Perform basic administrative tasks for Copilot and agents
Copilot Access, Licensing, Billing, and Settings
CoreSeparate named-user entitlement, supported pay-as-you-go services, feature controls, agent access, connector governance, and source permissions.
Aligned to the current AB-900 guide, verified July 22, 2026.
Why this matters
AB-900 expects you to separate entitlement, metered billing, feature settings, agent availability, connector permissions, and source access when administering Copilot.
Must Know
- A named-user Microsoft 365 Copilot license provides subscription entitlement to assigned users, subject to prerequisites and enabled service plans.
- Pay-as-you-go provides metered access only for supported services and scoped users or groups; supported services can change and must be verified.
- A PAYG billing policy links billing and scope, but the policy must also be connected to the intended supported service.
- A budget provides cost notifications; it is not automatically a hard stop unless a documented service control enforces one.
- Copilot Control System organizes security/governance, management controls, and measurement/reporting; actual controls can live across multiple admin centers.
- Agent availability controls who may use an agent; connector/action permission controls integrations; source permission controls accessible content.
- Neither licensing nor a Copilot setting repairs overshared SharePoint data.
Compare and Distinguish
- Named license vs PAYG: per-user subscription entitlement vs metered access for supported services and scoped users/groups.
- Billing policy vs connected service: cost/user definition vs activation of that policy for a specific Copilot service.
- Budget notification vs hard stop: threshold email/visibility vs explicit disconnection or supported disable control.
- Entitlement vs feature setting: right to use a product vs whether a supported scenario is allowed/configured.
- Agent availability vs connector control vs source permission: who can use the agent vs which integrations/actions are allowed vs which content the user can access.
- Copilot setting vs workload policy: central scenario control/shortcut vs detailed enforcement in Teams, Edge, Microsoft 365 Apps, Purview, or another service.
Scenario examples
- Scenario: Unlicensed users need approved SharePoint agents. Think: Configure a PAYG billing policy with Azure billing/users, connect it to SharePoint agents, and retain source permissions.
- Scenario: A budget threshold is reached. Think: Expect notification and review cost; do not assume the budget automatically blocked service.
- Scenario: The organization wants to disable Copilot web search. Think: Use the documented Microsoft 365 Apps cloud policy reached from Copilot settings, not a SharePoint permission change.
- Scenario: One agent should be unavailable. Think: Block or scope that agent rather than removing every user’s Copilot license.
- Scenario: Copilot reveals an overshared file. Think: Billing and feature toggles are not source remediation; correct SharePoint access.
Exam traps
- Creating a billing policy does not enable a service until the policy is connected to that service.
- PAYG never bypasses agent-file or source permission.
- A budget threshold notification is not automatically a hard stop.
- Not every Copilot capability has a generic on/off switch, and Copilot Control System is a framework rather than one master toggle.
- Disabling one service plan or scenario may affect related experiences; always use the documented scope.
Key takeaways
- Named user → license/service plan; metered user/group → billing policy + service connection.
- Budget alerts; explicit service controls stop. Billing never overrides permission.
- Entitlement, feature setting, agent availability, connector governance, and source access are separate layers.
How it works
- Named licensing follows user assignment and service-plan provisioning. PAYG follows billing policy → Azure subscription and scoped users/groups → connected supported Copilot service → metered usage and cost reporting.
- Microsoft 365 admin center exposes a Copilot settings catalog. Some entries configure directly; others are shortcuts to Teams, Microsoft 365 Apps, Power Platform, Purview, Defender, or another specialized surface.
- A control affects only its documented scenario. Disabling SharePoint/OneDrive Copilot service plan, blocking an agent, disabling web search, or removing source permission have different scopes and consequences.
Objects and administrative surfaces
- Licenses, service plans, users/groups, Copilot Settings, Billing & usage, billing policies, service connections, budgets, costs, and agent access — Microsoft 365 admin center.
- Azure subscription and cost analysis — Azure billing/Cost Management; SharePoint agent resource and agent-file/source permission — SharePoint admin center/sites.
- Agent environment, connectors, data policies, and advanced authoring — Power Platform admin center and Copilot Studio.
- Web-search cloud policy — Microsoft 365 Apps admin center; meeting Copilot policy — Teams admin center; data protection — Purview; identity/access — Entra.
When to use it
- Use named licensing for people who need the full licensed experience regularly; use PAYG for supported metered scenarios when usage-based access fits the population and governance model.
- Use group-scoped billing or feature controls for a pilot, then monitor access, usage, cost, and data readiness before expansion.
- Use the specific documented setting or workload policy for a feature; use source remediation for oversharing and connector governance for external actions/data.
Security and governance implications
- Use AI Administrator/Billing Administrator and other focused roles where supported; protect Azure billing ownership and document cost centers.
- Scope pilots to maintained groups, monitor spend and access, review agent/connector permissions, and disconnect obsolete service links.
- Avoid volatile prices and click paths in durable policy; validate current supported meters, prerequisites, and controls in Microsoft documentation.
Troubleshooting signals
- For named access, verify base prerequisites, license assignment source, service plan, provisioning, feature setting, application, and service health.
- For PAYG, verify Azure subscription state, billing policy, user/group scope, connection to the correct service, service enabled state, cost/usage visibility, and propagation.
- For SharePoint agents, also verify agent-file permission, knowledge-source permission, site restrictions, and agent availability.
- For a missing/blocked feature, identify whether the cause is entitlement, explicit Copilot setting, workload policy, agent/connector policy, Conditional Access, or source permission before changing anything.
More detail
- Named-user licensing assigns Microsoft 365 Copilot entitlement to specific people, subject to prerequisites and enabled service plans. It suits users who need the licensed work-grounded and in-app experience regularly.
- Microsoft 365 Copilot Chat provides enterprise-protected chat for eligible work users, with capabilities depending on license and configuration. Supported pay-as-you-go scenarios currently include Microsoft 365 Copilot Chat, SharePoint agents, and the Retrieval API preview; Copilot Studio has its own metering model.
- A pay-as-you-go billing policy links an Azure subscription/billing identity with users or groups for cost allocation and governance. Creating the policy is not enough: an administrator must connect the policy to a supported Copilot service. Only in-scope users receive the metered access that connection supplies.
- For SharePoint agents, access can come through a Microsoft 365 Copilot license or supported pay-as-you-go policy. Administrators link the policy to the SharePoint-agent resource and scope users/groups. The agent file and every knowledge source still enforce SharePoint permission.
- Administrators monitor usage and cost in Microsoft 365 Copilot Billing & usage/Cost Management and can also analyze Azure cost. A policy budget provides notifications at configured thresholds; it does not by itself prove that consumption stops at the budget.
- Copilot Control System is a framework with security/governance, management controls, and measurement/reporting pillars. Management includes licensing/metering, agent lifecycle, and customization; controls live mainly in Microsoft 365 admin center, Power Platform admin center, Copilot Studio, Purview, Defender, Entra, and workload centers.
- Durable examples of actual controls include scoping access to agents and allowed agent types, blocking an agent, enabling/disabling pay-as-you-go service connections, controlling self-service purchase, web search policy, image generation, screen/camera sharing, Copilot in admin centers, and Teams meeting behavior through Teams policy. Availability can depend on license and rollout.
- Connector controls decide whether and how external data/actions are available; agent availability decides who can use an agent; service plans and licenses decide entitlement; workload/source permissions decide accessible content. There is no generic toggle that repairs oversharing or overrides every product’s policy.
Ready for the quiz?
- How does a named-user license differ from PAYG?
- Why is creating a billing policy not the final PAYG step?
- Does reaching a budget threshold necessarily stop service?
- How do agent availability, connector/action permission, and source permission differ?
- Where should you fix content that Copilot surfaced because it was overshared?
Related objectives
- D3.1.b — Compare Copilot monthly license model to pay-as-you-go, including SharePoint
- D3.1.c — Identify which Copilot features can be enabled or disabled
- D3.2.a — Assign Copilot licenses
- D3.2.b — Monitor and manage Copilot pay-as-you-go billing policies