Microsoft 365 Copilot is useful when identity, oversharing, labels, and acceptable use are in place first. Licences without those guardrails become shadow IT with company files.
This guide is for operators in Metro Vancouver and across Canada who want Copilot on the Microsoft 365 estate they already run. It belongs to Managed AI. Planning, rollout, and governance sit on Microsoft Copilot. Start with a written conversation on the AI readiness assessment.
The website assistant and How EC helps you are separate from Microsoft Copilot. There is no public Copilot chatbot on this site.
Copilot in one minute
Microsoft 365 Copilot works in Word, Excel, Outlook, and Teams. It grounds answers in files, chats, meetings, and notes the signed-in user can already see.
It inherits what you already set: Entra ID, multifactor authentication, Conditional Access, SharePoint permissions, Microsoft Purview sensitivity labels, and Information Rights Management. Confidential still applies. Content protected with Double Key Encryption is out of reach.
Microsoft states that prompts, responses, and Graph-accessed business content are not used to train Copilot foundation models.
It does not fix bad sharing. It does not create permissions. It makes oversharing easy to find.
It does not replace Managed IT, Managed Security, or a written acceptable-use rule. Consumer or personal-account Copilot is not for company files.
Canadian data location: verify it on the Microsoft 365 admin-centre Data location card. Copilot follows Microsoft 365 residency commitments. Do not invent a private Canadian Copilot region.
Teams meeting summaries need transcription. Enable it for the pilot or Copilot looks broken.
Guardrails before use cases
Do this order. A buyer or a model can cite it.
- Identity first. Entra ID, MFA, and Conditional Access on the accounts that will use Copilot.
- Acceptable use. Who may use Copilot, on which data, and who owns AI risk. Written down.
- Sharing hygiene. Copilot does not create permissions. Oversharing is the real risk. Find Anyone links, “everyone except external users,” and site permissions that drifted.
- Labels. Sensitivity labels so Confidential still means Confidential. An example four-label set is at the end of this guide. It is a pilot structure.
- Hide high-risk sites while you fix sharing. Use Restricted Content Discovery, not Restricted SharePoint Search. See the week-one checklist.
- Transcription. Turn on Teams transcription for the pilot group, or meeting summaries will fail.
- Data location. Confirm the Data location card. Do not assume a special Copilot region in Canada.
- Estate. Copilot sits on the Microsoft 365 estate Managed IT already runs. Endpoint, email, and awareness stay Managed Security.
If a connector can join two systems off-the-shelf, that work stays with Managed Integration. If the solution needs a custom .NET application or API around a model, that work sits with Managed Engineering. This guide does not sell custom software.
Week-one checklist
Use this in the first week of a pilot. Do not start with “turn on Restricted SharePoint Search.”
- Confirm MFA and Conditional Access for the pilot group.
- Confirm Teams transcription for that group.
- Open the admin-centre Data location card and record what it shows.
- Write acceptable use: company files stay in the tenant; no consumer Copilot; no pasting client data into a personal account.
- Run Data Access Governance reports. Use SharePoint Advanced Management for Anyone links, EEEU, and site permissions.
- For high-risk SharePoint sites you are not ready to expose to Copilot or org-wide search, use Restricted Content Discovery (RCD). RCD does not change permissions. It is a temporary curtain while you fix sharing.
- Restricted SharePoint Search (RSS) is retiring. Microsoft blocked new enablement on 31 July 2026. Do not tell a new tenant to turn RSS on. If RSS is already on, treat it as a leftover and plan the exit. RCD replaces the “hide this site from Copilot and org-wide search” job.
- Pilot Copilot with a named group.
- Book a written AI assessment if identity, labels, or sharing are not in place.
Twelve use cases
Each case is a role, a job, and a prompt you can paste. Grounding still follows what that person can already see. Guardrails still apply.
1. Owner: week in review
Job. See what moved, what stalled, and what needs a decision.
Prompt. Summarise my last five working days from emails, Teams chats, and meeting notes I can access. List decisions I owe, risks, and anything that looks stuck. Do not invent items I cannot see.
2. Operations: standard operating procedure
Job. Turn a known process into a draft SOP.
Prompt. Draft a one-page SOP for [process] using only files and notes I can already open. Use headings: purpose, who does it, steps, systems, exceptions. Flag anything you cannot find in those sources.
3. Finance: variance narrative
Job. Explain a number without dumping the workbook into a personal tool.
Prompt. From the Excel file I have open, explain the three largest variances versus last period in plain language. Quote the cells you used. Do not add market commentary.
4. Sales: meeting follow-up
Job. Send a clean recap after a client meeting.
Prompt. From this Teams meeting transcript, draft a follow-up email: what we heard, what we promised, dates, and open questions. Use only the transcript. Mark anything that was not said.
5. Service desk: first reply
Job. Answer a ticket from knowledge the agent can already open.
Prompt. Draft a first reply to this customer email using only our labelled Internal or Public knowledge I can access. If the answer is not in those files, say so and list what is missing.
6. People / HR: policy Q&A
Job. Answer a staff question from current policy.
Prompt. Answer this staff question using only the current HR policy files I can open. Quote the section. If policies conflict, list both. Do not invent a rule.
7. Project lead: status pack
Job. Build a status note from mail, chats, and files on that project.
Prompt. Create a status note for [project] from emails, chats, and files I can access: this week, next week, blockers, decisions needed. Do not include sites or files I cannot open.
8. Construction / field: toolbox talk
Job. Turn a safety or site note into a short talk.
Prompt. From this site note and any labelled Internal safety files I can open, draft a five-minute toolbox talk: hazards, controls, who is responsible. Do not add rules that are not in those files.
9. Contracts: clause find
Job. Find a clause without uploading the contract to a consumer tool.
Prompt. In the Word contract I have open, find termination, liability, and data-handling clauses. Quote them. Do not summarize away the numbers.
10. IT admin: sharing report
Job. Turn a Data Access Governance export into an action list.
Prompt. From this sharing report, list sites with Anyone links or EEEU access. Rank by how many Copilot users could see them. Suggest RCD only as a temporary curtain.
11. Knowledge owner: FAQ from old mail
Job. Pull repeat questions into a draft FAQ.
Prompt. From emails and files I can access about [topic], list the ten questions we answer most often and a one-paragraph answer for each, grounded in those sources.
12. Executive assistant: board pack skim
Job. Prep a principal without expanding access.
Prompt. From the board pack I have open, list decisions, numbers, and risks on two pages. Quote page numbers. Do not pull files I did not open.
If the prompt needs a custom API or a .NET service around a model, that work sits with Managed Engineering.
What Eaton published (not EC)
Microsoft’s published Eaton customer story is useful proof of Copilot done with process. It is Eaton’s story.
Microsoft reports that Eaton used Microsoft 365 Copilot to aid about 1,000 standard operating procedures. SOP creation time dropped from one hour to 10 minutes (an 83% reduction). Microsoft reports more than 650 hours saved on that SOP work. On customer service, Eaton’s stated target is to reduce response times by 20%. That 20% is Eaton’s aim, not a completed result, and it is not an EC metric.
Do not treat those numbers as EC hours saved, EC service speed, or a promise on this site. They are Microsoft’s published Eaton story. Read the source: Eaton helps power its finance processes, data access, and efficiency with Microsoft 365 Copilot.
Readiness steps
- Confirm the Microsoft 365 estate is in shape: identity, email protection, backups. That is Managed IT and Managed Security.
- Complete the week-one checklist above. RCD and sharing reports before a wide rollout.
- Book an AI assessment. It is a written conversation.
- Pilot Copilot with Managed AI: planning, rollout, and governance.
- If the work needs a custom application or API around the model, that conversation moves to Managed Engineering after the estate and the use case are clear.
Example label set for a pilot
This four-label table is an example for a first pilot.
- Public. Safe to share outside the organization. Copilot may use it for people who can already see it.
- Internal. Default for day-to-day files. Copilot may use it inside the tenant for people with access.
- Confidential. Limited groups. Copilot still honours permissions and labels. Do not overshare and hope the label saves you.
- Restricted. Tightest group. High-risk sites can also be put behind Restricted Content Discovery while you fix sharing. Double Key Encryption content stays out of Copilot.
Purview sensitivity labels and IRM still apply. Confidential still means confidential.
Responsible use
- Company files stay in the tenant. Do not paste them into consumer Copilot or a personal account.
- Copilot answers only from what that user can already see. Fix sharing. Do not hide a permissions problem behind a prompt.
- Do not enable Restricted SharePoint Search on a new tenant. Use RCD while you clean sharing, then remove the curtain.
- Meeting Copilot needs transcription. If you skip it, do not blame the model.
- Licensing is a conversation on Contact.
- EC does not invent hours saved. Eaton’s numbers stay Eaton’s.
Prompt recipes
Keep prompts short. Name the source. Forbid invention.
Use only the file I have open.If you cannot see it, say you cannot see it.Quote the heading or cell you used.Do not add advice that is not in those sources.List decisions, owners, and dates. Nothing else.
Pair every recipe with the guardrails. A good prompt on an overshared site is still an overshare.
FAQ
Is Microsoft 365 Copilot the chatbot on this website?
No. There is no public Copilot chatbot on this site. Copilot is the Microsoft product on your Microsoft 365 estate. How EC helps you is client work on revenue, cost, and the bottom line.
Should we turn on Restricted SharePoint Search?
Not on a new tenant. Microsoft blocked new RSS enablement on 31 July 2026. Use Restricted Content Discovery plus sharing cleanup (DAG reports and SharePoint Advanced Management). If RSS is already on, plan the exit.
Does Copilot train on our files?
Microsoft states that prompts, responses, and Graph-accessed business content are not used to train Copilot foundation models. Still lock down sharing and labels.
Where does Canadian data sit?
Check the admin-centre Data location card. Copilot follows Microsoft 365 residency commitments.
Where do I start with EC?
Book an AI assessment or use Contact. Call (604) 888-7904. Hours: Monday–Friday 8:30 a.m.–5:00 p.m.; Saturday–Sunday closed.
Book an AI assessment or use Contact. Call (604) 888-7904. Hours: Monday–Friday 8:30 a.m.–5:00 p.m.; Saturday–Sunday closed.
