Summary

Completed

Microsoft 365 Copilot administration doesn't end at rollout—it continues as a series of individual, reversible decisions that tune capability against data exposure across the tenant.

What you learned

  • The Copilot tenant-settings catalog is a set of independent decisions—self-service purchases, Copilot in admin centers, release preferences, the AI disclaimer, and image and video generation—each with its own admin-center location and required role.
  • Web search for Microsoft 365 Copilot and Copilot Chat is governed by a single Allow web search in Copilot policy configured through the Cloud Policy service for Microsoft 365, not two separate switches, alongside a personal Web content toggle available only in Microsoft 365 Copilot.
  • Copilot Search is its own configuration surface, letting you define organization-specific acronyms and curate bookmarks that promote key destinations, so results reflect your organization's language and point people to the right places.
  • Non-Microsoft models come through two separate controls: connecting an independent provider (Mistral or xAI) under "AI providers for other large language models" requires Global Administrator, while enabling a Microsoft subprocessor (Anthropic or OpenAI) needs only AI Administrator—either way, access can be scoped to specific users or groups, up to 999 assignments per provider.
  • Copilot connectors extend grounding to external data through two models—synced connectors index content into Microsoft Graph and preserve source permissions, while federated connectors fetch content live without storing it in Microsoft 365.
  • Extending Copilot in SharePoint with skills and the Copilot Frontier program are two extensibility surfaces worth recognizing: skills automate existing permissions without a dedicated toggle, and Frontier gives tenants controlled, opt-in early access to preview capabilities.

Learn more