When I sit down with an IT leader to talk about Microsoft 365, the conversation almost always starts in one of three places. They already own the licenses and want to make sure they're getting value from them, they're weighing the financial or technical impact of moving up a tier, or a renewal is coming and they want to make the right call before they sign. Wherever it starts, they want to know where they stand and what the sensible next step is to ensure they actually get the benefits from the capabilities.
Over hundreds of those conversations, I noticed that most organizations take the same path through Microsoft 365, in roughly the same order (but maybe at different speeds), and I built the model below from that path. Once you can find your level, you can usually see your next step.
From the deck · The Microsoft 365 Maturity Model

Most organizations take the same path through Microsoft 365
The path follows the licensing tiers, because each tier adds what the next stage needs.
Level 1: Cloud Connected (Office 365). Your collaboration platform runs in the cloud, with mail in Exchange Online, files in OneDrive and SharePoint, and chat and meetings in Teams. Most of the organizations I work with finished this level years ago because they wanted to get out of the Exchange business. This was also their first step into cloud identity with Entra ID. Where it still comes up short is the departmental file shares left on a server in the closet, which limits what Purview and Copilot can do later, and backup. Microsoft keeps the service running, and keeping a copy of your data is still your job. It's actually in the terms of service that they recommend backups. Microsoft 365 Backup covers it natively, and Cohesity and Rubrik are great third-party options as well. You're here when your last on-premises Exchange server is retired and most have checked this box already as done. The benefit is more resilient communication and collaboration with a reduction in storage costs on-premises.
Level 2: Managed Everywhere (E3). Devices and identities are secured and managed from the cloud. Identities are protected with MFA, conditional access, and Windows Hello. Devices are provisioned with Autopilot, get their policy from Intune instead of domain controllers, and stay patched through update rings and Autopatch. This is the lightbulb moment for most businesses I work with, because it takes a lot of work off the IT team that they'd rather not be doing, like re-imaging machines, chasing patches, and troubleshooting policy that only applies when a laptop can see a domain controller. You're here when you could replace any laptop by shipping a new one to the user's house. The benefit here is more consistency, security, and compliance at the endpoint that leads to a reduction in time spent troubleshooting issues and managing logistics. The real win here is most take some big steps forward in securing their identity platform (Entra) across those endpoints but also into SaaS apps via Single Sign-On (SSO).
Level 3: Secured and Compliant (E5). Security operations and data protection cover modern threats. E5 adds a productivity bundle (Teams Phone, Power BI, and process automation), a security bundle (Defender across endpoints, email, identity, and cloud apps, plus Privileged Identity Management for admin accounts), and a compliance bundle (Purview to classify, label, and protect your data). This is where I see the biggest security and compliance gaps close, and where organizations consolidate the most vendors (cost and time savings), since the productivity bundle alone can retire a phone system and standalone BI tools. You’ve completed this step once you have a security platform across identity and endpoints that secures your access to data, networks, and applications while also working hand in hand with your compliance platform. The benefit is when you can confidently make intelligent conditional access decisions based on all the various signals available to you.
Level 4: AI Governed (E7). Secure, governed AI is in use to accelerate your business. E7 adds Copilot, Entra Suite, and Agent 365, so Copilot works on labeled, permission-trimmed data, identities are governed for both people and agents, and every agent is inventoried whether it came from Microsoft or a third party. You're here when you know which agents are running in your business and what data they touch, and you can manage and monitor them 24x7 like you can your users. The benefit is extending your security and compliance to agentic actions using the same methods and platforms you do for your users.
Each level makes the next one work
This is the part of the model I lean on most when we plan. Managed devices give conditional access real device signals to act on. Copilot can read everything a user already has access to, so the data labeling at Level 3 is what makes it safe to turn on. And agent governance at Level 4 depends on the identity, security, and compliance controls built at Levels 2 and 3. Taking the levels in order means each one's benefits show up sooner, because the groundwork for the next level is already in place.
How to use it depends on where you're starting
You already own the licenses
This is the one I see most, especially with E5. An organization moved to E5 for the security and compliance bundles, turned Defender on and never finished hardening it, and hasn't touched Purview yet. It's easy to buy these things, and you still have to deploy them and build them. The next step for that organization is finishing the level it already pays for, and in my experience that's the fastest return in the whole model.
You're weighing the financial or technical impact of the next level
On the financial side, the question is what the next level lets you retire as well just as much as it is what gaps it fills. My rule of thumb for E5 hasn't changed: it makes financial sense if you need two or more capabilities from the productivity, security, and compliance bundles, and the third-party contracts it replaces (email security, EDR, SIEM, the phone system, compliance platforms, etc.) often cover a good part of the difference.
A renewal is coming up
A renewal is the one point in the year (or 3YR) when the decision is fully open, and I'd rather see organizations make it with a plan than against a deadline. The question is whether to renew as-is, step up a level, or mix tiers by role. The most valuable thing we can do prior to a renewal is to build the plan for implementation against the renewal timelines of solutions you would retire. That way you can have a clear understanding of when you will start to extract the benefits, when other solutions drop off, and the overall cost and business justification to do so.
Where I'd start
Whichever situation you're in, start by finding your level with the "you're here when" line under each one, and be strict about it by counting what's deployed and running, not just what's licensed.
That's also the first thing we do in the M365 Productivity, Security, and Compliance Roadmap engagements I run. It starts with a simple export of your usage reports and your Secure Score. It's not the full story, but it lets us skip the tedious questions and get to the right ones. From there it's a collaborative engagement, usually two to three weeks, that builds a complete picture of what you own, what you need, how to put it in place, and what it costs, and it ends with a phased plan your leadership can fund. Because I've had this conversation hundreds of times, I can usually map the fastest path to the next level and when its benefits start to show up.
The next five posts take one level at a time, starting with Level 2 and the Intune work where most organizations see their first real payoff.
Working through the same problems?
Jason compares notes with IT leaders every week. Reach out on LinkedIn.