← All articles
Copilot Cowork · Just released

Is your Microsoft 365 tenant ready for Copilot Cowork?

By Stephen Bennett · 18 June 2026 · 7 min read

Microsoft Copilot Cowork went generally available worldwide yesterday — 17 June 2026. Before any user in your organisation can access it, there are three things that need to be in place: the right licence, usage-based billing configured by an admin, and governance controls that determine whether Cowork operates safely. This guide covers all three.

Action required by 1 July 2026: Tenants with users who were active in the Frontier preview must configure usage-based billing in the Microsoft 365 Admin Centre before 1 July 2026. Without it, those users lose Cowork access. This is an admin action — it cannot be delegated to end users.

What Copilot Cowork actually is

Cowork is best understood as the execution layer for Microsoft 365 Copilot. Where standard Copilot answers questions and drafts content, Cowork takes multi-step actions on your behalf — running tasks across Outlook, Teams, Word, Excel, and SharePoint simultaneously, in the background, without you needing to stay at your desk.

You describe the outcome you want. Cowork builds a plan. It executes the plan with checkpoints where you can approve, pause, or redirect. You get back completed work — not a draft, not a recommendation.

During the Frontier preview, customers used Cowork for spreadsheet editing, dependency flow chart generation, product version comparisons, and full sales pipeline reviews. More than half of the Fortune 500 had access during preview.

Important distinction: Cowork is not a new product you purchase separately. It is a capability included in your Microsoft 365 Copilot licence — but it is billed separately on a usage basis via Copilot Credits. The licence gates access. Billing configuration gates whether usage is actually possible.

Step 1: Verify licence eligibility

1
Check whether your users have a Microsoft 365 Copilot licence

Copilot Cowork is included in the Microsoft 365 Copilot user subscription licence (USL). It is also available via Agent 365 ($15/user/month) and is included in the new Microsoft 365 E7 SKU. It is not available on Microsoft 365 Business Standard, Business Premium, E3, or E5 without a Copilot add-on.

Where to check: Microsoft 365 Admin Centre → Billing → Licences. Look for "Microsoft 365 Copilot", "Agent 365", or "Microsoft 365 E7" in your assigned licences.

PlanCowork accessBilling model
Microsoft 365 Business Standard / Premium❌ Not included
Microsoft 365 E3 / E5 (without Copilot add-on)❌ Not included
Microsoft 365 Copilot (Premium add-on)✓ IncludedCopilot Credits — pay-as-you-go or P3 annual
Agent 365✓ IncludedCopilot Credits
Microsoft 365 E7✓ IncludedCopilot Credits

Step 2: Enable usage-based billing By 1 July 2026

2
Configure billing in the Microsoft 365 Admin Centre

Cowork tasks are billed via Copilot Credits — not included in the per-user licence price. Admins must explicitly enable usage-based billing before any user can access Cowork. Without this step, users will see the Cowork toggle in the Microsoft 365 Copilot app but will not be able to use it.

Where to go: Microsoft 365 Admin Centre → Copilot → Cost Management Dashboard. Choose between pay-as-you-go ($0.01/credit, no commitment) or Copilot Credits P3 (annual commitment, lower per-credit rate).

This is the most common blocker. Licence assignment alone is not sufficient — billing must be separately configured. Many admins who enabled Frontier access during preview have not yet done this step for the GA release. The deadline for existing Frontier users is 1 July 2026.

Step 3: Understand Cowork pricing

Cowork tasks are priced by complexity. Microsoft has grouped usage into three broad categories:

Each task consumes Copilot Credits based on model use, context retrieval, tool calls, and runtime. Microsoft's own testing showed Cowork was 30–40% cheaper per prompt than Claude Cowork using the Microsoft 365 connector. The Cost Management Dashboard provides per-user and per-task visibility once billing is active.

Step 4: Verify governance controls

Cowork operates under the same governance plane as Microsoft 365 Copilot and Agent 365. The controls that determine whether Cowork runs safely in your tenant are the same ones that govern Copilot today — no new stack to learn, no separate governance configuration.

4a
Purview audit logging — must be enabled

Cowork prompts, responses, and generated artefacts are captured in Microsoft Purview audit logs under the same schema as Copilot interactions. This is off by default and must be explicitly enabled. Without it, there is no record of what Cowork did on behalf of your users.

Where to check: Microsoft Purview compliance portal → Audit → Audit retention policies. Look for "Microsoft 365 Copilot" in the workload list.

4b
Sensitivity labels — must be published

Cowork inherits and displays sensitivity labels on documents and artefacts it generates. If labels exist but are not published to users, Cowork-generated content has no classification applied — meaning it could be shared or stored without appropriate protection.

Where to check: Microsoft Purview → Information protection → Label policies. At least one policy should be published to all users.

4c
DLP policies — extend to cover Copilot

DLP for Microsoft 365 Copilot is being extended to Cowork (rolling out in 2026). DLP policies that are scoped to Copilot will apply to Cowork generated content. Ensure existing DLP policies explicitly include Microsoft 365 Copilot as a protected location.

4d
Conditional Access and MFA — enforced for all users

Cowork acts as the authenticated user. A compromised account with Cowork access can execute multi-step workflows — a significantly higher risk than standard Copilot. MFA enforcement and Conditional Access policies covering all users and cloud apps are the baseline controls.

4e
SharePoint external sharing — restrict before deploying Cowork broadly

Cowork accesses SharePoint content on behalf of users to complete tasks. Broadly shared SharePoint sites expand what Cowork can read, reference, and include in outputs. Review external sharing settings before giving large user groups Cowork access.

Check your Cowork readiness automatically

M365Clarity now scans your tenant for Cowork eligibility, billing status guidance, and all 6 governance controls — showing which pass, which need review, and what to fix. Free to scan your own tenant.

Run a free scan →

For MSPs: what to do for each client

Cowork was used by more than half of the Fortune 500 during the Frontier preview. Your clients are likely to start asking about it — and some may already have Frontier users who need billing configured before 1 July.

  1. Identify Frontier exposure first. Any client with users who had Frontier programme access before 16 June needs billing configured by 1 July or those users lose access. Check with each client whether they enrolled in Frontier.
  2. Run a Cowork eligibility scan now. Know which clients have eligible Copilot licences before the conversation happens. M365Clarity shows this per tenant in the Copilot & AI tab.
  3. Governance before rollout. The six governance checks — audit logging, sensitivity labels, DLP, Conditional Access, MFA, SharePoint sharing — should be verified and clean before advising clients to deploy Cowork to broad user populations.
  4. Frame it as the next Copilot conversation. Most clients already have Copilot. Cowork is the natural next question: "Copilot helps you get answers — Cowork gets the work done." The governance readiness work you've already done for Copilot applies directly to Cowork.

M365Clarity for MSPs shows Cowork eligibility and governance readiness scores across all client tenants — in one portfolio dashboard. Identify who needs action before 1 July and who is ready to deploy. Start an MSP trial.

Summary — the four-step Cowork readiness checklist

  1. Licence check — confirm Microsoft 365 Copilot (Premium), Agent 365, or E7 is assigned to the users who will access Cowork
  2. Enable usage-based billing — M365 Admin Centre → Copilot → Cost Management Dashboard. Required before any user can use Cowork. Frontier users: do this before 1 July 2026.
  3. Set spending policies — configure spending controls and monitoring in the Cost Management Dashboard to avoid unexpected Copilot Credits consumption
  4. Verify governance controls — Purview audit logging on, sensitivity labels published, DLP covering Copilot, Conditional Access + MFA for all users, SharePoint sharing restricted

Items 1, 3, and 4 are standard Copilot readiness work. Item 2 — enabling usage-based billing — is the single new step that most admins will miss.

Related articles