"Use Copilot" might mean opening a chat, working inside Word, or using a security tool. The same name appears across several products. A simple map is enough to keep them straight.
Why are there so many Copilots?
Microsoft attaches the Copilot name to AI experiences built for different jobs, data, and people. You don't need all of them. You need to recognize the handful you might meet:
You don't need to memorize this catalog. For any request, note who is doing the work, where the information lives, and what result they need. Those details usually narrow the choice quickly. Documentation only confirms that a product exists. Access still depends on your subscription, tenant, and region, and your admin can confirm what your account has. The next lesson turns this map into a quick selection method.
Microsoft 365 Copilot grounds work answers
When you send a work prompt, a helpful model of the process is your prompt → grounding → generation → your review. Grounding supplies the information the answer can use. There are three common sources:
- Web grounding uses public web information for tasks such as public documentation, announcements, and general research.
- Work grounding uses emails, files, meetings, and chats that your organizational account is permitted to access.
- Explicit-source grounding limits the answer to content you name or paste, making the evidence easier to inspect.
Two names show up here. Microsoft Graph is the access path through which permitted work content reaches Copilot. If you couldn't normally open a file, Copilot can't use it just because you mentioned it. Work IQ is a layer that adds organizational context, using work data, memory, and inference to understand your role and situation. Keep one line in mind: grounding improves relevance. It does nothing for truth. A grounded source can still be outdated, incomplete, or misread, and context that helps Copilot orient is not the same as evidence for a specific fact. You still open the file and check.
There's one more stage worth naming. After generation, Microsoft's security and responsible-AI controls surround the interaction, and then a human reviews the result. Those controls reduce particular risks, such as content filtering and protection against certain attacks, but they are not a business-fact checker. The pipeline doesn't end when Copilot produces fluent text. It ends when an accountable person decides the answer is supported. That person is you.
Free chat and licensed chat
This distinction controls what a work chat can reach. The two Copilot Chat experiences have different access:
Web-based Copilot Chat comes at no extra cost with an eligible Microsoft 365 subscription. "Free" means no additional Copilot charge. Your identity still attaches to it, and the usual usage limits still apply. The licensed Microsoft 365 Copilot add-on is what enables work grounding: the ability to reason over your organization's own content through Microsoft Graph. (A lower-cost tier, Microsoft 365 Copilot Business, is listed at $21 per user per month, paid yearly.) The practical takeaway: if a colleague's Copilot can summarize their inbox and yours can't, that's usually a licensing gap.
Pasting a file into free chat gives Copilot one document to reason over. The licensed version can retrieve permitted material from your organization's files, email, and meetings through Microsoft Graph. The chat boxes may look similar, but their reach is different. When deciding whether a team needs the add-on, ask whether its work depends on company data that can't reasonably be pasted into each conversation.
Your data follows the product boundary
This tour of the family has to answer the question everyone has: where does my work data go? For Microsoft 365 Copilot and Copilot Chat, Microsoft documents a protection architecture called enterprise data protection (EDP). Two of its guarantees are concrete and worth remembering: your organization's data is not used to train the underlying large language models, and your data is encrypted both at rest and in transit.
What EDP does not do is equally important. Encryption doesn't prove a conversation retrieved a document, and being excluded from model training doesn't give any particular person permission to open a file. It helps to keep three separate questions straight. Licensing asks may this account use work-based chat? Authorization asks can this person open the source? Grounding asks what evidence did the answer use? A yes to one is not a yes to another: a licensed user can still be blocked from a file, and a fluent answer isn't proof it retrieved anything.
Data protection sits alongside all three, and none of them replaces the habit you're building across this module: checking that an answer is supported before you rely on it. Now that you can name the family and know what your license covers, the final lesson turns it all into a decision you can make in under a minute.