Skip to content

Security1 publisher2 min readPublished

Microsoft sends Autopilot, its Copilot agent that works while users are away, to private preview in September

Microsoft says Autopilot, a Copilot agent that keeps working while users are away, enters private preview at the end of September. Identity teams admitted to the preview get about five days to decide what it can reach and how its actions are recorded.

The Watch · Security desk

Illustration accompanying Microsoft sends Autopilot, its Copilot agent that works while users are away, to private preview in September

What happened

  • Microsoft introduced Autopilot as a Copilot agent it calls persistent, proactive and personal, one that keeps working while the user is away.
  • The same release adds Cowork, which takes a task the user defines and runs it end-to-end to return a finished result.
  • Microsoft also announced FinOps for AI capabilities for managing what customers spend on Copilot and agents.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure Nobody watches what Autopilot does while its user is offline, so the audit record is the main way to check what it touched.
  • decision Once Copilot picks between Chat, Cowork and Code itself, admin policies scoped to each capability will govern a choice the user no longer makes.
  • constraint The sandbox and in-tenant hosting Microsoft describes apply to Code, so admins cannot assume the same containment covers Autopilot.

Microsoft's overview gives Autopilot one sentence [12]. That sentence does not say what data the agent can read, which identity it acts under, or where its actions are recorded [1]. For a responder, those three answers decide whether an agent built to act while its user is away can be investigated later. I'd expect the first question from preview tenants to be whether an Autopilot action shows up in the audit trail under the user's name or as a separate agent. An incident review has to be able to tell the two apart.

The containment Microsoft does describe is for Code. According to the post, Code runs in a sandboxed environment and can be hosted within the customer's tenant [5]. Everything built in Code is grounded in work context through Microsoft IQ, and plugins sync automatically [8].

The capability with the least description also has the nearest date. Home and Code reach the Frontier program "in the coming weeks" [3]. The post is dated September 25, 2026 [10]. Autopilot's private preview arrives at the end of that month, about five days later [1].

The rest of the release shows what unattended output looks like in Microsoft 365. If Autopilot writes through the same paths as Cowork and Office in Copilot, its edits would land in shared files while the person who owns the task is offline. Office in Copilot creates or updates real documents, workbooks and presentations, "live for your whole team, not just you," Microsoft wrote [6].

What to watch

  • Microsoft documentation for the Autopilot private preview stating which identity the agent acts under and which permissions it holds.
  • Whether Autopilot actions appear in Microsoft 365 audit logs as a distinct agent or under the user's own account.
  • A release date for automatic routing between Chat, Cowork and Code, which Microsoft calls coming soon.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories