> ## Documentation Index
> Fetch the complete documentation index at: https://notes.kodekloud.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Introduction to Microsoft 365 Copilot

> Overview of Microsoft 365 Copilot, its tenant-aware security, Graph and LLM architecture, and how embedded AI enhances drafting, summarizing, analysis, and meeting recaps in M365 apps.

Welcome to the Microsoft 365 Copilot module. This article explains what Microsoft 365 Copilot is, how it works, and why it’s becoming a transformative AI assistant across the modern workplace.

Copilot is not a standalone chatbot. It’s an embedded productivity layer inside the Microsoft 365 apps people use every day — delivering contextual, permission-aware assistance directly where work happens.

## Copilot across Microsoft 365 apps

Copilot is integrated into Word, Excel, PowerPoint, Outlook, and Teams. It helps with drafting, summarizing, data analysis, slide creation, email triage, and meeting recaps — cutting repetitive work and enabling higher-value tasks.

| App | Primary capabilities | Typical example |
| - | - | - |
| Word | Drafting, rewriting, tone adjustment | "Create a project proposal from meeting notes." |
| Excel | Data analysis, trend detection, formula generation | "Show me trends in last quarter's sales and generate formulas." |
| PowerPoint | Generate slide decks from prompts or documents | "Build a presentation from this brief." |
| Outlook | Summarize threads, draft replies, prioritize mail | "Summarize this thread and suggest a reply." |
| Teams | Meeting summaries, action items, decisions | "Recap yesterday's stand-up and list action items." |

<Frame>
  <img src="https://mintcdn.com/kodekloud-c4ac6d9a/mEyt3y_XsHx_hEYV/images/AB-900-Microsoft-365-Copilot-and-Agent-Administration-Fundamentals/Microsoft-365-Copilot-And-Agents/Introduction-to-Microsoft-365-Copilot/m365-copilot-app-icons-features.jpg?fit=max&auto=format&n=mEyt3y_XsHx_hEYV&q=85&s=a485cfccb03451c88c8bc22b6673ec3e" alt="A presentation slide for Microsoft 365 Copilot showing the M365 logo branching to app icons (Word, Excel, PowerPoint, Outlook, Teams) with brief feature descriptions. It highlights Copilot capabilities like drafting and summarizing documents, analyzing data, creating decks, triaging inboxes, and recapping meetings." width="1920" height="1080" data-path="images/AB-900-Microsoft-365-Copilot-and-Agent-Administration-Fundamentals/Microsoft-365-Copilot-And-Agents/Introduction-to-Microsoft-365-Copilot/m365-copilot-app-icons-features.jpg" />
</Frame>

## How Copilot accesses data — tenant-aware and permission-trimmed

A key organizational question is: how does Copilot access enterprise data while keeping it secure? Copilot runs inside your Microsoft 365 tenant and honors the same access controls users already have. It does not grant new access or expose content to users who are not authorized.

Three core security properties define this model:

* Tenant isolation — Data remains separated between organizations.
* Inherited access controls — Copilot enforces the user’s existing permissions.
* User-scoped data — Outputs are generated based on the requesting user’s access.

<Callout icon="lightbulb" color="#1CB2FE">
  Copilot does not bypass existing security controls. It surfaces and synthesizes only the content a user is already authorized to access.
</Callout>

<Frame>
  <img src="https://mintcdn.com/kodekloud-c4ac6d9a/mEyt3y_XsHx_hEYV/images/AB-900-Microsoft-365-Copilot-and-Agent-Administration-Fundamentals/Microsoft-365-Copilot-And-Agents/Introduction-to-Microsoft-365-Copilot/microsoft-365-copilot-enterprise-security-boundary.jpg?fit=max&auto=format&n=mEyt3y_XsHx_hEYV&q=85&s=7886ab17ef5ff28c662ef4fb369c3a3a" alt="A slide titled &#x22;Microsoft 365 Copilot – Enterprise Security Boundary&#x22; showing a Microsoft 365 tenant graphic with a shield icon and callouts for Tenant Isolation, Inherited Access Controls, and User-Scoped Data. It notes that Copilot runs inside the tenant boundary, not the public internet." width="1920" height="1080" data-path="images/AB-900-Microsoft-365-Copilot-and-Agent-Administration-Fundamentals/Microsoft-365-Copilot-And-Agents/Introduction-to-Microsoft-365-Copilot/microsoft-365-copilot-enterprise-security-boundary.jpg" />
</Frame>

## Core architecture: how Copilot produces grounded, compliant responses

Copilot is built from three collaborating layers:

1. Microsoft Graph — the knowledge layer and permission-aware gateway to Microsoft 365 content (Exchange, SharePoint, OneDrive, Teams, Viva, etc.).
2. Large Language Models (LLMs) — the reasoning and language engines that interpret prompts and generate responses.
3. Orchestration service (semantic coordinator) — the component that determines required context, retrieves permission-trimmed data from Microsoft Graph, applies policies and compliance checks, and constructs the enriched prompt sent to the LLM.

<Frame>
  <img src="https://mintcdn.com/kodekloud-c4ac6d9a/mEyt3y_XsHx_hEYV/images/AB-900-Microsoft-365-Copilot-and-Agent-Administration-Fundamentals/Microsoft-365-Copilot-And-Agents/Introduction-to-Microsoft-365-Copilot/microsoft-365-copilot-core-architecture.jpg?fit=max&auto=format&n=mEyt3y_XsHx_hEYV&q=85&s=cf8c2b55afc2e448304c34e73eff9fc8" alt="A slide titled &#x22;Microsoft 365 Copilot — Core Architecture&#x22; showing three panels: Microsoft Graph, Large Language Models, and Orchestration Service. Each panel includes a short description of its role (data gateway, AI engines, and semantic coordinator)." width="1920" height="1080" data-path="images/AB-900-Microsoft-365-Copilot-and-Agent-Administration-Fundamentals/Microsoft-365-Copilot-And-Agents/Introduction-to-Microsoft-365-Copilot/microsoft-365-copilot-core-architecture.jpg" />
</Frame>

Example flow for a real request:

* The user submits a prompt (for example, "Summarize all customer issues discussed last month").
* The orchestration service identifies necessary content and retrieves permission-trimmed context from Microsoft Graph.
* The enriched prompt and context are sent to the LLM for grounding and reasoning.
* Enterprise guardrails, compliance, and policy checks are applied to the generated output before returning it to the user.

## Microsoft Graph — the organizational memory

Microsoft Graph provides a unified, permission-aware view of enterprise content and relationships: people, teams, files, meetings, chats, calendars, and tasks. Instead of searching multiple endpoints, the orchestration layer queries Graph for relevant, permission-trimmed data to ground LLM responses in real business context.

<Frame>
  <img src="https://mintcdn.com/kodekloud-c4ac6d9a/mEyt3y_XsHx_hEYV/images/AB-900-Microsoft-365-Copilot-and-Agent-Administration-Fundamentals/Microsoft-365-Copilot-And-Agents/Introduction-to-Microsoft-365-Copilot/ms-graph-services-data-sources.jpg?fit=max&auto=format&n=mEyt3y_XsHx_hEYV&q=85&s=78bc80f43d7e2a250b6aa9ffded6b02b" alt="A schematic diagram with &#x22;Microsoft Graph&#x22; in the center linked to surrounding services like Teams, Meetings, Files, Calendar, Chats, People, Tasks and Insights. Below it are labeled organization data sources (OneDrive, Exchange Online, SharePoint, Teams Chat & Viva) with example content types." width="1920" height="1080" data-path="images/AB-900-Microsoft-365-Copilot-and-Agent-Administration-Fundamentals/Microsoft-365-Copilot-And-Agents/Introduction-to-Microsoft-365-Copilot/ms-graph-services-data-sources.jpg" />
</Frame>

Because Graph returns permission‑aware content, Copilot’s answers are personalized and appropriate for the requesting user — ensuring relevance and compliance.

## LLMs — the reasoning and language layer

Think of Microsoft Graph as providing business knowledge and the LLM as the reasoning engine. The end-to-end interaction unfolds in three stages:

* Grounding — The orchestration service enriches the user prompt with permission-trimmed Graph content.
* Reasoning — The LLM interprets intent, synthesizes information, and performs analysis.
* Compliant output — Organizational safeguards and compliance checks are applied before delivering the response.

<Frame>
  <img src="https://mintcdn.com/kodekloud-c4ac6d9a/mEyt3y_XsHx_hEYV/images/AB-900-Microsoft-365-Copilot-and-Agent-Administration-Fundamentals/Microsoft-365-Copilot-And-Agents/Introduction-to-Microsoft-365-Copilot/llms-copilot-grounding-reasoning-compliant-output.jpg?fit=max&auto=format&n=mEyt3y_XsHx_hEYV&q=85&s=b192aa72a82e5dfe4f6fb20baa835b99" alt="A presentation slide titled &#x22;LLMs: The Reasoning Engine of Copilot&#x22; showing a three-step workflow: 1) Grounding, 2) Reasoning, and 3) Compliant Output. Each step briefly explains enriching prompts with permission‑trimmed Microsoft Graph data, the LLM interpreting intent to formulate an answer, and generating a response that meets enterprise guardrails." width="1920" height="1080" data-path="images/AB-900-Microsoft-365-Copilot-and-Agent-Administration-Fundamentals/Microsoft-365-Copilot-And-Agents/Introduction-to-Microsoft-365-Copilot/llms-copilot-grounding-reasoning-compliant-output.jpg" />
</Frame>

## Request flow summary

* User submits a prompt.
* Orchestration retrieves permission-trimmed context from Microsoft Graph and applies system policies.
* The LLM performs grounding and reasoning on the enriched prompt.
* Guardrails and compliance checks vet the output before it is returned.

This combination of enterprise data, enforced security, and advanced language models is what differentiates Microsoft 365 Copilot from generic AI assistants.

## Copilot in the Microsoft 365 user experience

Here are practical examples of how Copilot appears in the apps.

Inside Outlook on the web you can open Copilot to draft or edit emails. For example:

* "Send an email to admin saying that I’ll be delayed for the board meeting." Copilot can draft the email for review even if "admin" isn’t in your contacts.
* "Summarize this thread" yields a concise summary: key points, whether it’s a security or compliance alert, who performed actions, and potential follow-ups. Copilot can draft suggested replies or follow-up tasks.

<Frame>
  <img src="https://mintcdn.com/kodekloud-c4ac6d9a/mEyt3y_XsHx_hEYV/images/AB-900-Microsoft-365-Copilot-and-Agent-Administration-Fundamentals/Microsoft-365-Copilot-And-Agents/Introduction-to-Microsoft-365-Copilot/outlook-web-copilot-onedrive-summary.jpg?fit=max&auto=format&n=mEyt3y_XsHx_hEYV&q=85&s=94d12819c3c2688097dbe5d2aec2dfcc" alt="A screenshot of the Outlook web app showing Microsoft Copilot's OneDrive summary, listing recent documents (like &#x22;Microsoft Copilot Chat Files&#x22; and &#x22;Financial Report&#x22;) and key observations. A message input box for Copilot is visible at the bottom of the page." width="1920" height="1080" data-path="images/AB-900-Microsoft-365-Copilot-and-Agent-Administration-Fundamentals/Microsoft-365-Copilot-And-Agents/Introduction-to-Microsoft-365-Copilot/outlook-web-copilot-onedrive-summary.jpg" />
</Frame>

Copilot can surface files from OneDrive and provide summaries or previews. When a file’s contents are blocked from preview (for example, due to permissions or preview restrictions), Copilot will indicate it found the file but could not retrieve content. In many cases, Copilot can generate sample content or a draft that you can download and add to the original file manually.

<Frame>
  <img src="https://mintcdn.com/kodekloud-c4ac6d9a/mEyt3y_XsHx_hEYV/images/AB-900-Microsoft-365-Copilot-and-Agent-Administration-Fundamentals/Microsoft-365-Copilot-And-Agents/Introduction-to-Microsoft-365-Copilot/outlook-web-copilot-onedrive-alternatives.jpg?fit=max&auto=format&n=mEyt3y_XsHx_hEYV&q=85&s=e60506f27b1e21e12416590a1219a950" alt="A screenshot of Outlook on the web with the Copilot pane open, showing a message that it can't directly edit OneDrive files and listing alternative options (download, copy‑paste, or customize content). A message input box for Copilot is visible at the bottom of the page." width="1920" height="1080" data-path="images/AB-900-Microsoft-365-Copilot-and-Agent-Administration-Fundamentals/Microsoft-365-Copilot-And-Agents/Introduction-to-Microsoft-365-Copilot/outlook-web-copilot-onedrive-alternatives.jpg" />
</Frame>

Administrative and user controls:

* Data protection and retention settings applied to chats and prompts are respected.
* Administrators can configure available models and set response policies.
* Users can select response styles (quick answers vs. deeper reasoning).

## Key takeaways

* Copilot is an embedded AI assistant across Microsoft 365 apps that accelerates drafting, summarization, analysis, and meeting recaps.
* It runs inside your tenant boundary and enforces existing permissions — Copilot cannot access content a user isn’t authorized to view.
* The architecture combines Microsoft Graph (knowledge), orchestration (permission-trimmed context and policy enforcement), and LLMs (reasoning and language) to deliver grounded, compliant outputs.

For more information and references:

* Microsoft Graph overview: [https://learn.microsoft.com/graph/overview](https://learn.microsoft.com/graph/overview)
* Microsoft 365 documentation: [https://learn.microsoft.com/microsoft-365](https://learn.microsoft.com/microsoft-365)
* Microsoft Copilot information: [https://learn.microsoft.com/microsoft-365/copilot](https://learn.microsoft.com/microsoft-365/copilot)

In this lesson we covered Copilot’s embedded capabilities, tenant-aware security model, and the three-part architecture (Microsoft Graph, orchestration, and LLM) that powers grounded, compliant assistance inside the tools people use every day.

<CardGroup>
  <Card title="Watch Video" icon="video" cta="Learn more" href="https://learn.kodekloud.com/user/courses/ab-900-microsoft-365-copilot-and-agent-administration-fundamentals/module/972131f2-551c-41d9-b5a7-b836a9f5dce5/lesson/7c4c33bb-b8f6-4397-be80-f3b6da3149c8" />
</CardGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.