# Copilot readiness on Business Premium, without the reports everyone tells you to run

> Every Copilot oversharing guide tells you to run the Content Management Assessment and work the Data Access Governance reports. Those live in SharePoint Advanced Management, and SAM's prerequisites page does not list Microsoft 365 Business Premium as an eligible base subscription. Here is the same work, done by hand, with the commands and the hours.

[Home](https://tenantcraft.ca/)  [Insights](https://tenantcraft.ca/insights)  Copilot

Plan Aug 3, 2026  16 min read

Geri Crroj

Microsoft 365 consultant, Niagara, Ontario

You have 150 seats on Microsoft 365 Business Premium. Someone on the board asked about Copilot, the budget is moving, and you did the responsible thing. You read the readiness guidance.

Run the Content Management Assessment. Work the Data Access Governance reports. Find the sites shared with “Everyone except external users.” Fence off the worst ones with Restricted Content Discovery while you clean up.

So you sign in to the SharePoint admin center, open **Reports**, and Data access governance is not there. Neither is **Advanced Management** in the menu. You check your roles. You check whether somebody hid it. You start googling for a preview toggle.

There is no toggle. Those features belong to SharePoint Advanced Management, and Microsoft’s prerequisites page lists which base subscriptions qualify. Business Premium is not one of them.

The five minute version

1.  **This is a licensing line, not a mistake in your setup.** The SAM prerequisites page (ms.date 2026-06-30) lists Office 365 E3/E5/A5, Microsoft 365 E1/E3/E5/A5, and GCC/GCC-High/DoD as qualifying base subscriptions. Business Premium is not there.
2.  **Copilot Business is sold to Business Basic, Standard and Premium tenants, capped at 300 seats.** It gives you the same Copilot features. It does not appear to give you the admin tools every readiness article assumes you have.
3.  **You can rebuild most of the work with PnP PowerShell.** A group-level EEEU sweep and a sharing-link sweep cover roughly the top 90 percent of what the reports would show you.
4.  **Budget 45 to 65 hours over six to eight weeks** for a 60 to 300 seat tenant. Most of that is getting site owners to make decisions, not scripting.
5.  **Buying up to E3 plus Copilot to get the reports costs roughly CAD $49,000 a year more for 150 seats.** For most tenants that size, spend a fraction of that on the cleanup instead.

## Does Microsoft 365 Business Premium include SharePoint Advanced Management?

No. [Microsoft’s SAM prerequisites page](https://learn.microsoft.com/en-us/sharepoint/sharepoint-advanced-management-prerequisites) says your organization must hold one of these base licences: Office 365 E3, E5, or A5; Microsoft 365 E1, E3, E5, or A5; or Microsoft 365 GCC, GCC-High, or DoD. Business Premium is not on that list. The page carries an ms.date of 2026-06-30. Check it against your own tenant before you plan around it.

> Your organization must have one of the following base licenses: Office 365 E3, E5, or A5. Microsoft 365 E1, E3, E5, or A5. Microsoft 365 GCC, GCC-High, or DoD.

Microsoft Learn, Prerequisites for SharePoint Advanced Management

That list is the whole story. It is worth reading the rest of the same page slowly, though, because that is where the confusion starts.

Under the base subscription rule, Microsoft describes how you get SAM. Either one person in your organization holds a Microsoft 365 Copilot licence, or your subscription includes SharePoint K, P1 or P2 and you buy the SharePoint Advanced Management Plan 1 add-on, or you have Microsoft 365 E7.

Read that quickly and the middle one looks like a way in, because Business Premium does include SharePoint Online Plan 1. But the base subscription list sits above those three as a hard requirement, not as one option among them. The add-on route reads as an alternative to holding a Copilot licence. Not as an alternative to holding an enterprise base licence.

I have not found a Microsoft page that settles this either way. If you want to settle it for your own tenant, open the Microsoft 365 admin center, go to **Billing → Purchase services**, and search for SharePoint Advanced Management. If the add-on is offered against your subscription, buy one seat and see whether the SharePoint admin center lights up. If it is not offered, you have your answer, and it cost you ten minutes.

The 'organizations without SAM' note points at E5, not at you

The Data Access Governance reports page (ms.date 2026-07-09) has a note headed “For organizations without SharePoint Advanced Management.” It talks about switching on data collection, keeping 28 days of it, and waiting 24 hours for the first report.

That reads like a way in until you read the note above it. That one says IT administrators with Microsoft 365 E5 licensing can reach data access governance reporting but none of the other SAM features. They get no snapshot reports and no remedial actions, and they are capped at 10,000 sites on the activity reports.

E5 is on the base subscription list. Business Premium is not. So even the partial path starts above you. Check your own admin center anyway. If the activity reports are there, use them and skip the scripting below.

## What does Copilot Business actually get you, and what is the 300-seat limit?

Copilot Business is the small-business add-on. Per Microsoft’s Copilot Business FAQ, it is sold to organizations with 300 or fewer users on a Microsoft 365 Business Basic, Business Standard, or Business Premium plan, and it supports up to 300 seats per tenant. On what it does, the FAQ is direct: “The Copilot Business add-on delivers the same capabilities as the Microsoft 365 Copilot offering.”

That sentence is about what Copilot does for your users. It says nothing about SharePoint admin tooling, and the SAM prerequisites page is where the admin tooling is defined.

Two commercial terms matter for your timing. Copilot Business is annual commitment only, billed monthly or annually, with no month-to-month option. And the FAQ is clear that you cannot upgrade to an Enterprise plan from Business Standard or Business Premium with Copilot Business partway through. You wait for the commitment end date.

So if you sign a Copilot Business agreement this quarter and later decide you want SAM, you are locked out of the E3 route for a year.

Canadian list prices, checked on microsoft.com/en-ca on 3 August 2026. Business Premium is CAD $29.80 per user per month paid yearly. Copilot Business is CAD $28.50 per user per month, with a promotional CAD $24.43 running from 1 July to 30 September 2026 and applying to the first year only. Business Premium with Copilot is sold as a bundle at CAD $43.40.

Put those last two side by side before you sign anything. Business Premium plus the Copilot Business add-on is $58.30 per Copilot user. The Business Premium with Copilot bundle is $43.40 for what Microsoft’s own page calls work-grounded Copilot in Word, Excel, PowerPoint, Outlook and Teams. Neither route gets you SAM, so it does not change the argument below. But it is $14.90 a seat, and the two products sit on different pages of microsoft.com.

## The five things the reports would have told you

Before you replace something, name it properly. Across the Content Management Assessment and the Data Access Governance reports, this is the list:

1.  **Site permissions baseline.** A snapshot of the permission structure across every SharePoint and OneDrive site, ranked by how broad the access is, so you can see which sites thousands of people can reach.
2.  **“Everyone except external users” grants.** Where EEEU or Everyone is a recipient, at site, group, folder and file level, including the parent group when the access is indirect.
3.  **Sharing links.** Anyone links, People in your organization links, and Specific people links shared outside, created in the last 28 days.
4.  **Sensitivity label coverage on files.** Which sites hold files carrying which labels. Microsoft’s own table of SAM features included in Copilot licences marks this row “Requires E5 or G5,” so it is gated twice.
5.  **Ownership and lifecycle gaps.** The site ownership policy flags sites below a minimum owner or admin count that you set. The inactive site policy flags sites with no activity across SharePoint, Teams, Exchange and Viva Engage over a period you set, and can drop them to read-only or archive them.

Items 1, 2, 3 and 5 you can rebuild by hand. Item 4 you mostly cannot, and it matters less than you would think on Business Premium. The licensing section below says why.

## How do you find “Everyone except external users” grants without the report?

Two modules do it. The SharePoint Online Management Shell gives you the tenant-wide site list and the sharing controls. PnP PowerShell walks each site’s groups and role assignments.

Since 9 September 2024 PnP PowerShell needs your own Entra app registration, so `-ClientId` is required on interactive connections. Run `Register-PnPEntraIDAppForInteractiveLogin` once and keep the app ID, or set it as an `ENTRAID_CLIENT_ID` environment variable. Watch the name: `Register-PnPEntraIDApp` is the app-only version, for unattended runs, and it is not what the script below wants.

EEEU and Everyone show up in SharePoint as claims. The “Everyone except external users” login name follows the pattern `c:0-.f|rolemanager|spo-grid-all-users/<GUID>`, where the GUID is normally your tenant ID. The classic Everyone claim is `c:0(.s|true`. Microsoft does not document those strings in a product article, so match on the substring rather than an exact value.

```
Connect-PnPOnline -Url "https://contoso-admin.sharepoint.com" -Interactive -ClientId $appId

$sites = Get-PnPTenantSite | Where-Object { $_.Template -notlike "SPSPERS*" }
$hits  = New-Object System.Collections.Generic.List[object]

foreach ($site in $sites) {
    try {
        Connect-PnPOnline -Url $site.Url -Interactive -ClientId $appId

        # Path 1: EEEU sitting inside a SharePoint group
        foreach ($group in Get-PnPGroup) {
            $members = Get-PnPGroupMember -Group $group
            foreach ($m in $members) {
                if ($m.LoginName -like "*spo-grid-all-users*" -or $m.LoginName -eq "c:0(.s|true") {
                    $hits.Add([pscustomobject]@{
                        Site = $site.Url; Via = "Group: $($group.Title)"; Claim = $m.LoginName
                    })
                }
            }
        }

        # Path 2: EEEU granted directly on the web
        $web = Get-PnPWeb -Includes RoleAssignments
        foreach ($ra in $web.RoleAssignments) {
            $member = Get-PnPProperty -ClientObject $ra -Property Member
            if ($member.LoginName -like "*spo-grid-all-users*" -or $member.LoginName -eq "c:0(.s|true") {
                $hits.Add([pscustomobject]@{
                    Site = $site.Url; Via = "Direct on web"; Claim = $member.LoginName
                })
            }
        }
    }
    catch { Write-Warning "$($site.Url): $($_.Exception.Message)" }
}

$hits | Export-Csv .\eeeu-hits.csv -NoTypeInformation
```

On a 200-site tenant this takes roughly 25 to 45 minutes. Most of that is the per-site connection handshake, not the queries. Add a site collection admin sweep first if you are not already an admin everywhere, or the loop will throw 403s on the sites you are not.

Be honest with yourself about what it misses. It catches EEEU at site and site-group level. It does not walk every list, folder and file with broken inheritance, which is exactly what the SAM “Sites and files shared via special SharePoint groups” report does, right down to item level with a `ParentGroupName` column telling you how the access was granted. A file somebody dropped in a library and shared to Everyone in 2021 will not show up in the output above.

That gap is real. Plan around it rather than pretending the script closes it. In practice the site-level sweep finds the sites, and once you know which sites are affected you can walk their libraries one at a time. That is a doable job for ten sites and an impossible one for two hundred, so cut the list down hard before you start.

## How do you find and kill “Anyone” links without the sharing links report?

The SAM command is `Start-SPODataAccessGovernanceInsight` with `-ReportEntity SharingLinks_Anyone`. Its documentation says plainly that a SharePoint Advanced Management licence is required to run these reports. So on Business Premium it is not an option.

PnP can list links per item with `Get-PnPFileSharingLink -Identity <server relative path>`. That works, and it is genuinely slow, because it is one call per file. A library with 20,000 documents is an overnight job. Do not point it at the whole tenant. Point it at the ten sites your EEEU sweep flagged, plus anything owned by HR, finance, legal or the executive.

For everything else, use the blunt instrument. At this size it is often the right instrument. Anyone links only exist when sharing capability is set to `ExternalUserAndGuestSharing`. Drop a tenant or a site below that and new Anyone links cannot be created, and existing ones stop working. The documented values are:

| Value | Effect |
| --- | --- |
| `Disabled` | Sharing outside your organization is disabled |
| `ExistingExternalUserSharingOnly` | Only with external users already in your directory |
| `ExternalUserSharingOnly` | Share by email enabled, anonymous link sharing disabled |
| `ExternalUserAndGuestSharing` | Share by email and anonymous link sharing both enabled |

```
# Tenant-wide: stop Anyone links existing at all
Set-SPOTenant -SharingCapability ExternalUserSharingOnly

# Or leave the tenant open and clamp the sites that matter
Set-SPOSite -Identity "https://contoso.sharepoint.com/sites/HR" `
            -SharingCapability Disabled

# Kill "People in your organization" links on a specific site
Set-SPOSite -Identity "https://contoso.sharepoint.com/sites/Finance" `
            -DisableCompanyWideSharingLinks Disabled
```

`DisableCompanyWideSharingLinks` is the one people forget. Organization-wide links are internal, so they survive every external sharing setting you apply, and they lead to exactly the same oversharing that EEEU causes. Its settable values are `Disabled` and `NotDisabled`, plus an `Unknown` that shows up on read and cannot be written. That naming has caught out better admins than me: `Disabled` means the links are turned off.

Both changes are visible to users the moment you make them, so tell people first. This is the step where a quiet tightening generates twenty tickets on a Monday morning.

## What does Business Premium actually give you that helps?

More than the licensing tables suggest, as long as you are precise about the edges. From the Microsoft Purview service description (ms.date 2026-08-03):

| Capability | Business Premium | Notes |
| --- | --- | --- |
| Manual sensitivity labelling, including encryption | Included | Withhold the EXTRACT usage right and Copilot stops summarizing the file |
| DLP for Exchange Online, SharePoint Online and OneDrive | Included | Business Premium is named explicitly in the rights list |
| Audit (Standard), 180-day retention | Included | Includes Copilot interaction audit records |
| Client and service-side automatic labelling | Not included | Requires E5 or the Purview Suite add-on |
| DLP scoped to restrict Copilot processing files and emails | Not included | The service description marks Business Premium as “No” |
| Audit (Premium), 1-year and 10-year retention | Not included | Requires the Purview Suite for Business Premium add-on |

Rows one and five together are the real shape of your job.

Copilot honours the EXTRACT usage right on encrypted content, shown in the Purview portal as **Copy and extract content(EXTRACT)**. Give a user VIEW without EXTRACT and Copilot will not summarize the file for them. Microsoft is clear that it can still hand back a link, so the user can open the file outside Copilot. Manual labels with encryption are in Business Premium. The other control, scoping a Purview DLP policy to Copilot as a location, is not. So on Business Premium, encrypted manual labels are your file-level Copilot control, and there is nothing behind them if they fail.

One thing to know before you lean on it. Whoever applies the encryption is the Rights Management owner and always holds EXTRACT. So content a user encrypted themselves can always come back to them through Copilot.

That has a consequence people miss. Manual labelling means a human decides file by file. Fine for the 200 documents that genuinely matter. Impossible for 200,000. Your labelling scope has to be small and chosen on purpose, and the only way to choose it well is to have done the inventory work above first.

## Should you buy up, add Purview, or stay put?

For most 60 to 300 seat tenants: stay on Business Premium and spend the difference on the cleanup. The numbers are not close.

The comparison below assumes 150 base seats and 50 Copilot seats, at Canadian list prices checked 3 August 2026, annual commitment. Currency and terms will differ through a CSP.

| Option | Monthly | Annual | What you get |
| --- | --- | --- | --- |
| **A.** Business Premium + Copilot Business | $4,470 + $1,425 = **CAD $5,895** | **CAD $70,740** | Copilot. No SAM, no DAG reports, no RCD, no RAC |
| **B.** A + Defender and Purview Suites for Business Premium | A + **CAD $3,060** | A + **CAD $36,720** | Auto-labelling, DLP for Copilot, Audit (Premium). Still no SAM |
| **C.** Microsoft 365 E3 + Microsoft 365 Copilot | $7,935 + $2,035 = **CAD $9,970** | **CAD $119,640** | SAM, the DAG reports, RCD, RAC, Content Management Assessment |

Option C costs roughly **CAD $48,900 a year more than option A**. What that money buys is reporting and a couple of per-site controls. It does not fix a single permission. You would still do all the remediation work described above. You would just find the problems faster.

Option B is the one that gets mis-sold. The Purview service description names two add-ons here, Microsoft Purview Suite for Business Premium and Microsoft Defender + Purview Suite for Business Premium, and puts the same two conditions on both: they need a Microsoft 365 Business Premium base licence, and they cap at 300 seats. The Canadian add-on page lists the combined Defender and Purview Suites for Business Premium at CAD $20.40 per user per month paid yearly, which is the figure in row B. It is priced across all 150 seats rather than only the Copilot users, because the labelling rights are per user.

It does close the auto-labelling, Copilot-DLP and Audit (Premium) rows above, and those are real gaps. It does not grant SharePoint Advanced Management, and nothing on the SAM prerequisites page changes because you bought it. If a reseller offers it as the answer to “our DAG reports are missing,” that is the wrong product.

Buy up to E3 when the reporting genuinely pays for itself. That means several hundred sites, more than one admin, a compliance duty that needs per-item permission evidence, or a growth path past 300 seats that ends the Copilot Business option anyway. Below that, option A plus a disciplined manual pass is the better trade.

## How long does the manual pass take for 60 to 300 seats?

Order matters. You cannot triage what you have not inventoried, and you cannot label sensibly until you know what is overshared.

| Stage | Hours | Notes |
| --- | --- | --- |
| Site inventory: URLs, owners, storage, last activity | 3 to 5 | `Get-PnPTenantSite -Detailed` plus a spreadsheet |
| EEEU sweep: script, run, triage the output | 8 to 12 | Most of it is triage, not runtime |
| Sharing-link sweep on flagged sites, plus tenant clamp | 6 to 10 | Scoped to the sites EEEU flagged |
| Fix the worst ten sites | 10 to 16 | **This is where it stalls** |
| Label the genuinely sensitive content, manually, with encryption | 8 to 12 | Keep the scope under a few hundred files |
| Pilot to 15 or 20 users and watch for 30 days | 6 to 10 | Spread across the month, not in one block |

Call it 45 to 65 hours of admin time over six to eight weeks. Almost none of that is script runtime. The scripting itself is about a day.

It stalls at step four every time, and it is not a technical problem. Deciding whether the 2019 “Company Wide” site should still be readable by everyone is a business decision, and one admin cannot make it alone. They email a site owner who left in 2023, get no reply, and the project sits there.

So work out who decides for each of your ten sites before you start the sweep, not after. If you cannot name a person, that site’s answer is “lock it and see who complains,” and you should agree that rule with your leadership in advance.

The rest of the sequence is covered in more depth in [turn on Copilot without leaking your HR folder](https://tenantcraft.ca/insights/copilot-without-leaking-hr). If you are doing this alongside a tenant move, [permissions cleanup before migration](https://tenantcraft.ca/insights/permissions-cleanup-before-migration) is the same work at a better moment to do it.

01 Is SharePoint Advanced Management included with Copilot Business?

Microsoft's SAM prerequisites page (ms.date 2026-06-30) requires a qualifying base subscription first: Office 365 E3/E5/A5, Microsoft 365 E1/E3/E5/A5, or GCC/GCC-High/DoD. Business Premium is not listed. The separate condition about a Copilot licence granting SAM sits underneath that base requirement. The Copilot Business FAQ says the add-on "delivers the same capabilities as the Microsoft 365 Copilot offering," but that statement is about Copilot capabilities for users, not SharePoint admin tooling. Verify in your own admin center.

02 Can I use Restricted Content Discovery on Business Premium?

RCD is listed as a SharePoint Advanced Management feature, so it depends on the same prerequisites. If SAM is not provisioned in your tenant, the `Set-SPOSite -RestrictContentOrgWideSearch` parameter exists in the module but you should expect it to fail or be ignored. The closest thing you have on Business Premium is tightening actual permissions, which is the better fix anyway. See [the full read on RCD](https://tenantcraft.ca/insights/restricted-content-discovery-copilot) for why it was never a substitute for cleanup.

03 How do I see which sites are overshared without the Data Access Governance reports?

Enumerate sites with `Get-PnPTenantSite`, then per site walk `Get-PnPGroup` plus `Get-PnPGroupMember` and the web's role assignments, flagging any principal whose login name contains `spo-grid-all-users` (Everyone except external users) or equals `c:0(.s|true` (Everyone). That gives you site-level and group-level oversharing. It does not give you item-level grants on files with broken inheritance, which is the main thing the SAM report adds.

04 Do I need Microsoft 365 E5 to run Copilot safely?

No. E5 or the Purview Suite for Business Premium add-on gets you automatic labelling, DLP scoped to Copilot as a location, and Audit (Premium). Business Premium on its own gets you manual sensitivity labels with encryption, DLP for SharePoint, OneDrive and Exchange, and 180-day standard audit. Manual encrypted labels are enough to gate the files that genuinely matter, provided you keep the scope small enough for a human to apply them.

05 If I buy Copilot Business now, can I move to E3 later to get the reports?

Not until your commitment ends. The Copilot Business FAQ states you cannot upgrade to an Enterprise plan from Business Standard or Business Premium with Copilot Business, and must wait for the commitment end date. Copilot Business is annual commitment only. Decide the licensing question before you sign, not after.

The full Copilot readiness sequence, licence by licence

Copilot Readiness Governance Checklist

PDF · 7 pages · 44 checkpoints

[Email me the PDF](https://tenantcraft.ca/resources/guides/copilot-readiness-governance)

Two numbers are worth taking into your next budget conversation. The reports cost about CAD $49,000 a year for 150 seats. The cleanup they would have sped up costs about 55 hours.

Before you argue either one, run the EEEU sweep. It takes an afternoon to write and half an hour to run, and the length of the output tells you which number you are actually facing.

TWENTY MINUTES, NO PITCH

## Tell me what is stuck. I will tell you what it takes.

Same consultant from the first email to the last cutover. If I am not the right fit, I will refer you to someone who is.

[Book a 20-min call](https://tenantcraft.ca/contact) [See published rates](https://tenantcraft.ca/pricing)

---

_Canonical HTML: https://tenantcraft.ca/insights/copilot-readiness-business-premium-no-sam · Agent guide: https://tenantcraft.ca/llms.txt · Site map: https://tenantcraft.ca/sitemap-index.xml_
