We noticed that 21 users are using Cowork in Copilot, even though the administration portal shows Cowork as installed and available only for a specific group of six users. That group has no nested groups, and the "Shared with" section is empty. How can I determine why the other 15 users were able to access Cowork, and how can I block them without removing access for the six approved users?
3 Answers
The Agents > Cowork settings may be leftover from the preview experience and might not control access now that Cowork is generally available. Access is primarily managed through usage-based billing and spending policies. Check the Copilot cost-management area for each user’s assigned policy, Cowork activity, credits used, and last activity. An all-users credit policy could explain why the other 15 users gained access. Remove that broad assignment and apply the policy only to the security group containing the six approved users.
A user generally needs an eligible credit or pay-as-you-go policy to use Cowork. If a credit policy covered all users, that could have granted access even though the installation assignment listed only six people. After changing the policy, review the usage and policy assignments to confirm that the 15 unintended users no longer have an applicable Cowork allowance.
Avoid assigning one spending policy to everyone. Create a security group for the users who should have Cowork, then apply a policy to that group with the required Cowork and Work IQ services enabled. If everyone else still needs Copilot features, create a separate policy for them with Cowork disabled. Also check for overlapping or default policies that may still apply to all users.

That makes sense. We found a credit policy assigned broadly and removed the other users from it. We’ll monitor the usage report and check for any remaining policy that applies to everyone.