To control who can use Copilot Cowork, create a usage-based billing spending policy scoped to the intended users or Entra security group and select Cowork under the policy’s agents and services. Cowork is generally available; the former Frontier or Preview Cowork toggle no longer grants or denies access. Microsoft’s current Cowork admin guide and access guide describe the policy-based controls, while its Copilot security and governance overview covers broader Microsoft 365 protections. The steps below reflect those Microsoft Learn pages as accessed on October 4, 2026.
Understand which settings grant access
Access depends on spending-policy scope, not on whether Cowork is visible in the interface or which models are available. In the Microsoft 365 admin center, a user has Cowork access if at least one spending policy that applies to them selects Cowork. Multiple applicable policies can grant access; a more restrictive policy does not override a more permissive one.
- Access: An applicable usage-based billing spending policy selects Cowork.
- Visibility: The discoverability setting controls whether Cowork appears across Microsoft 365. It does not revoke policy-based access.
- Models: Model settings affect which models an eligible user can select. Microsoft says admins can turn off the Anthropic model family while leaving users able to use other permitted models.
- Spending: Limits constrain consumption, but they are not an access-denial switch. Microsoft’s access guide gives the example of a one-credit limit: the user still has access until that limit is reached.
For a user who should not have access, remove them from every applicable policy that selects Cowork. Changing discoverability, disabling a model family, or setting a very low limit is not a substitute.
Set up a controlled access group and spending policy
- Define the audience. Decide which users may use Cowork. For a pilot or staged rollout, an Entra security group gives you a clear audience to scope. If replacing a former preview allow-list, Microsoft’s admin guide describes representing that audience with an Entra security group.
- Inspect existing policy coverage. In the Microsoft 365 admin center, go to Copilot > Cost Management > Configuration. Review all spending policies and their scopes before creating or changing one; an existing overlapping policy that selects Cowork may already grant access to users outside the group you intend to enable.
- Create or edit the intended policy. Scope the policy to the chosen users or group and select Cowork under its agents and services. Verify the resulting scope and selection rather than assuming the new policy overrides other policies.
- Set a consumption limit deliberately. Cowork uses usage-based billing. Model responses, tool and skill calls, image generation, and browser tasks contribute to organizational consumption. Set appropriate per-user or per-group limits for the intended pilot, understanding that a limit only stops further use when reached; it does not keep the user from starting.
- Verify the effective audience. Check policy scopes for both intended users and users who should remain excluded. Recheck after group membership or policy changes, since any applicable policy selecting Cowork can grant access.
Decide what users can discover and which models they can use
Discoverability
Use the Cowork discoverability control to determine whether users see Cowork across Microsoft 365. Treat this as a presentation setting, not an entitlement control: a user covered by a Cowork-selecting spending policy can retain access even when discoverability is off.
#1 Best Overall
Model availability
Use model settings to limit the model choices offered to users who have Cowork access. Turning off the Anthropic model family, for example, changes the available choices; it does not remove the user’s Cowork access. Keep the model decision separate from the access policy so that each control has a clear purpose.
Govern plugins and connector reach
Cowork plugins from the Microsoft 365 App Store can add skills and connectors. Review which plugins are available, which are deployed, and which audiences can use them before enabling them broadly. Store availability alone is not evidence that a plugin’s connector permissions are appropriate for your organization.
Rank #2
- Review the connector authentication and permissions required by each plugin.
- Limit plugin availability and deployment to the audiences that need the capability.
- Use Microsoft’s plugin administration guidance for connector authentication and monitoring, and include plugin activity in your operational review.
Apply least privilege to connector access and assess the systems and data a connector can reach. A user’s ordinary access scope and the connector’s permissions both matter when evaluating the practical reach of a plugin.
Choose whether Cowork can use the browser
Cowork can perform web tasks in Microsoft Edge on a user’s device. Admins can turn Cowork browsing on or off for the tenant. Decide whether that capability fits the use case, then assess it under existing browser and data policies rather than as a separate, unrestricted path to the web.
Rank #3
- Browser tasks inherit existing Conditional Access, DLP, and tenant browsing policy.
- Existing Edge allowlists, blocklists, and view-only policies determine which sites are reachable.
- Cowork browser activity is recorded in the unified audit log.
Include the browser decision in the rollout approval and monitoring plan. If browser use is permitted, review the relevant Edge site controls and audit process alongside the Cowork tenant setting.
Apply the Microsoft 365 information-protection baseline
Before enabling Cowork for a wider audience, review whether users’ SharePoint and OneDrive permissions expose more content than intended. Microsoft’s Copilot security and governance overview recommends using SharePoint Advanced Management and Microsoft Purview capabilities, where licensed, to identify oversharing and manage access.
Rank #4
Align the rollout with the organization’s existing controls for sensitivity labels, DLP, retention, audit, and eDiscovery. The Microsoft overview groups foundational controls with A3/E3/G3 plans and optimized controls with A5/E5/G5 plans, but those groupings are not a guarantee that every feature is included for every tenant. Confirm each control’s entitlement and configuration against the tenant’s actual license before relying on it.
- Review broad or inherited SharePoint and OneDrive permissions and remediate unintended access.
- Confirm the sensitivity-label, DLP, retention, audit, and eDiscovery policies that apply to the intended users and content.
- Check which SharePoint Advanced Management and Purview capabilities are actually available in the tenant.
- Use least privilege for both users and connectors, and set audit and retention practices to meet organizational requirements.
Include scheduled and event-driven tasks in governance
Cowork scheduled and event-driven tasks run as the user who created them and use the data and governed tools that user can access. Treat these tasks as ongoing user activity, not as a separate identity with a wider entitlement.
By default, Cowork requests approval before sending email, posting a message, or changing a shared system, although users may pre-authorize actions. Rate limits, loop protection, unified audit logging, and Purview controls also apply. Decide whether users may pre-authorize actions under your organization’s rules, and include task activity in the same review practices used for Cowork access and tools.
Monitor the rollout and adjust scope
Use the Microsoft 365 admin center to review Cowork usage and manage the user or group limits established for the pilot. Review plugin, browser, and automated-task activity through the applicable admin and audit surfaces referenced by Microsoft’s Cowork admin guidance. As the audience grows, reassess group membership and policy overlap instead of assuming that the original policy remains the only source of access.
For a controlled rollout, keep the audience, spending policy, enabled plugins, browser decision, and monitoring responsibilities explicit. That makes it easier to identify whether a change concerns who can use Cowork, what they can connect to, or how their activity is governed.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Recommended Free Tools

