Copilot for Microsoft 365: 6 Critical Checks Before You Buy
Copilot for Microsoft 365 is unusual among IT purchases in that the thing most likely to go wrong is not the product. It is the state of your tenant on the day you turn it on. The licence is the easy part; what decides whether it is useful or embarrassing is a permissions model most organisations have never audited.
This is written for the person who has to answer “can we just buy Copilot?” It is not a review, and it does not tell you whether the AI is any good — that depends on your work. It sets out six things that are true before you buy, all of them from Microsoft’s own documentation, several of which are the reason a rollout stalls.
1. There are three products and they share a name
Start here, because half the confused conversations about Copilot for Microsoft 365 are actually two people discussing different products.
Microsoft 365 Copilot Chat is “automatically included and available to organizations that have an eligible Microsoft 365 subscription”. It comes in two flavours, and the distinction is the whole point: web-based chat “shows results from the internet” and is included “at no extra cost”, while work-based chat “shows results that the Microsoft Entra work or school account can access” and “is available with a Microsoft 365 Copilot license”.
So when someone says “we already have Copilot”, they usually have the free one, which cannot see a single file in your tenant. It is a competent chatbot with your company’s sign-in attached. The thing that reads your email and your SharePoint is the paid add-on.
Microsoft 365 Copilot is that add-on, and it attaches to a long list of base plans including all the Enterprise and Business ones. Microsoft 365 Copilot Business is a separate, narrower SKU whose prerequisites are only Business Basic, Business Standard, Business Premium and Apps for Business. Two add-ons, similar names, different lists.
We are not publishing a per-seat price. Microsoft’s technical documentation does not carry one — it links out to a commercial page — and what you pay depends on your agreement, your term and your currency. A number quoted here would be decoration rather than information.
2. Your SharePoint permissions become your AI policy
This is the sentence to take to whoever signs the purchase order. Microsoft’s data and privacy documentation states it plainly: “Microsoft 365 Copilot only surfaces organizational data to which individual users have at least view permissions.”
Read as reassurance, that sounds like a control. Read as a specification, it is a warning. Copilot does not grant new access and it does not leak across tenants — the Semantic Index “honors the user identity-based access boundary”. What it does is make existing access usable. A finance folder that was technically open to all staff but practically invisible because nobody browsed there is now one plain-English question away.
Microsoft puts the obligation exactly where it belongs, in the same paragraph: “It's important that you're using the permission models available in Microsoft 365 services, such as SharePoint, to help ensure the right users or groups have the right access to the right content within your organization.” And it explicitly extends that to external parties — “this includes permissions you give to users outside your organization through inter-tenant collaboration solutions, such as shared channels in Microsoft Teams”.
That is the real project. Buying Copilot for Microsoft 365 is a licensing exercise; being ready for it is a permissions clean-up, and the second one takes considerably longer. It is the same argument we made about the defaults that decide a distributed architecture — access nobody chose is still access.
3. The mailbox rule that catches people after they have paid
From the app and network requirements, stated twice on the same page because it surprises people: “Microsoft 365 Copilot is only supported on primary mailboxes that are hosted on Exchange Online. It isn't available on a user's archive mailbox, group mailboxes, or shared and delegate mailboxes that they have access to.”
If your organisation runs shared mailboxes as the front door — accounts, support, bookings, the ones a small business actually lives in — Copilot will not summarise them. Neither will it reach the archive, which for anyone with a large mailbox is where most of the history sits. That is not a bug, it is the supported scope, and it is worth establishing before somebody demonstrates Copilot to the finance team using the one mailbox that matters most to them.
4. Four settings that silently stop it working
The same requirements page lists prerequisites that are easy to fail quietly, because each produces an absence rather than an error.
- Privacy controls for connected experiences. If you have turned off connected experiences that analyse content — a setting many security-conscious organisations enabled years ago and never revisited — Copilot features “won't be available” in Word, Excel, Outlook, PowerPoint or OneNote.
- Device-based licensing. “Copilot isn't available when using device-based licensing for Microsoft 365 Apps for enterprise.” Shared-device estates should check this first, not last.
- WebSockets and TLS inspection. Copilot needs full WSS
connectivity to
*.cloud.microsoftand*.office.com. Microsoft names the culprits directly: a perimeter blocking WSS, “network devices attempting to perform Transport Layer Security (TLS) inspection”, and proxies with aggressive timeouts. - Meeting content. For Copilot to reference a Teams meeting after it ends, transcription or recording must be enabled — which is a policy and consent question in most organisations, not a toggle.
None of these throw an error that names the cause. The user simply does not see the button, and raises a ticket saying Copilot is broken.
Microsoft publishes a diagnostic for exactly this, and it is worth knowing before the first ticket rather than after: the Copilot License Details check, which Microsoft recommends using “to verify that a specific user account meets the necessary requirements to access Copilot features”. Run it against a real account rather than reasoning about the licence assignment from the admin centre, because the prerequisites for Copilot for Microsoft 365 span licensing, mailbox type, app privacy settings and network path at once, and only one of those is visible on a user’s licence page.
5. Where the data goes, and the exclusion worth reading
Microsoft is unambiguous, and repeats it twice on the privacy page: “Prompts, responses, and data accessed through Microsoft Graph aren't used to train foundation LLMs, including those used by Microsoft 365 Copilot.” Abuse monitoring with human review, available in Azure OpenAI, is something “Microsoft 365 Copilot services have opted out of”.
Interactions are retained, though. Prompts and responses are stored as a user’s Copilot activity history, encrypted, discoverable through Content search and Purview, and subject to retention policies you set. Users can delete their own history from the My Account portal. Anyone with a records-retention obligation should decide that policy before rollout rather than after the first request lands.
On residency, EU traffic stays inside the EU Data Boundary. But one line deserves more attention than it gets: “Models provided by Anthropic as a subprocessor are currently excluded from the EU Data Boundary.” Admins choose whether third-party models are used, so this is a decision available to you — but only if you know it exists. Customers outside the EU “may have their queries processed in the US, EU, or other regions”, which is worth knowing if you are answering a client questionnaire about where their data is handled.
6. The commitments are real, and they are conditional
Microsoft’s Copilot Copyright Commitment says that if a third party sues a commercial customer over the output, Microsoft will defend them and pay resulting judgments or settlements — “as long as the customer used the guardrails and content filters we have built into our products”. That clause is doing real work. An organisation that disables safety features to make Copilot more compliant may also be stepping outside the indemnity.
Two further limits belong in any internal policy. Microsoft states that generative AI responses “aren't guaranteed to be 100% factual” and frames the output as drafts for review rather than automation. And there is a restriction that surprises people in a good way: Microsoft blocks inferences, judgments or evaluations about an employee’s “performance, attitude, internal or emotional state, or personal characteristics” — so Copilot will not be your performance-management tool, by design.
One more governance surface arrives with the product rather than after it. Copilot for Microsoft 365 can be extended with agents and Microsoft Graph connectors that reach systems outside the tenant, and data from a connector “can be returned in Microsoft 365 Copilot responses if the user has permission to access that information”. Admins keep the decision: “Admins have full control to select which agents are allowed in their organization”, and the admin centre shows each agent’s required permissions and data access before you approve it. That is a consent decision of exactly the kind we covered in the architecture defaults piece, and it should sit with whoever already owns app consent rather than being handled ad hoc.
What to do before you buy Copilot for Microsoft 365
In order, and only the last one costs anything. Run a permissions review of the sites and libraries a curious employee would ask about first — finance, HR, legal, the leadership team’s workspace — and pay particular attention to anything shared externally. Confirm which of your mailboxes are shared or delegate, because those are out of scope. Check the connected-experiences privacy setting and whether you use device-based licensing. Decide your retention policy for Copilot activity history, and decide whether third-party models are permitted given the residency note.
Then buy a small number of licences and expand, rather than the reverse. The failure mode we would expect here is not that the AI disappoints. It is that it works exactly as documented, on a permissions model nobody had looked at in three years.
If the permissions half of that sounds like the larger problem, it usually is, and it is the same work as cybersecurity risk management rather than anything AI-specific. Our IT architecture and design work covers the tenant review this needs.