
Copilot readiness assessment — know what Copilot will see.
Copilot inherits every permission your users already have. SafeScan maps that exposure across your tenant, scores how ready you are out of 100, and hands your admin the exact PowerShell to close each gap — read-only, in under five minutes.

Copilot does not create exposure. It reveals it.
Every file a colleague could already open becomes something Copilot can quote. The risk was always there — Copilot just makes it trivially easy to find.
Permissions you set years ago
A folder shared with Everyone during a project in 2021, a site whose inheritance was broken to unblock one person, an anonymous link nobody revoked. Copilot reads all of it the moment you turn it on.
Reports without priorities
Generic compliance tools hand you a few hundred findings in no useful order. Knowing something is wrong is not the same as knowing what to fix first — and your admin loses a week deciding.
Scan, score, then actually fix it
SafeScan ranks every finding by severity, gives leadership one number to track, and generates the remediation script for each failing check. The loop closes in the same tool.
Six surfaces, one scan
From the board-level score down to the individual script that fixes a single misconfigured site.

The whole posture on one screen
A Copilot Readiness Score out of 100 with a per-domain breakdown, tiles for items at risk and critical findings, a severity donut, and a service-by-service summary across SharePoint, Entra ID, Purview, Teams and Microsoft 365.
- Readiness score, scored per domain
- Items at risk, critical, high and medium counts
- Members, guests and app registrations inventoried

Twenty-three checks, six domains, one verdict each
Exposure, Identity, Compliance, Teams, Licensing and Copilot — every check returns pass, warning or fail with a score and a one-line explanation, so nothing needs interpreting.
- Pass / warning / fail with a numeric score
- Domain-level scores roll up to the total
- Expand any check to see what it found

Every exposed item, worst first
The exact SharePoint path, who can reach it and how — internal, anonymous, external or broken inheritance — plus any sensitive-data matches, a recommended action and a status you can mark resolved.
- Critical to low severity with risk scores
- Audience type per item, including broken inheritance
- Financial, legal and HR sensitivity flags

The admin-centre path, written out
Each failing check comes with numbered steps through the relevant Microsoft admin centre and a link to the official documentation — so the fix is verifiable, not folklore.
- Numbered steps per failing check
- Microsoft documentation linked throughout
- Covers SharePoint, Entra ID, Purview, Teams and M365

Generated for your tenant, ready to run
A commented PowerShell script per failing check, written against your own environment. Copy it, review it, run it in your admin terminal, then rescan to prove the finding is closed.
- PowerShell 5.1 and 7+ compatible
- Commented, with output logging for audit
- Rescan to confirm the fix actually landed

The accounts and apps nobody is watching
Every user with MFA status, department and last sign-in, and every app registration with its secret expiry, permission count and risk flags — the governance gaps that never show up in a file-sharing report.
- Filter by needs attention, disabled or guest
- App secrets with nearest expiry date
- Permission counts and risk flags per registration
What each domain covers
Twenty-three checks, grouped the way an administrator actually thinks about a tenant.
Exposure
SharePoint and OneDrive oversharing, anonymous links, external sharing and sites whose permission inheritance has been broken.
Identity
MFA coverage, dormant and stale admin accounts, guest access and gaps in Conditional Access.
Compliance
DLP policy coverage, audit logging, sensitivity label usage and retention configuration.
Teams
External access settings, anonymous meeting joins, app governance and team sprawl.
Licensing
Unused licences, inactive users and SKU assignments worth revisiting before renewal.
Copilot readiness
The composite score, the oversharing Copilot would inherit, and the governance posture behind it.
PDF & Excel exports
Hand the findings to a CISO, an auditor or a client without giving them a licence and a login.
Multi-tenant management
One dashboard across every client tenant — built for MSPs and groups running several estates.
Rescan and compare
Re-run after remediation to prove the score moved, and keep a record of posture over time.
It reads. It never writes.
SafeScan asks for the minimum it needs to answer the question, and nothing beyond it.
Read-only by design
Only read scopes are requested, so there is no code path that could create, change or delete anything. The consent screen shows every permission before you approve it.
No file contents
Permissions and metadata only — who can reach what. The text inside documents, emails and Teams messages is never read.
Revoke in one click
Remove access from Microsoft Entra whenever you like. It ends immediately, and nothing is kept afterwards.
What teams found on their first scan
Security leads, CTOs and managed service providers on what changed after running SafeScan.
“We found 47 files shared with Everyone before our Copilot rollout. SafeScan saved us from a major data incident.”
“The Copilot Readiness Score gave our board a single number they could track month on month. It changed how we report on security posture.”
“As an MSP we manage 30+ Microsoft 365 tenants. The multi-tenant dashboard is exactly what we needed — one view, every client.”
Up and running in three steps
- 1
Connect
Sign in with Microsoft and approve read-only Graph consent. No agent to deploy, no app registration to build, no firewall change.
- 2
Scan
SafeScan runs all 23 checks across your tenant and scores each domain. Under five minutes for most estates — close the tab if you like.
- 3
Fix, then prove it
Work down the ranked findings using the admin steps or the generated scripts, then rescan to show the readiness score moving.
Copilot SafeScan: your questions answered
Can we buy through Microsoft?
Yes. Copilot SafeScan is listed on the Microsoft Marketplace and Azure Marketplace, so it can be billed through your existing Microsoft agreement.
What does Copilot SafeScan actually check?
Twenty-three automated checks grouped into six domains — Exposure, Identity, Compliance, Teams, Licensing and Copilot. Each returns a pass, warning or fail with a numeric score, so you can see at a glance which part of the tenant is dragging your readiness down.
How long does a scan take?
Under five minutes for a tenant of up to a thousand users; larger estates can take about fifteen. It runs in the background, so you can close the tab and come back to the finished result.
What permissions does it need?
Read-only Microsoft Graph scopes — Sites.Read.All, User.Read.All, Policy.Read.All and AuditLog.Read.All. There is no write scope anywhere in the consent, so the app physically cannot alter your tenant. The OAuth screen lists every permission before you approve it.
Does it read the contents of our files?
No. SafeScan looks at permissions and metadata — who can reach what. The text inside your documents, emails and Teams messages is never read and never leaves your tenant.
Can we remove its access later?
Yes, in one click from Microsoft Entra. Access ends immediately and nothing is retained afterwards.
What is the Copilot Readiness Score?
A single figure out of 100, broken down per domain, summarising how exposed your tenant would be the day Copilot is switched on. It gives a board or steering group one number to track month on month instead of a spreadsheet of findings.
Do the PowerShell scripts change anything by themselves?
No. SafeScan generates them; you review and run them in your own admin terminal. They are commented and log their output, so the change is auditable afterwards — and you rescan to confirm the fix landed.
What does it cost?
There is a free tier that runs a real scan of a real tenant, and paid plans for single-tenant, multi-tenant and MSP use, all with a seven-day trial. Current plans and prices are on the SafeScan site — or ask us and we will talk you through which fits.
Is it the same thing as a Copilot readiness assessment?
It is the technical half of one, automated. Our AI governance & readiness service wraps the scan in the parts software cannot do: agreeing remediation with data owners, persona use cases, training and a phased roll-out plan.
Related insights

Microsoft Copilot in Arabic: Gulf Dialect vs Modern Standard Arabic
Copilot performs differently across Arabic variants. See what works reliably in Modern Standard Arabic versus Gulf dialect before you roll out to your team.

Microsoft Copilot for DIFC Financial Institutions: A Compliance-First Approach
DIFC-regulated firms face stricter data and access requirements before Copilot rollout. See what a compliance-first Copilot deployment actually requires.

الأسئلة الشائعة عن مايكروسوفت كوبايلوت في الإمارات
إجابات مباشرة عن أكثر أسئلة مايكروسوفت كوبايلوت شيوعا لدى الشركات في الإمارات: أمان البيانات، دعم اللغة العربية، الأسعار، والجاهزية، في مكان واحد.
Buy it straight from Microsoft.
Prefer to buy through Microsoft? Get Copilot SafeScan on the Microsoft and Azure Marketplace — billed through your existing Microsoft agreement, with the procurement your finance team already trusts. The same product, one click away.


See what Copilot would find in your tenant
Run a free scan and get your Copilot Readiness Score, ranked findings and the scripts to fix them. No card, no agents, nothing written to your tenant.
Read-only Graph scopes · no file contents read · revoke access any time
