Microsoft 365 Copilot Chat is the AI assistant most Australian businesses already own. It is included at no additional cost with almost every Microsoft 365 business plan, carries enterprise data protection, and is grounded in the web rather than the tenant. Prompts and responses are not used to train the underlying models.
That combination matters because the alternative is already happening. Staff who are not given a sanctioned AI assistant use a consumer one, on a personal account, with company information pasted in. The business is paying for a protected assistant it has never introduced. This guide covers what Copilot Chat includes, where it appears, what the data protection actually covers, where the paid Microsoft 365 Copilot seat begins, and how to switch the free tier on as a decision rather than a discovery.
What does Copilot Chat include at no extra cost?
First, the name. Microsoft renamed this product more than once on its way here: what started as Bing Chat Enterprise became Microsoft Copilot, and since January 2025 the work version has been Microsoft 365 Copilot Chat. Microsoft's current documentation states that Copilot Chat is available at no extra cost for Microsoft Entra account users on an eligible subscription, and the eligibility list is broad. It covers Microsoft 365 Business Basic, Business Standard and Business Premium, Microsoft 365 E3 and E5, the frontline F1 and F3 plans, the education and government suites, Office 365 E1 through E5, and even standalone Microsoft Teams licences.
In practice, if a business runs Microsoft 365 in Australia, its staff are eligible. What they get is more than a chat box:
- Web-grounded chat on current models. Microsoft's documentation names GPT-5, with a model selector that lets users choose Auto, Quick response or Think deeper depending on the question.
- File upload. Users can upload or drag in a document and ask questions over it. Uploaded files are stored in the user's OneDrive for Business as part of enterprise data protection, not sent outside the tenant's boundary.
- Copilot Pages, a persistent canvas for working AI output into something reusable, and image generation.
- Word, Excel and PowerPoint agents inside the Microsoft 365 Copilot app, which can generate documents, workbooks and presentations from a prompt. Generated PowerPoint files save to the user's OneDrive; Word and Excel outputs are available for download.
- Access to agents generally, including agents an organisation builds or buys, on a metered pay-as-you-go basis covered later in this guide.
Where do staff find it?
Copilot Chat is deliberately close to hand, which is exactly why a business should know every surface it appears on:
- The Microsoft 365 Copilot app, on web, Windows, Mac and mobile. On the web it lives at m365copilot.com, which lands signed-in users at m365.cloud.microsoft/chat.
- Microsoft Teams, as Chat in the left navigation.
- Outlook, as both a full pane in the left navigation and a side pane next to the message being read or written.
- Microsoft Edge, as a sidebar when the user is signed in with their Entra account. With the page-context setting on, it can summarise the web page or PDF currently open.
- The Copilot key on newer Windows keyboards, which managed organisations can remap to open the Microsoft 365 Copilot app.
The visual cue that matters is the green shield at the top of the chat window. It confirms the session is running under enterprise data protection with the user's work identity. Microsoft also labels the in-app experiences: a user with a paid seat sees M365 Copilot (Premium) in Word, Excel and PowerPoint, while users without one see a Basic label or no in-app chat at all, depending on tenant configuration.
What does enterprise data protection actually cover?
Enterprise data protection is a defined commitment, not a marketing phrase. Microsoft's documentation states that Copilot Chat prompts and responses are processed within the Microsoft 365 service boundary, covered by the Microsoft Data Protection Addendum and Product Terms, with Microsoft acting as a data processor. The line worth reading twice:
"With EDP, prompts and responses are protected by the same contractual terms and commitments widely trusted by our customers for their emails in Exchange and their files in SharePoint."
Concretely, that means:
- Prompts, responses and uploaded content are not used to train the underlying foundation models. Microsoft states this without qualification for the work product.
- Data is encrypted at rest and in transit, with tenant isolation, and GDPR and ISO/IEC 27018 commitments apply.
- Prompts and responses are logged and stored in Exchange within the tenant, which makes them available for audit, eDiscovery and Microsoft Purview retention policies. Chat history is a governed record, the same as email.
- AI-specific protections apply: harmful-content filtering, prompt-injection defences, protected material detection, and Microsoft's Customer Copyright Commitment for outputs.
The web-query nuance worth knowing
Copilot Chat improves answers by sending generated search queries to the Bing service. Those queries are a few words derived from the prompt, sent without user or tenant identifiers, never shared with advertisers and not used for model training. Whole prompts, uploaded files and summarised pages are not sent. The nuance is that Bing operates outside the Microsoft 365 service boundary under its own data-handling terms, which is why Microsoft gives admins an Allow web search in Copilot policy to manage it, and why Copilot Chat shows users the exact queries it sent in the citations of each response. A well-run rollout decides the web search position rather than inheriting the default.
What can it not do without a Copilot licence?
The boundary is grounding. Copilot Chat answers from the web and from whatever the user explicitly gives it. It does not search the tenant. The paid Microsoft 365 Copilot seat is what connects the assistant to Microsoft Graph, and that changes the product entirely. Without the paid seat there is:
- No tenant grounding in chat. Copilot Chat does not search the organisation's files, emails, meetings or Teams messages to answer a question. Ask it what was agreed with a client last month and it has nothing to draw on.
- No in-app Copilot in Word, Excel and PowerPoint. The full drafting, rewriting and in-document editing experience inside the Office applications is paid. The free tier's Word, Excel and PowerPoint agents generate files from chat, which is useful but a different workflow.
- No Researcher or Analyst reasoning agents, and no prebuilt Microsoft agents grounded in the tenant.
- No semantic index over work data. Standard access rather than priority access to models and features.
Organisational content can still reach Copilot Chat in four deliberate ways: a user pastes or uploads it, references a specific file they can access from the prompt box, works with content they have open in supported apps, or uses an agent that has been granted access to tenant content. There is also one meaningful carve-out: Copilot Chat in Outlook can work with the user's own mail, calendar, meetings and a limited set of their files, using lexical indexing rather than the semantic index the paid seat uses. It is a genuine convenience for inbox triage, and considerably narrower than full Graph grounding.
For scale: the paid Microsoft 365 Copilot add-on is AU$44.90 per user per month ex GST paid yearly, and the Business add-on for smaller organisations is AU$31.40 ex GST paid yearly, with Microsoft running a first-year promotional price of AU$26.91 for orders placed between 1 July and 30 September 2026. Prices checked August 2026. The free tier is how a business finds out which roles justify that spend.
What are pay-as-you-go agents?
Agents are the part of Copilot Chat that can cost money, and the part Microsoft has put entirely in the admin's hands. An agent grounded in tenant content, whether built in-house or acquired, consumes Copilot Credits when Copilot Chat users interact with it. Microsoft bills that consumption in one of two ways: metered pay-as-you-go against an Azure subscription, using the Copilot Studio meter with a published rate of US$0.01 per message, or prepaid Copilot Studio capacity packs of 25,000 credits per month, with automatic switchover to pay-as-you-go if a pack runs out.
- Pay-as-you-go billing is disabled by default. Nobody incurs agent charges until an administrator creates a billing policy and connects it to the service.
- Billing policies can be scoped to specific groups, carry budget limits, and send email notifications at spending milestones.
- Usage is visible in the Microsoft 365 admin centre under Cost Management, with a detailed breakdown in the Azure portal.
- Copilot credit policies let an organisation run prepaid credits for defined user groups without any Azure subscription at all.
The practical read: agents are an opt-in economy with a meter, a budget and an off switch, which makes them a controlled way to give unlicensed staff a taste of tenant-grounded AI for cents per interaction rather than a per-seat commitment.
How should a business roll it out deliberately?
Copilot Chat is pinned by default for most eligible users, so the real choice is not whether staff encounter it but whether the business is ready when they do. The deliberate version takes an afternoon of admin work and a short announcement:
- 1Confirm eligibility and surfaces. Check which plans staff are on, then decide where Copilot Chat should appear. The pinning setting in the Microsoft 365 admin centre controls Outlook and Teams; since 28 January 2026 Chat is a standing part of the Microsoft 365 Copilot app's navigation for all tenants.
- 2Decide the web search position. Leave the Allow web search in Copilot policy on for current-information quality, or restrict it for groups with stricter handling requirements. Decide it, and record why.
- 3Decide the agent billing position. Leaving pay-as-you-go disconnected is a legitimate choice. If agents are wanted, set a billing policy with a budget and notification thresholds on day one.
- 4Publish two sentences of guidance: use the one with the green shield, signed in with your work account, and put work information in nothing else. Staff cannot follow a distinction nobody has drawn for them.
- 5Announce it with three worked examples relevant to actual roles: summarise this tender, draft this reply, compare these two quotes. A tool staff were shown gets used; a tool staff stumbled on gets mistrusted.
- 6Watch the Copilot Chat usage report in the admin centre. Sustained, heavy use in particular roles is the cleanest business case that exists for the paid seat, built on the organisation's own evidence.
For organisations that need to hold Copilot Chat back for some or all users, Microsoft provides the controls: unpin it, manage the Copilot app through Integrated Apps in the admin centre, manage the Teams app by group, and manage the Edge sidebar by policy. Blocked users see a clear explanation page, and admins can add a link to the company's own AI policy. Microsoft's guidance is to use these in-service controls rather than network-level blocking, which it does not support and which tends to break the surrounding applications.
The one decision this guide cannot make is whether the free tier is enough, because that depends on which roles need tenant grounding. Frontrow built a five-question tool that gives an answer with current AUD pricing attached.