Manage Microsoft Copilot Chat

Microsoft Copilot Chat eligibility

Microsoft Copilot Chat is available at no extra cost for eligible users who sign in with a Microsoft Entra work or school account and have a qualifying Microsoft 365 subscription.

  • Microsoft 365 A5, A3, or A1 (including MA5 or MA3 for students, MA5 or MA3 for faculty, and MA5 or MA3 student-use benefit)
  • Microsoft 365 E7, E5, or E3
  • Microsoft 365 F3 or F1
  • Microsoft 365 G5 or G3
  • Microsoft 365 Business Premium, Business Standard, or Business Basic
  • Microsoft Teams EEA, Teams Enterprise, or Teams Essentials
  • Office 365 A5, A3, A1 Plus, or A1
  • Office 365 E5, E3, E1 Plus, or E1
  • Office 365 F3
  • Office 365 G5, G3, or G1

The license versions designated as "(no Teams)" and "EEA (no Teams)" are also included.

Students aged 13 and older can use Microsoft Copilot Chat. To help ensure appropriate access, admins must take extra steps to manage deployment: Microsoft Copilot Chat for Students 13+.

Microsoft Copilot Chat is the baseline, secure AI chat experience included with eligible Microsoft 365 plans. Access to Copilot capabilities in Microsoft 365 apps, organizational data, advanced agents, and priority service depends on licensing and tenant configuration.

Note

Users might see labels such as Copilot Chat (Basic), Copilot (Basic), or Copilot (Premium). Available capabilities vary based on licensing and tenant configuration.

If you're an admin authorized to modify the EDU classification for your tenant members, you can use a PowerShell script. In the Microsoft Download Center, get Copilot for Education Control.

Pinning settings for Microsoft Copilot Chat

Microsoft Copilot Chat is pinned by default for most users who are eligible for Copilot Chat.

  • For tenants whose primary location is in the European Economic Area (EEA) or Switzerland, starting July 25, 2025, the Pin Microsoft Copilot Chat setting no longer governs the Microsoft Copilot app.
  • For tenants whose primary location is outside the EEA or Switzerland, starting January 28, 2026, the Pin Microsoft Copilot Chat setting no longer governs the Microsoft Copilot app.

The Pin Microsoft Copilot Chat in Microsoft 365 apps setting doesn't control Chat in the Microsoft Copilot app. Chat remains available in the app navigation.

For more information, see Pin Microsoft Copilot Chat in Microsoft 365 apps. You can also pin the Microsoft Copilot app to the Windows taskbar.

The following video outlines the advantages of pinning the Microsoft Copilot app to the Windows taskbar. It's 1 minute and 27 seconds long.

If pinning is set to Do not pin Copilot Chat in Microsoft 365 apps, Microsoft Copilot Chat isn't available by default in supported Microsoft 365 apps such as Outlook and Teams. However, users can still access Microsoft Copilot Chat through other available entry points unless administrators separately restrict access.

Manage web search queries in Microsoft Copilot Chat

To help improve the quality of responses, Copilot Chat can use web search queries sent to the Bing search service to ground responses in the latest information from the web. Learn more about how generated web search queries work in Microsoft Copilot Chat.

You can manage web search in Copilot Chat by using the Allow web search in Copilot policy, which is available in Cloud Policy service for Microsoft 365. The Allow web search in Copilot policy is also available in the settings section of the Copilot Control System page in the Microsoft 365 admin center. The policy allows you to manage web search at the tenant level and provides flexibility to modify it for specific groups and users if the tenant has special requirements. The Allow web search in Copilot policy also allows you to manage web search for users with an Microsoft Copilot add-on license.

If you don't configure the Allow web search in Copilot policy, web search is available to users by default in both Microsoft Copilot and Copilot Chat, unless you set the Allow the use of additional optional connected experiences in Office policy to Disabled. But turning off optional connected experiences restricts Microsoft Copilot Chat, Microsoft Copilot, and multiple experiences across Microsoft 365.

If you turn off web search in Microsoft Copilot Chat, web queries aren't sent to the Bing search service and Microsoft Copilot Chat uses only the underlying large language model (LLM) to generate responses.

Note

For US Government Community Cloud (GCC) and Department of Defense (DoD) customers:

  • Web search is available in GCC and DoD.
  • The Allow web search in Copilot policy is available in GCC and DoD in Cloud Policy service for Microsoft 365.
  • If the IT admin doesn't configure the Allow web search in Copilot policy, web search is turned off in GCC and DoD, regardless of how the Allow the use of additional optional connected experiences in Office policy is configured.

For more information on the Allow web search in Copilot policy, see Data, privacy, and security for web queries in Microsoft Copilot and Microsoft Copilot Chat.

Network requirements

Microsoft Copilot Chat adds generative AI capabilities to many Microsoft 365 applications by extending existing in-app features and introducing new ones. Admins can most effectively manage Copilot Chat experiences by using in-service controls provided through the Microsoft 365 admin center and individual applications.

Microsoft doesn't recommend and can't support attempts to manage Microsoft Copilot Chat and related settings through network-level restrictions such as selective domain, URL, IP blocking, or network-protocol filtering. Because Microsoft Copilot Chat is deeply integrated with applications, such network-level restrictions can lead to unpredictable results and might cause failures or block access to those applications.

For the full list of Microsoft 365 required endpoints (which includes Microsoft Copilot and Copilot Chat), see Microsoft 365 URLs and IP address ranges.

Microsoft Copilot Chat usage report

The Microsoft Copilot Chat usage dashboard provides insights into active usage of Copilot Chat. Admins can generate reports on total active users, average daily active users, total prompts submitted and average prompts per user, and active users of Copilot Chat in specific apps. For more information, see Microsoft 365 reports in the admin center.

Ensure users can access Microsoft Copilot Chat

Microsoft Copilot Chat is the secure AI chat experience available to eligible work and education users. Access to enterprise-protected Microsoft Copilot experiences depends on the account used to sign in.

Users can access Microsoft Copilot Chat through:

  • Microsoft Copilot Chat on the web
  • The Microsoft Copilot app for Windows, Mac, iOS, and Android
  • Supported Microsoft 365 apps, such as Outlook and Teams
  • Microsoft Edge side pane experiences, where available

Users can sign in to the Microsoft Copilot app with a work or school account or a personal Microsoft account. Chats, files, permissions, available experiences, and protections remain separate based on the account used to sign in.

  • To help ensure users receive enterprise protections, instruct them to sign in with their work or school account when using Microsoft Copilot Chat.
  • To manage whether users can sign in with personal accounts, see Tenant Restrictions v2.

Tip

To help users get started, see Get started with Microsoft Copilot Chat.

Manage Copilot Chat in Microsoft Edge

Users who sign in to Microsoft Edge with a Microsoft Entra work or school account can access Copilot Chat from the Copilot icon in the Edge sidebar. When users sign in with their work or school account, they receive enterprise data protection.

Admins can use Microsoft Edge policies to manage Copilot Chat in Edge:

  • To allow or block Copilot Chat from using browsing context, use the EdgeEntraCopilotPageContext policy. This policy controls whether webpage or PDF content can be used when generating responses to prompts.
  • To allow or block Copilot from using browsing context for users who sign in with a personal Microsoft account, use the CopilotPageContext policy.
  • To manage the visibility and availability of Copilot Chat in Edge, see the latest Microsoft Edge policy documentation and use the recommended Edge policy settings for your version of Microsoft Edge.

Manage the Copilot key

Some Windows devices include a dedicated Copilot key that provides quick access to Copilot experiences in Windows.

Keyboard with a dedicated Copilot key.

Organizations can configure how the Copilot key behaves by using Windows policy settings. For managed commercial and educational environments, admins can choose to remap the Copilot key to launch the Microsoft Copilot app or another approved experience that aligns with organizational requirements.

Users who sign in with a Microsoft Entra work or school account can access Copilot Chat through the Microsoft Copilot app, where enterprise protections and organizational controls apply.

For information about managing the Copilot key and related Windows policies, see Updated Windows and Microsoft Copilot Chat experience.

Manage Microsoft Copilot app availability

Users can access Microsoft Copilot Chat through the Copilot app across web, desktop, and mobile experiences. Users can also access Copilot Chat from supported Microsoft 365 applications, such as Outlook and Teams.

Administrators can manage Microsoft Copilot app settings through the Microsoft 365 admin center. Depending on licensing and tenant configuration, administrators can manage app features, user access, agent availability, and Copilot settings.

For more information, see:

Restrict access to Microsoft Copilot Chat

You can restrict user access to Microsoft Copilot Chat in your organization by taking certain actions, such as:

  • Unpinning Microsoft Copilot Chat
  • Limiting access to specific users or groups
  • Blocking access to Copilot Chat

You can also set up a custom URL to provide a company policy or information about why Microsoft Copilot Chat is blocked.

Unpin Copilot Chat

You can manage whether Microsoft Copilot Chat is pinned in supported Microsoft 365 applications by configuring the Pin Microsoft Copilot Chat in Microsoft 365 apps setting.

For more information, see Pinning options.

Important

Unpinning Copilot Chat doesn't remove access to Copilot Chat. Users might still be able to access Copilot Chat through the Copilot app and other supported Microsoft 365 experiences.

Limit access to specific users or groups

Organizations can manage the availability of Copilot experiences for specific users or groups through the Microsoft 365 admin center.

Depending on your organization's configuration, use app management controls to make Microsoft Copilot experiences available only to selected users, such as users who are assigned a Microsoft Copilot add-on license.

For more information, see:

Block access to Copilot Chat

Admins can block access to Copilot Chat for all users or for specific users and groups, including users who are assigned an eligible Microsoft Copilot license.

When access is blocked, users can't use Copilot Chat in supported experiences, including the Copilot app, Outlook, Teams, and web-based Copilot Chat experiences.

Users might still see Chat in the Copilot app navigation. If they select Chat, they're shown an in-product message explaining that access is disabled by organizational policy.

Screenshot showing the message displayed when access to Microsoft Copilot Chat is blocked by policy.

Provide a company policy URL

Your organization can provide a URL that points to internal guidance, support information, or company policy. Users see this link on the page that displays when access to Copilot Chat is blocked.

To configure a custom URL:

  1. Sign in to the Microsoft 365 admin center.

  2. Select Copilot > Settings.

  3. Select View all.

  4. Select Custom link for blocked Microsoft Copilot app.

  5. Enter the URL for your internal guidance page.

Users see the link text View info from your organization, which directs them to the URL you configured.

Microsoft recommends preparing your organization for AI-powered experiences by building a strong security foundation. Security recommendations for Microsoft Copilot are based on Zero Trust, an industry-standard security framework. See Apply principles of Zero Trust to Copilot Chat. By following these recommendations, you can strengthen your organization's security posture while enabling AI experiences.

When you introduce Copilot Chat to your environment, you have an opportunity to review and strengthen security protections for web-grounded prompts. These protections include controls for user identities, devices, and application access.

Diagram showing a staged approach to building security for AI experiences, beginning with protections for web-grounded prompts in Microsoft Copilot Chat.

Your organization can adopt a staged approach to securing AI experiences, starting with protections for web-grounded prompts in Copilot Chat and expanding to Microsoft Copilot experiences that use organizational data. Security protections for AI experiences grounded in security data, such as Microsoft Security Copilot, focus on least-privilege access, threat protection, and security operations readiness.

For more information, see Use Zero Trust security to prepare for AI companions, including Copilot.