What is Microsoft 365 Copilot?
By Emil Björk · Microsoft ecosystem consultant, Gothenburg
Microsoft 365 Copilot brings generative AI into Word, Excel, Outlook, Teams, and the rest. What it actually does, how grounding works, what it costs, and what to fix before rollout.
Microsoft 365 Copilot is Microsoft's generative-AI assistant embedded across the Microsoft 365 apps. It drafts documents, summarises mail threads and meetings, analyses Excel tables, builds slides, and answers questions grounded in your own tenant's content — your files, your emails, your chats. It is also a per-user paid add-on with real prerequisites, so the practical questions are what it genuinely does well, how it gets at your data, and what has to be true of your tenant before you switch it on.
Where it shows up
- Word — drafting from prompts, rewriting passages, summarising long documents. See Copilot in Word.
- Excel — explaining formulas, analysing tables, generating charts and pivots from plain-English questions (Copilot in Excel).
- PowerPoint — generating decks from a Word document or prompt, restyling, speaker notes (Copilot in PowerPoint).
- Outlook — drafting replies, summarising threads, coaching tone (Copilot in Outlook).
- Teams — live meeting recap, action items, "catch me up" on chats and channels (Copilot in Teams); the meeting features are the most consistently praised part of the whole product.
- Microsoft 365 Copilot Chat — the standalone chat surface (in Teams, the Microsoft 365 app, and the browser) that answers questions across everything you can access in the tenant, or against the web.
- Plus Copilot experiences in SharePoint, OneNote, Loop, Planner, Forms, and Stream, with the list growing every quarter.
Beyond the built-in experiences, agents extend Copilot with custom behaviour and external data — built declaratively or in Copilot Studio.
How it works: grounding is the whole trick
Copilot uses frontier large language models, but the models aren't the differentiator — access is. When you prompt Copilot, it first retrieves relevant content from your tenant through the Microsoft Graph: files, mail, chats, meetings, people, and their relationships. That retrieved context is fed to the model alongside your prompt, and the response cites its sources. This is retrieval-augmented generation applied to your working life, and it's why Copilot can answer "what did we decide about the Q3 pricing change?" while a consumer chatbot can't.
Three properties follow from the architecture, and they're the ones that matter in governance conversations:
- Copilot respects existing permissions. It retrieves only what the signed-in user can already open. It never grants access.
- But it makes existing access discoverable. Files a user could always open but would never have found are now one question away. Copilot doesn't create oversharing; it puts a searchlight on it.
- Prompts and responses stay in the tenant's compliance boundary. They aren't used to train the foundation models, and they're subject to retention, eDiscovery, and audit like other Microsoft 365 content. The detail lives in Microsoft 365 Copilot data security.
Licensing
Microsoft 365 Copilot is a per-user add-on (list price around $30/user/month, annual commitment) on top of a qualifying base licence — Business Standard, Business Premium, E3, or E5 among others. There's no E5-style bundle that includes it; everyone pays the add-on. The maths, the qualifying SKUs, and the "who actually needs a licence" question are covered in Microsoft 365 Copilot licensing.
The free tier muddies naming: Microsoft 365 Copilot Chat (no add-on licence) gives signed-in users web-grounded chat with enterprise data protection, plus pay-as-you-go agent options — useful, but it does not touch your tenant content. The paid licence is what buys tenant grounding and the in-app experiences, and that's where the real value sits.
What to fix before rollout
The technical enablement is a licence assignment; the project is everything around it:
- Permissions hygiene first. Overshared SharePoint sites, "Everyone" links, and ancient open Teams become visible fast. SharePoint permissions, external sharing, and the reports in SharePoint Advanced Management are the pre-work — the full checklist is in Copilot rollout prerequisites.
- Baseline sensitivity labels. Copilot honours encryption and label-based restrictions, making labels one of the few sensitivity-aware controls over what it retrieves.
- Pilot with intent. Pick users with real use cases, measure, and expand on evidence — see pilot best practices.
- Invest in adoption. Usage drops off after week two unless people learn where Copilot is genuinely good (meetings, summarisation, first drafts) versus merely present. The adoption playbook and prompt engineering guide cover this.
An honest assessment
Where Copilot earns its price today: meeting recap and catch-up, summarising long threads and documents, first drafts of routine writing, and finding things you didn't know existed. Where it still underwhelms: complex Excel work on messy real-world workbooks, polished decks straight from a prompt, and anything requiring judgement about which the tenant holds no written context. Licence the people whose weeks are made of meetings and correspondence first; be more sceptical about blanket enterprise-wide assignment until your own pilot data argues for it.
The one-line summary: Copilot is a permissions-respecting retrieval layer over your tenant with a language model on top. Get the permissions and labels right and it's the most useful thing Microsoft has shipped in years; skip that work and it's a very efficient oversharing detector.
Spot something wrong or want a topic covered? Send it through the contact form.