A professional reviews an AI-powered dashboard displaying software performance metrics, security checks, and task statuses.
Houston-based Microsoft consultancy EPC Group has published TAR-8, its "8-Surface Tenant AI Readiness Standard." It is a free, 24-point rubric for deciding whether a Microsoft 365 and Azure tenant is ready for Microsoft 365 Copilot, AI agents and approved external models, and it scores eight areas from Entra identity to Teams transcripts and Power BI models. EPC announced it on September 23, 2026 through EIN Presswire, and AiThority carried the same text a day later. Microsoft did not create TAR-8 and does not certify against it. EPC also sells a paid assessment built on the rubric. Even so, it is one of the more concrete public attempts to turn the vague claim "we're Copilot-ready" into questions an administrator can check. Its real strength is simple: every score has to be backed by an export, a report or a log.

Most of what follows comes from EPC's own announcement and its standard page. The AiThority and EIN Presswire items carry the same press-release copy, so they count as one source. We found no independent review of TAR-8. The Microsoft context around it, though, can be checked against Microsoft's own documentation, and much of the practical value lies in how closely TAR-8's questions follow what Microsoft already tells admins to do.

TAR-8 targets the gap Microsoft's Copilot readiness report leaves open​

EPC's case starts with a limit of Microsoft's own tooling. The Microsoft Copilot readiness report in the Microsoft 365 admin center (Reports → Usage → Microsoft Copilot) is a licensing and adoption tool. Microsoft Learn says it identifies which users are technically eligible for Copilot, helps admins assign licenses and tracks usage of the apps Copilot works best with. Its Readiness tab covers the past 28 days. It counts prerequisite licenses, users on the Current Channel or Monthly Enterprise Channel, and assigned versus available Copilot licenses. It also flags the top 25% of unlicensed users as "suggested candidates," based on how much they use Teams, Outlook and Office documents.

None of that tells you what Copilot will find once it is switched on. EPC's founder, Errin O'Connor, puts it this way in the announcement: a Copilot license tells you who can use a tool, but not whether a Teams transcript is governed, whether a Power BI answer comes from a trusted model, or whether an agent can change a customer record. TAR-8 asks a different question. What can an AI system find, return, change, keep or send once it is connected to company data?

That framing matches Microsoft's own security model. Microsoft says Copilot builds on the existing security of SharePoint, email, Teams and OneDrive, and that it reaches OneDrive files only within each user's existing permissions. In a FastTrack blog post, Microsoft says Copilot "does not create new permissions or expose data users cannot already access," but it does make existing access more discoverable, bringing years of accumulated oversharing, excessive permissions, unlabeled content, unmanaged connectors, and governance gaps into sharper focus. TAR-8 is EPC's attempt to list those gaps across the whole tenant, not just SharePoint.

Eight Microsoft 365 and Azure surfaces, from Entra ID to external models​

The standard splits a tenant into eight "surfaces." EPC stresses that an AI deployment brings no identity, classification, permissions or business process of its own. It relies on what the tenant already has. The eight are:

#SurfaceMicrosoft products in scopeWhat TAR-8 asks for as evidence
1IdentityEntra ID, Conditional Access, privileged access, app consent, agent identitiesPolicy exports, sign-in records, a current agent inventory
2Sensitive dataPurview sensitivity labels, DLP, retentionLabel coverage, DLP policy exports, activity reports
3Content estateSharePoint, OneDrive, ExchangePermissions inventory, SharePoint data access governance report, remediation record
4ConversationsTeams chats, meeting transcripts, recordings, recapsTeams policy exports, retention configuration, access records
5Reports and dashboardsPower BI semantic models, Microsoft FabricEndorsed-model inventory, access test, lineage export
6Business applicationsDynamics 365, Dataverse, Power Platform, Copilot StudioAgent register, connector policy, approval-flow definition, action audit trail
7Infrastructure and external modelsAzure, Microsoft Foundry, integrations with Claude, ChatGPT, Gemini, private modelsRecords of retrieval-time access checks, data sent, network controls and logging
8Ownership and evidenceGovernance register, review cadenceNamed owners, agent sponsors, exceptions, review records

Some of these sharpen questions admins often skip. On sensitive data, EPC says putting a label on a document is only part of the answer. The assessment also checks whether the control still works when the content turns up in a prompt, a grounding request or a response, where the product supports that. On reports, the standard points out that a polished dashboard does not show that an agent will use the right metric or stay within the user's authorized scope. So it asks for named owners, endorsed definitions, tested row-level security and traceable lineage.

Surface 6 is where the risk shifts from reading data to acting on it. In Dynamics 365, Dataverse, Power Platform and Copilot Studio, EPC notes, an agent may update a record, trigger a workflow or contact a customer. The surface checks the agent's identity and permissions, connector policies, action logging, and any required human approval.

Surface 7 is the one most likely to be wrongly assumed. EPC states that a third-party model does not automatically inherit Microsoft 365 permissions, labels or retention rules, and that each integration has to be designed and tested for those boundaries. This fits the limits of Microsoft's documentation. Microsoft says Copilot works within the Microsoft 365 trust boundary and respects Purview labels and encryption. That promise covers Microsoft 365 Copilot, not a custom pipeline that sends tenant documents to another vendor's API.

How the 24-point TAR-8 score and its deployment gates work​

Each surface gets a score from 0 to 3:

  • A score of 0 ("unknown") means nobody can say what the current state is. EPC's web version adds that this includes an inventory more than a year old.
  • A score of 1 ("inventoried") requires a dated inventory with a named owner. Exceptions are listed but not yet fixed.
  • A score of 2 ("controlled") means the relevant control is configured and active, with exceptions documented. The web version asks for a policy export showing the control switched on, and for each exception to have a reason and an expiry date.
  • A score of 3 ("evidenced") requires recent operating evidence reviewed by the owner, such as an audit log, report, access test or policy export. The web version sets a window of the last 90 days.

The top score is 24. EPC's page groups totals into bands: 0–8 exposed, 9–15 inventoried, 16–20 controlled, 21–24 evidenced. EPC says plainly that the total is not a pass certificate. The gates matter more than the sum:

  1. Any surface at 0 means the tenant is "not ready," whatever the total.
  2. Identity, sensitive data and content must each reach 2 before Copilot is enabled broadly or tenant-wide.
  3. Conversations, reports and business applications must each reach 2 before agents may take actions.
  4. Infrastructure and external models must reach 2 before any external model connects to tenant data.
  5. Ownership and evidence is reviewed every quarter.

The gates are the most useful part of the design. A tenant could score 20 by excelling at Power BI governance and Teams retention while its SharePoint permissions are a mess. Under TAR-8, that tenant still fails the broad-Copilot gate. EPC's example is an organization with plenty of eligible licenses but widely accessible financial files in SharePoint that nobody has reviewed. The rubric sends that team to fix the content surface first.

The thresholds are EPC's own choice. Microsoft has not published a numeric gate like "content must score 2." No outside body has validated the cut-offs either. They are an opinion about ordering, though a defensible one, since the content gate lines up with Microsoft's own advice.


TAR-8's content surface restates Microsoft's SharePoint oversharing playbook​

The content-estate surface shows where TAR-8 adds structure and where it repeats known advice. Microsoft's guidance for getting ready for Copilot with SharePoint Advanced Management tells admins to use data access governance reports and insights to identify and prioritize oversharing risks and to restrict access to sensitive content. It also warns that by default, SharePoint sets sharing settings to the most permissive option. Microsoft's data-readiness page lists the same basics: fix sharing settings, make sure every site has a valid owner, clean up unused sites, and find sites with potentially overshared content.

TAR-8 also separates hiding content from fixing access, which admins often confuse. EPC says restricted discovery can contain exposure during cleanup but does not replace correcting access rights. Microsoft's documentation agrees. It describes Restricted Content Discovery as a way to reduce accidental exposure while leaving site permissions unchanged, and notes that SharePoint and OneDrive access controls influence what Copilot can discover and reference, without changing user permissions. Microsoft's FastTrack team recommends using RCD during a pilot as a temporary way to narrow the SharePoint sites Copilot can ground against while you review permissions and governance controls before broad rollout. Then turn it off after validation rather than treating it as a long-term control.

Restricted Access Control is the tool that actually limits access. Microsoft explains that a restricted access control policy means all access to the site is restricted to only the group of users specified in the policy. Accordingly, the content from the site is visible in Microsoft Copilot only for this restricted group of users.

EPC's page adds some dated claims that raise the urgency of this surface. It says Copilot in SharePoint became an opt-out preview in mid-June 2026, on by default for Copilot-licensed users unless an admin limits it. It also says Restricted SharePoint Search stopped accepting new enablements on July 31, 2026, which would remove the old allow-list workaround. EPC is the only source here for those dates. Microsoft's current training materials do describe Restricted SharePoint Search as "legacy," asking learners to explain how legacy Restricted SharePoint Search affects organization-wide discovery, which fits the direction EPC describes. Admins who planned to rely on Restricted SharePoint Search should check its status in their own SharePoint admin center before building a rollout around it.

What TAR-8 is, what EPC sells, and where the evidence stops​

EPC calls TAR-8 an "open standard," and the rubric, scoring definitions and interactive scorecard are free. According to EPC, the scorecard runs in the browser, sends nothing to EPC, and stores the result in the page address so it can be shared as a link. The current version is v1.0.1. EPC says it re-checks the standard against Microsoft Learn every 90 days.

The standard is also a sales channel, and the announcement makes no secret of it. EPC offers a scoped Tenant AI Readiness Assessment that it describes as read-only. It reviews reports and exports and does not change tenant settings, and its scope is set after a discovery call. The promised deliverables are a score for each surface with any unmet gates flagged, a prioritized remediation plan, and an "evidence pack" for security, executive, audit or insurer review. The announcement links each surface to a follow-on EPC service line, from Entra and Conditional Access work to Purview, Fabric governance, Foundry architecture and a "virtual Chief AI Officer" retainer.

EPC is careful about what the standard is not. It says TAR-8 is not a Microsoft program, not an external audit, not regulatory approval and not a certification. Mapping its surfaces to the NIST AI Risk Management Framework and ISO/IEC 42001 concepts does not confer ISO certification or prove compliance. Those limits should shape how you use the score. A TAR-8 "21" is a record of your own evidence, not something a regulator or auditor has agreed to accept. EPC's claims of more than 300 Copilot initiatives and 300 AI implementations come from the firm itself.

What this means for Microsoft 365 admins planning Copilot and agents​

Whether you pay anyone for an assessment is a separate question. The real decision is whether your rollout plan has evidence behind each surface Copilot or an agent will touch. You can use TAR-8's structure for free as a checklist. Most of the evidence it asks for comes from Microsoft tools you may already have: Conditional Access policy exports, Purview label and DLP reports, SharePoint data access governance reports, Teams retention settings, and Power Platform connector policies.

Teams that have only run the Copilot readiness report and assigned licenses have covered eligibility, not exposure. Teams planning agents that write to Dataverse or Dynamics 365 records have the most new ground to cover, because TAR-8's surface 6 asks for things many tenants have never inventoried: agent identities, approval flows and action audit trails. Organizations wiring Claude, ChatGPT or Gemini into tenant data need to test each integration's retrieval and logging on its own terms, not assume Microsoft 365 controls carry over.

  • Use the Copilot readiness report for licensing and update-channel eligibility only. It does not measure permissions, labels or agent behavior.
  • Run SharePoint data access governance reports before broad Copilot enablement. Treat Restricted Content Discovery as short-term containment and use permission fixes or Restricted Access Control as the lasting fix.
  • Apply TAR-8's gating logic even if you ignore its total. A single unassessed surface should block the matching deployment step.
  • Before any agent is allowed to take actions, record each agent's identity, owner, connectors and approval points.
  • Treat every external-model integration as its own security boundary, with retrieval-time access checks, logging and data-handling controls you have verified yourself.
  • Present a TAR-8 score to auditors or insurers as your own evidence, not as a Microsoft or third-party certification.

TAR-8 will not tell you anything a careful Microsoft 365 architect doesn't already know. What it does is force that knowledge into eight scored areas with an evidence requirement and hard gates, which is exactly what a CIO's "are we ready?" question tends to skip. Because EPC ties the rubric to a 90-day review of Microsoft Learn, it will stay useful only as long as it keeps pace with Microsoft's fast-moving agent and SharePoint controls. Admins can take the structure, fill it with evidence from their own tenant, and decide separately whether they need outside help to close the gaps it exposes.