What it does
The Copilot Control System (CCS) is Microsoft's umbrella name for the admin surfaces that govern Copilot: managing access, securing data, and measuring adoption. It's not a single console — it's a badge stuck on tools you already touch (Microsoft 365 admin center, Purview, Entra, the Copilot dashboard).
Key facts
- Three pillars: manage (agents, licences, settings), secure (Purview, oversharing controls, DSPM for AI), measure (usage and adoption reporting).
- Most controls live in the Microsoft 365 admin center under Copilot, plus Purview and Entra for the security half.
- No extra SKU to "turn on" CCS — it's the framing, not a product line item.
- Agent governance and pay-as-you-go controls fold in here too.
When to use / skip
You don't opt in or out. Treat CCS as the checklist for what you must configure before and after enablement. Skip the marketing framing; go straight to the underlying consoles.
Configuration decisions
- Who holds which admin role across admin center, Purview and Entra.
- Whether security posture (oversharing, sensitivity labels) is signed off before licences land.
Gotchas
- People hear "Control System" and expect one dashboard. It's a collection of existing tools — set expectations early or you'll field confused questions.
- Security controls sit in Purview, not the Copilot blade. Easy to miss if you only look where the licences are.
Consultant notes
- Use CCS as a readiness rubric with the customer, not a product pitch — it maps neatly onto a rollout plan.
- Get Purview and Entra owners in the room early; the "secure" pillar is where projects stall.
- Oversharing remediation belongs before enablement, not after users start asking Copilot awkward questions.
- Agree who owns the "measure" pillar — adoption reporting drifts without a named owner.
Recheck when Microsoft reshuffles the admin center Copilot blades.