Building and customizing solutions using Microsoft 365 Copilot APIs and tools
As admin, Copilot must first be licensed, then access can be controlled at several levels: tenant, app, and per‑user/group.
- Verify and assign Copilot licenses
- Ensure users who should have Copilot have a supported Microsoft 365 subscription and a Copilot license assigned.
- If Copilot is missing or disabled for a user, confirm:
- They have a license that supports Microsoft 365 Copilot.
- Copilot isn’t blocked by organizational policies.
- Enable/disable Copilot for admins in Microsoft 365 admin centers
- Copilot for admins is automatically enabled for all admin users if the tenant has at least one Copilot license.
- To disable Copilot for specific admins:
- Create a security group named
CopilotForM365AdminExclude. - Add the admins who should not see Copilot in admin centers to this group.
- Microsoft 365 admin centers will disable the Copilot experience for any admin in this group.
- Create a security group named
- Copilot respects role-based access control and does not make configuration changes without explicit consent.
- Control Copilot access in Viva apps (per people/groups) To enable or disable Copilot in Viva apps for specific users or groups:
- Go to the Copilot settings page in the Microsoft 365 admin center.
- Choose the Viva app for which access should be controlled.
- Under Custom policies for people and groups, select Create policy.
- Name the policy (for example, “Disable for users in office X”).
- Choose one of:
- Off for specific people – disables Copilot in that Viva app only for the selected users/groups.
- On for specific people – enables Copilot in that Viva app only for the selected users/groups.
- Add the users or groups.
- Select Save.
- Changes can take up to 24 hours to take effect.
- To modify or remove a policy, use Edit or Delete from the same Copilot settings page.
- Turn Copilot off in desktop apps (per device/app) Even when licensed, users (or admins via configuration/communication) can turn Copilot off in specific apps without removing licenses:
On Windows (Word, PowerPoint, Excel):
- In the app, go to File > Options > Copilot.
- Clear the Enable Copilot checkbox.
- Select OK, then restart the app.
- Re‑enable by checking Enable Copilot again.
On Mac (Word, PowerPoint, Excel):
- In the app, select the app menu (for example, Word) > Preferences.
- Go to Authoring and Proofing Tools > Copilot.
- Clear the Enable Copilot checkbox.
- Close and restart the app.
- Re‑enable by checking Enable Copilot again.
- Ensure Copilot appears and works for enabled users If Copilot is licensed and should be enabled but is missing or not working:
- Confirm the user is signed in with the correct account that has a Copilot license (for business: Microsoft 365 Business Basic/Standard/Premium, E3, E5, F1, or F3 plus Microsoft 365 Copilot; for home: Microsoft 365 Personal/Family or Copilot Pro).
- Refresh the license in desktop apps:
- Windows: File > Account > Update License, then restart all Microsoft 365 apps.
- Mac: app menu (for example, Word) > About <app> > More Info… > Refresh License, then restart apps.
- For Mac, ensure privacy settings allow Copilot:
- In Word: Word > Preferences > Privacy.
- Turn on Experiences that analyze your content and All connected experiences.
- For web apps, refresh the browser page and ensure third‑party cookies are allowed if there are license validation issues.
- Using personal Microsoft 365 Premium/Family/Personal at work
- Users with Microsoft 365 Personal, Family, or Premium can use Copilot at work with their work files while file access remains tied to the work account.
- Organization policy controls still apply; admins can disable Copilot usage via cloud policy for work content even when users sign in with a personal subscription.
- Multiple account access is supported in Word, Excel, PowerPoint, and Outlook; users can add a personal account via the profile menu and still remain under enterprise identity, permissions, and compliance policies.
To summarize admin control:
- License level: assign/remove Copilot licenses and supported M365 plans.
- Tenant/app level: use Copilot settings in the Microsoft 365 admin center (including Viva custom policies) and the
CopilotForM365AdminExcludegroup for admin centers. - Client level: instruct or configure users to toggle Enable Copilot in app options if they want it off locally.
References:
- Copilot is missing, disabled, or doesn't work correctly
- Copilot for admins in Microsoft 365 admin centers
- Control access to Microsoft 365 Copilot in Viva
- Turn off Copilot in Microsoft 365 apps
- How to find and enable missing Copilot button in Microsoft 365 apps
- Use Microsoft 365 Personal, Family, or Premium at work