Craig Stanley
Home / Capabilities / Cowork / Spending policies for Cowork: access and budget in one setting

Spending policies for Cowork: access and budget in one setting

In Microsoft 365, a spending policy that selects Cowork both lets people in and caps their spend. Lowering a limit won't keep anyone out.

· 3 min read · Craig Stanley
In short, explained

The setting that lets someone use Cowork is the same one that says how much they can spend. Setting a tiny allowance still lets them in.

Admins give people Cowork by adding them to a spending policy that includes Cowork. That policy also sets how many credits they can use each month. Microsoft warns that even a one-credit limit still gives access, so to keep someone out, leave them out of every Cowork policy.

At GA, Cowork access is granted solely by inclusion in a spending policy (Copilot > Cost Management > Configuration) that selects Cowork; the legacy agent entry has no effect. Policies set policy and per-user limits, billing method, alerts and request routing, resetting monthly at 00:00 UTC. Discovery without UBB enables in-app access requests.

One setting, two jobs

In most systems, access and budget are separate controls. For Cowork, Microsoft has joined them. Its admin documentation says a spending policy is an access control as well as a budget.

Anyone in scope of a spending policy that selects Cowork can use it, "regardless of how small the credit limit is". Microsoft's example is a policy with a limit of one credit, which still grants access: users can open Cowork and start work until the limit is reached. To keep someone out, Microsoft says, don't include them in any spending policy that selects Cowork.

Where it's set

Spending policies are in the Microsoft 365 admin center under Copilot, then Cost Management, then Configuration. Microsoft's steps for a new policy are: choose the users or security groups in scope, select Cowork (and any other services), set limits, choose a billing method and create the policy.

Microsoft's usage-based billing documentation adds the details I'd plan around. Policies can have an overall monthly limit and a per-user limit. Admin alerts go out when policy usage reaches a threshold you set, and users can be notified as they approach their own limit. When a limit is hit, people lose access for the rest of the month, and Microsoft's Cowork page says limits reset at the start of the month (00:00 UTC). The Overview tab refreshes every four hours, so the dashboard isn't live. Spending policies set limits only; Microsoft notes they don't reserve or allocate credits to anyone.

During the Frontier and preview period, Cowork was allowed or blocked through its entry under Agents. Microsoft says that control no longer works at general availability. The entry is still visible, but configuring it has no effect on who can use Cowork.

Two more defaults to know

If an admin makes Cowork discoverable but hasn't enabled usage-based billing, Microsoft says users can request access from within the app, and admins then review those requests.

Spending policies also have an "Auto-apply new services" setting, on by default, so future services can join an existing policy automatically. I'd turn that off on any broad policy, as I explain in What changes for your licences.

A worked example

These figures are illustrative. A 300-person organisation wants Cowork for its 25-person finance team, with a ceiling it can explain to the finance director.

SettingValue
ScopeSecurity group "Cowork finance" (25 people)
ServicesCowork only; auto-apply new services off
Per-user limit2,000 credits a month
Policy limit40,000 credits a month
AlertAt 75% of the policy limit

The maximum monthly spend is 40,000 credits, or $400, about £308 at $1 = £0.77 for illustration. The policy limit is lower than 25 × 2,000 = 50,000, on the assumption that not everyone will use their full allowance in the same month. If they do, the policy limit stops spending first.

Before go-live, I'd check that nobody outside finance is in any other policy that selects Cowork. Because access comes from any matching policy, a forgotten test policy for "All staff" would let everyone in.

Reading it as a decision

A spending policy is a decision with three parts: who can delegate work to an agent, how much, and who gets told when it's nearly used up. I'd record it like any other decision, with an owner and a review date, and look at it in the weekly review.

What I'm still checking

I'm not sure how Microsoft handles someone who's in two Cowork policies with different limits. Microsoft links a separate page on how access is determined across policies, which I haven't worked through yet. I'd avoid overlapping policies until I have.

Sources

Read next

A question to take awayWhich of these do you already pay for and not use?

About me

Craig Stanley

Microsoft AI consultant and technical architect, based in Whitley Bay. Over the last few years I've delivered Microsoft 365 Copilot, Copilot Studio agents, Microsoft Foundry (formerly Azure AI Foundry) work and governance for UK public sector and financial services organisations.

What interests me is the decision underneath the tool: what it costs, what it risks, and whether a small, transparent model can make it better. I write the methods up here and on Substack so anyone can use them.

I write this site to learn in public: explaining each idea simply is how I check I understand it. Why I write this site.

Find me