Configure Microsoft Copilot policies

The latest version of Microsoft Copilot includes the following policies. You can use these policies to configure how Microsoft Copilot runs in your organization.

Note

This article applies to Microsoft Copilot version 146 or later.

Available policies

These tables list all of the group policies available in this release of Microsoft Copilot. Use the links in the table to get more details about specific policies.

Browsing

Policy Name Caption
BrowsingEnabled Enable browsing capabilities

Additional

Policy Name Caption
ComponentUpdatesEnabled Enable component updates in Microsoft Copilot
CopilotCoworkToolActionsEnabled Allow Cowork to take actions on your behalf

Browsing policies

BrowsingEnabled

Enable browsing capabilities

Supported versions for BrowsingEnabled
  • On Windows and macOS since 152 or later
Description for BrowsingEnabled

This policy controls whether browsing capabilities are enabled in Microsoft Copilot.

If you enable this policy or don't configure it, browsing capabilities will be available in Microsoft Copilot. Users will be able to browse the web within the application.

If you disable this policy, browsing capabilities will be disabled in Microsoft Copilot.

Supported features for BrowsingEnabled
  • Can be mandatory: Yes
  • Can be recommended: No
  • Dynamic Policy Refresh: Yes
Data Type for BrowsingEnabled

Boolean

Windows information and settings for BrowsingEnabled

Group Policy (ADMX) info

  • GP unique name: BrowsingEnabled
  • GP name: Enable browsing capabilities
  • GP path (Mandatory): Administrative Templates/Microsoft Copilot/Browsing
  • GP path (Recommended): N/A
  • GP ADMX file name: CopilotApp.admx

Windows Registry Settings

  • Path (Mandatory): SOFTWARE\Policies\Microsoft\Copilot
  • Path (Recommended): N/A
  • Value Name: BrowsingEnabled
  • Value Type: REG_DWORD

Example value:

0x00000001

Mac information and settings for BrowsingEnabled

Preference Key Name: BrowsingEnabled Example value: <true/>

Additional policies

ComponentUpdatesEnabled

Enable component updates in Microsoft Copilot

Supported versions for ComponentUpdatesEnabled

On Windows and macOS since 152 or later

Description for ComponentUpdatesEnabled

If you enable or don't configure this policy, component updates are enabled in Microsoft Copilot.

If you disable this policy or set it to false, component updates are disabled for all components in Microsoft Copilot.

However, some components are exempt from this policy. This includes any component that doesn't contain executable code, doesn't significantly alter the behavior of the browser, or that's critical for security. That is, updates that are deemed "critical for security" are still applied even if you disable this policy.

Examples of such components include the certificate revocation lists and security lists like tracking prevention lists.

Disabling this policy can potentially prevent the Microsoft Copilot developers from providing critical security fixes in a timely manner and is thus not recommended.

Supported features for ComponentUpdatesEnabled
  • Can be mandatory: Yes
  • Can be recommended: No
  • Dynamic Policy Refresh: No - Requires browser restart
Data Type for ComponentUpdatesEnabled

Boolean

Windows information and settings for ComponentUpdatesEnabled

Group Policy (ADMX) info

  • GP unique name: ComponentUpdatesEnabled
  • GP name: Enable component updates in Microsoft Copilot
  • GP path (Mandatory): Administrative Templates/Microsoft Copilot/
  • GP path (Recommended): N/A
  • GP ADMX file name: CopilotApp.admx

Windows Registry Settings

  • Path (Mandatory): SOFTWARE\Policies\Microsoft\Copilot
  • Path (Recommended): N/A
  • Value Name: ComponentUpdatesEnabled
  • Value Type: REG_DWORD

Example value:

0x00000001

Mac information and settings for ComponentUpdatesEnabled

Preference Key Name: ComponentUpdatesEnabled Example value: <true/>

CopilotCoworkToolActionsEnabled

Allow Cowork to take actions on your behalf

Supported versions for CopilotCoworkToolActionsEnabled

On Windows since 152 or later

Description for CopilotCoworkToolActionsEnabled

This policy controls whether Cowork is allowed to take actions on behalf of the user in Microsoft Copilot.

If you enable this policy, Cowork can take actions on behalf of the user, and users can't change this setting on the Settings page.

If you disable this policy, Cowork can't take actions on behalf of the user, and users can't change this setting on the Settings page.

If you don't configure this policy, users can turn this setting on or off on the Settings page.

Supported features for CopilotCoworkToolActionsEnabled
  • Can be mandatory: Yes
  • Can be recommended: No
  • Dynamic Policy Refresh: Yes
Data Type for CopilotCoworkToolActionsEnabled

Boolean

Windows information and settings for CopilotCoworkToolActionsEnabled

Group Policy (ADMX) info

  • GP unique name: CopilotCoworkToolActionsEnabled
  • GP name: Allow Cowork to take actions on your behalf
  • GP path (Mandatory): Administrative Templates/Microsoft Copilot/
  • GP path (Recommended): N/A
  • GP ADMX file name: CopilotApp.admx

Windows Registry Settings

Path (Mandatory): SOFTWARE\Policies\Microsoft\Copilot Path (Recommended): N/A Value Name: CopilotCoworkToolActionsEnabled Value Type: REG_DWORD

Example value: 0x00000001

See also