πŸ‡¨πŸ‡¦VancouverπŸ‡¨πŸ‡¦TorontoπŸ‡ΊπŸ‡ΈMiamiπŸ‡ΊπŸ‡ΈOrlandoπŸ‡ΊπŸ‡ΈLos Angeles
1-855-KOO-TECH
KootechnikelKootechnikel
Insights Β· Field notes from the SOC
Plain-language briefings from the people watching the alerts.
Weekly Β· No spam
AI productivity & agent platform

Microsoft Copilot

The AI that sits inside the work your team already does.

Kootechnikel delivers licensed Copilot rollout, permissions hygiene, and Purview data-boundary configuration for British Columbia SMBs β€” so Copilot surfaces the right answers without exposing the wrong files.

Forrester's 2024 TEI study measured up to 353% three-year ROI for SMBs that rolled out Microsoft 365 Copilot with proper readiness work. Microsoft reported 15 million paid Copilot seats by early 2026 β€” but only a 35.8% active-user conversion rate. That gap is the MSP's job to close.

What it is

Microsoft Copilot is a family of at least ten distinct SKUs, not a single product. Confusing one for another is the most common mistake Vancouver SMBs make when shopping the platform β€” the free Copilot Chat is not the paid Microsoft 365 Copilot, Copilot Studio is not GitHub Copilot, and Security Copilot is a different purchase, license model, and governance story entirely.

Underneath every Copilot product is the same Microsoft 365 service boundary: prompts and data stay inside the tenant's trust surface, models don't train on your data, and Microsoft Purview can apply sensitivity labels, DLP, and audit to every interaction. Copilot does not create new access β€” it surfaces existing access. That means every piece of incidental oversharing in SharePoint becomes instantly, conversationally discoverable.

We run Copilot rollouts as a six-phase lifecycle: discovery, readiness audit, remediation, pilot, broad rollout, and ongoing governance. The seats are the cheapest part. The value is in the remediation work that happens before the first prompt is typed β€” and the governance work that prevents the oversharing that kills every bad rollout.

The Copilot family

Ten-plus distinct products under one brand

By April 2026, β€œCopilot” is a family of at least ten distinct SKUs. Mixing them up is the most common mistake SMBs make when shopping the platform.

  • Microsoft 365 Copilot (flagship add-on)

    Lives inside Word, Excel, PowerPoint, Outlook, Teams, Loop, OneNote, Whiteboard, and Forms. Draft, summarize, explain, triage β€” grounded in Microsoft Graph so every response ties back to your own emails, files, meetings, and chats. Knowledge workers on a qualifying base license.

    LicensingRequires M365 E3/E5 or Business Basic/Standard/Premium base. Enterprise add-on US$30/user/month. New SMB (<300 seats) Business SKU at US$21/user/month (promotional US$18 through June 30, 2026). Bundled with Business Premium at US$32/user/month on annual commit.

  • Microsoft 365 Copilot Chat (free + paid)

    Two things share this name. Free tier: web-grounded chat with enterprise data protection, no Graph access, no in-app Copilot. Paid tier: the Copilot add-on above β€” Graph grounding, in-app Copilot, priority model access, agents. Ignite 2025 announced in-app Copilot Chat previews to non-licensed users in Outlook/Word/Excel/PowerPoint rolling out through early 2026.

    LicensingFree tier included with any M365 business license. Paid tier requires the Copilot add-on.

  • Copilot Studio (build your own agents)

    Low-code maker environment for custom AI agents and multi-agent systems. 1,400+ system connectors via MCP, Power Platform, and Microsoft Graph. Agents surface inside Microsoft 365 Copilot Chat, Teams, websites, or standalone. September 2025 shifted to Copilot Credits currency.

    LicensingCapacity-based. Prepaid at US$200/month per 25,000 Credits, or pay-as-you-go at US$0.01/Credit via Azure. Credit Pre-Purchase Plan (annual) saves 5–20%. No per-agent fee β€” capacity pools across tenant.

  • GitHub Copilot (code completion + agents)

    The original Copilot. Five tiers. 2025–2026 additions: Agent mode, MCP server support across all tiers, cloud-hosted coding agents, Copilot CLI, Copilot code review on pull requests. Copilot Workspace for Enterprise.

    LicensingFree ($0, 50 agent requests + 2,000 completions/mo); Pro ($10/mo); Pro+ ($39/mo, Claude Opus 4.7 + GitHub Spark); Business (~$19/user/mo, policy controls + IP indemnity); Enterprise (~$39/user/mo, Copilot Workspace + org knowledge bases).

  • Microsoft Security Copilot (SOC augmentation)

    Generative AI for security analysts. Investigates incidents, writes KQL, explains threats, reverse-engineers malware, drafts incident reports. Plugs into Defender XDR, Sentinel, Entra, Intune, Purview, and third-party tools.

    LicensingProvisioned Security Compute Units at US$4/SCU/hr; overage US$6/hr. Microsoft 365 E5 customers get 400 SCUs/month per 1,000 licenses free (capped at 10,000 SCUs) β€” effectively standard for E5 shops. A single 24/7 SCU costs ~$2,920/mo; real SOC usage typically 3–5 SCUs.

  • Copilot for Sales

    Embedded in Outlook and Teams for sellers. Meeting prep briefs, opportunity history summaries, contextual reply drafts, CRM field updates from email content, lead scoring. Works with Dynamics 365 Sales and Salesforce. 2026 release wave 1 upgraded to a "daily command center" with chat and mobile enhancements.

    LicensingNow included in the Microsoft 365 Copilot add-on. The separate $20/user/month Dynamics 365 Copilot SKU has been folded in.

  • Copilot for Service

    Suggests replies, recommends next actions, summarizes cases, deflects common tickets in the agent desktop. Integrates with ServiceNow, Salesforce Service Cloud, Zendesk.

    LicensingIncluded in the Microsoft 365 Copilot add-on.

  • Copilot for Finance

    Lives in Excel and Outlook for finance pros. Automates variance analysis, accelerates reconciliations, drafts collections emails, investigates anomalies. 2026 wave 1 upgraded as a "Finance Agent" daily command center.

    LicensingIncluded in the Microsoft 365 Copilot add-on.

  • Microsoft Agent 365 (new β€” GA May 1, 2026)

    The governance control plane for agents. Treats agents like identities: tenant-wide registry, access controls, monitoring, Entra/Purview/Defender policy enforcement. Announced at Ignite 2025 via the Frontier program; GA May 1, 2026.

    LicensingUS$15/user/month standalone, or bundled in the new E7 Frontier Suite.

  • Microsoft 365 E7 Frontier Suite (new β€” GA May 1, 2026)

    New super-SKU announced March 9, 2026. Bundles M365 E5 + Microsoft 365 Copilot + Entra Suite + Agent 365 at a ~15% bundle discount versus component pricing.

    LicensingUS$99/user/month.

Under the hood

How Copilot actually works

When a user types a prompt in Word, Outlook, or the Copilot app, the request never just goes "to ChatGPT." It takes a defined path inside the Microsoft 365 service boundary β€” the logical wall that contains your tenant's data. Copilot pre-processes the prompt through a step Microsoft calls grounding: it queries Microsoft Graph (the unified API over your emails, files, chats, meetings, calendar, and identity) and the semantic index (a per-user vector index that understands your content lexically and semantically). Grounding pulls only what the signed-in user has permission to access β€” Copilot inherits the user's Entra ID identity, Conditional Access policies, MFA state, and every SharePoint/OneDrive/Exchange ACL already on the data. If the user can't open it, Copilot can't see it.

The grounded prompt is then sent to a large language model hosted inside Microsoft's Azure-managed inference environment. As of 2026 that includes OpenAI GPT-5, GPT-5.1, and β€” following Microsoft's onboarding of Anthropic as a subprocessor in late 2025 β€” Anthropic models as well. Data is encrypted in transit; inference runs inside Microsoft's service boundary; and per Microsoft's commercial data protection commitment, prompts, responses, and Graph-grounded data are never used to train the foundation models. The EU Data Boundary and Advanced Data Residency commitments pin processing geography. Multi-tenant isolation is enforced at the Azure layer β€” other tenants cannot see your prompts or responses.

After the model returns a response, Copilot post-processes: responsible-AI filters (hate/violence/self-harm/PII), citation assembly (every answer links back to Graph documents that grounded it), and compliance hooks β€” Microsoft Purview can apply sensitivity labels to Copilot output, log the interaction for audit, and enforce DLP on both prompt and response. Critically, Copilot does not create new access β€” it surfaces existing access. That sounds innocuous until you realize every piece of incidental oversharing in SharePoint becomes instantly, conversationally discoverable. Which is why prerequisite #4 matters more than the license itself.

Key capabilities

  • Graph-grounded in your own data

    Every response is grounded against the Microsoft Graph β€” your emails, files, meetings, and chats β€” and only content the signed-in user can already access.

  • Cross-app context

    Draft in Word, summarize 30 days of Teams chat, explain a pivot in Excel, triage Outlook inbox, generate a PowerPoint from a Word doc β€” all inside the apps your team already uses.

  • Purview-governed

    Sensitivity labels and DLP policies apply to Copilot prompts and responses. AI Hub (DSPM for AI) shows which users and which sensitive data is flowing through Copilot.

  • Commercial data protection

    Prompts, responses, and Graph-grounded data are not used to train foundation models. Multi-tenant isolation enforced at the Azure layer β€” other tenants cannot see your data, period.

  • Model choice

    OpenAI GPT-5 / GPT-5.1 plus Anthropic models (onboarded as a Microsoft subprocessor in late 2025) across Copilot surfaces. Sora 2 video generation in Create.

  • Copilot Studio for custom agents

    Low-code agents connecting to 1,400+ systems via MCP. Agents surface inside Microsoft 365 Copilot Chat, Teams channels, websites, or as standalone endpoints.

  • Agent 365 governance

    GA May 1, 2026. Treats agents like identities: tenant-wide registry, access controls, monitoring dashboard, Entra/Purview/Defender policy enforcement.

  • British Columbia residency

    Canadian regions plus Advanced Data Residency add-on satisfy PIPEDA, BC PIPA, FOIPPA, and health-sector data-residency requirements.

The MSP-critical section

Prerequisites

A Copilot rollout that skips any of these will either leak data, underdeliver ROI, or both. In that order of cost.

  • 01

    Base licensing

    Microsoft 365 Copilot requires a qualifying base: E3, E5, F3, or Business Basic/Standard/Premium. Business Premium + Copilot at $32/user/month (annual) is the sweet spot for most BC SMBs.

  • 02

    Entra ID in a healthy state

    Cloud-identity or hybrid-identity only β€” on-prem-only AD doesn't work. Conditional Access enforced, MFA enabled, guest accounts reviewed. Copilot honors guest access; your external auditor's guest account can ground responses in your content.

  • 03

    SharePoint / OneDrive permissions hygiene

    The #1 blocker, full stop. Broken inheritance, "anyone with the link" sharing, stale site access, and orphaned Teams sites all become Copilot surface area. SharePoint Advanced Management (SAM β€” included with Copilot) surfaces oversharing; Restricted SharePoint Search (RSS) whitelists reviewed sites; the new SharePoint Admin Agent automates remediation.

  • 04

    Microsoft Purview foundation

    Sensitivity label taxonomy (Public / Internal / Confidential / Highly Confidential), auto-labeling on top 5 sensitive data types (SIN, credit cards, PHIPA/PIPEDA categories), DLP on Exchange/SharePoint/Teams, Insider Risk policies on. Copilot responses inherit the highest sensitivity label of any source.

  • 05

    Teams + Exchange Online + OneDrive active

    Copilot needs Exchange Online (not on-prem hybrid with mailboxes still on-prem), OneDrive provisioned, and Teams active. Skype for Business is out β€” it's Teams only.

  • 06

    Network

    No special firewall rules for most tenants. For SD-WAN / zero-trust / proxy setups, validate *.office.com, *.microsoft.com, *.cloud.microsoft, *.office365.com on the optimize/allow list without TLS inspection. Copilot is latency-sensitive.

  • 07

    Microsoft 365 Apps current channel

    Copilot requires recent Microsoft 365 Apps builds. Outlook needs New Outlook for full parity. Semi-Annual Enterprise lags features; Current Channel or Monthly Enterprise recommended during rollout.

  • 08

    Audit and backup

    Purview Audit (Standard or Premium) on, ideally Premium's 1-year retention. Microsoft 365 Backup (or Veeam) recommended β€” Copilot generates, and agents modify, content at machine speed; undo-by-restore matters.

Kootechnikel’s approach

Six-phase rollout framework

Every phase has a deliverable the client sees. This is the plan, not just the plan to make a plan.

  1. Phase 1

    Discovery & business case

    • Stakeholder workshop: which departments, which use cases, which KPIs (hours saved, win rate, time-to-quote, ticket deflection).
    • Inventory current M365 licensing, baseline Secure Score, review org chart and power-user candidates.
    • Deliverable: a one-page business case with target ROI and six-month milestones.
  2. Phase 2

    Readiness audit

    • SharePoint oversharing scan via SAM: "anyone" links, external sharing, broken inheritance, inactive sites.
    • Purview gap assessment: sensitivity labels, DLP, Insider Risk, Audit configuration.
    • Entra posture review: Conditional Access, MFA, guest accounts, legacy auth, high-privilege role sprawl.
    • Deliverable: redline report with every blocker tagged Must-Fix / Should-Fix / Monitor plus effort estimate.
  3. Phase 3

    Remediation & governance foundation

    • Deploy sensitivity label taxonomy and auto-labeling rules.
    • Remediate top oversharing sites; enable Restricted SharePoint Search during rollout.
    • Tighten Conditional Access; enable the new AI-specific "Protect AI with Conditional Access" template.
    • Stand up SharePoint Admin Agent in monitor mode.
    • Deliverable: governance baseline document and a "Copilot-safe" tenant state.
  4. Phase 4

    Pilot (4–8 weeks, 15–50 users)

    • Stand up a Copilot Champions cohort across 2–3 departments.
    • Weekly prompt libraries, coached use-case sessions, Copilot Dashboard onboarded for adoption telemetry.
    • Pilot scorecard: weekly active users, prompts per user, use-case coverage, qualitative feedback.
    • Deliverable: pilot readout with measured hours-saved per user and a go/no-go recommendation.
  5. Phase 5

    Broad rollout & adoption

    • Phased license expansion department-by-department, not a flash cut.
    • Per-department "day-in-the-life" training built on the real prompts that worked in pilot.
    • Prompt library per role (finance, ops, sales, HR, IT).
    • Deliverable: org-wide adoption plan with named champions, office hours cadence, and 90-day milestone.
  6. Phase 6

    Measure, govern, optimize (ongoing quarterly)

    • Quarterly Copilot Business Review: license utilization, use-case coverage, hours-saved tracking, reclaim of inactive seats.
    • Governance drift check: new oversharing, label coverage trends, Purview AI Hub findings, Agent 365 registry hygiene.
    • Roadmap update: new Copilot agents, Copilot Studio candidates, model-choice tuning.
    • Deliverable: quarterly CBR deck the client can walk into their board meeting with.

Who it’s for

  • A 60-person Vancouver law firm wanting to cut matter-summary and client-communication drafting time by 30-40%, with sensitivity labels keeping privileged client content out of the wrong summaries.
  • A 120-person professional services firm buying E5 β€” getting the bundled 400 SCUs of Security Copilot for free and wanting a partner to actually enable it for the SOC.
  • A mid-market finance or operations team with a messy SharePoint tenant that needs oversharing remediation before any Copilot license gets issued.
Real failure modes

Risks we actually see

Not vendor FUD. These are specific things Kootechnikel has encountered in Vancouver tenants this year.

  • Oversharing via inherited permissions

    The classic. A 2019 SharePoint migration with "Everyone except external users" on the root hub means Copilot can now conversationally summarize HR salary bands to any licensed user. Copilot doesn't create the leak β€” it makes an existing leak unavoidable.

  • Prompt injection via untrusted email

    2025–2026 saw two real exploits: EchoLeak (CVE-2025-32711), a zero-click exfil via markdown in email, and XPIA (Cross-Prompt Injection) which hijacks Copilot summary output to produce convincing phishing inside the Copilot trust surface. Both patched, but the attack class is live. Mitigation: keep M365 Apps current, enable Defender for Office 365 Safe Links/Attachments on Copilot-processed mail.

  • Hallucination in legal, financial, or clinical context

    Copilot is grounded but not infallible. It will confidently cite a clause from an outdated contract, or confuse two similarly-named customers in a pipeline summary. High-stakes outputs need human-in-the-loop by policy, not by hope.

  • Shadow Copilot

    Staff refused an enterprise seat still have their personal Microsoft account with free consumer Copilot on their phone β€” and nothing stops them from pasting work content into it. Free consumer Copilot is NOT under your tenant's Enterprise Data Protection boundary. Mitigation: acceptable-use policy, Intune app protection, Purview endpoint DLP, plus a sanctioned good-enough alternative.

  • Cost creep from under-utilized licenses

    At US$30/user/month ($360/year), a Copilot seat used twice a month is a negative-ROI line item. Forrester: bottom-quartile SMBs see 132% ROI, top-quartile 353% β€” the difference is adoption discipline, not the product. Measure monthly; reclaim dormant seats quarterly.

  • Agent sprawl

    As Copilot Studio and Agent 365 mature, non-IT staff can build agents touching sensitive data. Microsoft's February 2026 security blog flagged this as a top-10 risk class. Mitigation: Agent 365 registry, Purview DSPM for AI, approval workflow on agent publishing.

British Columbia lens

Governance & compliance

  • PIPEDA + BC PIPA + FOIPPA

    Canadian federal and BC provincial privacy laws. Copilot outputs processing PII trigger PIPEDA/PIPA obligations; sensitivity labeling and DLP are how we prove we meet them. FOIPPA (public bodies, health authorities, school districts) requires Canadian residency.

  • Purview sensitivity labels + auto-labeling

    Label taxonomy (Public / Internal / Confidential / Highly Confidential) with auto-labeling on PII, SIN, health identifiers, and financial data. Copilot responses inherit the highest label of any grounding document.

  • Purview DSPM for AI (AI Hub)

    Purpose-built dashboard for Copilot and agent activity. Shows which users are using Copilot, what sensitive data appeared in prompts, which responses referenced labeled content. This is the control pane we watch.

  • Conditional Access for Copilot

    The new 'Protect AI with Conditional Access' policy template enforces compliant-device and MFA before Copilot access. Integrates with Entra ID P1/P2 already present in Business Premium or E3/E5.

  • Compliance Manager + Purview Audit Premium

    PIPEDA, ISO 27001, SOC 2 templates track control coverage. Premium Audit provides 1-year retention and high-value event categories β€” evidence for regulators and cyber-insurance.

  • Communication Compliance

    Policies catch inappropriate Copilot-generated content before it leaves the tenant β€” relevant for regulated industries and public-sector clients.

Integrations

Native in every Microsoft 365 app (Word, Excel, PowerPoint, Outlook, Teams, Loop, OneNote, Whiteboard, Forms) and the Microsoft 365 Copilot Chat surface. Agents built in Copilot Studio integrate with 1,400+ external systems via MCP, Power Platform connectors, and Microsoft Graph. Security Copilot plugs into Defender XDR, Sentinel, Entra, Intune, Purview, and third-party tools (ServiceNow, Splunk, etc.). Copilot for Sales works with Dynamics 365 Sales and Salesforce; Copilot for Service with Dynamics 365, ServiceNow, and Salesforce Service Cloud.

Partner status & certifications

Microsoft Solutions Partner β€” Modern Work (designation under the Microsoft AI Cloud Partner Program). Specializations relevant to Copilot include Adoption and Change Management, Identity and Access Management, Information Protection and Governance, and the new Secure AI Productivity specialization (April 2026, replacing Teamwork Deployment).

Pricing model

Copilot add-on licensed per-user-per-month on top of a qualifying Microsoft 365 base. We resell through our CSP channel with quarterly right-sizing reviews β€” most BC SMBs save 10–15% vs. direct MCA retail and avoid the enterprise-only $30 tier when the $21 Business SKU fits. Forrester measured ROI ranging 132% (bottom quartile) to 353% (top quartile) β€” the difference is adoption discipline, not the product.

Verified public pricing, April 2026

Licensing economics

  • Microsoft 365 Copilot (enterprise add-on): US$30/user/month, annual commit. Requires E3, E5, Business Basic/Standard/Premium, or F3.
  • Microsoft 365 Copilot Business (SMB, <300 seats): US$21/user/month; promotional US$18/user/month through June 30, 2026.
  • Bundled: Business Basic + Copilot US$27/mo; Business Standard + Copilot US$22/mo; Business Premium + Copilot US$32/mo (annual commit).
  • Microsoft 365 E7 Frontier Suite (GA May 1, 2026): US$99/user/mo. Bundles E5 + M365 Copilot + Entra Suite + Agent 365. ~15% savings.
  • Agent 365 (standalone): US$15/user/month.
  • GitHub Copilot: Free $0; Pro $10; Pro+ $39; Business ~$19; Enterprise ~$39 per user per month.
  • Microsoft Security Copilot: US$4/SCU/hour provisioned; US$6/hour overage. M365 E5 gets 400 SCUs/month per 1,000 licenses free (capped at 10,000 SCUs).
  • Copilot Studio: US$200/month per 25,000 Credits, or US$0.01/Credit PAYG. Annual Pre-Purchase Plan saves 5–20%. No per-agent fee.
  • Copilot for Sales / Service / Finance: now included in the Microsoft 365 Copilot add-on.
  • July 2026 price hike: Microsoft announced across-the-board Office suite increases effective July 1, 2026. Annual commitments locked before that date keep current pricing.
Honest filter

Who should NOT adopt yet

We will tell a prospect to wait if any of these apply. Remediation is cheaper than a regulator letter.

  • Unhygienic SharePoint β€” more than ~5% of content is "anyone with the link" shared, or significant broken inheritance. Fix first. An oversharing remediation engagement is cheaper than the regulator letter.
  • No sensitivity label taxonomy and no plan for one. Copilot with no labels is Copilot with no guardrails.
  • On-prem-heavy tenants. If primary file share is still Windows file server or on-prem Exchange is still hosting mailboxes, Copilot can't ground against that content. Modernize first.
  • Fewer than ~10 knowledge workers. ROI math at the small end is unforgiving. Better served by Copilot Chat (free) plus Business Premium + Copilot for the two heaviest-use roles.
  • No budget for adoption work. Licenses without rollout land at Forrester's 132% bottom-quartile result, not 353% top-quartile. If the budget conversation ends at seat cost, the project will underdeliver.
  • Pending M&A or tenant migration in next 6 months. Deploy to destination state, not in-flight state.
  • Regulated sector with unfinished residency decision. Public sector and health authority clients that haven't provisioned Advanced Data Residency or finalized FOIPPA review should finish that first.
The deliverables, plainly stated

What Kootechnikel actually does

  • Copilot Readiness Assessment

    Two-week engagement producing a written go/no-go, a remediation backlog with effort estimates, and a business case the client brings to finance. Fixed fee.

  • SharePoint oversharing remediation

    Using SharePoint Advanced Management, Restricted SharePoint Search, and the SharePoint Admin Agent to clean up before the first prompt is typed.

  • Purview foundation buildout

    Sensitivity label taxonomy, auto-labeling rules, DLP policies, AI Hub (DSPM for AI), Compliance Manager PIPEDA/SOC 2 templates.

  • Pilot program operation

    Champion identification, prompt library curation, weekly coaching, adoption telemetry instrumentation.

  • License optimization and CSP procurement

    Resell Microsoft 365 Copilot through our CSP channel with quarterly right-sizing. Most BC SMBs save 10–15% vs. direct MCA retail.

  • Copilot Studio agent development

    Low-code agent builds for specific workflows (ticket triage, proposal generation, finance close helpers), with MCP integration and Agent 365 governance.

  • Security Copilot enablement for SOC

    Stand up Security Compute Units, connect Defender/Sentinel/Entra plugins, build analyst playbooks β€” especially important for E5 shops with 400 free SCUs they're not using.

  • Ongoing governance & Quarterly Business Reviews

    Adoption telemetry, utilization reclaim, governance drift detection, agent registry hygiene, roadmap alignment with Microsoft's release waves.

Why we chose them

Copilot is the single biggest productivity bet Microsoft has made this decade, and it's going to be in every SMB tenant within 24 months whether we guide it or not. The question isn't whether to adopt. It's whether you adopt with clean sharing, labeled data, and measured utilization β€” or whether you paste $360/user/year into a tenant that leaks HR salaries conversationally to anyone with a license. We run the full rollout lifecycle because the license is the 20% and the remediation, pilot, and governance work is the 80% that decides whether the investment pays back.

Copilot is coming to every tenant. Make yours the one that actually works.

Two-week readiness assessment. Fixed fee. One written report with a clear go/no-go, a remediation backlog, and a business case your CFO will sign off on.