Copilot Playbook
Shadow AI Assessment
Updated August 26, 2026
Assessment Guide · Governance

The Shadow AI Assessment Guide

Discovering, governing, and monetizing AI use in Microsoft SMB tenants.

Prepared by Ken Lince — Sr. Director, Cloud Engineering, TD SYNNEX

The question isn’t whether your customer’s employees are using AI. It’s whether you’re the one who found out first.

A structured Shadow AI assessment is the single best first conversation a Microsoft partner can have with an SMB in 2026 — it opens with the customer’s own problem, not your product, and it compounds into a durable governance practice.

1. Why Shadow AI Is the First Conversation

By the time a partner sits down to talk about a Copilot license, the AI conversation has usually already started — just not with IT in the room. Employees are pasting client emails into free ChatGPT accounts, dropping proprietary code into personal Cursor or Claude sessions, and running meeting recordings through consumer transcription apps. None of it shows up in a firewall log, because every one of those tools is a trusted TLS endpoint that every URL filter waves through as "productivity."

The pitch that stalls

Lead with the plumbing. Permissions, Conditional Access, MFA. Technically correct, and it asks a prospect to get excited about your compliance checklist before they've agreed there's a problem worth solving.

The pitch that opens doors

Lead with Shadow AI discovery. It starts from something the prospect already privately suspects is true about their own business, and offers to make it visible — on their terms, before someone else finds it for them.

The reframe to walk in with

Governance and consumption are the same problem, not two separate ones. Whatever AI surface a customer eventually turns on — Copilot, a sanctioned ChatGPT Enterprise seat, an internal agent — inherits whatever permissions and data hygiene already exist in the tenant. An assessment that surfaces unsanctioned AI use is also the exact prerequisite work for making any AI purchase pay off. Governance readiness is consumption readiness.

↑ Back to Table of Contents

2. The Shadow AI Reality — What SMBs Actually Have Running

2.1 · The pattern you will find on nearly every engagement

62%
of AI-using employees use chatbots or virtual assistants as their primary AI tool; writing/editing tools rank second
Gallup, 2025 workplace AI research
91%
of employees report their organization uses at least one AI tool today
McKinsey, State of AI, 2025
~20%
of data breaches now involve Shadow AI as a contributing factor, per industry breach research
Verizon DBIR, most recent edition
66%
of AI-using workers admit they used AI despite believing it violated company policy
PagerDuty, 2026 workplace survey
~75%
of workers use AI at work, and most of that use is unauthorized — a consolidation of several analyst studies
Community synthesis of Gartner, Microsoft, IBM, Cyberhaven, Netskope research
$400K
estimated annual cost per company in security and compliance exposure from unmanaged AI use — a community benchmark, not a survey figure
Industry benchmark estimate; treat as directional
Read the numbers as a range, not a receipt

The figures above come from a mix of primary research (Gallup, McKinsey, PagerDuty) and secondary community synthesis. Use the primary-sourced ones with confidence in an executive conversation; treat the synthesized and benchmark figures as directional, and always re-check the current edition of any cited report before quoting an exact number to a customer.

2.2 · The categories you'll actually find

The following categories show up on nearly every SMB discovery scan, well before any purpose-built discovery tool is even switched on. Treat this as the starter checklist for the conversation, not an exhaustive taxonomy.

CategoryCommon toolsTypical exposure
General LLM assistantsChatGPT, Claude, Gemini, Copilot Chat (personal), Perplexity, Meta AIClient emails, contracts, HR data pasted into personal accounts
AI coding assistantsGitHub Copilot (personal), Cursor, Windsurf, Codeium, Claude CodeProprietary source code, secrets, connection strings
Meeting notes / recordingOtter.ai, Fireflies.ai, Fathom, Read.ai, Zoom AI CompanionConfidential meeting content, financials, personnel decisions
Writing / editingGrammarly (personal), Wordtune, QuillBotLegal, HR, client-facing content routed through personal accounts
Productivity / knowledgeNotion AI, ClickUp AI, Coda AI, MemCompany docs, project plans, roadmaps
Design / marketingCanva AI, Adobe Firefly, Midjourney, IdeogramBrand assets, client campaigns, PII embedded in image inputs
Sales / RevOps AIGong, Apollo.io AI, Clay, LavenderFull CRM records synced to an unmanaged AI vendor
Enterprise search / RAGGlean, Guru, You.com Enterprise, DustBroad SharePoint/Drive access under a personal or loosely-scoped grant
Web-scraping AIDiffbot, Browse.ai, Bardeen, PhantomBusterUndocumented data-extraction pipelines with no security review
Voice / avatar AIElevenLabs, HeyGen, Synthesia, DescriptExecutive voice cloning, deepfake and impersonation risk
↑ Back to Table of Contents

3. Microsoft's Four-Step Model — Discover, Block, Protect, Govern

Microsoft publishes a formal deployment model in Microsoft Purview called Prevent data leak to shadow AI. It's worth anchoring to because it's the reference architecture a customer's auditors, cyber insurer, and Microsoft account team already expect to see reflected in a serious engagement.

01
Discover
Unknown AI use is surfaced
Defender for Cloud Apps
Entra Internet Access
Purview DSPM for AI
02
Block
Unsanctioned apps blocked, deliberately
Conditional Access
Session policies
Intune / Defender for Endpoint
03
Protect
Sensitive data can't leave
Purview DLP (AI category)
Sensitivity labels
Purview browser extension
04
Govern
Prompts retained and auditable
Purview Audit (Premium)
Communication Compliance
eDiscovery

3.1 · What each step actually means for a partner

1
Discover

Defender for Cloud Apps has had Cloud Discovery for years; the AI-specific category plus the Entra Internet Access network-layer signal together approximate visibility partners historically had to buy from a dedicated CASB vendor.

2
Block

Two enforcement paths: Conditional Access plus a Defender for Cloud Apps session policy for browser sessions, or Intune / managed-browser enforcement at the device level. Community best practice: don't block everything on day one — close the highest-risk consumer apps first and monitor the rest while the sanctioning conversation happens.

3
Protect

Purview DLP now has an AI-app category as a first-class condition. A reasonable starter rule: location = devices onboarded to Defender for Endpoint; condition = a Confidential label or a sensitive info type; action = block upload to the AI-app category; mode = audit first for two weeks, then enforce.

4
Govern

Configure Audit (Premium) retention — a full year, not the 180-day default — before an incident, not after. Communication Compliance can capture AI interaction logs where the tool integrates with Microsoft's information-protection stack; for third-party tools, coverage depends entirely on the vendor.

3.2 · The two-layer simplification worth teaching every customer

Microsoft MVP Nikki Chapple frames the same architecture as two decisions, and it's the cleanest version of this story for an executive conversation:

Control the apps

Decide where data is allowed to go. This is Defender for Cloud Apps, Entra, and Intune working together to build the sanctioned/monitored/blocked list.

Control the data

Decide what data is allowed to leave, regardless of destination. This is Purview DLP, sensitivity labels, and DSPM for AI.

The line to borrow for the executive room

Microsoft provides the control plane. The customer's organization defines the control model. Your job as the partner is to help them write that model down — nobody else in the room is going to.

↑ Back to Table of Contents

4. The Assessment Delivery Model

4.1 · The five-capability self-audit — can you deliver this today?

Before quoting a Shadow AI assessment, run the same five-capability audit on your own tenant first. Selling discovery you haven't personally survived is the fastest way to under-scope a SOW — dual-track it: run the snapshot on yourself, then sell it to customers.

#CapabilityWhy the assessment needs itTypical SMB-partner starting point
1Identity and access visibilityWho is using what, under which accountUsually already have it — Entra ID P1 ships in Business Premium
2Application discoveryThe engine that finds unsanctioned AI toolsConfirm — needs Defender for Cloud Apps
3Data classification and DLPTo say what data went where — this is what sells the remediationPartial — sensitivity labels ship in Business Premium; deeper DLP needs the Purview add-on
4Policy authoringWrite the AI Acceptable Use Policy and the DLP rulesHave the skill — the AUP itself is almost always missing
5Ongoing monitoringThe step that converts a one-time report into recurring revenueConfirm — needs the licensing in place at the customer or partner-tenant level

4.2 · The engagement flow — from first meeting to managed governance

Week 0

Executive AI conversation · 30 min

Frame Shadow AI as an ongoing exposure, not a one-time compliance exercise. Get a named executive sponsor and confirm scope, seat count, and data sensitivity.

Week 1

Discovery configuration · 4–8 hrs

Enable Cloud Discovery, Entra Internet Access, and DSPM for AI. Deploy the Purview browser extension to a pilot device group. Onboard endpoints to Defender for Endpoint if not already done.

Weeks 2–3

Telemetry collection · 10–21 days

Passive collection, no user disruption. A 14-day minimum is the community standard; extend to 21 days if usage is unusually cyclical (month-end close, seasonal work).

Week 4

Analysis and report drafting · 8–16 hrs

Categorize discovered apps, attribute usage by user and department, quantify sensitive-data exposure, map to risk ratings, and prioritize remediation.

Week 5

Executive readout · 60–90 min

A focused deck: exposure heatmap, top apps, top exposed users, business impact, remediation roadmap, licensing gaps, and the next-step SOW menu.

Week 6+

Remediation SOWs and managed-governance kickoff

Fixed-fee AUP, oversharing remediation, sanctioned-app onboarding, and the Managed AI Governance retainer.

4.3 · Realistic timing and staffing for a 25–300 seat customer

PhaseElapsed timePartner effortSkills required
Executive intake1–2 days~2 hrsAI-fluent seller / vCIO
Discovery tool configuration2–5 days4–8 hrsM365 admin comfortable in Defender + Purview
Telemetry collection14–21 daysPassive
Analysis + report3–5 days8–16 hrsSecurity analyst / consultant
Executive readout1 day2 hrs + prepvCIO / AI practice lead
Total4–6 weeks16–28 hrs1 practice lead + 1 M365 admin
What that envelope implies for pricing

Community-reported SMB assessment pricing clusters around $1,500–$7,500 fixed fee for a 20–200 seat customer, climbing past $15K for regulated or mid-market accounts. Independent MSP benchmarking (Cynomi) puts the share of assessment clients who convert to a follow-on retainer at 50%+ — and that conversion rate rises further when the assessment surfaces a specific, named risk rather than a generic score. Treat both figures as planning inputs, not guarantees, and validate against your own delivery cost.

4.4 · What the finished engagement produces

01

Exposure heatmap

Departments crossed with the sensitivity of the data leaving them.

02

Ranked AI app inventory

Top apps by user count, top apps by risk.

03

Ranked exposure list

Highest-risk individuals, with a separate executive-only version.

04

SharePoint oversharing summary

What any future AI product would be able to see on day one.

05

Licensing gap analysis

Current state versus recommended state, mapped to the Suite add-ons in Section 6.

06

Three-tier remediation roadmap

Quick wins (0–30 days), foundational (30–90 days), strategic (90+ days).

07

Draft AI Acceptable Use Policy

Customized to the sanctioned tools and the customer's vertical, not boilerplate.

08

Follow-on SOW menu

Priced by service line — see Section 10.

↑ Back to Table of Contents

5. A Sample Engagement — 120 Users, 50 Copilot Seats

This is a composite, representative walkthrough built to teach the pattern of a common SMB deal — the numbers are illustrative of what a real 14-day scan at this seat count typically turns up, not a specific named customer's data.

5.1 · The profile

5.2 · Handling "we don't own Purview or Defender for Cloud Apps"

This is the objection that stalls the deal if it's handled as a forklift upgrade to E5. It isn't one. Microsoft sells a Defender Suite and a Purview Suite specifically scoped to Business Premium, and the two can be bundled at a meaningful discount when purchased alongside Copilot. The pitch is not "buy more Microsoft" — it's "the tool that powers this assessment is the same tool that governs Copilot after it's turned on."

A version of the talk track

You're about to spend real money on 50 Copilot seats. Before you turn it on, we need to know two things: what your team is already pasting into ChatGPT and Claude today, and whether Copilot's own grounding is going to surface data your labels weren't ready for. We do that with a four-week Shadow AI and Copilot Readiness Assessment. The Purview Suite add-on we'll turn on for those 50 seats does triple duty — it powers this assessment now, it governs Copilot once it's live, and it gives you your first documented AI compliance evidence ahead of your next cyber-insurance renewal.

5.3 · Representative findings, at this seat count

58of 120 users touched an unsanctioned AI tool
/
120total headcount
=
~48%of the whole company, in 14 days
The gate

The customer doesn't get to flip on Copilot until the oversharing findings are remediated — not because the partner is being obstructive, but because AI output layered on top of ungoverned data will erode the customer's confidence in the product itself before it ever has a chance to prove its value. Show the value of getting this right first; then sell the protection that keeps it right.

↑ Back to Table of Contents

6. The Licensing Motion — Positioning the Suites

6.1 · What changed for SMB licensing

6.2 · The upsell logic worth teaching

The pitch that stalls

"You need to upgrade to E5." A Business Premium customer hears this as "double my Microsoft bill," and the deal stalls right there.

The pitch that lands

Same Copilot engine, right governance stack. The Copilot AI experience is the same on Business Premium and E5 — the difference is the governance tooling in the base SKU, not the AI feature set. Business Premium + Copilot + the Suite add-ons gets there without the forklift.

Verify before quoting

Exact feature coverage between the Business Premium Suite add-ons and full E5 Compliance shifts as Microsoft updates its licensing tables. Confirm the specific capability — especially anything DSPM- or Copilot-assessment-related — against the current Microsoft licensing comparison before a proposal goes out.

↑ Back to Table of Contents

7. Sanction, Don't Just Block

The instinct after a discovery scan is to block everything unsanctioned. Resist it. Blocking without sanctioning drives usage further underground — onto personal devices and personal networks the partner has zero visibility into — and it burns the goodwill that made the customer receptive to the conversation in the first place. The credible position is narrower and more durable: bring the tools people already trust under management, rather than take them away.

The reframe for a Claude- or ChatGPT-attached team

If your team relies on Claude or ChatGPT, we're not taking it away. We're bringing it inside the fence — enterprise SSO, SCIM provisioning, an admin console, a signed data processing agreement, and audit logging. Once that's in place, the tool your team already trusts is no longer a liability on your books; it's an asset with a paper trail.

The plan for a customer who won't adopt Microsoft's own AI stack

Step 1

Sanction their preferred tool

Move them to an enterprise tier — Claude Enterprise, ChatGPT Enterprise, or another vendor's enterprise plan, matched to their preference.

Step 2

Wire it to Entra

SSO via SAML, SCIM for lifecycle management, and an admin console configured for data retention, model access, and audit export.

Step 3

Layer Purview around it

The browser extension, DLP AI-category policies, and Defender for Cloud Apps monitoring — the same tools, pointed at a different sanctioned destination.

Step 4

Keep it recurring

Monthly reporting on usage, cost, and DLP incidents under the same Managed AI Governance retainer described in Section 10.

↑ Back to Table of Contents

8. The Top AI Apps — Enterprise Onboarding Matrix

Keep this as a living document — expand it quarterly. Pricing and SSO/SCIM support change often enough that this table intentionally omits dollar figures; confirm current terms directly with each vendor before quoting a sanctioned-app onboarding SOW.

#AppCategoryEntra SSOSCIMAdmin consoleNotable data-boundary / governance
1OpenAI ChatGPT EnterpriseLLM assistant✅ SAMLGlobal Admin consoleData excluded from training by default; SOC 2
2OpenAI ChatGPT BusinessLLM assistant✅ SAML (Business tier)Workspace adminData-exclusion by default
3Anthropic Claude EnterpriseLLM assistant✅ SAML✅ (JIT/SCIM)Console organizationsAudit logs, custom retention, RBAC
4Anthropic Claude TeamLLM assistant✅ SAMLPartialTeam adminSmaller-org tier
5Google Gemini EnterpriseLLM assistant + agents✅ via IdP configGoogle Cloud consoleSeparate token/compute billing
6Gemini in Google WorkspaceAssistant✅ (Workspace SSO)Workspace adminBundled in Business Standard/Plus/Enterprise plans
7Perplexity Enterprise ProResearch / search✅ SAMLEnterprise adminSOC 2
8GitHub Copilot Business / EnterpriseAI coding✅ SAML via GitHub Enterprise CloudGitHub org / enterprise settingsIP indemnification (Business+); public-code filter
9Cursor Teams / EnterpriseAI coding✅ SAML 2.0PartialCursor orgPrivacy Mode retention controls
10Codeium / WindsurfAI coding✅ SAML (Teams/Enterprise)Windsurf adminCodebase-indexing scope configurable per repo
11GleanEnterprise search + assistant✅ SAML/OIDCGlean workspace adminPermissions-aware connectors; tenant data boundary maintained
12Notion AIProductivity✅ SAMLNotion workspace adminDPA available; enterprise data segregation
13Grammarly Business / EnterpriseWriting✅ SAMLGrammarly admin consoleEnterprise data doesn't train models
14Otter.ai EnterpriseMeeting AI✅ SAMLOtter adminMeeting retention and sharing controls
15Fireflies.ai BusinessMeeting AI✅ SAMLPartialFireflies adminStorage-region controls
16Zoom AI CompanionMeeting AI✅ Zoom SSO / EntraZoom adminOff by default; no third-party training on customer data
17Read.ai / Fathom BusinessMeeting AIVaries; some SAMLPartialVendor adminConsent / recording notifications
18Copilot Studio / custom agentsAgent platform✅ via Microsoft 365 identityN/APower Platform admin centerFull Purview + Entra governance, natively
19Microsoft Copilot Chat (free)LLM assistant✅ EntraN/AM365 admin centerEnterprise Data Protection at the commercial data boundary
20Canva Enterprise (Magic AI)Design✅ SAMLCanva adminEnterprise-wide brand kit + admin controls
21Adobe Firefly for EnterpriseDesign✅ SAMLAdobe Admin ConsoleCommercial-safe training-data statement
22MidjourneyDesign⚠️ Discord-based, limited SSO⚠️Server-level moderationRecommend blocking for regulated data
23HeyGen / Synthesia EnterpriseVideo / avatar✅ SAMLPartialVendor adminVoice-cloning consent + retention controls
24ElevenLabs EnterpriseVoice AI✅ SAMLPartialVendor adminVoice-clone authorization controls
25Gong / Clari CopilotSales AI✅ SAMLGong / Clari adminCRM data-boundary controls
26Apollo.io AISales AI✅ Growth/EnterprisePartialApollo adminCRM sync scope controls
27ClayData enrichment AI✅ SAML (Enterprise)PartialClay workspaceMulti-source enrichment audit trail
28Jasper EnterpriseMarketing AI✅ SAMLPartialJasper adminBrand voice + guardrails
29Writer EnterpriseEnterprise gen-AI✅ SAMLWriter adminCustom private models; data isolation
30Mistral Le Chat EnterpriseLLM assistant✅ SAMLPartialMistral adminEU-data-residency option

For each partner-sanctioned app, the onboarding pattern is the same six steps:

  1. Add the app via the Entra ID enterprise app gallery, or configure a custom SAML app.
  2. Configure single sign-on with the vendor's SP metadata.
  3. Configure SCIM for lifecycle management — this is what makes the AI account disappear the day the employee does.
  4. Configure the vendor's admin console: data retention, model access, audit export.
  5. Get the data processing agreement signed and complete a privacy review.
  6. Mark the vendor's domain Sanctioned in Defender for Cloud Apps, and add it as a monitored destination in Purview DLP.
↑ Back to Table of Contents

9. Finding the Conversation — Reading Partner Signal Data

Microsoft's partner-facing propensity tooling in Partner Center — surfaced through the AI Business Solutions & Security Partner Experience (ASPX) — exposes weekly-refreshed, per-tenant signals that map directly onto a Shadow AI conversation. If your organization has Partner Center access, these are worth building into a weekly call-list routine rather than treating as background reporting.

SignalWhat it tells the partnerThe Shadow AI conversation move
Free Copilot Chat MAU (unlicensed)Users on free Copilot Chat this monthThese users are proving demand — and are very likely also using ChatGPT/Claude under personal accounts. Sell the assessment.
Free-to-paid whitespace %Ratio of free monthly active users to paidA high ratio signals both Copilot license upsell potential and Shadow AI exposure
Copilot-eligible seatsThe Copilot-eligible base at the tenantTotal addressable seats for both the license conversation and the governance retainer
Users hitting free-tier usage limitsFree-tier users being throttledThe strongest demand signal available — "your own users hitting a wall" is the opener
Adoption statusAn estimate of the tenant's Copilot healthA "failure to adopt" flag is usually a governance problem, not a licensing one — an assessment opportunity
Data security maturityA tiered estimate from Minimal to Advanced-HealthyThe sharpest single opener — Minimal and Limited-Unhealthy tenants are the top of the weekly call list
The pattern worth running weekly

Rank tenants by a blend of (a) users hitting free-tier usage limits, (b) unlicensed Copilot Chat activity, and (c) a weak data-security maturity signal. Take the top 15–20 for the week's call list. The customer's own numbers make the strongest possible opener: "You have people already hitting a usage ceiling on the free tier. They're trying to do AI work today — the only question is whether it's happening inside your tenant or inside their personal accounts."

↑ Back to Table of Contents

10. The Revenue Ladder — Six Service Lines

The assessment is the land. What makes the practice durable is that every rung above it has a natural trigger from the one below — nothing has to be sold cold. Pricing ranges below are editorial estimates meant as a starting point; test them against your own cost model before quoting.

1
Shadow AI Assessment
One-time, fixed fee

The land. A discovery-led engagement that converts into a specific finding ("here are the 14 AI tools your staff used last month, and here is the client data that left your environment") rather than a generic audit pitch.

Price: $1,500–$7,500 SMB; $15K+ regulatedBuyer: Owner/GM, 20–200 seats
2
AI Acceptable Use Policy authoring
One-time deliverable

Sold immediately after the assessment. A customized policy referencing the sanctioned tools, prohibited data classes, and — critically — an enforcement design. Never sell a policy without a control attached to it.

Price: $1,000–$5,000Motion: "You have a policy for passwords. You have none for the fastest-spreading tool in your business."
3
Managed AI Governance
Recurring MRR

The recurring engine: ongoing enforcement, policy cascade, blocking of unsanctioned tools, identity-gated access, and a monthly usage/risk report the customer can hand to an auditor or insurer. Best packaged as a tier on an existing MSP contract rather than a standalone SKU.

Price: ~$2–$8/seat/monthMotion: "Your AUP is only a document until something enforces it."
4
Insurance / compliance readiness
Sprint + recurring

Triggered by a cyber-renewal date or an enterprise customer's security questionnaire. "If your application asks whether employees share data with AI systems, right now the honest answer is 'we don't know' — here's how we get you an answer you can support."

Price: $2,500–$10,000 sprint; ISO 42001 $15K–$50K+
5
vCISO / compliance advisory retainer
Recurring retainer

For firms that need security leadership but can't justify a full-time hire. The MSP market's own data backs the trend: Cynomi's 2025 benchmark found the share of MSPs and MSSPs offering vCISO services rose from 21% to 67% year over year.

Price: $2,600–$15,000/monthBuyer: 50–1,000 employee firms
6
Client training / enablement
Runs alongside every rung

Short, role-based modules on what not to paste into public AI tools, with completion tracking. "Training completion records are exactly what your insurer and your auditor ask for."

Price: $2–$5/user/month
↑ Back to Table of Contents

11. Objection Handling

ObjectionThe reframe
"Our staff isn't using AI."The bet is on naming exactly how many are, before an audit — or a breach — does it for you. A large share of AI-using employees are on personal accounts, not sanctioned ones.
"We already have DLP."Traditional DLP watches for structured data — credit card numbers moving to a file-sharing site. It does not watch for a paragraph of client content pasted into a browser tab. That's exactly the gap the Purview browser extension exists to close.
"Our firewall blocks the risky stuff."ChatGPT, Claude, Gemini, and Perplexity are all trusted TLS endpoints categorized as productivity tools by every standard URL filter. A firewall has no reason to block any of them.
"Our team is small — it's fine."A 40-seat firm shows roughly the same statistical distribution of AI use as a 400-seat firm — it just has less resilience per incident when something goes wrong.
"We'll deal with it after we turn on Copilot."Then Copilot inherits every oversharing permission that already exists, and the customer's first real AI experience is AI surfacing content they didn't know was exposed. Show the value first — but gate it behind the governance work.
"We'll just block everything."Blocking without sanctioning pushes usage further underground, onto personal devices you can't see at all. Sanction one or two tools, monitor the rest, block only the highest-risk consumer apps.
"An AUP is enough."A policy with no enforcement behind it is a wall with no gate. Sell the policy with the control attached, every time.
"We don't own Purview or Defender for Cloud Apps."The Business Premium Purview Suite add-on is a fraction of the Copilot spend, and often discounted further when bundled with it. It powers the assessment today and governs Copilot tomorrow. See Section 6.
↑ Back to Table of Contents

12. Companion Assets Worth Building

Ten asset concepts worth productizing on top of this guide — each one shortens the sales cycle for a rung on the ladder in Section 10.

01

Shadow AI Assessment Playbook

A full week-by-week delivery method mapped to Microsoft's four-step model, with tool-configuration walkthroughs, a report template, and an executive-readout skeleton.

Enables rung 1
02

AI App Enterprise Onboarding Matrix

The living matrix in Section 8, expanded quarterly with SSO/SCIM detail, DPA availability, and data-training defaults per vendor.

Enables rung 3
03

AI Acceptable Use Policy template

A modular template — sanctioned-tools list, prohibited data classes, monitoring statement, enforcement steps, framework crosswalk.

Rung 2
04

Executive read-out deck template

Cover, exposure heatmap, top apps, top exposed users, business impact, remediation roadmap, licensing gap, timeline, appendix.

Bridges rung 1 → 2–5
05

Partner-signal runbook

The Section 9 method, turned into a weekly 30-minute routine that converts propensity data into a ranked call list.

Front-loads rung 1
06

Fixed-fee SOW templates

One per service line in Section 10, with deliverables and exclusions pinned so the assessment doesn't quietly become an unpaid Purview deployment.

All rungs
07

Recurring QBR pack

Monthly and quarterly cadence: AI usage summary, newly discovered apps, DLP incident summary, sanctioned-app health, license utilization, risk-register updates.

Rungs 3–5
08

"Sanction, don't block" briefing

The Section 7 material as a partner-branded one-pager. Converts the biggest objection into a three-minute pre-read that lands the meeting.

Enables rungs 2–3
09

License uplift calculator

Business Premium vs. Business Premium + Suites vs. E5, with the Shadow AI capability delta line by line.

Enables every Copilot deal
10

Regulated-vertical addenda

HIPAA / GLBA / SOC 2 / ISO 42001 / EU AI Act supplements to the base playbook, capturing the extra evidence requirements and where the premium sits.

Rungs 1, 2, 4, 5
↑ Back to Table of Contents

13. Where the Premium Sits — Regulated Verticals

Vertical-specific work in a regulated customer is genuine additional scope, not padding — and it's usually visible enough that the customer recognizes it as real. Community-observed pricing premiums of roughly 20–40% above generalist rates in these verticals reflect that extra work, not markup for its own sake.

VerticalFrameworkWhat's different
HealthcareHIPAAPHI-specific sensitive-info-type tuning, a signed BAA for every sanctioned AI vendor, and an ePHI-specific incident-response overlay.
FinanceGLBA, SOC 2Client financial data classification, customer-identification data classes, and non-public information DLP.
LegalPrivilege & ethical wallsAttorney-work-product classification, matter-scoped access control, and ethical-wall enforcement wherever an AI agent could otherwise cross one.
Public sectorGovernment / defenseData-residency and sovereignty considerations; sanctioned-app selection narrows to vendors with a compliant government-cloud boundary.
EU / globalEU AI Act, ISO 42001Formal AI system inventory, risk classification, and human-oversight documentation — genuine implementation-grade compliance work.
↑ Back to Table of Contents

14. "It's Not a Big Deal" — And Why That's Wrong

The objections you'll hear, and the honest answer to each

"Nobody in our shop is doing this." Even a single unlicensed Copilot Chat user, or one hit in a two-week Defender for Cloud Apps scan, closes this objection in days, not weeks.

"We already have DLP." DLP was built to watch structured data leave through a file share, not to watch a paragraph get pasted into a browser tab.

"Our firewall blocks the risky stuff." Every major consumer AI assistant is a trusted, categorized productivity endpoint. Firewalls let it through by design.

"We're too small to matter." Smaller firms show the same adoption pattern as large ones — with less resilience when something goes wrong.

"We'll deal with it after Copilot is live." By then, Copilot has already inherited every oversharing permission in the tenant.

"Blocking is the answer." Blocking without sanctioning drives use further underground, to devices and networks the partner can't see at all.

"An AUP is enough." A policy with no enforcement mechanism behind it protects no one.

↑ Back to Table of Contents

15. The Partner's Non-Negotiables

01

Discover before licensing

The first paid conversation is Shadow AI discovery, not a Copilot quote.

02

Governance readiness is consumption readiness

Any AI product a customer later turns on inherits whatever data hygiene already exists.

03

Keep the customer's preferred AI

Sanction it. Don't block it. Bring it under Entra and Purview management instead.

04

Anchor to Microsoft's four-step model

Discover, Block, Protect, Govern — every finding maps to a step.

05

Business Premium plus Suites, not a forced E5 upgrade

The Copilot engine is the same; the Suite add-ons are the SMB-native governance path.

06

Sell the ladder, not the SKU

Assessment → AUP → Managed Governance → Insurance readiness → vCISO. Every rung triggers the next.

07

Run it on yourself first

Before selling a Shadow AI assessment, complete one on your own tenant.

08

Use your own signal data as the weekly call list

Free-tier usage limits and weak security-maturity scores are the strongest openers you have.

09

A policy without a control isn't governance

Never sell an AUP without an enforcement mechanism attached to it.

↑ Back to Table of Contents

16. Next Steps

What to build first, in rough priority order:

  1. Publish this guide as the standing Shadow AI reference page, and link it from every related asset on the site.
  2. Ship the License Uplift Calculator (companion asset 9) as an embedded, interactive tool.
  3. Turn the AI App Onboarding Matrix (Section 8) into a living page with a quarterly refresh cadence.
  4. Package the AUP template, executive read-out deck, QBR pack, and the six SOW templates as a downloadable, email-gated partner kit.
  5. Ship the "Sanction, Don't Block" briefing as an open, ungated download — it's the objection-handler most partners will forward inbound.
  6. Add a regulated-vertical addendum library as expandable subsections under each vertical in Section 13.
  7. Wire the partner-signal runbook (Section 9) as a partner-only page behind Partner Center authentication.
  8. Cross-link every asset to its named source — Chapple, Tenant Wizards, CIAOPS — so the practice stays grounded in named, checkable authority.
↑ Back to Table of Contents

17. Reference Library & Further Reading

Every linked item below was checked at the time this guide was written. Product pages, pricing, and licensing tables change on Microsoft's own schedule — re-verify before quoting a customer. Items without a live link are cited by name only; confirm the current URL before publishing them externally.

Microsoft, official

MVP and community authority

Research and benchmark data

A note on sourcing

Statistics with a live link above are attributed to the specific report that produced them. A handful of figures throughout this guide — the ~75% shadow-AI-use estimate, the $400K exposure benchmark, and the SOW pricing ranges in Sections 4 and 10 — are community or editorial estimates rather than primary survey data. They're useful for planning and framing; treat them as directional in front of a customer, and lead with the primary-sourced numbers when precision matters.

↑ Back to Table of Contents

Prepared by Ken Lince — Sr. Director, Cloud Engineering, TD SYNNEX  ·  ken.lince@tdsynnex.com

Re-verify pricing, licensing tables, and product names before re-delivering this content — this space moves quickly.