Microsoft 365 Copilot is the AI assistant built into Word, Excel, PowerPoint, Outlook, Teams and OneNote. It drafts, summarises and answers questions using your organisation's own emails, files, chats and meetings as well as the web. It was launched as Copilot for Microsoft 365 and Microsoft has since renamed it, so you will see both names used for the same product.
This guide covers what Copilot does, how it gets to your data, the different versions and what they include, what needs to be in place before you roll it out, and how to judge whether it is paying for itself. It is written for the people who have to make the decision and then live with it, usually IT, digital workplace and operations leads.
Microsoft 365 Copilot is a large language model assistant that works inside the Microsoft 365 apps people already use. The difference between it and a public chatbot is grounding. When someone asks Copilot a question, it looks through the content that person already has access to in Microsoft 365, through Microsoft Graph, and uses that to build the answer. So "summarise what was agreed about the Glasgow office move" comes back with an answer drawn from the actual emails, Teams chats and meeting notes, with links to the sources.
It sits in two places. There is Copilot Chat, a chat window in Teams, Outlook, the Microsoft 365 app and the browser, where people ask questions across all their work content. And there is Copilot inside each app, which works on whatever is open in front of you: a document in Word, a spreadsheet in Excel, a thread in Outlook or a meeting in Teams.
The time savings come from the dull parts of the job: the first draft, the catch-up after a week off, the meeting notes nobody wanted to write. Copilot is less useful for work that depends on judgement or on information that is not in Microsoft 365 at all.
Copilot only uses content the signed-in user already has permission to see. Microsoft's documentation describes access as scoped by user permissions, with security and compliance controls enforced, and prompts and responses covered by the same contractual commitments as email in Exchange and files in SharePoint.
That sounds reassuring, and from a security point of view it is. The catch is that most tenants have far more open than anyone realises. Sites shared with "everyone except external users", old Teams with nobody left as owner, folders shared with a link years ago and never tidied up. Before Copilot, all of that was technically visible but nobody went looking. Copilot goes looking every time someone asks a question, and it will happily summarise a salary spreadsheet or an HR case file for someone who should never have had access in the first place.
So the question to ask before rollout is not whether Copilot is secure. It is whether your permissions are right, because Copilot will expose every mistake in them.
Microsoft currently separates Copilot into three levels, and the naming causes a lot of confusion.
All three are covered by Enterprise Data Protection when users sign in with their work accounts, and for customers in the EU, traffic stays within the EU Data Boundary. Microsoft changes the packaging and the pricing regularly, so check the current position before you budget. We are happy to talk it through against your existing licences.
The licence is the easy part. These are the things that decide whether the rollout goes well:
We run a Copilot readiness assessment that checks all of this across the whole tenant and ranks the issues by risk and effort, so you know what has to be fixed before switching Copilot on and what can wait. If you want the wider view of where AI would pay back across the organisation, not only Copilot, our AI readiness assessment covers that.
We would not recommend licensing everyone on day one. A phased rollout gives you evidence before you commit the budget.
Our Microsoft 365 Copilot service covers the rollout, training and adoption, and we can pick up the governance work through SharePoint governance if the assessment finds gaps.
It depends on who gets it and whether they use it. Copilot pays back fastest for people who spend a large part of their week in email, meetings and documents, and slowest for people whose work happens mostly outside Microsoft 365. A licence that sits unused is pure cost, which is why usage reporting matters as much as the rollout itself.
The organisations that get value from it tend to do three things: they sort out their content and permissions first, they give people practical training on their own tasks, and they review licence usage every quarter and move licences to where they are being used.
Copilot on its own answers questions across your content. Agents take it further by focusing on a particular job, such as answering HR policy questions, handling IT requests or working through a specific process, and they can connect to systems outside Microsoft 365. Simple agents can be built by the business, and more involved ones are built in Copilot Studio. The same rule applies: an agent is only as good as the content and permissions underneath it, so the readiness work pays off twice.
Yes. Microsoft launched the product as Copilot for Microsoft 365 and later renamed it Microsoft 365 Copilot. Both names refer to the AI assistant built into the Microsoft 365 apps.
No. Copilot only uses content the signed-in user already has permission to access. The risk is that many users have access to more than they should, because of old sharing links and overly open sites, and Copilot makes that content much easier to find.
Microsoft states that prompts and responses are protected by the same contractual terms that apply to email in Exchange and files in SharePoint, and that Enterprise Data Protection applies when users sign in with their work accounts. Your organisation's data is not used to train the underlying foundation models.
If your tenant has grown over several years without a regular permissions review, yes. The assessment finds the oversharing, unowned sites and stale content that would otherwise turn up in Copilot's answers, and gives you a plan to fix them before rollout.
A readiness assessment typically takes two to three weeks. The fixes that follow depend on what it finds, but most organisations can start a pilot within a few weeks by dealing with the high risk issues first and working through the rest alongside it.
Word, Excel, PowerPoint, Outlook, Teams and OneNote, plus Copilot Chat in Teams, Outlook, the Microsoft 365 app and the browser.
ThinkShare is a Microsoft partner specialising in SharePoint, Microsoft 365 and AI readiness. If you are planning a Copilot rollout, or you have licences that are not being used as much as you hoped, get in touch and we will talk it through.