Microsoft 365 Copilot rollouts are giving managed service providers a larger operational role, but the immediate work is less about “deploying AI” than auditing the SharePoint, Teams, OneDrive and Microsoft Entra ID permissions that AI will faithfully use. For Windows and Microsoft 365 administrators, that is the useful takeaway from a new Workplace Insight commentary: Copilot readiness has turned routine tenant hygiene into a billable, recurring service. The article, written by inforcer Microsoft 365 Team Lead Graham Morrison, makes the case that MSPs are moving from reactive support into AI governance. That direction is real. Microsoft’s own Copilot deployment guidance tells customers to identify overshared sites, inactive or ownerless content, risky links, sensitive files, and complex permission models before broad deployment.
But the source deserves to be read for what it is: a vendor-authored argument for a category of service that inforcer sells. Inforcer markets multi-tenant Microsoft 365 policy management, Copilot readiness assessments, user and group administration, and configuration-drift remediation to MSPs. The commentary’s central diagnosis is sound; its conclusion that a third-party platform is the natural answer is a commercial proposition, not an independently established result.

A cybersecurity analyst monitors an interconnected access-control dashboard across multiple screens.Copilot exposes permission debt; it does not bypass permissions​

The article’s most important technical point is also the one that is easiest to misunderstand. Microsoft 365 Copilot accesses enterprise data through Microsoft Graph and scopes retrieval to the signed-in user’s existing permissions. It does not grant a user access to a confidential SharePoint library, executive mailbox, or HR folder that the user could not already reach.
That does not make old permissions harmless. It changes how visible their consequences become.
A file that was accidentally shared with a broad Microsoft 365 group years ago may be technically available to hundreds or thousands of people, yet remain difficult to find through ordinary folder navigation and keyword search. Copilot can reduce that friction by answering a natural-language request, summarizing related material, or pointing the user toward content they already had rights to access. The access-control failure came first; AI raises the likelihood that somebody will discover and use the data.
This distinction matters operationally and legally. Calling every such event a “Copilot breach” can point an investigation at the wrong cause. If an employee receives a Copilot answer based on a document they were mistakenly allowed to open, the remediation is to fix the SharePoint, OneDrive, Teams, group-membership, or Entra ID entitlement that made the content available—not to treat Copilot as an independent permissions system.
Microsoft now explicitly frames oversharing as a Copilot readiness problem. Its current guidance directs administrators to use Microsoft Purview and SharePoint Advanced Management to find high-risk sites and sensitive content, then apply interim protections while they remediate access and sharing. The vendor has also added Copilot-focused data-security and compliance insights in the Microsoft 365 admin center.
For MSP customers, the practical concern is not whether the tenant has an AI policy in a document repository. It is whether the provider and customer can answer basic questions with evidence:
  • Which SharePoint sites have broad internal access, anonymous or organization-wide sharing links, broken inheritance, no owner, or no recent review?
  • Which groups still contain former employees, migration-era accounts, guests, or membership rules nobody can explain?
  • Which repositories hold payroll data, contracts, product plans, legal material, health information, or other sensitive content without enforceable labels and data-loss controls?
  • Which AI features, agents, Graph connectors, and third-party applications are permitted to retrieve tenant data, and who owns each one?
Those are governance questions with technical answers. They have existed for years, but a Copilot rollout gives executives a reason to fund them.

JLL’s survey supports the workforce premise, not the MSP demand claim​

Morrison’s article opens with JLL’s 2026 Future of Work Survey, which surveyed more than 2,200 C-suite executives and corporate real estate leaders in 21 countries between January and April. JLL reported in July that 60% of respondents expect AI to reinvent roles rather than replace them, and the same proportion expect workforce growth rather than contraction.
That is a useful counterweight to the simplistic claim that AI adoption automatically means headcount cuts. It also helps explain why companies are treating AI as an operational change rather than a narrowly scoped automation exercise.
What the survey does not establish is that AI is producing broad demand for MSPs. JLL’s respondents were senior business and corporate real estate leaders; the survey was designed around workforce, workplace, and real-estate decisions. It did not measure Microsoft 365 adoption, Copilot readiness, outsourced IT spend, or the share of organizations assigning governance work to MSPs.
The claim that MSPs are becoming “essential partners” therefore needs more support than the JLL headline can provide. It is plausible, particularly among small and midsize organizations without dedicated identity, information-governance, and security teams. But the submitted commentary supplies no customer adoption numbers, no managed-service revenue data, no survey of IT buyers, and no breakdown separating enterprises from smaller firms.
That gap changes how IT leaders should read the piece. The evidence supports a stronger need for continuous Microsoft 365 governance as AI use grows. It does not prove that outsourcing is the only—or even the predominant—way organizations will meet that need.
Large enterprises may build internal Copilot governance teams around Microsoft Purview, SharePoint Advanced Management, Entra ID, Defender, and security operations staff. Regulated organizations may retain outside specialists for assessments but keep approval, data classification, and access decisions in-house. Smaller firms may use an MSP because the alternative is no sustained governance function at all.
The market opportunity for providers is real, but it flows from a familiar problem: cloud tenants accumulate exceptions faster than organizations remove them.

Multi-tenant management solves scale, but it creates a new concentration of risk​

The article accurately describes the service-delivery problem. A one-time permission cleanup for one customer is a project. Maintaining secure baselines across dozens or hundreds of tenants is an ongoing operations discipline, especially when policies change, users arrive and leave, acquisitions add new domains and identities, and product features expand.
A centralized management layer can make that work less manual. Inforcer says its platform lets MSPs standardize policies, assess tenant configurations, manage users and groups, detect drift, back up policy settings, and run Copilot-readiness assessments across customer estates. ITPro has separately reported on inforcer’s Copilot Manager launch and its positioning around AI governance for MSP customers.
However, centralization is not automatically a security improvement. A platform that can review or change identity, endpoint, sharing, and policy settings across many customers becomes a high-value administrative control plane. The provider must protect it accordingly: phishing-resistant MFA, separate administrative accounts, role-based access, approval workflows for high-impact changes, audit logs, alerting, tenant isolation, offboarding procedures, and tested recovery plans all become part of the service.
Microsoft’s own Microsoft 365 Lighthouse illustrates the same tradeoff. Lighthouse provides eligible MSPs with multi-tenant management and monitoring capabilities for small and medium business customers, including baselines, device protection, proactive account management, alerts, and delegated administration. Microsoft recommends using Granular Delegated Admin Privileges, or GDAP, to grant technicians only the roles needed for their work.
Lighthouse is not universally applicable. Microsoft’s documented requirements include eligible customer subscriptions, delegated access, a maximum of 2,500 licensed users per actively managed tenant, and a customer tenant located in the same geographic region as the managing partner. Those constraints leave room for third-party products and for MSPs whose service model requires functionality beyond Lighthouse.
Still, it means the choice is not simply “manual admin portals or a commercial platform.” Any MSP evaluating a Copilot-readiness tool should compare it with the Microsoft capabilities already included in its tenants and partner relationships. The Workplace Insight article does not provide that comparison, and neither it nor inforcer’s public product material identifies pricing, required Microsoft licensing, or the precise policy coverage needed for a given customer.

Readiness work needs an owner, a baseline, and a recurring review​

The strongest part of the argument is that Copilot readiness cannot be treated as a pre-launch checkbox. A tenant may pass an initial review and still drift: a department creates a broad group for a time-sensitive project; a manager shares a folder widely; a leaver’s account remains active; a merger imports old permissions; a site loses its owner; or an agent is connected to a new data source.
MSPs are well placed to make that review repeatable, but customers should resist handing over governance without retaining decision-making authority. The provider can inventory risks, propose a baseline, execute approved remediation, monitor deviations, and respond to incidents. The customer still needs named owners for information classification, data-retention rules, privileged access, exception approvals, and acceptable AI use.
A credible Copilot readiness engagement should therefore produce more than a scorecard. It should leave the customer with a documented permission-remediation queue, named site and data owners, a baseline for external sharing and guest access, a plan for inactive accounts and groups, evidence of sensitivity-label and data-loss-prevention coverage, and a repeatable process for reviewing changes.
AI will increase the value of that operating model because it gives users a faster route to the data their organizations have already exposed. The MSP opportunity is not a magical new Copilot layer. It is the disciplined, continuous administration that makes Microsoft 365 permissions, policies, and data ownership defensible before a natural-language interface turns old tenant mistakes into visible business problems.

References​

  1. Primary source: Workplace Insight
    Published: 2026-08-03T14:38:36+00:00
  2. Related coverage: learn.microsoft.com
  3. Related coverage: jll.com
  4. Related coverage: learn.microsoft.com
  5. Related coverage: jll.de
  6. Related coverage: inforcer.com
  7. Related coverage: itpro.com
  8. Related coverage: itpro.com