Microsoft Copilot specifications
| What it is | An assistant embedded across Microsoft 365, grounded in your tenant’s own content |
| Sees | Documents, mail, chats and meetings the signed-in user already has permission to open |
| Surfaces | Word, Excel, PowerPoint, Outlook, Teams, plus a standalone chat |
| Licensing | Per-user add-on on top of an existing Microsoft 365 subscription |
| Governance | Inherits tenant permissions, sensitivity labels, retention and audit |
| Consumer version | A separate free Copilot exists and does not see organisational data |
| Hard prerequisite | Correct permissions across SharePoint and OneDrive — see below |
| Poor fit for | Non-Microsoft organisations, small teams, tenants with loose file permissions |
The permissions problem that decides every rollout
What goes wrong
Copilot respects existing permissions exactly. That sounds reassuring and is the source of the most common deployment failure.
Most organisations have SharePoint sites and OneDrive folders shared far more widely than anyone intended — a “everyone in the organisation” link on a salary review, an HR site inheriting open permissions, a finance folder somebody shared in 2019. Nobody notices, because nobody browses to those places.
Copilot browses everywhere at once. Ask it about compensation and it will faithfully answer from a document you technically had access to and never knew existed.
What that means practically
The tool did not leak anything — the permissions were already wrong. But Copilot converts a latent misconfiguration into an immediate and visible one, which is why serious deployments begin with a permissions audit rather than a licence purchase.
Microsoft provides tooling for exactly this. Skipping it is the single most expensive mistake available in this product.
Deploying it without an incident
| 1. Audit oversharing first | Find sites and files shared organisation-wide. This is the whole risk, and it exists before Copilot arrives — Copilot only makes it findable. |
| 2. Apply sensitivity labels | Labels are how you keep genuinely restricted material out of scope. Without them, permissions are your only control. |
| 3. Pilot with one department | Ideally not HR or finance. A pilot surfaces the permissions problems while they are small. |
| 4. Tell users which Copilot they have | The free consumer version cannot see tenant data. Users comparing the two conclude the paid one is broken, or worse, paste work material into the consumer one. |
| 5. Start in Teams and Outlook | Meeting recaps and mail triage deliver value immediately. Excel is the weakest surface and a poor first impression. |
| 6. Measure actual usage after 60 days | Per-user licensing across a whole organisation is expensive, and adoption is frequently concentrated in a minority. |
Copilot against Gemini, and against the standalone assistants
| What decides it | Microsoft Copilot | Google Gemini |
|---|---|---|
| Reads your own data | Microsoft 365 tenant | Google Workspace |
| Governance maturity | Strong — labels, audit, retention | Workspace-level |
| Best surfaces | Teams, Outlook | Gmail, Docs |
| Weakest surface | Excel, despite expectations | Uneven across apps |
| Standalone quality | Behind the leaders | Competitive |
| Choose when | You are a Microsoft organisation | You are a Google organisation |
As with Gemini, this is not really a model comparison. Organisations choose the assistant that can already see their files, and that decision was made by whoever chose the email platform years ago.
Judged purely as a chat assistant against ChatGPT or Claude, Copilot is not the strongest option. Nobody buys it for that.
Where it disappoints in practice
- Excel is weaker than everyone expects. The application people most want AI help with is the one where it delivers least reliably.
- Quality varies sharply by surface. Teams recaps are genuinely good; some other integrations are a sidebar.
- It only knows what is in the tenant. Knowledge in people’s heads, in email nobody kept, or in another system is invisible.
- Per-user licensing across everyone, used heavily by a minority.
- Naming confusion costs real support time.
Who Copilot is for
Organisations already committed to Microsoft 365 with reasonable information governance. Enterprises whose compliance requirements rule out consumer AI tools — the tenant-level controls are the reason this product exists. Teams heavy on Teams meetings, where recap and catch-up are the strongest features.
Not for non-Microsoft organisations, for small teams where per-user licensing outweighs the benefit, or for tenants whose permissions have never been audited — those should fix the permissions first regardless of whether they ever buy this.
Other enterprise assistants
- Google Gemini — the same argument for Google organisations.
- ChatGPT — stronger standalone, without tenant grounding.
- Writer — when the requirement is enforcing style and compliance.
- Notion AI — if the knowledge actually lives in Notion.
Compiled from Microsoft’s documentation and public sources. We have not hands-on tested this tool. Last reviewed 17 August 2026.