What it does
The Copilot Control System is Microsoft's umbrella for the controls admins use to secure, manage and measure Copilot: access, data protection, agent lifecycle and usage reporting in one framing.
Key facts
- It pulls together existing tooling rather than adding a new console: Purview for data security, Entra for identity, the Microsoft 365 admin centre for agent and licence management, and the Copilot dashboard for adoption.
- Agent governance lives here too, covering who can build and deploy agents and what data they reach.
- Reporting surfaces which users and departments are active, useful for licence reclaim and adoption cases.
When to use / skip
Use it as the checklist for a governance review. Skip treating it as a product you deploy, it's a way of organising work you'll do across several admin centres anyway.
Configuration decisions
- Who can create and publish agents, and whether that's restricted to a governed group.
- Which Purview policies (labels, DLP, retention) apply before Copilot goes broad.
- How access is scoped: staged pilot group versus tenant-wide licensing.
Gotchas
- The "control system" name suggests a single pane of glass. In practice you're hopping between four admin centres, and permissions to each sit with different teams. Sort out who owns what before the review, not during.
- Agent controls have shipped in stages. Check the current state in your tenant rather than trusting a six-month-old article.
Consultant notes
- Treat this as the agenda for your Copilot security workstream, then map each item to a named owner. The gaps are always in agent governance and DLP.
- The adoption reporting is genuinely useful for the CFO conversation about licence spend. Pull it before renewal.
- Don't over-promise the single-console experience to admins. Manage expectations and they'll trust you.
*Review when the Copilot Control System documentation is next upda