The setting that lets someone use Cowork is the same one that says how much they can spend. Setting a tiny allowance still lets them in.
Admins give people Cowork by adding them to a spending policy that includes Cowork. That policy also sets how many credits they can use each month. Microsoft warns that even a one-credit limit still gives access, so to keep someone out, leave them out of every Cowork policy.
At GA, Cowork access is granted solely by inclusion in a spending policy (Copilot > Cost Management > Configuration) that selects Cowork; the legacy agent entry has no effect. Policies set policy and per-user limits, billing method, alerts and request routing, resetting monthly at 00:00 UTC. Discovery without UBB enables in-app access requests.
One setting, two jobs
In most systems, access and budget are separate controls. For Cowork, Microsoft has joined them. Its admin documentation says a spending policy is an access control as well as a budget.
Anyone in scope of a spending policy that selects Cowork can use it, "regardless of how small the credit limit is". Microsoft's example is a policy with a limit of one credit, which still grants access: users can open Cowork and start work until the limit is reached. To keep someone out, Microsoft says, don't include them in any spending policy that selects Cowork.
Where it's set
Spending policies are in the Microsoft 365 admin center under Copilot, then Cost Management, then Configuration. Microsoft's steps for a new policy are: choose the users or security groups in scope, select Cowork (and any other services), set limits, choose a billing method and create the policy.
Microsoft's usage-based billing documentation adds the details I'd plan around. Policies can have an overall monthly limit and a per-user limit. Admin alerts go out when policy usage reaches a threshold you set, and users can be notified as they approach their own limit. When a limit is hit, people lose access for the rest of the month, and Microsoft's Cowork page says limits reset at the start of the month (00:00 UTC). The Overview tab refreshes every four hours, so the dashboard isn't live. Spending policies set limits only; Microsoft notes they don't reserve or allocate credits to anyone.
During the Frontier and preview period, Cowork was allowed or blocked through its entry under Agents. Microsoft says that control no longer works at general availability. The entry is still visible, but configuring it has no effect on who can use Cowork.
Two more defaults to know
If an admin makes Cowork discoverable but hasn't enabled usage-based billing, Microsoft says users can request access from within the app, and admins then review those requests.
Spending policies also have an "Auto-apply new services" setting, on by default, so future services can join an existing policy automatically. I'd turn that off on any broad policy, as I explain in What changes for your licences.
A worked example
These figures are illustrative. A 300-person organisation wants Cowork for its 25-person finance team, with a ceiling it can explain to the finance director.
| Setting | Value |
|---|---|
| Scope | Security group "Cowork finance" (25 people) |
| Services | Cowork only; auto-apply new services off |
| Per-user limit | 2,000 credits a month |
| Policy limit | 40,000 credits a month |
| Alert | At 75% of the policy limit |
The maximum monthly spend is 40,000 credits, or $400, about £308 at $1 = £0.77 for illustration. The policy limit is lower than 25 × 2,000 = 50,000, on the assumption that not everyone will use their full allowance in the same month. If they do, the policy limit stops spending first.
Before go-live, I'd check that nobody outside finance is in any other policy that selects Cowork. Because access comes from any matching policy, a forgotten test policy for "All staff" would let everyone in.
Reading it as a decision
A spending policy is a decision with three parts: who can delegate work to an agent, how much, and who gets told when it's nearly used up. I'd record it like any other decision, with an owner and a review date, and look at it in the weekly review.
What I'm still checking
I'm not sure how Microsoft handles someone who's in two Cowork policies with different limits. Microsoft links a separate page on how access is determined across policies, which I haven't worked through yet. I'd avoid overlapping policies until I have.
Sources
- Microsoft Learn, Manage Copilot Cowork for your organization, accessed 11 October 2026.
- Microsoft Learn, Managing AI experiences enabled by usage-based billing, accessed 11 October 2026.
- Microsoft Learn, Monitor Copilot Credit spending, accessed 11 October 2026.
- Microsoft Learn, Credit usage for Microsoft Copilot Cowork tasks, accessed 11 October 2026.
- Microsoft Learn, Understand usage-based billing and cost management for Copilot Credits, accessed 11 October 2026.