A comprehensive deep-dive into how Microsoft 365 Copilot works — from architecture to Wave 3's latest frontier innovations.
Microsoft 365 Copilot is the AI system embedded across Microsoft 365 — Word, Excel, Teams, Outlook, and beyond. It combines state-of-the-art language models with your organisation's data through Work IQ and Microsoft Graph, within your security and compliance boundaries. Wave 3 (March 2026) transforms it from conversational assistant to autonomous agent capable of multi-step, multi-hour work.
Every Copilot interaction passes through a multi-stage orchestration pipeline. Semantic Kernel routes each request through safety filters, Work IQ retrieval, model selection, and response delivery. Wave 3 adds Cowork's task-plan execution layer for long-running work.
Natural language input from Word, Excel, Teams, Outlook, or the new Cowork canvas. With Wave 3, prompts can describe multi-step outcomes that run for minutes or hours — not just single-turn questions.
Content safety filters run, PII is detected and masked, and Conditional Access + entitlement checks validate the user. Enterprise Data Protection policies apply before any data retrieval begins.
Work IQ — Microsoft's intelligence layer — synthesises signals across emails, meetings, chats, files, and contacts. The Semantic Index (vector-based) retrieves the most relevant chunks, permission-scoped to the signed-in user only.
The raw prompt, retrieved Graph content, active document, conversation history, and system instructions are assembled into a grounded prompt. For Cowork tasks, a structured task plan and checkpoint instructions are also included.
Semantic Kernel selects the optimal model — GPT-5.3 Quick Response, GPT-5.4 Think Deeper, Claude Sonnet 4.5, or others. GPT-5's real-time router auto-selects Instant vs Thinking per prompt. All (Azure OpenAI/ GPT) inference runs inside Microsoft's Azure tenant with zero data leakage to public APIs.
Output passes through a second safety filter, formatted for the target app, delivered with citations. For Cowork, the orchestrator executes the next action in the task plan, checks back at configured checkpoints, and continues — audited at every step via Purview.
Select a scenario and run the pipeline to see how Copilot orchestrates each stage — including a Cowork multi-step scenario.
The grounded prompt sent to the LLM is a carefully assembled package. Wave 3 expands context with richer Work IQ signals and Cowork task state.
Copilot grounds responses in your organisational data — retrieved in real time, scoped to the signed-in user's permissions. Wave 3 added Dynamics 365 and Power Apps as native grounding sources.
Copilot only surfaces content the signed-in user already has permission to see. SharePoint permissions, Purview sensitivity labels, DLP policies, and Conditional Access are all respected. If a file is restricted, Copilot won't retrieve it — even for Cowork tasks. All Cowork actions are fully auditable via Microsoft Purview.
Copilot isn't a single LLM call. The Semantic Kernel orchestration layer decides which models, skills, plugins, and data sources to invoke. In Wave 3, it also coordinates Cowork tasks running across apps over extended periods.
Microsoft's multi-model architecture means Copilot is never locked to one provider. Here's how the model roster evolved from GPT-5 through to the March 2026 frontier — including Anthropic's Claude.
Work IQ is the intelligence layer that gives Copilot and agents full knowledge of how you work, with whom you work, and the content you collaborate on. It's what separates Copilot from a generic model-plus-connector solution.
Work IQ amplifies your individual intelligence by tapping into your organisation's collective knowledge. It continuously synthesises signals across all M365 services, building a rich real-time context model that powers Copilot's responses, personalises outputs, and lets Cowork act with the same understanding you bring to your job.
Without Work IQ, an AI model only sees what you paste into a prompt. With Work IQ, Copilot knows the full history of a project — who said what in which meeting, what decisions were made in emails, which documents are most relevant, and what the current state of your work actually is.
Maps relationships between people, projects, documents, and decisions across your entire M365 estate in real time.
Understands the sequence and recency of work — what's current, what's stale, and what's upcoming.
Knows who you collaborate with most, who owns what, and who the key stakeholders are for any project.
Refreshes continuously — so Copilot and Cowork always reflect the current state of your files, meetings, and chats.
Agent 365 is the enterprise control plane for AI agents — the single place IT and security leaders use to observe, govern, secure, and manage every agent across the organisation. In just two months of preview, tens of millions of agents appeared in the registry.
Centralised visibility of all agents — Microsoft first-party, third-party, and custom — in a single inventory. Monitor agent activity, usage patterns, and agent-to-agent interactions via the Agent 365 registry.
Set policies for which agents can run, which data sources they can access, and what actions they can take autonomously. Approval workflows for sensitive agent actions before execution.
Powered by Defender, Purview, and Entra Agent ID. Agents get Entra identities, can be phishing targets, and are protected with the same security infrastructure as human users. "AI agents are as subject to phishing attacks as people are."
Full lifecycle management: deploy, update, disable, or retire agents at scale. Integrated with Intune, Defender, and Purview for compliance and audit support across all agent actions.
💰 PRICING
Agent 365: $15 / user / month standalone · Or included in M365 E7 Frontier Suite at $99/user/monthTwo purpose-built reasoning agents — GA for all M365 Copilot licence holders since June 2025. Researcher now orchestrates other agents, and both are deeply integrated with Work IQ. March 2026: Researcher adds GPT + Claude "Critique" for accuracy validation.
Multi-step research at work. Combines OpenAI's deep research model with M365 Copilot's orchestration and Graph search. Integrates third-party data from Salesforce, ServiceNow, Confluence, Jira, and more. Can call other agents for specialised sub-tasks. March 2026: GPT drafts, Claude critiques research outputs.
Thinks like a skilled data scientist. Uses chain-of-thought reasoning to progress iteratively through analytical problems. Runs Python in real time — code is visible, verifiable, and auditable. Outputs feed directly into Researcher for integrated qualitative + quantitative insights.
Notebooks are persistent, AI-powered workspaces. Instead of context scattering across emails, chats, and documents, Notebooks aggregate all project content — with AI reasoning applied continuously. Available on desktop, web, and the Copilot mobile app.
Based on all 5 sources, the project is in Phase 2 (Identity migration). Key risk: 3 legacy apps not yet remediated. Stakeholder sentiment is positive with concern around the March 28 cutover. Notebook will update this summary as new content is added.
Generates a podcast-style audio briefing — two AI hosts walking through key points. Customisable narration style and length. Available in OneDrive, Outlook, Teams, Word, and the Copilot mobile app.
Wave 3 embeds Copilot natively in Word, Excel, PowerPoint, and Outlook — turning document creation from a blank-page task into an iterative, conversational collaboration, grounded in Work IQ context at all times.
Agent Mode turns document creation into an interactive dialogue inside the canvas. Copilot drafts, suggests refinements, asks clarifying questions, and applies native Word styles — grounded in Work IQ.
Plans, executes, and validates multi-step tasks directly in the grid. Inserts real Excel formulas and structures. Every change is transparent, auditable, and reversible. "It speaks Excel."
Full decks from a Copilot Page, Word doc, or brief. Brand templates, speaker notes, and contextual explanations on any element. Right-click any object → "Explain" for full context.
Draft and refine emails, manage calendars and RSVPs. Copilot finds available meeting times, sends invites, and keeps calendars up to date — all via natural language in the chat sidebar.
Cowork is the headline feature of Wave 3. It transforms Copilot from a chat assistant into an autonomous agent that executes multi-step, multi-hour tasks across your entire M365 environment — with transparent checkpoints, enterprise governance, and Anthropic's Claude powering its reasoning.
State a goal, not a single task. E.g., "Prepare the Q1 board presentation using SharePoint reports, Teams transcripts, and the Excel financial model."
Breaks the goal into discrete steps, identifies M365 resources to access, and presents the plan for your review before starting execution.
Cowork works across Outlook, Teams, SharePoint, Word, Excel, and PowerPoint simultaneously — reading emails, analysing transcripts, pulling data, generating deliverables.
At predefined intervals, Cowork pauses, shows progress, requests confirmation on sensitive actions, and allows you to redirect or halt work at any time.
All Cowork actions are logged in Microsoft Purview. Outputs are native M365 artifacts — version-controlled and governed by your existing DLP, sensitivity label, and compliance policies.
Runs in the cloud within your M365 tenant. Covered by Enterprise Data Protection. Powered by Work IQ for full org context. Uses Anthropic's Claude model for multi-step reasoning and the same agentic harness as Claude Cowork — but enterprise-grade, cloud-based, fully auditable. Available in Frontier from March 30, 2026.
Runs locally on a user's device. Anthropic's standalone agentic product. Microsoft's Cowork is built on the same agentic platform but runs in the cloud with M365 governance and Work IQ integration. "We actually don't work locally, and that's a feature, not a bug." — Jared Spataro, Microsoft
Cowork accesses data across multiple M365 services in a single workflow. Ensure permissions models are airtight, configure Purview audit logging for Cowork events, and define which actions require human approval before enabling in production.
Copilot Cowork is built in close collaboration with Anthropic, bringing the technology platform that powers Claude Cowork into Microsoft 365 Copilot. It uses Claude as the AI powering multi-step reasoning — but runs enterprise-grade in your M365 tenant with Work IQ and Enterprise Data Protection. The broader Copilot multi-model strategy also includes Claude Sonnet 4.5 for Computer Use agents and the new GPT + Claude Critique capability in Researcher. "We have the ability to reach across the industry and look at innovations coming from OpenAI, from Anthropic, and bring them into this system." — Jared Spataro, Microsoft CMO AI@Work
Microsoft's Agent Store has grown into a full ecosystem. First-party, third-party, and custom agents are all discoverable, pinnable, and governed via Agent 365 — with new agents added continuously through the Frontier programme.
Deep research across work + web. Board briefs, competitive analyses, client prep. Orchestrates other agents. New: GPT drafts, Claude critiques (Mar 2026).
Runs Python, detects patterns, generates charts. Built on o3-mini. Raw spreadsheet → executive insight in minutes. Code is transparent and verifiable.
Long-running, multi-step task execution. Breaks goals into plans, runs across M365, checks in at configurable checkpoints. Powered by Claude + Work IQ.
Autonomously builds pipeline, nurtures leads, personalises outreach. Connects to Salesforce and Dynamics 365. Sellers focus on closing; agent handles prospecting.
Automates repetitive tasks across M365 apps using simple prompts — meeting summaries, task digests, scheduled triggers. Enterprise-grade security built in.
Powered by People Skills data layer. Builds dynamic skill-based teams and helps employees discover colleagues with specific expertise across the organisation.
Personal survey expert. Gathers training feedback, measures employee sentiment, runs customer research. Describe what you want to learn — no survey builder expertise needed.
Build agents connected to 1,400+ systems via MCP, Power Platform, and Graph. Multi-agent orchestration. Computer Use via Claude Sonnet 4.5. Governed by Agent 365.
Announced March 9, 2026, Microsoft 365 E7 bundles E5 + Copilot + Agent 365 + the full security stack into a single Frontier Suite — at a price below buying them individually. More than 90% of the Fortune 500 now use Microsoft 365 Copilot.
Announced March 9, 2026 · E5 + Copilot + Agent 365 + Entra + Defender + Intune + Purview in one solution