Before you assign Microsoft 365 Copilot licenses, confirm that each user has a qualifying base license, a Microsoft Entra work account with a usage location, an Exchange Online mailbox, a OneDrive account, and Microsoft 365 Apps on Current Channel or Monthly Enterprise Channel, and that your network allows *.cloud.microsoft. Then assign the Copilot license to a security group on Billing > Licenses in the Microsoft 365 admin center, or with Set-MgGroupLicense or Set-MgUserLicense in Microsoft Graph PowerShell, and verify with the Copilot readiness report.
Who this is for and what you will have at the end
This guide is for Microsoft 365 administrators who have bought Copilot licenses, or are about to, and want users to see Copilot the day they're licensed rather than a week later after a round of tickets. It assumes users already exist in Microsoft Entra ID with Microsoft 365 workloads.
At the end you will have:
- A prerequisite checklist you can run per user or per pilot group.
- Microsoft 365 Apps moved to a supported update channel.
- Copilot licenses assigned to a pilot group, then a wider group, through the admin center or PowerShell.
- A verification and troubleshooting routine for users who still don't see Copilot.
A naming note: Microsoft has renamed Microsoft 365 Copilot to Microsoft Copilot and Microsoft 365 Copilot Chat to Microsoft Copilot Chat. The license appears as Microsoft Copilot in the admin center, while some licenses and SKUs still use the older name during the transition. This article uses "Copilot" for the licensed product.
The prerequisite checklist
Work through this table for the pilot group first. Each row is a documented requirement.
| Requirement | What to check | Notes |
|---|---|---|
| Qualifying base license | User has an eligible Microsoft 365, Office 365, Teams, Exchange, SharePoint, OneDrive, Planner, Project or Visio plan | Copilot is an add-on; Microsoft 365 E7 includes it |
| Entra work or school account | User is a member account in your tenant | Guests and other cross-tenant users can't be licensed |
| Usage location | UsageLocation set to a valid two-letter country code | Required for direct assignment; group-based licensing falls back to the tenant location |
| Exchange Online mailbox | Primary mailbox hosted in Exchange Online | Needed for email, calendar and meeting experiences; group mailboxes aren't supported |
| OneDrive | User has a provisioned OneDrive account | Some Copilot features require it |
| Microsoft 365 Apps | Installed with user-based licensing | Copilot isn't available with device-based licensing |
| Update channel | Current Channel or Monthly Enterprise Channel | Not Semi-Annual Enterprise Channel |
| Office Feature Updates task | Runs on schedule and reaches the network | Needed for core Copilot experiences in Word, Excel, PowerPoint and OneNote |
| Teams | Supported Windows, Mac, web, Android or iOS client | Turn on transcription or recording for meeting content after the meeting ends |
| Outlook | Supported classic Outlook or new Outlook for Windows and Mac | Mailbox in Exchange Online |
| Browser | Current Edge, Chrome, Firefox or Safari | Third-party cookies must be enabled for Word, Excel and PowerPoint for the web |
| Network | *.cloud.microsoft allowed, Microsoft 365 endpoints allowed, WebSocket Secure connectivity | Allow the whole *.cloud.microsoft domain, not selected hosts |
| Loop and Whiteboard | Enabled for the tenant | Only if users need Copilot in those apps |
Base licenses
The current eligible list includes Microsoft 365 E5, E3, F1 and F3, Microsoft 365 Business Premium, Standard and Basic, Microsoft 365 Apps for enterprise and for business, Office 365 E5, E3, E1 and F3, Microsoft Teams Enterprise, Teams EEA and Teams Essentials, Exchange Plan 1, Plan 2 and Kiosk, SharePoint Plan 1, Plan 2 and Kiosk, OneDrive for work and school Plan 1 and Plan 2, several Planner, Project and Visio plans, and Microsoft Clipchamp. Government (G5, G3, G1, F1, F3) and education (A5, A3, A2, A1) plans have their own lists. Check the licensing article linked below before purchase, because the list changes.
Network
Copilot traffic is Microsoft 365 traffic, with two specifics that commonly break pilots:
- Allow
*.cloud.microsoft. The primary URL of the Copilot app is moving tocopilot.cloud.microsoft. Microsoft doesn't support allowing only selected application URLs in that domain. If you block it to stop personal Microsoft account sign-in, use tenant restrictions instead. - Allow full WebSocket Secure connectivity to
*.office.com,*.cloud.microsoftandcopilot.cloud.microsoft. TLS inspection, proxies with aggressive timeouts and SSE or SASE services that block WSS cause Copilot integrations to fail.
Microsoft provides a connectivity test for the Copilot app at https://connectivity.m365.cloud.microsoft/copilot.
Step 1: Check the readiness report
The Copilot readiness report shows which users are technically eligible.
- In the Microsoft 365 admin center, select Reports > Usage.
- Under Reports, select Microsoft Copilot, then Copilot.
- Review the Readiness tab: Total Prerequisite Licenses, Users on an eligible update channel, Assigned Licenses and Available Licenses.
The user table includes Has Copilot license been assigned, Uses eligible update channel, Teams, Outlook and Office document activity, and Suggested candidate for Copilot, which flags the top 25% of unlicensed users by usage of the apps where Copilot adds value. Select Export to work in a spreadsheet. If user names are hidden, change the report privacy setting in the admin center. The report can take up to 72 hours to become available.
Step 2: Move devices to a supported update channel
Copilot needs Microsoft 365 Apps on Current Channel or Monthly Enterprise Channel. Microsoft announced channel changes from July 2026 in which Semi-Annual Enterprise Channel receives feature and security updates monthly, on the same basis as Monthly Enterprise Channel. Until your devices report an eligible channel in the readiness report, treat them as not ready.
Option A: Cloud Update (recommended)
- Sign in to the Microsoft 365 Apps admin center at
config.office.com. - On the Recommendation based on your tenant card, select Enable cloud. After Monthly Enterprise appears under Cloud Update, return to Home and select Finish enabling cloud to add the Current profile.
- Go to Inventory, select Show all devices, then Switch device update channel.
- Enter the Entra group you'll use for Copilot licenses (Entra groups used here can contain a mix of user and device objects and can be nested up to three levels), choose the channel, and select Move devices.
The channel change can take up to 24 hours. It's a point-in-time action, so users added to the group later need another channel change. The channel change feature is in public preview.
Option B: Intune settings catalog
Create a Windows 10 and later settings catalog profile with Microsoft Office 2016 (Machine) > Updates settings:
| Setting | Value |
|---|---|
| Enable Automatic Updates | Enabled |
| Hide option to enable or disable updates | Enabled |
| Hide update notifications | Disabled |
| Office 365 Client Management | Disabled |
| Update Channel | Enabled, Current Channel or Monthly Enterprise Channel |
| Update Deadline | Enabled, 1 |
| Update Path | Current Channel: http://officecdn.microsoft.com/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60; Monthly Enterprise: http://officecdn.microsoft.com/pr/55336b82-a18d-4dd6-b5f6-9e5095c314a6 |
| Target Version | Disabled |
If you deploy Microsoft 365 Apps as a required Intune app with a different channel in its configuration, the app re-enforces its own channel and devices flip back. Exclude the Copilot group from that app or create a new app with the target channel.
Step 3: Prepare the licensing groups
Use security groups for pilot and production waves, for example Copilot-Pilot and Copilot-Wave2. Keep these rules in mind:
- Group-based licensing in the Microsoft 365 admin center doesn't support nested groups. Only direct members of the licensed group get a license.
- Users without a usage location inherit the tenant's location. If you have users in several countries, set the location during user creation.
- When moving users between licensed groups, add them to the new group, confirm the license appears, then remove them from the old group. The reverse order leaves them unlicensed until processing finishes.
Step 4: Assign the licenses
In the Microsoft 365 admin center
You need at least the Groups Administrator, License Administrator or User Administrator role.
- Go to Billing > Licenses and select Assign licenses.
- Search for the group and select it.
- Select the Microsoft Copilot subscription.
- Optionally select Turn apps and services on or off to exclude specific service plans.
- Select Assign licenses.
You can also open Billing > Licenses > Microsoft Copilot to assign to individual users, or use the Copilot setup guide in the admin center, which walks through the same assignment.
With Microsoft Graph PowerShell
Connect with the scopes needed to read SKUs and assign licenses:
Connect-MgGraph -Scopes User.ReadWrite.All, Organization.Read.All, LicenseAssignment.ReadWrite.AllFind the Copilot SKU and how many units are consumed. In the licensing reference, the Copilot product's string ID is Microsoft_365_Copilot, but confirm what your tenant shows:
Get-MgSubscribedSku -All |
Where-Object SkuPartNumber -like '*Copilot*' |
Select-Object SkuPartNumber, SkuId, ConsumedUnitsFind pilot users without a usage location, and set it before direct assignment:
Get-MgUser -All -Select Id,DisplayName,UserPrincipalName,UsageLocation,UserType |
Where-Object { $_.UsageLocation -eq $null -and $_.UserType -eq 'Member' }
Update-MgUser -UserId "megan@contoso.com" -UsageLocation USAssign the license to one user:
$copilotSku = Get-MgSubscribedSku -All | Where-Object SkuPartNumber -eq 'Microsoft_365_Copilot'
Set-MgUserLicense -UserId "megan@contoso.com" -AddLicenses @{SkuId = $copilotSku.SkuId} -RemoveLicenses @()Or assign it to a group, which is easier to audit and reverse:
$copilotSku = Get-MgSubscribedSku -All | Where-Object SkuPartNumber -eq 'Microsoft_365_Copilot'
$params = @{
addLicenses = @(@{ skuId = $copilotSku.SkuId; disabledPlans = @() })
removeLicenses = @()
}
Set-MgGroupLicense -GroupId "<group-object-id>" -BodyParameter $paramsSet-MgGroupLicense accepts LicenseAssignment.ReadWrite.All as its least privileged permission. To exclude service plans, put their ServicePlanId values from the SKU's ServicePlans in disabledPlans.
Step 5: Configure Copilot settings
Go to Microsoft 365 admin center > Copilot to view license assignment status, manage data security and compliance controls, configure plugins and permissions, and control the use of web data as grounding data. Decide on web search before wide rollout; the web search admin guide covers the Cloud Policy setting and what data leaves the tenant. Also review oversharing in SharePoint, since Copilot can reach anything a user can already open.
Verify the assignment
- In Billing > Licenses > Microsoft Copilot, confirm the group and the assigned count.
- Check a user under Users > Active users, or with PowerShell:
Get-MgUserLicenseDetail -UserId "megan@contoso.com" | Select-Object SkuPartNumber- Run the Copilot License Details diagnostic (
https://aka.ms/CopilotLicenseDetails) for the user. It checks whether the account meets the licensing requirements for Copilot features. - Ask the user to open Word or Outlook. Copilot can take up to 24 hours to appear and may need an app restart.
Troubleshooting
| Symptom | Likely cause | Fix |
|---|---|---|
| Copilot missing in desktop apps after a day | Semi-Annual Enterprise Channel, or the app hasn't restarted | Move the device to Current or Monthly Enterprise; restart the app |
| Copilot missing on a shared or kiosk device | Device-based licensing for Microsoft 365 Apps | Use user-based licensing |
| Copilot button greyed out on a document | File is read-only | Open an editable copy |
| Copilot missing in Word for the web | Third-party cookies blocked | Allow third-party cookies for Microsoft 365 web apps |
| Copilot loads then fails or hangs | WebSockets blocked or TLS inspection on *.cloud.microsoft | Allow WSS and exclude the domains from inspection |
| User in a nested group got no license | Nested groups aren't supported for group licensing | Add the user directly to the licensed group |
Set-MgUserLicense fails for a synced user | No usage location | Set UsageLocation first |
| Group shows users with errors | Insufficient licenses, conflicting service plans, missing dependencies, proxy address or usage location problems | Open the product, select Errors & issues, fix the cause, then Reprocess |
| Guest user can't be licensed | Cross-tenant users aren't supported | License the user's account in its home tenant |
Rollout and closing checklist
Microsoft's guidance is three phases: a pilot group of early adopters across business units, a wider deployment by group, and an operate phase using the Copilot usage report and the Copilot Dashboard in Viva Insights. Assign licenses to a wave only after its devices show an eligible update channel.
- Base license, usage location, mailbox and OneDrive confirmed for the wave.
- Devices on Current or Monthly Enterprise Channel in the readiness report.
*.cloud.microsoftand WSS allowed; connectivity test passed.- Licenses assigned to a non-nested security group; errors tab empty.
- Copilot settings, web search and SharePoint oversharing reviewed.
- Pilot users verified with the License Details diagnostic.
Tenants still consolidating mail and files from another platform should finish that first; the Google Workspace to Microsoft 365 migration guide covers mailbox and OneDrive cutover, both of which Copilot depends on.
References
- Microsoft Copilot requirements
- License options for Microsoft Copilot
- Set up Microsoft Copilot and assign licenses
- Microsoft Copilot readiness report
- Change update channel to prepare devices for Copilot
- Assign or unassign licenses to a group in the Microsoft 365 admin center
- Assign Microsoft 365 licenses to user accounts with PowerShell
- Set-MgGroupLicense
- Product names and service plan identifiers for licensing