Microsoft 365 Copilot Guide

Practical prompts, security and governance for business.

Work smarter. Prompt better. Stay in control.

An IT.ie practical guide · 10 chapters 55 copy-ready prompts Reviewed October 2026

Microsoft 365 Copilot: what it is, and what it is not

Microsoft Copilot provides AI assistance across Copilot Chat and Microsoft 365 applications such as Word, Excel, PowerPoint, Outlook and Teams. Available features, access to organisational information and priority access depend on the user’s Microsoft 365 subscription, Copilot licence, administrator settings and platform.

What Copilot is

  • An AI assistant that supports writing, analysis, communication and collaboration.
  • A tool that can use your instructions, selected files and, where licensed and permitted, organisational content.
  • A starting point for work that should be reviewed, refined and validated.

What Copilot is not

  • A guaranteed source of truth.
  • A replacement for professional judgement, subject-matter expertise or approval processes.
  • A reason to bypass data protection, confidentiality or information-governance requirements.

Important: Features vary by licence, app, platform, tenant configuration, permissions and rollout stage. If an option is not visible, check with your Microsoft 365 administrator.

Try this prompt

Summarise this guide in five practical actions I can apply today, then suggest the best place to start based on my role.

Principles that will not change

Regardless of future Copilot updates:

  1. Users remain responsible for outcomes.
  2. AI-generated content requires human review.
  3. Copilot respects existing permissions.
  4. Data governance remains essential.
  5. Better prompts generally produce better results.
  6. Security and compliance remain organisational responsibilities.

The CRIT prompt model

CRIT is a prompting framework developed by Geoff Woods, author of The AI-Driven Leader, to turn AI from a question-and-answer tool into a more effective thought partner. The Interview step is the key difference: it encourages Copilot to ask clarifying questions when important information is missing, rather than guessing.

Scattered documents flowing through context, role, interview and task panels into a finished document
C

Context

Provide the background, audience, purpose, constraints and relevant source material.

R

Role

Tell Copilot which perspective or expertise to adopt, such as marketing manager, project lead or critical reviewer.

I

Interview

Encourage Copilot to ask clarifying questions when important information is missing, unclear or contradictory. Behaviour may vary by Copilot experience, application and context.

T

Task

State the outcome required, including format, tone, length, structure and any checks Copilot should perform.

Build your own CRIT prompt

We’ve pre-filled the example from the guide. Edit each part, then copy the finished prompt into Copilot.

Your prompt


                        

Why CRIT works: Context reduces ambiguity, Role sets the perspective, Interview invites a clarification step, and Task defines the deliverable. For a simple, well-defined task Copilot can usually proceed straight away. For higher-impact or ambiguous work, the Interview step helps surface missing information before a draft is produced.

Two instructions worth keeping

Add these to any prompt when accuracy matters.

Quality control

Prioritise accuracy over agreement. Challenge assumptions, identify missing context and highlight uncertainty. Separate fact from opinion. Do not invent missing information. Cite or identify the source for important claims where possible.

Source control

Use only the attached document as your source. If the document does not contain the answer, say so rather than filling the gap from general knowledge.

There are many prompting models, including RACE, RISEN, CO-STAR and CREATE. We have found CRIT and the Copilot Refinement Loop the most useful.

The Copilot Refinement Loop

Don’t treat Copilot’s first response as the finished product. The best results often come from an ongoing conversation where you review, challenge and refine the output. CRIT helps you build a better prompt; the Refinement Loop helps you improve what happens next.

In practice · Initial prompt

Draft an email to customers explaining our new service.

Repeat review, challenge and refine until it is right.

Copilot tips and best practices

Use Copilot as an iterative working partner. Give it a clear task, review the result and then refine it.

  • Be specific about the result you need, the audience and the required format.
  • Provide relevant context and point Copilot to the right source material.
  • Ask follow-up questions and refine the first draft.
  • Request alternatives, risks, counterarguments or missing information.
  • Verify names, numbers, dates, quotations, legal points and other consequential claims.
  • Treat generated content as a draft until a person has reviewed it.
  • Do not paste sensitive information into locations or experiences that your organisation has not approved.

General-purpose prompts

Summarise

Summarise this document in five points. Separate decisions, risks and actions.

Create

Draft a one-page project proposal from these notes for a senior management audience.

Improve

Rewrite this text for clarity. Keep the meaning, remove repetition and use plain English.

Challenge

Review this plan critically. Identify assumptions, gaps, dependencies and alternative options.

Transform

Turn these notes into a table with owner, action, deadline and status columns.

Copilot experiences and availability

The term Copilot covers several related experiences. Here is a practical distinction. Confirm current availability before making a purchasing or deployment decision.

ExperiencePractical description
Copilot ChatSecure AI chat for research, drafting and working with supplied content.
Copilot PagesA persistent, editable and collaborative content canvas.
Microsoft 365 CopilotA broader Copilot experience across Microsoft 365 applications and organisational content.
Word, Excel and PowerPoint AgentsCan help create, draft or generate content based on natural-language instructions where supported by the relevant Copilot experience.
Custom agentsTask-specific or knowledge-specific Copilot experiences.

Microsoft Copilot capabilities, licensing, interfaces and commercial models evolve regularly. Examples reflect capabilities available at the time of publication. Availability depends on Microsoft’s licensing model, tenant configuration, regional availability and organisational settings.

Copilot in Word, Excel, Outlook, PowerPoint and Teams

Pick an app to see what Copilot is good for there, then copy a prompt straight into it.

Word

Writing, reviewing and structuring

Use Copilot in Word to create a first draft, restructure content, summarise a document and improve clarity. Always verify substantive claims and ensure the finished document follows your organisation’s standards.

Notes and images flowing into a structured Word document
Draft and structure

Create a two-page customer brief with an executive summary, business challenge, proposed approach, benefits and next steps.

Rewrite for an audience

Rewrite this section for a non-technical executive audience. Keep all important facts.

Review critically

Identify unclear claims, repetition, unsupported statements and missing evidence in this document.

Repurpose content

Convert this report into a concise FAQ for customers.

Format information

Convert the following list into a table with category, requirement, evidence and owner.

Copilot Chat, Pages and agents

Beyond the individual apps, three experiences extend what Copilot can do. Broader reasoning across organisational emails, meetings, chats and files depends on the user’s Copilot licence and available experience.

Chat messages flowing into a Pages canvas and out to Word, Excel, Outlook, PowerPoint and automation agents

Copilot Chat

A conversational workspace for research, drafting and reasoning. It can work with web information, uploaded or selected files and content available in supported applications.

Copilot Pages

A persistent, editable canvas beside Copilot Chat to develop, refine and share content with colleagues. Supported Pages content can be converted into Word or PowerPoint.

Agents

Extend Copilot for particular tasks and may connect to organisational knowledge or processes, depending on account type, licensing and administrator settings.

Copilot Chat

Compare these three options using cost, implementation effort, risk and expected business value. State any missing evidence.

Pages

Turn this discussion into a structured working page with objectives, decisions, actions and open questions.

Research

Research this topic using authoritative sources. Distinguish verified facts from analysis and provide citations.

Agents

Use the appropriate available agent to create a first draft, then tell me which sources and assumptions were used.

Word, Excel or PowerPoint Agents

Draft a two-page proposal with an introduction, problem statement, solution, timeline and next steps.

Availability of Copilot Chat, Pages, agents and Microsoft 365 Copilot depends on Microsoft’s licensing model, tenant configuration, regional availability and organisational settings. Review and refine agent-created content in the relevant application before sharing.

Copilot Cowork: delegating multi-step work

Copilot Cowork is an agentic capability in Microsoft Copilot for multi-step work across Microsoft 365. Instead of only suggesting what to do, it can help plan and carry out a sequence of actions where supported, showing progress and seeking approval before sensitive actions such as sending, posting or scheduling.

A multi-step workflow running from documents through research, email, data, an approval checkpoint and scheduling to a finished report

How Cowork differs from Copilot Chat

Copilot Chat

  • Best for focused questions, summaries, drafts and analysis within a conversation.
  • Usually produces information or content for you to act on.
  • Useful when the task is quick and bounded.

Copilot Cowork

  • Best for coordinated, multi-step work across applications, files and services.
  • Can help with actions such as drafting documents, preparing communications for approval and proposing meetings, where supported.
  • Useful when the outcome requires several connected steps or recurring work.

Practical business use cases

Meeting preparation

Prepare a briefing for tomorrow’s customer meeting using the relevant emails, files and previous meeting notes. Create a one-page brief and draft an agenda for my approval.

Campaign coordination

Using the approved campaign brief, create a customer email, a short Teams update and a campaign checklist. Save the files and show me everything before anything is sent or posted.

Research and reporting

Research this topic using authoritative sources, compare the findings with our available internal material and produce an executive report with citations, risks and recommendations.

Recurring status updates

Every Friday, prepare a weekly status summary from the available project information and present the draft for review.

Document and file management

Create a project folder, organise the supplied files by workstream and prepare an index that explains what each file contains.

Inbox and calendar support

Identify the messages that require action, draft responses for review and propose suitable meeting times where a meeting is requested.

Important control: Cowork operates with the user’s existing permissions. Review generated files and approve communications, calendar changes, payments or other consequential actions before execution. Avoid using Cowork as the final decision-maker for legal, medical, financial, employment or other high-impact matters.

Understanding agent costs and consumption

Agentic AI systems such as Copilot Cowork can consume resources based on the complexity of the task. Factors that may influence consumption:

  1. Number of steps in a workflow
  2. Volume of data processed
  3. Number of systems accessed
  4. Frequency of execution
  5. Use of reasoning-intensive tasks
  6. Use of document generation or analysis

Example workflows by relative consumption

Lower

Customer meeting summary

  • Read meeting notes
  • Produce summary
  • Create action list

Fast execution · Lower consumption · Suitable for daily use

Moderate

Marketing campaign assistant

  • Review multiple documents
  • Compare previous campaigns
  • Create draft campaign plan
  • Suggest messaging

Moderate consumption · Useful for recurring planning tasks

Higher

New customer onboarding workflow

  • Gather information from multiple systems
  • Create documentation
  • Generate tasks
  • Route information to teams

Higher consumption · Greater business value · Requires governance and monitoring

Cost planning: These examples describe relative consumption only; actual consumption varies with the task and how it is run. Start with a controlled pilot, review usage by task type and set sensible limits using the usage and cost reporting available to your organisation. Confirm current Microsoft and partner commercial terms before making decisions.

Securing Copilot and agents

Copilot is permission-aware, not risk-free. It does not grant new access, but it can make information that a user already has permission to access easier to find, combine and summarise. Existing oversharing, stale permissions, ownerless sites or poorly labelled information can therefore become more visible and more consequential.

Key areas to review

Open each area to see the risk and the recommended control direction.

01Identity and access
Risk to considerCompromised accounts or excessive privileges expand what Copilot can retrieve or act upon.
Recommended control directionApply MFA, Conditional Access, least privilege, role review and managed-device requirements.
02SharePoint and OneDrive oversharing
Risk to considerBroad groups, public links, broken inheritance, stale permissions or ownerless sites can expose information through search and Copilot.
Recommended control directionUse SharePoint Advanced Management and Microsoft Purview to identify, restrict and remediate overshared content.
03Sensitivity and data loss prevention
Risk to considerSensitive information may be included in prompts, responses or generated files and then shared onward.
Recommended control directionApply sensitivity labels, encryption, DLP, retention and appropriate restrictions on web-grounded prompts and file processing.
04Data quality and lifecycle
Risk to considerOld, duplicated or inaccurate content can ground confident but incorrect answers.
Recommended control directionAssign owners, archive obsolete sites, remove duplicates and maintain authoritative sources.
05Agents, plugins and connectors
Risk to considerExtensions can introduce new data sources, actions, publishers and external endpoints.
Recommended control directionApprove agents centrally, review permissions, privacy terms, connectors, authentication and data egress before deployment.
06Prompt injection and malicious content
Risk to considerDocuments, emails or websites may contain hidden instructions intended to redirect an AI system.
Recommended control directionUse Microsoft’s layered protections, Defender and Purview controls where licensed, restrict risky sources and train users to stop unexpected behaviour.
07Agentic actions
Risk to considerAI may misinterpret a request, send incorrect content, alter shared systems or trigger an unintended workflow.
Recommended control directionRequire human approval for consequential actions, define allowed actions, use narrow scopes and monitor automated tasks.
08Audit, retention and investigation
Risk to considerWithout logs and retention, organisations may be unable to investigate inappropriate access or AI activity.
Recommended control directionEnable and review unified audit logging, define retention, use eDiscovery and monitor Copilot and agent reports.
09Third-party and web use
Risk to considerWeb grounding and external connectors may involve different sources and data-handling paths.
Recommended control directionControl web access, use approved connectors, apply DLP and verify citations before acting.
10Human verification
Risk to considerGrounded answers can still be incomplete, outdated or inaccurate.
Recommended control directionRequire review of sources and expert approval for legal, financial, regulatory, safety or security decisions.

What Microsoft protects, and what your organisation must manage

Microsoft platform protections
Organisation responsibilities
Copilot respects the signed-in user’s Microsoft 365 permissions and tenant controls.
Review whether those permissions are appropriate and remove excessive or obsolete access.
Prompts, responses and Microsoft Graph data are not used to train foundation models for organisational Copilot use.
Set policies for acceptable use, sensitive prompts, retention, investigation and feedback.
Enterprise data protection, encryption, compliance controls and prompt-injection mitigations apply according to the service and licence.
Configure available Entra, Purview, Defender, SharePoint and admin controls rather than relying on defaults alone.
Copilot and agents can be audited and monitored through Microsoft 365 and security tooling.
Assign owners, review alerts and reports, test controls and maintain an incident-response process.

How ready is your organisation?

Tick each item from the guide’s readiness checklist that is already in place. Your answers stay in this browser and aren’t sent anywhere.

Copilot generally reveals the state of the organisation’s existing identity, permission and information-governance controls. Secure deployment starts with data and access readiness, continues with policy and technical guardrails, and depends on informed human oversight.Core principle

Security, privacy and governance

Copilot operates within Microsoft 365 controls and the access available to the signed-in user, so permission hygiene is essential. Combine Copilot adoption with data classification, least-privilege access, retention, sensitivity labels, acceptable-use rules and human review.

Good practice for users

  • Use approved work accounts, applications and data sources.
  • Check recipients before sending generated content.
  • Do not assume a confident answer is correct or complete.
  • Validate sensitive, contractual, regulatory, financial, safety or security-related outputs with a qualified person.
  • Report inaccurate, unsafe or inappropriate results through approved channels.

Good practice for organisations

  • Review oversharing and permissions before and during deployment.
  • Define where AI may and may not be used.
  • Apply appropriate identity, device, information-protection and retention controls.
  • Train users in prompting, verification, confidentiality and escalation.
  • Monitor adoption and value without using AI output as an unsupported measure of individual performance.

Ten prompts every business user should know

These adaptable prompts cover common communication, analysis and planning tasks.

Summarise today’s most important information from the selected sources. Separate urgent items, decisions and actions.

Draft a response using the context provided. Do not invent commitments or facts that are not in the source.

Explain this spreadsheet in plain English. Highlight trends, anomalies and data-quality limitations.

Review this proposal critically. Identify risks, assumptions, missing evidence and questions a customer may ask.

Create a customer presentation from this report. Use a clear storyline and keep each slide focused on one message.

Prepare me for this meeting using the available context. Include objectives, background, likely questions and decisions required.

Summarise the actions from this conversation. Include owner and deadline only where explicitly stated.

Turn these notes into a project plan with phases, deliverables, dependencies, risks and owners.

Rewrite this for senior management. Lead with the decision required and the business impact.

What am I missing? Challenge the current approach and present credible alternative viewpoints.

A simple verification checklist

Run through this before you share anything Copilot has produced.

Understanding AI hallucinations

Copilot can occasionally generate information that appears convincing but is incorrect, incomplete or unsupported by source data. Users should:

  • Verify important information
  • Check cited sources
  • Review generated content before sharing
  • Apply professional judgement

Microsoft 365 Copilot questions we hear most

Does Microsoft 365 Copilot give users access to information they could not see before?

No. Copilot respects the signed-in user’s existing Microsoft 365 permissions and does not grant new access. However, it can make information a user already has permission to see easier to find, combine and summarise, so existing oversharing or stale permissions become more visible.

Is my data used to train Copilot’s AI models?

For organisational Copilot use, prompts, responses and Microsoft Graph data are not used to train foundation models. Organisations still need to set their own policies for acceptable use, sensitive prompts, retention and investigation.

What is the CRIT prompt model?

CRIT stands for Context, Role, Interview and Task. It was developed by Geoff Woods, author of The AI-Driven Leader. The Interview step asks Copilot to raise clarifying questions when important information is missing, rather than guessing.

How is Copilot Cowork different from Copilot Chat?

Copilot Chat is best for focused questions, summaries, drafts and analysis within a conversation. Copilot Cowork is designed for coordinated, multi-step work across applications, files and services, showing progress and seeking approval before sensitive actions such as sending, posting or scheduling.

Where should a business start with Microsoft 365 Copilot?

Start with one frequent, low-risk workflow such as summarising a document, preparing a meeting brief or drafting a routine email. Save the prompt that works, verify the output and refine the process. Scale only when quality, governance and human ownership are clear.

Sources and further guidance

This guide was drafted from the existing IT.ie Copilot cheat sheet and updated using Microsoft support material available at the time of preparation. Microsoft changes Copilot experiences regularly, so check feature availability in your own tenant.

This guide was created by IT.ie and is not a Microsoft publication. Microsoft, Microsoft 365, Copilot, Word, Excel, PowerPoint, Outlook and Teams are trademarks of the Microsoft group of companies. Reviewed October 2026.

Keep the full guide to hand

Download the complete 29-page Microsoft 365 Copilot Guide as a PDF to share with your team, print for a workshop or keep beside you while you work.

Questions about Copilot? Talk to IT.ie

Whether you are planning a rollout, tightening security and governance, or want help getting more from the prompts in this guide, our Microsoft 365 specialists in Ireland are happy to help.

  1. Talk to us

    Tell us about your team and what you want Copilot to help with.

  2. Choose your Copilot Champions

    Pick the curious, influential people who will use Copilot every day and help others adopt it. A focused group of champions gets far more from Copilot than spreading it thinly.

  3. Put it to work

    Use Copilot on real emails, meetings, documents and spreadsheets, with practical prompts like the ones in this guide.

  4. Decide what’s next

    We review what worked with you, so you can decide where Copilot belongs in your business.

Download the free PDF guideMicrosoft 365 Copilot Guide · 29 pages · 2.5 MB
Call us free1800 353 353
Prefer to chat?Live chat

Get in touch

Send us your question and one of our team will get right back to you.


Download The Social Engineering Guide

Fill in your details below and hit download.