Copilot Cowork is live: what to lock down before AI starts completing multi-step work

Copilot Cowork became generally available worldwide on 16 June 2026, and the useful part is that it is off by default. That gives you a short window to tidy up your Microsoft 365 tenant before you let an agent start working across it.

Cowork is not just another writing assistant. It can carry out longer, multi-step tasks across Microsoft 365, including Outlook, Teams, Word, Excel, PowerPoint, SharePoint and calendars. You describe the outcome you want, and Cowork works through the task, with user approval required before actions happen.

Why tenant hygiene matters first

Here is the uncomfortable part. Cowork inherits the state of your tenant. If permissions are loose, if SharePoint sites are badly named, or if sensitive files sit in folders nobody properly owns, an agent can surface that information very quickly.

A bit of SharePoint housekeeping is no longer optional admin. It is a security control. Getting your Microsoft 365 and Office 365 environment in order first is what stops a helpful tool from quietly oversharing.

Picture a real request. Someone asks Cowork to pull together everything on the Henderson account. If an old payroll spreadsheet or confidential board paper sits in a library that person can technically access, it may be included in the output. Nobody meant any harm. The data simply moved somewhere it should not. That is close to the lesson the retail sector learned the hard way, and it is worth reading how access and supplier risk played out after the M&S and Co-op attacks.

Where to focus before you flip the switch

Area Why it matters First step
Permissions and sharing Cowork can reach what the user can reach Review oversharing and stale access
Sensitivity labels Labels help control confidential data Apply labels to sensitive files
Identity and MFA A compromised account can trigger agent activity Enforce MFA and review admin roles
Stolen credentials Reused passwords can end up for sale Add dark web monitoring
Email threats Agents do not remove social engineering risk Run phishing simulations
Spend controls Usage-based billing can climb quietly Set tenant, group and user caps

Start with identity and access

Start with identity, because that is what an agent borrows when it works on someone’s behalf. Pair multi-factor authentication with endpoint detection and response so a stray login does not turn into an agent acting on your data.

Reused passwords are the quieter risk. If a member of staff has recycled a work password on a site that was later breached, it may already be circulating, which is exactly what dark web monitoring is there to catch.

Do not forget email, labels and existing controls

Email is another soft spot. Cowork will not remove the risk of a convincing invoice scam, and attackers are still leaning hard on impersonation. Layered anti-phishing protection and regular simulations keep people sharper.

Labels matter too. Cowork prompts, responses and generated files sit within Microsoft 365 governance, including audit, eDiscovery, retention and Purview controls. Sensitivity labels are inherited and displayed, but that only helps if labels are already applied properly.

Many of the controls you need are already inside the stack, as our run-through of useful Office 365 features shows. The same caution applies to other AI tools your team may already use, which is why we covered securing Teams meetings against external AI bots and what the latest Microsoft 365 pricing and security changes mean for the protections you pay for.

Set spending limits before usage grows

Then there is cost. Cowork requires a Microsoft 365 Copilot licence and is billed by usage in Copilot Credits. Microsoft says task cost is based on factors such as model use, context retrieval, tool calls and runtime, so heavy tasks can cost more than expected.

Set budgets, alerts and spending limits before anyone starts. To put the stakes in context, M&S warned of a roughly £300 million hit to operating profit after its 2025 cyberattack, so getting governance wrong can dwarf the cost of a few credits.

If you run several sites or offices abroad, the cleanup needs to be consistent everywhere, which is where global IT support earns its keep. And if you are mid-migration, fold this into the plan, since our data migration services can sequence the work so governance lands before the agent does.

Frequently asked questions

Is Copilot Cowork on by default?

No. Cowork is off by default. Admins decide when to enable it in their tenant and who gets access.

What is the difference between Copilot and Copilot Cowork?

Standard Copilot helps with tasks such as drafting, summarising and finding information while you stay in control. Cowork is more agentic. It can carry out longer, multi-tool tasks across Microsoft 365, with approval before actions happen.

Is Copilot Cowork secure?

It works within Microsoft 365 governance, but it inherits your existing permissions and data structure. Weak access controls and messy data remain weak access controls and messy data.

Do we need a licence?

Yes. Cowork requires a Microsoft 365 Copilot user subscription licence, with usage then billed through Copilot Credits.

Get your environment ready first

Turning Cowork on is a quick admin decision. Making sure it behaves is the real work, and it is far cheaper to do before launch than after an awkward incident. If you would like a clear readiness review of permissions, labelling, identity and spend controls before you enable it, talk to the team at Northern Star managed IT support and we will help you switch it on with confidence rather than crossed fingers.