Copilot Readiness Assessment Tool

Copilot Readiness Assessment Tool

Consultant-grade readiness assessment for Microsoft 365 Copilot. Goes beyond the Microsoft baseline check with 46 cross-domain composite assessments, a readiness scorecard, time-to-ready estimation, a five-phase remediation roadmap, and presentation-ready PowerPoint, Excel, Word, and CSV deliverables generated directly from your tenant data.

JFDI Copilot Readiness Assessment Tool Dashboard view showing readiness score, priority counts, domain health bars, and top actions

Know whether your Microsoft 365 tenant is ready for Copilot, and what to fix first

The JFDI Copilot Readiness Assessment Tool analyses your live tenant and scores readiness across Microsoft 365, Entra, Defender, Purview, Power Platform, and Copilot Studio, assessing each service where it is provisioned in your tenant. It then generates the executive deck, prioritised remediation backlog, and phased roadmap you need to move from assessment to rollout, all written directly from your tenant data.

It goes beyond Microsoft’s baseline readiness checks with 46 cross-domain composite assessments, a Copilot Rollout Risk Score from a SharePoint permissions export you provide, time-to-ready estimation, and consultant-grade PowerPoint, Excel, Word, and CSV outputs.

In one assessment run, you get

  • A Copilot readiness score across all six in-scope domains
  • A prioritised remediation backlog with an effort estimate and an owner for every finding
  • A time-to-ready estimate in weeks, derived from finding complexity and volume
  • A five-phase rollout roadmap, from blockers to ongoing adoption
  • A Copilot Rollout Risk Score when you supply a SharePoint permissions export
  • An executive PowerPoint deck, plus Excel, CSV, and Word outputs for delivery teams

Why Microsoft’s baseline isn’t enough

The Microsoft baseline tool runs 182 individual licence and feature checks across six service areas, then outputs a flat recommendations list. The JFDI tool starts from the same tenant data and goes further:

46 composite assessments

Cross-domain analyses that synthesise findings from M365, Entra, Defender, Purview, Power Platform, and Copilot Studio to reveal insights no single-domain check can surface.

Readiness scorecard

Per-domain readiness scores (0-100%), an overall organisational score, and a verdict that tells you how many findings stand between you and the next readiness tier.

Time-to-ready estimation

Minimum and maximum weeks until deployment-ready (clearing Phase 0 blockers and Phase 1 pre-deployment work), with per-phase effort breakdowns in hours derived from finding complexity, priority, and volume.

5-phase remediation roadmap

Blockers, Pre-deployment, Early Lifecycle, Optimisation, and Adoption Opportunities, sorted by complexity and domain so the execution order is obvious.

Consultant-grade deliverables

A presentation-ready PowerPoint deck, multi-worksheet Excel workbook, CSV export, and ~200-word executive summary, written directly from your tenant data.

Delta reporting

Capture assessment snapshots and demonstrate measurable progress between engagements: Resolved, Regressed, Improved, New Finding, Unchanged.

The biggest Copilot risk isn’t licensing, it’s what Copilot can already see

The single biggest deployment-day shock with Microsoft 365 Copilot is over-shared SharePoint content. Copilot does not need a permission of its own; it surfaces whatever the prompting user has access to. Sites set to “Everyone except external users”, libraries shared via “Anyone with the link” anonymous links, individual permission grants outside SharePoint groups, broken inheritance, and forgotten restore-snapshot sites all become Copilot exposure paths the moment a licence is provisioned.

The JFDI tool ingests existing permissions reports and turns them into a Copilot Rollout Risk Score: a single 0-to-100 metric with five colour-banded thresholds (Clean, Low, Moderate, High, Severe). A supplementary Permission Hygiene % sits alongside it and tells you how much of the estate is on clean inheritance.

What it analyses

The score is a weighted composite of five sub-scores:

  • Unique Permission Breadth: proportion of resources that break inheritance from their parent site.
  • External Exposure: external Full Control grants, elevated external access, and the breadth of sites exposed externally.
  • Direct Grant Density: permissions granted to individual users outside SharePoint groups, weighted by severity (Full Control, Edit, or Read).
  • Broadcast Sharing: Anyone anonymous links, Everyone except external users (EEEU) grants, and Everyone permissions at site level.
  • Stale and Ownerless Surface: inactive risky sites, ownerless sites, and restore/snapshot collections that still appear in tenant search.

What it reads

The tool accepts permissions reports from the providers consultants and tenant admins already use, in either CSV or XLSX. Two complementary source types are supported:

Type A: detailed permissions

Line-by-line permission exports, down to the individual user, resource, and how access was granted. Casper365 full permissions export is the native format. Other providers, such as ShareGate, Quest On Demand, and SysKit Point are supported via column mapping. Unlocks the full per-user remediation register and external-user detail.

Type B: site-level summary

Microsoft’s own SharePoint Advanced Management (SAM) ‘Site permissions across your tenant’ report. Aggregates broadcast-sharing signals (Anyone links, EEEU counts, Everyone access, external sharing posture) per site collection.

Using both gives the most complete picture. Type A supplies user-level detail; Type B adds broadcast-sharing signals Type A may not capture. Non-Casper365 sources are handled via a simple JSON column-mapping file, with no per-tool parser engineering required.

What it produces

  • Copilot Rollout Risk Score with band (Clean, Low, Moderate, High, or Severe), embedded into the deck and the Word report alongside the readiness scorecard.
  • Per-site risk summary: every site labelled Critical, High, Medium, Low, Archive, or Clean, with the driving signals shown.
  • Highest-risk areas panel: the small set of sites driving most of the score, ready to bring into an executive conversation.
  • Remediation appendix: direct-grants register, external-user detail, broken-inheritance hotspots, and restore-site inventory, in tables consultants can hand to the remediation team.
  • CSV recommendations row alongside the rest of the findings, so over-sharing items are roadmapped and included in time-to-ready alongside every other remediation.

How the assessment runs

The assessment runs as a guided pipeline. Connect it to a tenant, authenticate, and wait for collection to complete.

Setup screen showing Tenant ID, Sign in with Microsoft authentication, six-domain scope selection, and optional imports

1. Configure the tenant and scope

Enter the Entra Tenant ID for the tenant you are assessing (licensed deployments are validated against this Tenant ID), sign in with Microsoft (or use a service principal for unattended collection of the Graph, Defender, and Power Platform domains), and choose which of the six domains to assess: M365, Entra ID, Defender, Purview, Power Platform, and Copilot Studio. Optional imports (for example, a SharePoint permissions report for the over-sharing analysis) attach in the same step.

Pipeline status during assessment with each domain fetching data in parallel and an elapsed-time counter

2. Watch the pipeline run

The pipeline collects data in parallel from Microsoft Graph, Defender, Exchange Online, and the Power Platform API (which also powers the Copilot Studio assessment). Each domain reports its own elapsed time and progress so consultants and tenant administrators can see exactly where collection is up to.

Pipeline status at completion with each domain showing Complete plus its recommendation count, and Generating Reports running the export step

3. Get the recommendations

Each domain completes with a recommendation count, broken down by high, medium, and low priority across the composite assessments. The Generating Reports phase writes the XLSX, CSV, PowerPoint, and Word outputs, and the dashboard opens with the score, verdict, and remediation roadmap ready to walk through.

Cross-domain intelligence

The 46 composite assessments are where the tool’s value lives. Each one synthesises findings from multiple Microsoft 365 domains to surface insights no single-domain check can reveal.

Copilot capability readiness

  • Copilot Dependency Mapping: maps six Copilot capabilities (meeting intelligence, document drafting, email assistance, chat, Power Platform integration, and security/compliance) to their prerequisite service chains and identifies blocking gaps.
  • Copilot ROI Readiness: calibrates the expected return tier (high, medium, or low) based on actual usage patterns rather than licence presence.
  • Copilot Licence-Security Alignment: detects tenants where Copilot is licensed but the security foundations (MFA, conditional access, DLP) are not yet in place.

Organisational maturity

  • Collaboration Maturity: five-factor model scoring Teams adoption, meeting culture, SharePoint engagement, email maturity, and multi-platform activation. Produces an Early Stage, Developing, Mature, or Advanced level.
  • Content Ecosystem Health: evaluates content quality, governance, and discoverability across SharePoint, OneDrive, and Exchange as a proxy for Copilot’s knowledge-retrieval effectiveness.
  • Digital Workplace Breadth and Communication Patterns: measure how broadly the collaborative infrastructure is deployed and how ready the communication flow is for AI augmentation.

Risk and exposure

  • Quantified Data Exposure: calculates the data surface area Copilot will have access to, factoring in sensitivity labels, DLP coverage, and sharing policies.
  • Guest Copilot Exposure: assesses the risk of external users interacting with Copilot-surfaced content.
  • Shadow AI Exposure, Operational Risk, and Data Governance: three composites drawing on Microsoft Defender for Cloud Apps (Cloud App Discovery) to surface the unsanctioned generative-AI tools already in use, who is using them, the data flowing to them, and a per-app risk score, so you address an existing shadow-AI risk before Copilot goes live. Where Cloud App Discovery isn’t provisioned, the assessment flags that visibility gap itself.
  • Legacy Authentication Risk, Unmanaged Device Risk, Vulnerable Device Risk, and Mobile Compliance: residual auth and device-level Copilot exposure assessments.
  • Permanent Admin Copilot Exposure: flags standing admin access that Copilot could inadvertently leverage.

Governance alignment

  • Copilot MFA Coverage and Copilot Audit Trail Completeness: MFA enforcement and audit logging scoped specifically to Copilot-licensed users.
  • Adoption-Aligned Priority: aligns remediation priorities with where the organisation is actually working, not theoretical best practice.
  • Auto-labelling Readiness, Label Encryption Coverage, and DLP Communication Coverage: Purview-specific composites for information-protection maturity.
  • Secure Score Readiness: correlates Microsoft Secure Score with Copilot deployment posture.

The business-intelligence layer

Every finding the tool surfaces is enriched with the metadata stakeholders ask for before they sign off a programme.

Readiness scorecard

Per-domain readiness scores for M365, Entra, Defender, Purview, Power Platform, and Copilot Studio. Active-usage detection flags domains with no assessed activity so consultants don’t over-index on inactive services.

Enriched verdict

Goes beyond a binary ‘Ready / Not Ready’. The verdict sits on a four-tier scale (Not Ready, At Risk, Needs Improvement, Ready) and tells you exactly how many findings stand between you and the next tier, with progression guidance like ‘Resolve 3 more high-priority findings to move from At Risk to Needs Improvement’.

Collaboration maturity model

A five-factor quantitative model producing a maturity level. Enables consultants to frame Copilot as building on existing habits rather than introducing new ones, and gives executives concrete evidence of organisational readiness beyond technology.

Remediation effort scoring

Each finding carries an effort estimate, from 1-2 hours up to 1-3 days, and is assigned to the team that owns the fix (Identity & Access, IT Security, Compliance, or Platform). Those estimates feed directly into the roadmap and the time-to-ready calculation.

A phased remediation roadmap

The tool organises every recommendation into a five-phase roadmap, sorted by complexity and domain so the execution sequence is obvious from day one.

  • Phase 0, Blockers (immediate): critical gaps that prevent Copilot deployment entirely.
  • Phase 1, Pre-deployment (1-2 weeks): high-priority items to address before pilot rollout.
  • Phase 2, Early Lifecycle (first 30 days): medium-priority items to harden during initial adoption.
  • Phase 3, Optimisation (90 days): lower-priority items that improve Copilot effectiveness.
  • Phase 4, Adoption Opportunities (ongoing): success findings and expansion recommendations.
Roadmap view showing the Blockers phase expanded with five critical findings. Each finding has its domain, title, severity context, and the remediation guidance written underneath. Subsequent phases (Pre-deployment, Early Lifecycle, Optimisation) collapse with their finding counts.

Consultant-grade deliverables, generated from your tenant data

PowerPoint deck

Title slide, executive summary narrative, readiness scorecard, status distribution donut, domain findings bar chart, 6-axis polar radar chart, detailed findings (auto-paginated), quick wins, phased roadmap, dependency mapping, delta slides when a baseline exists, and next steps. Charts rendered as embedded PNGs so the deck displays correctly on any system.

Excel workbook

Multi-worksheet workbook with recommendation details and all metadata, the scorecard summary, and the roadmap phasing breakdown. Filterable and sortable for customer-side analysis.

CSV export

Flat recommendation list for import into project management tools, ServiceNow, or any custom workflow that needs a structured backlog.

Executive summary narrative

An auto-generated ~200-word summary that profiles the tenant, delivers a verdict statement with finding counts, highlights critical gaps by domain concentration, acknowledges existing strengths, and recommends prioritised next steps.

Charts inside the application

Charts view inside the application with a tabbed strip across the top (Findings Distribution, Findings by Priority, Findings by Status, Domain Readiness) and a pie chart showing 85 findings out of 321 checks split across Insight, Action Required, Attention Required, Critical, Missing Prerequisite, Warning, and Other categories

The Charts view inside the application gives consultants four interactive lenses on the same data: findings distribution (status pie), findings by priority (stacked bar per domain), findings by status (stacked bar per domain), and a six-axis domain-readiness radar. Each chart is exported as an embedded PNG in the PowerPoint deck, so the customer’s presentation displays correctly on any system without chart-rendering dependencies.

The three exemplar charts below show the same outputs as they appear in the PowerPoint deck, drawn from a redacted customer assessment.

Export to whichever format your stakeholders need

Export menu offering CSV, Excel, PowerPoint, and Word output formats

The Export action surfaces every output format generated by the pipeline: a presentation-ready PowerPoint deck for executives, a multi-worksheet Excel workbook for the remediation team, a flat CSV for project-management imports, and a Word document for internal documentation. Every format is built from the same underlying assessment state, so there is no double-keying.

Track measurable progress between engagements

The tool captures point-in-time assessment snapshots. When a baseline snapshot exists, it produces a change analysis with five status transitions: Resolved, Regressed, Improved, New Finding, and Unchanged. Consultants use this to demonstrate measurable progress between engagements and to give customers evidence of remediation ROI.

Where your data goes

The tool runs against a live Microsoft 365 tenant, so it is worth being explicit about where that data goes.

  • Runs as a cross-platform desktop application (Windows, macOS, Linux) on the consultant’s or administrator’s own machine.
  • Authenticates with Microsoft identity (interactive sign-in, or a service principal for unattended collection of the Graph, Defender, and Power Platform domains).
  • Reads tenant configuration and the selected reports from Microsoft Graph, Defender, Exchange Online, and the Power Platform API (which also powers the Copilot Studio assessment).
  • Generates every output locally. All analysis runs on your machine.
  • No tenant assessment data is sent to JFDI servers. Every report is generated and stored on your own machine. (Licence activation validates your Entra Tenant ID against JFDI’s licensing service; nothing from your assessment is transmitted.)

For the full picture of what the tool reads, the authentication models on offer, and how access is granted and revoked, see the permissions and privacy reference, written for the administrators and security reviewers who sign off the access before an assessment runs.

Pricing

The Copilot Readiness Assessment Tool is licensed per Microsoft 365 tenant. Each licence is activated against a specific Entra Tenant ID and allows unlimited assessment runs, exports, snapshots, and delta reporting for that tenant. Once activated, a licence cannot be reassigned to another tenant. It runs as a cross-platform desktop application (Windows, macOS, Linux). Buy directly from us as a perpetual licence, or subscribe on the Microsoft Marketplace.

Single tenant licence

£1,500
per Microsoft 365 tenant

One licence for one Microsoft 365 tenant, bound to its Entra Tenant ID and not reassignable once activated. Unlimited assessment runs for that tenant. Includes all six in-scope domains, the SharePoint over-sharing analysis when a permissions export is supplied, and the complete deliverable set (PowerPoint, Excel, Word, CSV).

  • Licensed for one specific Entra Tenant ID (not reassignable once activated)
  • Unlimited assessment runs for that licensed tenant
  • All 46 cross-domain composite assessments
  • Copilot Rollout Risk Score (SharePoint over-sharing)
  • PowerPoint, Excel, Word and CSV deliverables
  • Assessment snapshots for delta reporting between engagements
  • Cross-platform desktop application (Windows, macOS, Linux)

10-tenant licence pack

£10,000
pack of 10 tenant licences

Ten tenant licences for MSPs and larger teams assessing multiple customer tenants. Each licence is activated against one specific Entra Tenant ID. Saves a third on the per-licence price, with centralised licence administration.

  • Ten tenant-bound licences, one Entra Tenant ID each
  • Saves a third versus ten single tenant licences
  • Centralised licence administration
  • All 46 composite assessments and the full deliverable set
  • Copilot Rollout Risk Score (SharePoint over-sharing)
  • Assessment snapshots for delta reporting between engagements

Prefer a subscription? Now on Microsoft Marketplace

For teams that need a longer runway to embed the findings — rerunning the assessment as remediation lands, tenancies grow, or risk profiles shift — the tool is also available as a monthly or annual subscription on the Microsoft Marketplace, billed through your existing Microsoft agreement. Live pricing tracks your local currency and is shown at checkout.

Monthly subscription

See Marketplace
billed monthly

Ideal for short evaluation windows or a single remediation cycle. Cancel or upgrade at any time.

  • Rerun the assessment as often as your programme needs
  • All 46 cross-domain composite assessments and the SharePoint over-sharing score
  • Full deliverable set (PowerPoint, Excel, Word, CSV)
  • Cross-platform desktop application (Windows, macOS, Linux)
  • Billed monthly through your Microsoft agreement

Annual subscription

See Marketplace
billed annually

Continuous readiness tracking through remediation and rollout — with the effective per-month rate around two-thirds lower than the monthly plan.

  • Effective per-month rate around two-thirds lower than the monthly plan
  • Rerun the assessment continuously across the year
  • All 46 cross-domain composite assessments and the SharePoint over-sharing score
  • Full deliverable set (PowerPoint, Excel, Word, CSV)
  • Cross-platform desktop application (Windows, macOS, Linux)
  • Billed annually through your Microsoft agreement

Azure customers can also deploy the tool directly from the Azure Portal.

Built to take an executive sponsor through findings and plan

Microsoft’s baseline tool is a useful inventory of what is missing. The JFDI Copilot Readiness Assessment Tool turns the same data into a programme: scored, prioritised, time-bounded, and packaged as deliverables your sponsor can sign off.

Frequently asked questions

Assess your tenant’s Copilot readiness

We run the assessment against your live tenant, walk you through the scorecard and roadmap, and hand over the PowerPoint and Excel deliverables for your internal and executive stakeholders.