1Security + Microsoft Copilot Autopilot

Autopilot works while you are offline. 1Security shows what it can reach before it starts.

Microsoft Copilot Autopilot is a teammate that never logs off: it has a name, a role, a goal, its own identity in your tenant, and it picks work back up days later without a prompt. Before you hand it a goal, 1Security counts what that identity walks into - organization-wide links, anyone links, dormant sites, nested groups, access that was meant to be temporary - resolved to files and ranked by the sensitive data inside. After it starts, the same screens show who owns it, what it read and changed, what it costs in credits, and the day its behaviour leaves its own baseline. Read-only consent, first numbers the same day.

  • Own Entra identity
  • Runs without a prompt
  • Billed in Copilot Credits
  • Private preview
  • measured on one graph
  • 9
    exposure paths a new identity inherits on day one, each counted per site and per file
  • Same day
    from read-only consent to the first reach numbers
  • 30 days
    of history behind every agent baseline, so unusual means unusual for this agent
  • 72 h
    default review window in front of every fix - nothing changes unreviewed

What Autopilot does

A teammate with a name, a role and a goal.

Microsoft announced Autopilot on 25 September 2026 as the persistent agent inside the new Copilot. Three of its design decisions matter to whoever runs the tenant.

  • It keeps working when you close the laptop

    Autopilot watches channels, follows up on threads, runs recurring work and picks a project back up days later. Nobody has to type a prompt, which is the point - and why its activity deserves its own record.

  • It has an identity of its own

    Autopilot lives in your tenant with its own identity, memory, computer and workspace. Its actions are attributed to the agent rather than to whoever pressed go, so they can be audited like the actions of an account.

  • It shows up where people work

    Teams, Outlook, chats, channels and documents: colleagues @mention it like a co-worker, with permissions, audit and governance behind it through Entra and Agent 365, and usage billed in Copilot Credits.

The next question

The agent is a week old. The permissions it walks into are ten years old.

An agent with its own identity is the right design: you can name it, audit it and switch it off. It also means the agent has a reach of its own, and that reach is assembled from two things - what you grant it on purpose, and what your tenant already hands to any identity that lives inside it.

The first part gets reviewed. Someone decides which sites and mailboxes the new teammate needs. The second part is the one nobody decided: the "Everyone except external users" grant from a 2019 deadline, the organization-wide link on a budget folder, the group the agent joins on Monday that is nested inside three others. None of it shows up on the screen where the agent is configured.

A person with the same access opens forty files a week and never finds the rest. An agent that works around the clock toward a goal reads whatever helps, and can act on it. The readiness question for Autopilot is the one Copilot raised, with the patience of a machine behind it.

Exposure paths

Nine ways in that a readiness checklist skips.

Most Copilot checklists say "review SharePoint permissions" and stop. These are the specific paths 1Security counts, each one a filter you can open and page through.

  • Organization-wide links

    A "People in your organization" link works for every account in the tenant. Filter files by link scope and sensitive info, and the internal payroll spreadsheet that any new identity can open is a row, with the link named.

  • Anyone links

    A link that needs no sign-in works for whoever, or whatever, holds the URL - and an agent reads threads full of them. Links with no password and no expiry on sensitive files are typically a short list, and the first one to close.

  • Dormant sites

    In a typical tenant more than half of all sites saw no activity in a year. They still hold files and permissions, and an agent looking for context does not know a 2021 project site is stale. Filter: no activity in the last year.

  • Nested groups

    Add the agent to one team and it inherits every group that team sits inside. 1Security resolves nesting to total users, accessible files and accessible sites, so you see what one membership opens before you approve it.

  • "Temporary" access nobody revoked

    The contractor added for a migration, the direct grant for an audit, the link shared "just for this week". Links past their expiration date, external users who never left and direct grants on single files are each their own filter.

  • Folders with their own permissions

    A site can look tidy while one folder three levels down broke inheritance years ago. Site-level reviews never open it. 1Security resolves access per file, so the folder that is wider than its site shows up as what it is.

  • Sensitive files in an open location

    The site was shared widely when it held lunch menus. Then someone saved a contract export there. The content scan, with 300+ detectors plus OCR, flags the file where it landed and lists who can open it.

  • Sites and groups with no owner

    An ownerless site has nobody to approve members or answer "should the agent be here". Orphaned indicators - no owners, no users, no activity - are filters on sites and groups alike.

  • Other people's OneDrives

    Every employee carries a personal site, and many shared a folder from it with the whole company once. Those shares appear per owner on the access graph, with the sensitive info types inside.

What 1Security adds

Reach, owners, activity and spend - one row per agent.

1Security connects read-only to the same tenant and treats an agent the way it treats every identity: what it can open, who answers for it, what it did and what it cost.

  1. 01

    Reach, before the first goal

    The files, sites, users and mailboxes the agent identity can reach, each with the path that produces it - direct grant, group, link - and ranked by the sensitive information types inside. An access review for a teammate that has not started yet.

  2. 02

    Ownership you can name

    Owners and sponsors, the people entitled to use the agent, and the people actually seen using it, kept as three separate lists. When the owner leaves the company, the agent shows up as orphaned instead of quietly running on.

  3. 03

    Activity, including what it changed

    Every action the agent took, broken down by type: read, modified, shared, sent, deleted. "Which files did the agent edit last night" is a tab on its drawer, with three years of history behind it.

  4. 04

    Spend next to reach

    Copilot Credits per agent and per user, kept past the 30 days the admin-center report holds, on the same row as the files and sensitive data in reach. The most expensive agent and the widest-reaching one are each a sort.

Anomaly alerting

A baseline per agent, because nobody watches a night shift.

An agent that works unprompted has no human noticing when its work changes shape. 1Security gives every agent its own baseline: today's activity against the median of its previous 30 days, scored against that agent's normal variability. Four times its usual file reads becomes one episode above your alert line, within minutes of the audit event.

Volume is only half of it. Every read is stamped at ingestion for whether the content carried sensitive data at that moment, so a second detector watches the share of the agent's activity that touches sensitive material. The day its reading shifts toward payroll and contracts while the total stays flat is the day you want the alert, and volume alone would never raise it.

There are no rules to write. Baselines build silently from the first two weeks of history and then go live, and severity is lifted for agents with broad reach or sensitive information within it - so the episode that reaches your inbox is the one about the agent that matters.

Credits

An agent that never stops is a meter that never stops.

Autopilot is billed by usage, in Copilot Credits, because it works when no licensed user is present. Microsoft gives admins spending policies and shows end users their own balance. What a monthly total cannot say is which agent spent it, on whose goal, and against which data.

1Security keeps credits per agent and per user as durable history: the admin-center credits report holds 30 days and has no API, so a regular import of that report is what makes "what has this agent cost us since it started" answerable in a quarter. Spend is scored like any other metric, against the agent's own history, and prepaid pools are watched while the burn is still a budget conversation.

  • 30 days
    is all the admin-center credits report keeps - imported history outlives it
  • Per agent
    and per user: who spent the credits, on which agent
  • 1 row
    credits, reach and sensitive data in reach, side by side

Access control

Close the path, and it closes for every agent that follows.

Agent 365 and Entra govern the agent. 1Security fixes the data side: the link, the grant, the membership, the site - from the row that measured it, and only once you turn write access on.

  1. 01

    Close the short lists first

    Sensitive files behind organization-wide links, sensitive files behind anyone links, dormant sites with external users. Expire the links, remove the grants, and the reach is gone for the agent and for everyone else riding the same path.

  2. 02

    Keep sites out of AI search

    For sites you cannot clean this month, block the content from Copilot's organization-wide search. It runs as the site's own native setting, visible and reversible in the Microsoft admin centers.

  3. 03

    Restrict the agent itself

    Disable an agent's Entra identity so anything it does with its own account fails, or quarantine a Copilot Studio agent so it stops answering. Each change is read back from Microsoft before it is called applied.

  4. 04

    Nothing fires unreviewed

    Every action is staged as a proposal inside a review window, 72 hours by default. Approve it, reject it, or route it to the owner of the resource. Everything that ran sits in one audit trail: who decided, when, and what changed.

  • Read-only by default
  • Write access is a separate consent
  • Review window per policy
  • Owner review
  • Full audit trail

The rollout

Four steps between the preview invite and the first goal.

Autopilot is in private preview, which is the cheapest moment to do this. None of the steps below needs preview access.

  1. 01

    Connect read-only, count the nine paths

    One consent screen, nothing installed, nothing written. By the end of the day each exposure path is a number: files behind organization-wide links, dormant sites, ownerless groups, sensitive files in open locations.

  2. 02

    Fix the intersections

    Not all of it - the short lists where sensitive content meets a wide path. Most tenants can close those in a week, with owners reviewing the proposals.

  3. 03

    Start the first agent on a narrow goal

    Give it the sites the job needs and check its resolved reach before the first run. If the number is larger than the grant you made, the difference is one of the nine paths, named.

  4. 04

    Review weekly, from one screen

    Reach drift, files modified, credits, episodes above the alert line, and whether the owner still works here. A ten-minute review, because every number is already computed.

Questions

What teams ask before the rollout.

Autopilot is still in private preview. What can we do today?

Everything on the data side. The nine exposure paths exist in your tenant whether or not you have preview access, and 1Security measures them from a read-only connection the same day. On the agent side, Microsoft has not yet published the full admin controls for the preview, so treat any detail of how Autopilot identities are provisioned as subject to change. 1Security reads Entra agent identities through its standard consent, and new agent types join the same inventory as Microsoft exposes them.

Do we need Agent 365 or E5 for this?

Not for the exposure paths, activity or anomaly baselines: those run on the Microsoft licenses you already own, starting at Business Basic. Entra-backed agent identities need nothing beyond the standard read consent. The declarative Copilot agent catalog is a Microsoft API that requires a single Agent 365 seat on the admin who connects it; without it, the rest of the screen still works and says so plainly.

Does 1Security need write access to our tenant?

No. It runs read-only from one consent screen, and every number on this page comes from that connection. Remediation is a separate, opt-in consent, and every action it takes is staged behind a review window, named in an audit trail and reversible where Microsoft allows it.

Is this a replacement for Agent 365, Purview or Entra?

No. Agent 365 and Entra govern the agent: its registration, identity, lifecycle and policies. Purview classifies and protects content. 1Security answers the question underneath both: what a given identity, human or agent, can actually open today, through which path, and what it did. Your Purview labels are imported and shown next to our own detections.

How is this different from a Copilot readiness assessment?

Copilot answers a person from what that person can open. Autopilot acts on its own identity, continuously, and can change things. So the review adds three questions a Copilot assessment never needed: what does the agent's own identity reach, what did it modify, and what did it spend. The oversharing cleanup underneath is the same work, and it pays off for both.

How do you track what an agent costs?

Interaction volume per agent comes from the audit log on the licenses you own. Copilot Credits come from the admin-center credits report, imported on a regular cadence because Microsoft keeps 30 days and offers no API. Azure-side tokens and dollars are read with a reader role. Each number keeps its source, so measured and imported never mix silently.

Keep reading

The pages this one builds on.

  • 1Security + Microsoft Agent 365

    How the pairing works for every agent you register, and for the ones nobody registered.

    See the pairing →
  • Copilot readiness assessment

    The oversharing measurement that predicts what an AI rollout surfaces, per site and per user.

    See the assessment →
  • AI spend tracking

    Interactions, credits, tokens and dollars per agent, next to what each agent can reach.

    See spend tracking →

Know what Autopilot can reach before you give it a goal.

Connect read-only in the morning. By the end of the day: the nine exposure paths counted, the sensitive files behind each, and a row waiting for every agent that joins your tenant.

Or find out from what the agent brings back.