputs above and shown so you can rebuild it against your own cost base rather than copy it. The evidence and its weaknesses are set out in section 18 of the full guide.
It qualifies the buyer — someone who will not pay for an assessment will not pay for remediation; charging filters, and the credit removes the reason to object. It stops the report walking — a free report goes to a cheaper remediator; a credited report is money already committed to you. It keeps the scopes separate — review billed separately from remediation, with the customer's decisions documented before any cleanup begins. That boundary is what stops an assessment quietly becoming an unpaid Purview deployment.
“You are on Business Premium, and that was the right call — it is a genuinely good security stack and it did the job you bought it for. Copilot adds one requirement nobody was scoping for when you bought it, which is knowing who can see what across your SharePoint.
The good news is that the data protection side is a ten-dollar add-on, and Microsoft is running it at half price alongside Copilot until the end of the year. Nobody is asking you to move to E5.
The permissions side needs one extra piece, and there are three ways to get it — one of which costs about as much as three licenses. Let me find out which one applies to you before either of us assumes it is expensive.”
“I am not going to tell you Copilot is dangerous, because mostly it isn't. What I will tell you is that when Forrester looked at the companies who got the returns Microsoft advertises, seven in ten had done a data security project first. That is the difference between the deployments that worked and the ones that quietly stalled. I would rather put you in the first group, and it is cheaper to do that now than to unpick it later.”
That reframing converts governance from a tax into a success factor, and it survives being checked. The source is Forrester's commissioned Total Economic Impact study — sixteen decision-makers across twelve organizations plus 367 surveyed users. Use the 70% finding; do not use the headline ROI figures, which are an enterprise composite.
| Objection | The answer |
|---|---|
| “Our last MSP reviewed us and said we were fine.” | Attack the date, never the predecessor. Permissions drift, and the AI control plane did not exist when that review was written. |
| “Why am I paying monthly for a one-time cleanup?” | Drift, and the control plane changing underneath them. The three answers in 8.2, in that order. |
| “Microsoft says Copilot respects permissions, so we're covered.” | The statement is accurate and it is about access control — whether a user is permitted to open a file. It says nothing about exposure — whether they will ever find it. Nobody browses to /Company/Shared/Old HR/2019; natural language search removed that friction entirely. The proof the distinction is real: Restricted Content Discovery exists. Microsoft built a feature whose entire purpose is to stop Copilot surfacing content users are already permitted to open. |
| “You are just selling us more stuff.” | “Fair. Assessments at your size routinely find 10 to 30% of license spend Range going to the wrong place — wrong SKUs, seats assigned to leavers, duplicated add-ons. I would rather find that first and put it against the cost of this work than ask you to fund it out of fear of something that might not happen.” Checkable, and it reframes you as reducing their spend. |
| Trigger | Who it covers | Why it forces the conversation |
|---|---|---|
| Cyber insurance renewal | Everyone | Annual, sector-agnostic, headcount-agnostic, hard date, named signer. Nothing else has all five. Generative-AI exclusion endorsements took effect 1 January 2026 and carriers are adding AI sublimits. Limit: there is no published, adjudicated claim denial attributable to AI use — argue the underwriting shift, not a denial. |
| An enterprise client's security questionnaire | Anyone with an enterprise customer | Arrives without warning, blocks a contract renewal, and needs answering this week. Highest urgency and margin available. Build the response artifact once. |
| FTC Safeguards Rule | Accountants, tax preparers, auto dealers arranging finance, mortgage and insurance brokers under GLBA | Written risk assessment and a designated qualified individual. Trap: the fewer-than-5,000-consumers exemption removes exactly the assessment you were planning to sell. Check the count first. |
| CMMC Phase 1 | Defense contractors and subcontractors | In force since 10 November 2025; self-assessment gates contract award. Sharpest deadline available, narrow slice of the channel. |
| ABA Formal Opinion 512 and 35+ state bars | Law firms of any size | Issued 29 July 2024. For a small firm this is the partner's license, which concentrates attention. |
| Illinois HB 3773 | Any employer with Illinois staff | Effective 1 January 2026. Reaches employers who have never thought of themselves as regulated. |
| HIPAA's existing risk-analysis duty | Covered entities and business associates | Already in force. Benefits administration drags ordinary companies into business-associate status more often than they realize. |
Most partner marketing overstates regulatory applicability to small business, and sophisticated buyers know it. EU AI Act: enforcement provisions apply from 2 August 2026, but high-risk obligations moved to December 2027 and August 2028, and an SMB using Copilot is a deployer, not a provider. Colorado: SB 24-205 was repealed and replaced; the replacement takes effect 1 January 2027. California ADMT: 1 January 2027, gated behind CCPA thresholds most sub-100-seat businesses do not meet. When a customer says “I read the EU AI Act is going to hit us,” the winning answer is “probably not, and here is why.”
| Claim in circulation | The problem |
|---|---|
| “802,000 at-risk files per organization” | Presented as current; traces to a 2022 report. Date it or drop it. |
| “150–300 overshared SharePoint sites per tenant” | No published methodology, and it describes enterprise tenants. Actively misleading in an SMB room. |
| “99% of organizations have sensitive data exposed to AI” | Real vendor research, but too high to be believed. Use the 1-in-10-had-any-labeled-files figure instead — modest, checkable, and the customer recognizes it as true about themselves before you finish the sentence. |
| The Gartner pilot-progression percentage | Two sample sizes and two percentages circulate for one finding, and a competing survey reports the opposite. Cite the governance-delay pairing — roughly two-thirds of IT leaders reported governance and security consumed significant time — not the decimal. |
| “Get your team SC-400” | Retired 30 May 2025. The replacement is SC-401. |
| “Enable Restricted SharePoint Search while we review permissions” | New enablement was blocked on 31 July 2026. Microsoft directs you to Restricted Content Discovery. Any playbook opening with this step is unexecutable. |
| “SAM is included with Copilot, so the E5 objection is dead” | True only on an E-SKU base. This over-correction is now as common as the error it replaced. Section 5.1. |
| “The EU AI Act will hit your business next year” | High-risk obligations moved to 2027–2028, and an SMB using Copilot is a deployer, not a provider. |
| “Colorado's AI Act takes effect in February 2026” | Repealed and replaced. The replacement takes effect 1 January 2027. |
| Any FY27 Microsoft incentive rate | All sit behind partner sign-in. Name mechanisms; get rates from Partner Center yourself. |
| “MaestroBridge” as an AvePoint product | No such product exists. Maestro is the classification engine inside Opus. |
| A published SANS AI acceptable use policy template | Could not be found. Do not cite one. |
| Any claim that a company was fined or sanctioned for AI oversharing | There is no enforcement action anywhere — no GDPR fine, no FTC action, no ICO reprimand. Inventing regulatory risk is how you lose a customer's lawyer. There is also no published, named-company case study of Copilot surfacing HR or salary data to the wrong employee. Argue from mechanism. |
Three claims this guide deliberately does not make, because no primary source settles them. Each is a question for a licensing desk or a distributor — get the answer in writing and it stops being a risk. Do not settle them by buying a seat and watching the portal: portal behavior is not an entitlement, it changes without notice, and an audited customer is measured against licensing terms rather than against what worked in your tenant last quarter.
Microsoft states it at organization level and publishes no guidance for tenants holding a mix. Ask: Microsoft licensing desk or TD SYNNEX · affects route 3 in 5.2.
Microsoft's page says “policy-based controls for AI experiences” and never uses the term DSPM; the Purview service description has no DSPM section. Highest risk of a confident wrong claim in the whole motion — describe the capability, confirm the product surface in configuration. Ask: Microsoft licensing desk.
Corroborated by community and reseller sources, not by a Microsoft page. If it does, $15 per user per month is the price of shadow AI discovery for an SMB. Ask: Microsoft licensing desk or TD SYNNEX.
Its risk prioritization draws on Microsoft sensitive information types and the activity feed. Ask: AvePoint · question 3 in 10.5.
Most deployments proceed without an incident. If Copilot were routinely producing HR disasters across tens of thousands of tenants, some would have surfaced through employment tribunals or trade press. The dominant observed customer-side outcome is delay and friction, not breach.
Vendor-side product failures like CW1226324, and security research disclosed and patched before exploitation. EchoLeak (CVE-2025-32711) and CoSnitch (CVE-2026-24301) belong in a technical conversation and nowhere near a business owner. Cite them for mechanism; never imply harm occurred.
The index remembers what you revoked. Lasso Security found 20,580 repositories across 16,290 organizations still reachable through Copilot after being made private, because a search cache retained them. The principle transfers directly to Microsoft 365 — and it is precisely why Restricted Content Discovery requires a reindex rather than taking effect instantly.
Before you quote this work, complete it in your own tenant. Publish four labels. Watch the 24-hour propagation actually take 24 hours. Run an auto-labeling simulation and discover it fired 300 activity alerts because you did not scope the alert policy first. Break something with an encrypting label and find out what it costs to unbreak.
Every hour of that is an hour you will not lose in front of a customer, and it converts the numbers in section 11 from something you read into something you know. Beyond that the floor is low: one person holding SC-401, one person who can chair a room of business owners, and a written decision about who signs the irreversible changes in 6.4.
The customer does not need to be frightened into this. Seven in ten of the organizations that got the returns Microsoft advertises did the data security work first.