Copilot Cowork now inherits browser controls

Microsoft updated its Copilot Cowork admin guidance on 5 August. Cowork browser tasks run in Microsoft Edge under the user’s existing sign-ins and tenant browsing policies, while usage-based billing, discoverability, plugins, models, automated tasks and audit visibility are administered through the Microsoft 365 admin center.
Before Cowork, an AI assistant could be assessed mainly as another chat surface. That is no longer enough once it can use a signed-in browser, call plugins, or prepare scheduled and event-driven work. The useful control is not a separate blanket ban. Microsoft says browser tasks inherit existing Conditional Access, data-loss prevention and Edge browsing policies, but admins still need to decide whether Cowork is discoverable, who can consume credits and which plugins or preview models are allowed.
Analysis
For one pilot group, map the Edge allow/block rules, Copilot credit limit and approved plugins that will apply before making Cowork discoverable. Then test one browser task and confirm its audit entry and approval behaviour before wider rollout.
Source note
Pulse published by Collab365 Spaces, reviewed by Helen Jones on . Cite as "Copilot Cowork puts browser actions under existing tenant controls", Collab365 Spaces.