Reference
Policies for Copilot
See the Copilot inventory reference for the objects these templates work on.
| Policy | Description | Severity | Category | Checks |
|---|---|---|---|---|
| Copilot Adoption Opportunity - E3/E5 Users ⭐ | Identifies E3/E5 licensed users eligible for Copilot, helping prioritize rollout to users with necessary prerequisites. Organizations invest significantly in E3/E5 licenses that can be upgraded with Copilot capabilities, and identify these users through analytics to prepare for future rollouts. Users can be reviewed and licenses can be automatically assigned based on additional criteria or schedules. | Medium | Adoption | User |
| Copilot License Assigned to Disabled Account ⭐ | Flags disabled accounts retaining active Copilot licenses, enabling immediate cost recovery through license reassignment. Copilot licenses assigned to disabled accounts waste valuable resources and budget that could benefit active users, therefore immediately reassign these licenses by reviewing all flagged accounts, confirming their disabled status, removing the Copilot license assignment, and implementing automated processes to revoke licenses when accounts are disabled to prevent future occurrences. | High | Costs | User |
| Copilot Licensed but No Credit Usage ⭐ | Flags users with a Microsoft 365 Copilot license but zero credit consumption, enabling enablement outreach or license reclamation. A user holding a Microsoft 365 Copilot license but consuming zero credits is paying for capability they are not using. Reach out to understand the adoption barrier, provide enablement, or reclaim the license and reassign it to a user who will benefit, to avoid paying for idle licenses. | Medium | Costs | Copilot credits consumption |
| User At or Over Copilot Credit Limit ⭐ | Flags users who have consumed 100% or more of their monthly Microsoft 365 Copilot credit limit, so limits or coaching can be applied before overage costs accrue. A user at or above their monthly Copilot credit limit will have requests throttled or billed as overage. Review whether the user genuinely needs a higher limit (and raise it deliberately), or whether the consumption indicates inefficient prompting that training can address, so credit budgets stay predictable. | Medium | Costs | Copilot credits consumption |
| Cowork Users Relying Heavily on Scheduled Automation ⭐ | Flags Cowork users running a high number of scheduled (autonomous) tasks, so unattended automation can be reviewed for continued need and correctness. Cowork can run tasks on a schedule without a person in the loop, so a user with a high share of scheduled tasks is delegating meaningful work to autonomous runs. Confirm these scheduled tasks are still needed and produce the expected output, because abandoned or misconfigured schedules keep consuming Copilot capacity and can act on stale instructions long after the user has moved on. | Medium | Adoption | Copilot Cowork usage |
| External Website Data Source Risk ⭐ | External connections that load data from websites into M365 Copilot can introduce unverified, outdated, or malicious information, leading to incorrect results or risks. External website connections pose risks to Copilot's response accuracy because unverified web sources can contain outdated, biased, or incorrect information that gets incorporated into AI-generated answers, potentially leading to flawed business decisions or compliance issues. Validate all external website connections by documenting their reliability, implementing regular accuracy checks, restricting connections to trusted and verified sources only, and establishing a review process where connection owners must justify the business need and demonstrate data quality controls before approval. | High | ExternalAccess | External Graph Connection |
| Inactive Copilot Users - 30 Days ⭐ | Reports on users with unused Copilot licenses for 30+ days, enabling proactive engagement or license reallocation. This policy only works correctly with non-anonymized data. Users who haven't accessed Copilot for 30 days indicate either adoption challenges or misallocated licenses that drain your licensing budget, so reach out to these users to understand barriers to usage, provide additional training if needed, or reallocate licenses to users who will actively benefit from Copilot's capabilities, while establishing regular usage monitoring to optimize license distribution. | Medium | Costs | User |
| Missing External Connection Documentation ⭐ | Flags external connections lacking descriptions, ensuring users understand data sources in their Copilot results. Undocumented external connections in Copilot can lead to inaccurate or incomplete responses when users query data from these sources, potentially causing business decisions based on partial information, so document all external connections with clear descriptions of data sources, update frequencies, and data scope to ensure users understand what information Copilot accesses and can trust the results. | Medium | ResponseAccuracy | External Graph Connection |