Microsoft copilot: a cost, security and reliability assessment

What is Microsoft 365 Copilot? 

Microsoft 365 Copilot is the marketing name the company uses to describe a collection of services based on large language models such as OpenAI’s ChatGPT (Microsoft runs the data centers that host ChatGPT and has invested billions in OpenAI). 

From the Wikipedia article

On September 21, 2023, Microsoft began rebranding Bing Chat, Microsoft 365 Copilot and Windows Copilot to Microsoft Copilot.[59] A new logo was also introduced, moving away from the use of color variations of the standard Microsoft 365 and Bing logos. Additionally, the company revealed that it would make Copilot generally available for Microsoft 365 Enterprise customers purchasing more than 300 licenses starting November 1, 2023.” 

[...] 

Microsoft provides this high-level graphic to illustrate the M365 Copilot logical flow (from the article, Microsoft 365 Copilot architecture and how it works): 

Copilot Issues 

For organizations, Copilot presents several challenges. These can be divided into three main categories: 

  • Cost 

  • Security 

  • Reliability 

 Cost  

 Microsoft Copilot Chat and Microsoft 365 Copilot 

Microsoft Copilot chat is (as of today) built into the use of other M365 licenses and is ‘free’. Microsoft 365 Copilot (the product marketed to enterprises) is 30 EUR per user per month, based on an auto-renewing, annual commitment.  

Enterprise agreement discounts are possible, but the amount of discount can vary depending on the negotiated rate and how well the contract was negotiated. 

Image below from the Copilot pricing page 

GitHub Copilot 

 

GitHub Copilot is the version of the Copilot suite designed for software developers. It applies large language model methods and systems to programming tasks. 

Recently, Microsoft announced that GitHub Copilot use would no longer be billed at a flat rate but based instead on token consumption (tokenization is the method used to give large language models, or LLMs, the ability to convert inputted text and images into machine readable symbols, statistically manipulated, that, after processing, produce outputs in the form of generated text or synthetic images). 

This pricing change has caused GitHub Copilot bills to skyrocket (see: GitHub Copilot AI token charges to go up 10×–100×) . Another impact: it is very difficult for organizations to track the sources of their GitHub Copilot spending. 

Link - 

GitHub Copilot is moving to usage-based billing 

 https://pivot-to-ai.com/2026/05/18/github-copilot-ai-token-charges-to-go-up-10x-100x/ 

A Note About Microsoft Pricing 

Microsoft pricing is a convoluted and complex topic, and a full discussion is beyond the scope of this document. It’s important to note, as mentioned above, that cost depends upon the type of arrangement an organization has made with Microsoft. The three basic options are: 

  • Pay as You Go (PaYG) 

  • Enterprise Agreement (EA) 

  • Cloud Solution Provider program (CSP) 

Pay as You Go pricing is the retail price of a Microsoft product or service. For example, Microsoft 365 Copilot’s per user price of 30 EUR or USD per month is the retail, or PaYG, price. If your organization uses Copilot, at the PaYG pricing tier, even a modest staff count of 500 users would mean a 15K per month or 180K yearly cost. 

Enterprise Agreement pricing is not published but based on a negotiated rate between an organization and Microsoft. The ‘quality’ of the contract is dependent on how well, or poorly,  a contract is negotiated 

Cloud Solution Provider pricing is based on the rate an organization can pay for services as part of a contract with a Microsoft partner firm. CSP partners offer lower rates but also add margins to a per unit cost. 

 

Key Cost-Related Questions: 

1. What is the cost of M365 Copilot and GitHub Copilot to the org? 

2. What is the reason for this expense? 

3. What impact will this expense have on other initiatives and staff? 

4. How does the use of Microsoft 365 and GitHub Copilot align with the organization’s goals? What is the measurable value-add? 

5. What type of pricing plan (PaYG, EA, CSP) does the organization use? 

Security 

 

Data Sovereignty 

 

Microsoft claims that Microsoft 365 Copilot is secure. Here is how it describes its Copilot security method in the article, Data, Privacy, and Security for Microsoft 365 Copilot

When you enter prompts using Microsoft 365 Copilot, the information contained within your prompts, the data they retrieve, and the generated responses remain within the Microsoft 365 service boundary, in keeping with our current privacy, security, and compliance commitments. Microsoft 365 Copilot uses Azure OpenAI services for processing, not OpenAI's publicly available services. Azure OpenAI doesn't cache customer content, and Copilot modified prompts Microsoft 365 Copilot. 

[...] 

The Microsoft 365 service boundary is one level of concern; another is the location of the data, i.e., which data center hosts the data. 

EU and EFTA (European Free Trade Association) data should stay within the EU and EFTA geographical regions. The use of ‘Flex Routing’ for Microsoft 365 Copilot breaches this. From the Microsoft article, ‘Flex routing (EU and EFTA)’: 

Flex routing lets customers in the European Union (EU) and the European Free Trade Association (EFTA) allow large language model (LLM) inferencing to occur outside the EU Data Boundary during periods of peak demand to help maintain a consistent Copilot experience. Inferencing is the processing step when an AI model executes the prompt to produce an output or response, such as summarizing content or answering a question. 

[...] 

Microsoft, facing data center capacity issues (see for example, ‘Microsoft Azure's UK South region experiences capacity issues – report') is encouraging European customers to allow Copilot data to be processed outside of the EU/EFTA boundary. 

Configuration 

Microsoft Copilot is not optimally secure by default. Organizations must follow configuration best practices to decrease vulnerabilities, where possible (see, for example, the article, ‘One-Click Microsoft 365 Copilot Flaw Could Have Let Attackers Steal Emails, Files, and MFA Codes’). 

Microsoft publishes security guidelines for configuring Microsoft 365 Copilot (see the article, ‘Configure a secure and governed foundation for Microsoft 365 Copilot’). 

Image from the article: 

Terms of Service 

Like all software products, Microsoft 365 Copilot is sold within a legal framework that protects Microsoft from any harm or organizational damage caused by its use. 

Consider the following from the Microsoft Copilot Terms of Use

 

Copilot may include advertising. 

 Copilot may include both automated and manual (human) processing of data. You shouldn’t share any information with Copilot that you don’t want us to review. 

 We plan to continue to develop and improve Copilot, but we make no guarantees or promises about how Copilot will operate or that it will operate as intended. 

 Sometimes, we may offer certain features or services as part of “Copilot Labs.” These features and services are highly experimental and may not always work as intended. 

 We may add, modify, or remove features or services from Copilot Labs at any time for any reason. 

 We may limit the speed or performance of Copilot as we think necessary. 

 When you request that Copilot take Actions on your behalf, you are solely responsible for those Actions and any results or consequences. 

Copilot can make mistakes, and it may not work as intended.  

Do not use Copilot as a substitute for professional advice. Always verify the accuracy of information presented by Copilot before you rely on it.  

We are not responsible for any consequences that arise from your use of or reliance on Copilot. 

 

These terms of service should be considered a security risk to an organization because of the intrusive, data gathering function of Copilot. 

 

Key Security-Related Questions 

 

  1. Is Flex Routing in-use? 

  1. Have the recommended security best practices been followed? 

  1. Is there an internally published report of known vulnerabilities and how they have been remediated? 

  1. What steps have been taken to protect staff identities from data breach caused by the use of Microsoft 365 Copilot? 

  1. Is there an internally published plan for how data breaches via Copilot will be handled? 

  1. Have the Terms of Service been taken into account? 

Reliability 

 

Hallucinations 

Large Language Models or LLMs, which are the foundation of all versions of Microsoft Copilot, are subject to a type of error called ‘hallucination’ 

‘Hallucinations’ are described in this Wikipedia article

"...a chatbot powered by large language models (LLMs), like ChatGPT, may embed plausible-sounding random falsehoods within its generated content. Detecting and mitigating errors and hallucinations pose significant challenges for practical deployment and reliability of LLMs in high-stakes scenarios, such as chip design, supply chain logistics, and medical diagnostics." 

[...] 

To the above list of scenarios, we can add organization documents, including various forms of critical information that must be accurate for contractual, regulatory, and other reasons. 

The article, Copilot Hallucination Risks Explained details some of the common risk types 

Key Reliability-Related Questions 

  1. Have staff been informed about the possibility of ‘hallucinated’ outputs from Microsoft 365 Copilot? 

  1. Does the organization have a policy on reducing risks? 

  1. What steps have been taken to mitigate the risks posed by hallucinations to the reliability of output from Microsoft 365 Copilot? 

Next
Next

Avoiding Surprises with Azure Cost Alerts