What it does
Microsoft 365 Copilot is the AI layer that sits across Word, Excel, PowerPoint, Outlook, Teams and Copilot Chat. It combines a large language model with your organisation's Microsoft Graph data and the apps you already use.
Key facts
- The pipeline is roughly: user prompt → grounding against Microsoft Graph and the semantic index → call to the model → response with citations back into the app.
- It respects existing permissions. Copilot only surfaces content the signed-in user can already open. It does not widen access.
- Prompts and responses stay inside your Microsoft 365 service boundary and aren't used to train the foundation models.
- Requires Microsoft 365 Copilot licences assigned on top of a qualifying M365/Office 365 base plan.
When to use / skip
This is the whole-suite play, not a single feature. If you're scoping a Copilot rollout at all, start here to set expectations about what "grounding" actually means before anyone touches a licence.
Configuration decisions
- Who gets the first tranche of licences, and on what criteria.
- Whether Copilot Chat can reach the web, and under which policy.
- How you'll handle oversharing before you switch anyone on.
Gotchas
- Copilot inherits your permissions mess. If SharePoint is oversharing, Copilot makes that instantly visible to everyone.
- "It respects permissions" is true but not reassuring on day one — that's exactly why the oversharing surfaces.
Consultant notes
- Do the SharePoint/OneDrive access review before rollout, not after. This is where most projects wobble.
- Licences are pricey and assigned per user — build a real business case, don't sprinkle them around.
- Value tracks adoption, not deployment. Budget for enablement, not just the switch-on.
Worth revisiting after the next release wave.