Use structured tenant discovery to identify Copilot readiness gaps, governance blockers, security risks, and the first AI engagement your MSP can scope with confidence.
Why this matters: Baseline data collection should be structured and repeatable. These scripts reduce the time spent gathering tenant facts so the assessment can focus on interpretation, stakeholder interviews, and remediation planning.
Install these PowerShell modules on the engineer machine running the discovery. You need a work account with Global Reader + Security Reader + Exchange View-Only in the client tenant — temporary assignment, remove after engagement.
Install-Module Microsoft.Graph -Scope CurrentUserInstall-Module ExchangeOnlineManagement -Scope CurrentUserInstall-Module MicrosoftTeams -Scope CurrentUserInstall-Module Az.Accounts -Scope CurrentUserInstall-Module PnP.PowerShell -Scope CurrentUser| Role | Required? | Notes |
|---|---|---|
| Global Reader | Required | Minimum for read-only discovery. Can be temporary — remove after engagement. |
| Exchange View-Only Organization Management | Required | Required for Exchange Online discovery. |
| Teams Administrator | Optional | Needed if scoping Teams governance. Can use Global Reader for basic Teams config. |
| SharePoint Administrator | Optional | Needed for full SharePoint site-level data. PnP requires explicit site access. |
| Security Reader | Required | Needed for Defender, Secure Score, and Conditional Access policy reads. |
Start with tenant setup and profile discovery to frame the client conversation. The Integrator toolkit extends this into Copilot footprint, security posture, data governance, usage, automation readiness, report compilation, workbook, and client report templates.
The complete system turns raw tenant findings into a client-ready readiness report, roadmap, and scoped follow-on engagement.
You now have structured data. Here is what to do with it before the client presentation.
Open the HTML report first. RED findings need to be resolved before any AI deployment. AMBER findings go into the roadmap. Share this internally with your delivery lead before the readout.
Use the risk register output to map each finding to the eight PSF domains. This gives your readout structure and connects every finding to a recognised governance framework.
The scripts get the technical picture. The interviews get the human one. Use the Assessment Facilitation Guide to run structured conversations with business owners before presenting.
Sort findings by RAG status and business impact. Red findings = immediate blockers. Amber = 30-day targets. Green = baseline to maintain. Each finding becomes a scoped deliverable.
The discovery report, risk register, roadmap, and ROI model together form the readout deck. Use the assessment report template from the toolkit and the ROI calculator to complete the package.
Every finding should resolve to a concrete next step. The next scope may cover remediation, policy work, or deployment depending on what the client prioritises.
These engagement artefacts help delivery teams turn discovery output into a board-ready readout, roadmap, and proposal.
Use this discovery path to identify blockers, shape the roadmap, and package a credible first AI engagement for the client.
Foundational reference pages for practitioners and teams evaluating production AI safety, agent readiness, and certification paths.