AI engineering

Microsoft 365 Copilot License Assignment: Prerequisites and Rollout

Check base licenses, update channels, mailboxes, OneDrive, Teams and network access, then assign Copilot licenses with group-based licensing or Microsoft Graph PowerShell.

11 min read
On this page

Before you assign Microsoft 365 Copilot licenses, confirm that each user has a qualifying base license, a Microsoft Entra work account with a usage location, an Exchange Online mailbox, a OneDrive account, and Microsoft 365 Apps on Current Channel or Monthly Enterprise Channel, and that your network allows *.cloud.microsoft. Then assign the Copilot license to a security group on Billing > Licenses in the Microsoft 365 admin center, or with Set-MgGroupLicense or Set-MgUserLicense in Microsoft Graph PowerShell, and verify with the Copilot readiness report.

Who this is for and what you will have at the end

This guide is for Microsoft 365 administrators who have bought Copilot licenses, or are about to, and want users to see Copilot the day they're licensed rather than a week later after a round of tickets. It assumes users already exist in Microsoft Entra ID with Microsoft 365 workloads.

At the end you will have:

  • A prerequisite checklist you can run per user or per pilot group.
  • Microsoft 365 Apps moved to a supported update channel.
  • Copilot licenses assigned to a pilot group, then a wider group, through the admin center or PowerShell.
  • A verification and troubleshooting routine for users who still don't see Copilot.

A naming note: Microsoft has renamed Microsoft 365 Copilot to Microsoft Copilot and Microsoft 365 Copilot Chat to Microsoft Copilot Chat. The license appears as Microsoft Copilot in the admin center, while some licenses and SKUs still use the older name during the transition. This article uses "Copilot" for the licensed product.

The prerequisite checklist

Work through this table for the pilot group first. Each row is a documented requirement.

RequirementWhat to checkNotes
Qualifying base licenseUser has an eligible Microsoft 365, Office 365, Teams, Exchange, SharePoint, OneDrive, Planner, Project or Visio planCopilot is an add-on; Microsoft 365 E7 includes it
Entra work or school accountUser is a member account in your tenantGuests and other cross-tenant users can't be licensed
Usage locationUsageLocation set to a valid two-letter country codeRequired for direct assignment; group-based licensing falls back to the tenant location
Exchange Online mailboxPrimary mailbox hosted in Exchange OnlineNeeded for email, calendar and meeting experiences; group mailboxes aren't supported
OneDriveUser has a provisioned OneDrive accountSome Copilot features require it
Microsoft 365 AppsInstalled with user-based licensingCopilot isn't available with device-based licensing
Update channelCurrent Channel or Monthly Enterprise ChannelNot Semi-Annual Enterprise Channel
Office Feature Updates taskRuns on schedule and reaches the networkNeeded for core Copilot experiences in Word, Excel, PowerPoint and OneNote
TeamsSupported Windows, Mac, web, Android or iOS clientTurn on transcription or recording for meeting content after the meeting ends
OutlookSupported classic Outlook or new Outlook for Windows and MacMailbox in Exchange Online
BrowserCurrent Edge, Chrome, Firefox or SafariThird-party cookies must be enabled for Word, Excel and PowerPoint for the web
Network*.cloud.microsoft allowed, Microsoft 365 endpoints allowed, WebSocket Secure connectivityAllow the whole *.cloud.microsoft domain, not selected hosts
Loop and WhiteboardEnabled for the tenantOnly if users need Copilot in those apps

Base licenses

The current eligible list includes Microsoft 365 E5, E3, F1 and F3, Microsoft 365 Business Premium, Standard and Basic, Microsoft 365 Apps for enterprise and for business, Office 365 E5, E3, E1 and F3, Microsoft Teams Enterprise, Teams EEA and Teams Essentials, Exchange Plan 1, Plan 2 and Kiosk, SharePoint Plan 1, Plan 2 and Kiosk, OneDrive for work and school Plan 1 and Plan 2, several Planner, Project and Visio plans, and Microsoft Clipchamp. Government (G5, G3, G1, F1, F3) and education (A5, A3, A2, A1) plans have their own lists. Check the licensing article linked below before purchase, because the list changes.

Network

Copilot traffic is Microsoft 365 traffic, with two specifics that commonly break pilots:

  • Allow *.cloud.microsoft. The primary URL of the Copilot app is moving to copilot.cloud.microsoft. Microsoft doesn't support allowing only selected application URLs in that domain. If you block it to stop personal Microsoft account sign-in, use tenant restrictions instead.
  • Allow full WebSocket Secure connectivity to *.office.com, *.cloud.microsoft and copilot.cloud.microsoft. TLS inspection, proxies with aggressive timeouts and SSE or SASE services that block WSS cause Copilot integrations to fail.

Microsoft provides a connectivity test for the Copilot app at https://connectivity.m365.cloud.microsoft/copilot.

Step 1: Check the readiness report

The Copilot readiness report shows which users are technically eligible.

  1. In the Microsoft 365 admin center, select Reports > Usage.
  2. Under Reports, select Microsoft Copilot, then Copilot.
  3. Review the Readiness tab: Total Prerequisite Licenses, Users on an eligible update channel, Assigned Licenses and Available Licenses.

The user table includes Has Copilot license been assigned, Uses eligible update channel, Teams, Outlook and Office document activity, and Suggested candidate for Copilot, which flags the top 25% of unlicensed users by usage of the apps where Copilot adds value. Select Export to work in a spreadsheet. If user names are hidden, change the report privacy setting in the admin center. The report can take up to 72 hours to become available.

Step 2: Move devices to a supported update channel

Copilot needs Microsoft 365 Apps on Current Channel or Monthly Enterprise Channel. Microsoft announced channel changes from July 2026 in which Semi-Annual Enterprise Channel receives feature and security updates monthly, on the same basis as Monthly Enterprise Channel. Until your devices report an eligible channel in the readiness report, treat them as not ready.

  1. Sign in to the Microsoft 365 Apps admin center at config.office.com.
  2. On the Recommendation based on your tenant card, select Enable cloud. After Monthly Enterprise appears under Cloud Update, return to Home and select Finish enabling cloud to add the Current profile.
  3. Go to Inventory, select Show all devices, then Switch device update channel.
  4. Enter the Entra group you'll use for Copilot licenses (Entra groups used here can contain a mix of user and device objects and can be nested up to three levels), choose the channel, and select Move devices.

The channel change can take up to 24 hours. It's a point-in-time action, so users added to the group later need another channel change. The channel change feature is in public preview.

Option B: Intune settings catalog

Create a Windows 10 and later settings catalog profile with Microsoft Office 2016 (Machine) > Updates settings:

SettingValue
Enable Automatic UpdatesEnabled
Hide option to enable or disable updatesEnabled
Hide update notificationsDisabled
Office 365 Client ManagementDisabled
Update ChannelEnabled, Current Channel or Monthly Enterprise Channel
Update DeadlineEnabled, 1
Update PathCurrent Channel: http://officecdn.microsoft.com/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60; Monthly Enterprise: http://officecdn.microsoft.com/pr/55336b82-a18d-4dd6-b5f6-9e5095c314a6
Target VersionDisabled

If you deploy Microsoft 365 Apps as a required Intune app with a different channel in its configuration, the app re-enforces its own channel and devices flip back. Exclude the Copilot group from that app or create a new app with the target channel.

Step 3: Prepare the licensing groups

Use security groups for pilot and production waves, for example Copilot-Pilot and Copilot-Wave2. Keep these rules in mind:

  • Group-based licensing in the Microsoft 365 admin center doesn't support nested groups. Only direct members of the licensed group get a license.
  • Users without a usage location inherit the tenant's location. If you have users in several countries, set the location during user creation.
  • When moving users between licensed groups, add them to the new group, confirm the license appears, then remove them from the old group. The reverse order leaves them unlicensed until processing finishes.

Step 4: Assign the licenses

In the Microsoft 365 admin center

You need at least the Groups Administrator, License Administrator or User Administrator role.

  1. Go to Billing > Licenses and select Assign licenses.
  2. Search for the group and select it.
  3. Select the Microsoft Copilot subscription.
  4. Optionally select Turn apps and services on or off to exclude specific service plans.
  5. Select Assign licenses.

You can also open Billing > Licenses > Microsoft Copilot to assign to individual users, or use the Copilot setup guide in the admin center, which walks through the same assignment.

With Microsoft Graph PowerShell

Connect with the scopes needed to read SKUs and assign licenses:

Connect-MgGraph -Scopes User.ReadWrite.All, Organization.Read.All, LicenseAssignment.ReadWrite.All

Find the Copilot SKU and how many units are consumed. In the licensing reference, the Copilot product's string ID is Microsoft_365_Copilot, but confirm what your tenant shows:

Get-MgSubscribedSku -All |
    Where-Object SkuPartNumber -like '*Copilot*' |
    Select-Object SkuPartNumber, SkuId, ConsumedUnits

Find pilot users without a usage location, and set it before direct assignment:

Get-MgUser -All -Select Id,DisplayName,UserPrincipalName,UsageLocation,UserType |
    Where-Object { $_.UsageLocation -eq $null -and $_.UserType -eq 'Member' }
 
Update-MgUser -UserId "megan@contoso.com" -UsageLocation US

Assign the license to one user:

$copilotSku = Get-MgSubscribedSku -All | Where-Object SkuPartNumber -eq 'Microsoft_365_Copilot'
Set-MgUserLicense -UserId "megan@contoso.com" -AddLicenses @{SkuId = $copilotSku.SkuId} -RemoveLicenses @()

Or assign it to a group, which is easier to audit and reverse:

$copilotSku = Get-MgSubscribedSku -All | Where-Object SkuPartNumber -eq 'Microsoft_365_Copilot'
$params = @{
    addLicenses    = @(@{ skuId = $copilotSku.SkuId; disabledPlans = @() })
    removeLicenses = @()
}
Set-MgGroupLicense -GroupId "<group-object-id>" -BodyParameter $params

Set-MgGroupLicense accepts LicenseAssignment.ReadWrite.All as its least privileged permission. To exclude service plans, put their ServicePlanId values from the SKU's ServicePlans in disabledPlans.

Step 5: Configure Copilot settings

Go to Microsoft 365 admin center > Copilot to view license assignment status, manage data security and compliance controls, configure plugins and permissions, and control the use of web data as grounding data. Decide on web search before wide rollout; the web search admin guide covers the Cloud Policy setting and what data leaves the tenant. Also review oversharing in SharePoint, since Copilot can reach anything a user can already open.

Verify the assignment

  1. In Billing > Licenses > Microsoft Copilot, confirm the group and the assigned count.
  2. Check a user under Users > Active users, or with PowerShell:
Get-MgUserLicenseDetail -UserId "megan@contoso.com" | Select-Object SkuPartNumber
  1. Run the Copilot License Details diagnostic (https://aka.ms/CopilotLicenseDetails) for the user. It checks whether the account meets the licensing requirements for Copilot features.
  2. Ask the user to open Word or Outlook. Copilot can take up to 24 hours to appear and may need an app restart.

Troubleshooting

SymptomLikely causeFix
Copilot missing in desktop apps after a daySemi-Annual Enterprise Channel, or the app hasn't restartedMove the device to Current or Monthly Enterprise; restart the app
Copilot missing on a shared or kiosk deviceDevice-based licensing for Microsoft 365 AppsUse user-based licensing
Copilot button greyed out on a documentFile is read-onlyOpen an editable copy
Copilot missing in Word for the webThird-party cookies blockedAllow third-party cookies for Microsoft 365 web apps
Copilot loads then fails or hangsWebSockets blocked or TLS inspection on *.cloud.microsoftAllow WSS and exclude the domains from inspection
User in a nested group got no licenseNested groups aren't supported for group licensingAdd the user directly to the licensed group
Set-MgUserLicense fails for a synced userNo usage locationSet UsageLocation first
Group shows users with errorsInsufficient licenses, conflicting service plans, missing dependencies, proxy address or usage location problemsOpen the product, select Errors & issues, fix the cause, then Reprocess
Guest user can't be licensedCross-tenant users aren't supportedLicense the user's account in its home tenant

Rollout and closing checklist

Microsoft's guidance is three phases: a pilot group of early adopters across business units, a wider deployment by group, and an operate phase using the Copilot usage report and the Copilot Dashboard in Viva Insights. Assign licenses to a wave only after its devices show an eligible update channel.

  • Base license, usage location, mailbox and OneDrive confirmed for the wave.
  • Devices on Current or Monthly Enterprise Channel in the readiness report.
  • *.cloud.microsoft and WSS allowed; connectivity test passed.
  • Licenses assigned to a non-nested security group; errors tab empty.
  • Copilot settings, web search and SharePoint oversharing reviewed.
  • Pilot users verified with the License Details diagnostic.

Tenants still consolidating mail and files from another platform should finish that first; the Google Workspace to Microsoft 365 migration guide covers mailbox and OneDrive cutover, both of which Copilot depends on.

References

Questions people ask

What license do users need before they can get Microsoft 365 Copilot?

Copilot is an add-on, so each user needs a qualifying base plan such as Microsoft 365 E3 or E5, Office 365 E1, E3 or E5, Microsoft 365 Business Basic, Standard or Premium, Microsoft 365 F1 or F3, or Microsoft 365 Apps for enterprise. Microsoft 365 E7 already includes Copilot. Microsoft keeps the full list in the Copilot licensing article.

Which Microsoft 365 Apps update channel does Copilot need?

Current Channel or Monthly Enterprise Channel. Copilot is available in all update channels except Semi-Annual Enterprise Channel, and the Copilot readiness report shows which users are on an eligible channel.

How long after license assignment does Copilot appear in Word and Excel?

For some apps it can take up to 24 hours, and users might need to restart or refresh the app. The file must also be editable rather than read-only for Copilot to work on it.

Can I assign Copilot licenses to guest users?

No. Assigning Copilot licenses to cross-tenant users, including guests, isn't supported. Copilot also isn't available with device-based licensing for Microsoft 365 Apps for enterprise.

Microsoft 365 CopilotMicrosoft 365 Admin CenterMicrosoft Entra IDMicrosoft Graph PowerShellMicrosoft 365 Apps
  1. Audit, Retain and Search Microsoft 365 Copilot Prompts with Purview

    Find Copilot interactions in the Purview audit log, keep or delete prompts and responses with a retention policy, and search or purge them with eDiscovery when something goes wrong.

    AI engineering11 min read
  2. Azure OpenAI Keyless Access: Managed Identity, Entra ID and Private Endpoints

    Remove API keys from Azure OpenAI: call it with a managed identity and Entra ID RBAC, disable local auth, and reach it only through a private endpoint with public network access turned off.

    AI engineering12 min read
  3. Build RAG Over SharePoint Documents Without Breaking Permissions

    Ground an internal AI assistant on SharePoint files so each user only gets answers from documents they can open, using the Copilot Retrieval API or Azure AI Search with ACL ingestion.

    AI engineering12 min read