All Posts
AI Services

Microsoft Copilot Autopilot Is Coming to Your M365 Tenant

· Infonaligy

Copilot Autopilot gives AI agents their own identity, memory, and workspace inside M365. Three things to prepare before private preview starts this month.

Microsoft Copilot Autopilot Is Coming to Your M365 Tenant

Microsoft announced Copilot Autopilot on September 25, and it changes the relationship between your business and AI inside Microsoft 365. Unlike Copilot Chat, which answers when you ask, and Cowork, which handles tasks within a single session, Autopilot is an autonomous agent with its own identity, memory, and persistent workspace. You assign it a name, role, and goal. It monitors Teams channels, follows up on stalled threads, carries out recurring work, and resumes projects days later without being prompted again.

Private preview starts at the end of October 2026, with metered billing. If your business runs M365, an autonomous AI agent with access to your data, email, and collaboration tools is about to become available to anyone with admin access. The governance, permissions, and cost controls need to be in place before someone turns it on.

How Autopilot Differs From What You’re Already Using

Microsoft’s AI tooling now has three distinct tiers, and understanding the differences matters for how you manage each one.

Copilot Chat is on-demand. You open a chat window, type a question, and get an answer. It reads documents you point it to and generates responses within that conversation. When you close the window, the session ends. There’s no ongoing activity, no background monitoring, no memory of previous conversations beyond what’s in your chat history.

Cowork is session-based. You delegate a multi-step task to Cowork (research a topic, draft a presentation, analyze a dataset), and it works through the steps within a defined session. It can use tools, access files, and produce deliverables, but the scope is a single task with a clear endpoint. When the task finishes, Cowork stops. Billing is per task based on credits consumed, which is why setting up spending limits matters.

Autopilot is continuous. It gets its own identity in your tenant, like adding a new employee with a defined role. It has persistent memory across sessions, meaning it remembers context from prior interactions and builds on previous work. It monitors designated channels and workflows, takes actions on its own schedule, and picks up where it left off after days or weeks. Microsoft’s first Autopilot, Scout, already demonstrated this model by scheduling meetings, prepping documents, and flagging stalled decisions without being prompted.

The critical distinction: Copilot Chat and Cowork act when a human initiates something. Autopilot acts on its own based on standing instructions. That’s a fundamentally different trust model, and it requires different controls.

1. Audit Your M365 Permissions and Sensitivity Labels Now

Autopilot operates within the same permission boundaries as the user or service account it’s assigned to. If your M365 environment has loose permissions (many users with broad SharePoint access, no sensitivity labels on confidential documents, no information barriers between departments), Autopilot inherits all of that looseness.

The scenario that should concern you: someone assigns an Autopilot agent the goal of “keep our executive team informed about project status across all departments.” The agent dutifully monitors every Teams channel and SharePoint site it has access to, summarizes what it finds, and delivers briefings that include HR discussions, financial projections, and client contract details that weren’t intended for broad circulation. The agent didn’t violate any rules. The permissions allowed it. Nobody thought about what “monitor everything” means when the agent can actually do it.

Before private preview arrives, complete these steps:

  • Run a permissions audit across SharePoint, Teams, and OneDrive. Identify users and groups with overly broad access. The M365 permissions audit checklist we published earlier this year covers this process in detail, and it applies directly to Autopilot preparation.
  • Apply sensitivity labels to confidential content. Microsoft Purview sensitivity labels control what AI agents can access and summarize. Documents labeled “Confidential” or “Highly Confidential” can be excluded from agent processing entirely. If you haven’t deployed sensitivity labels yet, this is the forcing function.
  • Set up information barriers for departments that shouldn’t cross. HR data, executive compensation discussions, M&A materials, and legal matters should have explicit barriers that prevent any AI agent from crossing department boundaries, regardless of what permissions a user technically has.

The permissions model that worked when AI tools were passive (waiting for a user to ask a question about a specific document) breaks when AI tools are active (continuously scanning everything they have access to). Fix the permissions before the agent starts using them.

2. Define an Acceptable Use Policy for Autonomous Agents

Your existing AI acceptable use policy probably covers which AI tools employees can use and what data they can share. Autopilot introduces a new category: AI that acts autonomously within your environment without direct human prompting for each action.

The policy questions are different from what you’ve addressed before:

Who can create and configure Autopilot agents? This shouldn’t be available to every employee with an M365 license. Creating an autonomous agent that monitors business communications and takes actions is an admin-level decision. Define which roles have permission to create agents, and require approval before any agent goes live.

What goals and scopes are acceptable? An Autopilot agent assigned to “follow up on overdue invoices in the finance team’s channel” is narrowly scoped and relatively low risk. An agent assigned to “improve team productivity across the entire organization” is essentially unconstrained. Your policy needs to define acceptable scope boundaries and require that agent goals be specific, documented, and reviewed.

How are agents monitored and audited? Every Autopilot agent should have a designated human owner who reviews its activity regularly. Microsoft provides audit logs for agent actions in the M365 compliance center. Your policy should require weekly reviews of agent activity during the first 90 days, shifting to monthly once behavior patterns are established and validated.

When do agents get shut down? Define the triggers: an agent that accesses data outside its intended scope, generates unexpected costs, or produces outputs that require correction should be paused immediately and reviewed. Automatic shutdown triggers based on anomaly detection through Agent 365 governance controls are worth configuring from day one.

Write this policy now, while Autopilot is still in preview. Policies written after an incident are always more restrictive and less thoughtful than policies written in advance.

3. Set Up Cost Management Before Metered Billing Starts

Autopilot uses the same metered billing model as Cowork, where you pay per task based on credits consumed. The difference is that Cowork tasks are human-initiated (someone deliberately delegates a task), while Autopilot tasks can be self-initiated (the agent decides to take action based on its monitoring and goals).

This distinction creates a cost risk that Cowork alone doesn’t. A Cowork user who runs 10 tasks per day made 10 conscious decisions. An Autopilot agent running continuously might execute dozens of actions per day based on its standing instructions, and nobody prompted any of them individually. If the agent decides that “following up on stalled threads” means checking 50 Teams channels every hour and drafting follow-up messages for each one, the credit consumption adds up fast.

Microsoft’s cost management controls in the M365 admin center (the same ones covered in our Cowork billing guide) apply to Autopilot:

  • Set per-agent spending limits. Cap the monthly credit consumption for each Autopilot agent individually. Start conservative (low limits) and increase as you understand the agent’s actual usage patterns.
  • Configure alerts at 50% and 80% of the spending cap. Don’t wait until the limit is hit. Early warnings give you time to evaluate whether the spending is productive before the agent gets throttled.
  • Review the first month’s billing line by line. Autopilot’s activity logs show which actions consumed credits and how much each one cost. Correlate activity with business value. An agent spending $300/month on follow-up messages that your team ignores isn’t providing value. One spending $150/month on meeting prep that saves your executives two hours per week might be worth increasing.

The billing lessons from Cowork’s first quarter apply directly. Businesses that set limits before enabling the tool had predictable costs. Businesses that didn’t discovered the problem on their invoice.

The October Preparation Window

Microsoft Ignite runs November 17 through 20, and Microsoft has signaled that additional Autopilot details, including broader availability timelines and enterprise governance features, will be announced there. Private preview starts at the end of this month. That gives you roughly three weeks to prepare.

Here’s the sequence:

  1. This week: Run the permissions audit. Identify and fix oversharing in SharePoint, Teams, and OneDrive. Apply sensitivity labels to your most confidential content.
  2. Next week: Draft or update your AI acceptable use policy to address autonomous agents. Define who can create agents, what scopes are acceptable, and what monitoring is required.
  3. Before October 31: Configure spending limits and alerts in your M365 admin center. Designate agent owners for any Autopilot agents you plan to create during preview.
  4. During preview: Start with a single, narrowly scoped agent. Monitor its behavior, review its activity logs weekly, and validate its cost before expanding.

If your Dallas-Fort Worth business hasn’t touched M365 governance since your initial Copilot rollout, this is the moment to revisit it. Autonomous agents amplify whatever your current governance posture is, for better or worse.

Need Help Preparing for Copilot Autopilot?

Our team can audit your M365 permissions, configure Agent 365 governance controls, and build your autonomous AI policy before private preview arrives.

Get a Free Assessment

Serving Businesses Across Texas & Oklahoma