Fusion Computing Limited Logo

Free Microsoft 365 Copilot readiness scan · Canada · 2026

Is your tenant Copilot-ready?

Answer 10 quick questions and see your Copilot readiness score across licensing, data hygiene, identity, rollout and enablement — with your ranked gaps and a 30/60/90-day plan. No email until you see your score.

4 steps · quick to finishNo email until you see the number
1 / 5 · Your business

Tell us about your business

Two quick questions to size your report. Not scored.

How many employees?
What brings you here?

Why Canadian teams run the scan with Fusion Computing

  • Microsoft's engine

    The official open-source readiness assessment, not a vendor quiz

  • Minutes, not weeks

    API-driven analysis of your actual configuration

  • Branded readout

    A Fusion Computing report with priorities, not a raw CSV dump

  • Read-only

    Scoped service principal, removed after the run

What the scan reads

Seven service areas, straight from your tenant

No questionnaires and no self-reporting. The engine queries Microsoft Graph, Defender, Exchange Online, and Power Platform APIs and scores what is actually configured.

  • M365 licensing

    Copilot-relevant licensing and feature availability across the tenant, so you know what you are already paying for.

  • Entra ID

    Identity protection and access controls: the Conditional Access and MFA posture that decides what Copilot can reach.

  • Defender XDR

    Security posture and threat-detection configuration scored against what a Copilot rollout assumes is in place.

  • Purview

    Data classification, sensitivity labels, and DLP policies: the controls that stop Copilot from surfacing what it should not.

  • Power Platform

    Environment governance and AI Builder readiness, where ungoverned automation usually hides.

  • Copilot Studio & agents

    Agent deployment configuration and inventory, including Agent 365 readiness signals.

The deliverable

A branded report your leadership can actually read

The raw engine outputs spreadsheets. According to Microsoft (2026), the assessment scores each check from live tenant APIs; we turn that output into a branded Fusion Computing readout: every finding marked Compliant, Warning, or Not Configured, ranked by priority, with the specific recommendation attached.

Across our client tenants, the Warning rows we see most are in Purview and Entra ID, the settings that decide what Copilot can surface. You get the report and a 30-minute walkthrough with a consultant who runs these rollouts, so the fix list lands as decisions, not homework.

Built in the open

The engine is Microsoft's, and you can read the source

  • Microsoft (2026), MIT license

    Official Microsoft open-source tool

    The assessment engine is published by Microsoft and reviewable line by line. Fusion Computing automates the run and brands the report.

    Read more
  • Microsoft 365 Copilot Blog (2026)

    Launched January 2026

    Microsoft's own adoption guidance: data-driven readiness assessment in minutes, generated from tenant APIs instead of questionnaires.

    Read more
  • Microsoft Work Trend Index (2025)

    40%+ Copilot productivity gains

    But only once data classification, sensitivity labels, and conditional access are in place. The scan shows whether yours are.

    Read more
  • Statistics Canada (2024)

    Only 1 in 7 Canadian businesses use AI

    Adoption concentrates in firms with documented governance. The scan gives a Canadian business the configuration baseline insurers and privacy regulators expect, before the licences are committed.

    Read more

Who it is for

Run it before the licences, not after

The scan fits any Canadian business on Microsoft 365 that is weighing Copilot. In practice, most teams that book it are at one of these four decision points.

  • Pricing a rollout

    You are budgeting Copilot licences and want to know what has to be fixed first, with evidence.

  • Already piloting

    Copilot is live for a few users and you want to know what it can reach before you widen the ring.

  • Board or insurer asked

    Someone wants a documented readiness position, and a vendor questionnaire will not cut it.

  • Comparing options

    You are weighing Copilot against custom AI and want a configuration-level baseline either way.

How it works

Three steps, none of them a workshop

The scan itself is automated, so your total time investment is about an hour across two short calls: one to set up read-only access, one to walk the branded report.

  • 1. 30-minute setup call

    We scope the run and set up read-only API access with your admin: a documented service principal you can revoke the same day.

  • 2. The automated run

    The engine queries your tenant and scores every check. Minutes of runtime; we review and interpret the output.

  • 3. Branded readout

    A 30-minute walkthrough of the Fusion report and the prioritized fix list. The report is yours either way.

Mike Pearlstein, CISSP, founder and security lead at Fusion Computing

CISSP-led interpretation

Mike Pearlstein, CISSP, Founder of Fusion Computing

Mike has run Microsoft 365 security programs for Canadian businesses since 2012. “The engine is excellent and it is free, so we give the run away. The value we add is the interpretation: most tenants we scan show Warning rows in Purview and Entra ID that decide whether Copilot becomes a productivity story or an oversharing story.”

CISSPSince 2012Microsoft 365Copilot rollouts

Frequently asked questions

A Copilot readiness scan is an automated, API-driven evaluation of whether a Microsoft 365 tenant is ready for Copilot. Fusion Computing's free scan runs Microsoft's official open-source assessment engine (MIT licensed, published 2026) against the live tenant and scores seven service areas: M365 licensing, Entra ID, Defender XDR, Purview, Power Platform, Copilot Studio, and Agent 365. Every check is marked Compliant, Warning, or Not Configured with a priority and a recommendation, delivered to Canadian businesses as a branded report with a 30-minute walkthrough.

Yes, genuinely. The assessment engine is Microsoft's own open-source tool (MIT licensed), the run is automated, and the readout call is 30 minutes. Because our delivery cost is small, we can give it away. Our deeper engagements, like the AI Technical Readiness Assessment and the Cybersecurity Gap Assessment, are paid, and we are upfront about that distinction.

A read-only service principal with scoped permissions to Microsoft Graph, Defender, Exchange Online, and Power Platform APIs. Nothing is installed on endpoints, no third-party agents are involved, and nothing leaves your tenant except the report. Access is documented during setup and you can revoke it the same day the run completes.

Seven service areas: M365 licensing, Entra ID, Defender XDR, Purview, Power Platform, Copilot Studio, and Agent 365 readiness. Every check is marked Compliant, Warning, or Not Configured with a priority level and a specific recommendation, plus a Fusion-written executive summary and fix list.

It is a configuration-level scan, not a compliance guarantee, and Microsoft's own documentation says the same about the engine. It reads tenant settings through APIs; it does not review governance policy, shadow-AI usage, or the content your users have actually overshared. Those questions belong to the paid AI Technical Readiness Assessment.

Yes. The Purview and data-protection findings are read against the expectations Canadian regulators and insurers actually apply: PIPEDA federally, PHIPA for Ontario health information, and Quebec's Law 25. The scan runs read-only inside your own tenant, so data residency is unaffected, and Fusion Computing is Canadian-owned and Canadian-staffed. The branded report notes where a finding carries a Canadian compliance implication, not just a Microsoft best-practice one.

The scan is the automated, free entry point: a snapshot of what your tenant configuration allows today. The AI Technical Readiness Assessment is the paid, CISSP-led engagement for the broader review: how AI reaches your data across Copilot and the third-party tools your staff use, permissions and oversharing, identity scoping, and a remediation roadmap. Scope and deliverables are confirmed in writing before work begins. Run the scan first; commission the assessment where it flags risk.

Especially then. Most Warning rows we see are Purview and Entra ID settings that decide what Copilot can surface to whom. Running the scan after purchase tells you whether to widen the rollout or fix data protection first, before more users start asking Copilot questions.

About an hour of your time across two calls, with the automated run and our interpretation in between. Booking to branded readout is typically a few business days.

See what Copilot will actually find

Book the free scan. Read-only, automated, and the branded report is yours whether or not you ever buy anything from us.