What is Microsoft 365 Copilot Cowork and what are its enterprise governance…

What is Microsoft 365 Copilot Cowork and what are its enterprise governance risks?

2026-04-26 · governance-policy security-risk knowledge-management enterprise-adoption · medium · source → · wiki →
key claims
  1. Cowork is a preview Microsoft 365 Copilot agent that can execute multi-step work across Outlook, Teams, documents, calendars, and enterprise search, and it is explicitly designed to request user approval before sensitive actionsMicrosoft (n.d.)Microsoft (n.d.)Cowork (n.d.)
  2. Cowork custom skills are not the same technical category as Microsoft's formal extensibility options, because they are per-user instruction files loaded into a prebuilt agent rather than packaged agents, connectors, or custom orchestration componentsMicrosoft (n.d.)Declarative (n.d.)Custom (n.d.)
  3. Cowork operates in the caller's existing Microsoft 365 security context, which means the dominant risk is not hidden privilege escalation but the faster operationalization of already overshared content and already overbroad user accessManage (n.d.)Cowork (n.d.)
  4. Microsoft explicitly states that custom skills created by users are not validated by Microsoft, so enterprises cannot treat those skills or their outputs as vendor-assured controls or reviewed business proceduresCowork (n.d.)Microsoft (n.d.)
  5. Microsoft's baseline privacy, retention, and residency commitments still apply to Cowork interaction content, including no training on prompts or responses, permission trimming, and local-geography storage commitments for interaction data at restMicrosoft (n.d.)Microsoft (n.d.)Privacy (n.d.)
  6. Anthropic subprocessor dependence creates a material regional governance decision because Anthropic-backed features are outside the EU Data Boundary, disabled by default in the EU, EFTA, and UK, and unavailable in government and sovereign cloudsAnthropic (n.d.)Microsoft (n.d.)Microsoft (n.d.)
  7. Microsoft supplies meaningful enterprise controls through DLP, audit logs, and group-scoped availability management, but the documented DLP inability to inspect the contents of uploaded prompt attachments leaves a concrete preventive-control gapLearn (n.d.)Overview (n.d.)Manage (n.d.)
  8. Cowork creates moderate operational lock-in because even though a skill file is portable as Markdown text, the useful workflow depends on Microsoft-specific permissions, data locations, scheduling, approval patterns, and integrated action surfacesMicrosoft (n.d.)Microsoft (n.d.)Custom (n.d.)

Research Question

What is Microsoft 365 (M365) Copilot Cowork, how does it technically differ from custom Microsoft Copilot Skills, and what are the governance, legal, and shadow Information Technology (IT) risks it introduces for enterprise organisations?

Findings

(Populated from section 6 Synthesis above.)

Executive Summary

Key Findings

  1. High confidence. Cowork is a preview Microsoft 365 Copilot agent that can execute multi-step work across Outlook, Teams, documents, calendars, and enterprise search, and it is explicitly designed to request user approval before sensitive actions.
  2. High confidence. Cowork custom skills are not the same technical category as Microsoft's formal extensibility options, because they are per-user instruction files loaded into a prebuilt agent rather than packaged agents, connectors, or custom orchestration components.
  3. High confidence. Cowork operates in the caller's existing Microsoft 365 security context, which means the dominant risk is not hidden privilege escalation but the faster operationalization of already overshared content and already overbroad user access.
  4. High confidence. Microsoft explicitly states that custom skills created by users are not validated by Microsoft, so enterprises cannot treat those skills or their outputs as vendor-assured controls or reviewed business procedures.
  5. High confidence. Microsoft's baseline privacy, retention, and residency commitments still apply to Cowork interaction content, including no training on prompts or responses, permission trimming, and local-geography storage commitments for interaction data at rest.
  6. High confidence. Anthropic subprocessor dependence creates a material regional governance decision because Anthropic-backed features are outside the EU Data Boundary, disabled by default in the EU, EFTA, and UK, and unavailable in government and sovereign clouds.
  7. High confidence. Microsoft supplies meaningful enterprise controls through DLP, audit logs, and group-scoped availability management, but the documented DLP inability to inspect the contents of uploaded prompt attachments leaves a concrete preventive-control gap.
  8. Medium confidence. Cowork creates moderate operational lock-in because even though a skill file is portable as Markdown text, the useful workflow depends on Microsoft-specific permissions, data locations, scheduling, approval patterns, and integrated action surfaces.
  9. Medium confidence. The defensible adoption pattern is a governed low-code rollout in which Cowork is limited to approved groups and bounded use cases until permissions cleanup, DLP coverage, audit review, and a skill registration process are demonstrably in place.

Assumptions

Explicit assumptions made during the investigation and the justification for each.

Analysis

Risks, Gaps, and Uncertainties

Open Questions


sources

Connected items

Loading…

View full knowledge graph →