The Risks of Self-Service Purchasing for Microsoft 365 Copilot: A Comprehensive Guide

Microsoft’s recent rollout of the self-service purchasing feature for Copilot in Microsoft 365 has introduced both greater flexibility and new challenges for end users.

Luke Greening

Luke Greening

|

Solutions Architect

Posted on: January 24, 2025

|

Last updated: January 21, 2026

|

11 min read

Luke Greening

Luke Greening

|

Solutions Architect

Posted on: January 24, 2025

|

Last updated: January 21, 2026

Read time: 11 minutes

Microsoft 365 Copilot

Summary:

  • Self-service purchasing removes centralised IT control, creating visibility gaps and increasing the likelihood of shadow IT.

  • Administrators lose oversight of who has bought Copilot, which complicates tracking usage, licence consistency, and compliance.

  • Copilot may expose sensitive data if permissions are poorly managed.

  • Users can unintentionally misuse Copilot to surface or share protected information.

  • Self-service purchasing weakens audit trails.

  • Uncontrolled spending becomes likely when users independently buy Copilot licences.

Microsoft’s recent rollout of the self-service purchasing feature for Copilot in Microsoft 365 has introduced a new level of flexibility for end users. However, this feature also brings significant challenges and risks that organisations must carefully consider. In this blog post I will explore the implications, associated risks, and strategies for planning to remove the self-service purchasing capability within a Microsoft 365 tenant.

The problem: Lack of Centralised Control

The primary issue with self-service purchasing is the shift from centralised to decentralised control over licences and access. This can extend across many services within Microsoft 365 and the following detail may be used to support the removal of other self-service purchasing services. Traditionally, IT administrators manage licences and ensure that only authorised users have access to specific tools and functionalities within Microsoft 365. However, self-service purchasing allows end users to add Copilot to their Microsoft 365 plans directly, bypassing the need for administrative approval. While this can streamline productivity and efficiencies, it is not without challenges:

  • Lack of visibility: Shadow IT causes organisations visibility issues and as a result administrators may not be immediately aware of which users have purchased Copilot, making it difficult to track usage and compliance.
  • Inconsistent licensing: Without centralised oversight, there’s a risk of inconsistent licensing practices across different departments or teams.

Risks Associated with Self-Service Purchasing of Microsoft 365 Copilot

1. Data Security and Privacy Concerns

  • Data exposure: Copilot can access all organizational data (unless there are controls limiting its scope) that users have at least view permissions for. Without a solid permission model, Copilot might reveal information to users in the organization based on the current permissions applied to content.
  • Misuse of data: Without proper controls for the scope and permissions of data, users might misuse Copilot to access or share sensitive information, leading to potential data breaches, oversharing or compliance violations.

2. Compliance and Governance Issues

  • Regulatory compliance: For organisations in regulated industries, self-service purchasing can complicate adherence to data protection laws, making it tough to ensure all users use Copilot compliantly.

An example of non-compliant use for Copilot is when users inadvertently share sensitive or protected information with unauthorised individuals. Cases such as this are often a result of poor permissions across Microsoft 365 data, allowing Copilot to access and surface data that should be restricted. For instance, if a user has broad access to confidential data across a number of data repositories and Copilot generates a summary or response that includes sensitive details, it could lead to data leakage or compliance violations.

To mitigate such risks, it is crucial organisations implement strict permissions management, sensitivity labels and ensure a continuous monitoring process is put in place ensuring only authorised users can access and surface specific data through Copilot.

  • Audit trails: Self-service purchases can make it challenging to maintain clear audit trails, which are crucial for regulatory compliance and internal audits.

3. Cost Management

  • User or organisational spend: End users may purchase Copilot without considering the overall budget or the organisation’s licensing strategy, leading to uncontrolled spending.
    • Expenses are incurred at the time of service acquisition by the user. This may involve the utilisation of organisational resources, such as company credit cards.
  • Licensing strategy: Unused Copilot licenses can lead to unnecessary costs and complications. It’s important to track license purchases and plan for their removal or alignment with organizational needs.

Mitigate the risks associated with Self-Service trials and purchasing.

Organisations should consider the following steps to plan for removing the self-service capability within a tenant and the associated risks as previously explained:

1. Conduct a Risk Assessment

  • Evaluate the current state of your Microsoft 365 tenant, including user permissions, data access controls, data cataloguing and existing usage of Copilot, where applicable.
  • Identify any potential vulnerabilities or areas where self-service purchasing could lead to misuse or data exposure.

2. Implement Centralised Controls

  • Where possible utilise existing tools or purchase new tools like Varonis, Sharegate, TreeSize to gain visibility into user permissions and data access within your tenant, or develop custom PowerShell scripting that can be ran on a scheduled basis.

3. Educate End Users

  • Provide training and documentation to help end users understand the importance of centralised control and the risks associated with self-service purchasing. This would typically align to organisations who wish to allow the use of self-service trials and purchasing as part of a strategy.

4. Remove self-service trials and purchasing

  • After completing an audit and assessing the risk, organisations should disable self-service purchasing for Copilot and other potential trials within Microsoft 365 where current licensing strategy doesn’t cater for this. Learn how to turn off self-service purchasing for Copilot below.

5. Review and Audit Regularly

  • Regularly review user permissions and data access to ensure that they align with your organisation’s security and compliance requirements.
    • Permission reviews may be requested by Site/Team owners through an IT function, where reports can be run, or directly from the SharePoint Site or M365 group.
  • Conduct periodic audits of user permissions to identify any potential issues or areas for improvement.

How to turn off self-service purchasing of Microsoft 365 Copilot

Admins can do this directly from the admin centre as detailed below, or by using PowerShell.

  1. Access the M365 admin portal
  2. Expand Settings and select Org Settings
  3. Scroll down to Self-service trials and purchases
  4. Click Copilot
  5. Select Do not allow and save your changes

When removing self-service trials and purchasing, any acquired licenses will remain active until the expiration date, or admins remove the license from the users associated Microsoft 365 account.

Conclusion

While self-service purchasing for Microsoft 365 Copilot offers convenience and flexibility, it also introduces significant risks that organisations must manage carefully. By conducting a thorough risk assessment, implementing centralised controls, and educating end users, organisations can mitigate these risks and ensure a secure and compliant environment for Copilot usage.

Receive more blogs like this straight to your inbox

Sign up to receive our latest blogs and stay up to date with our latest news, Microsoft 365 updates, events, webinars and workshops.

Last updated 21 Jan 2026

About the Author: Luke Greening

Luke Greening
Previously designing and implementing large scale intranets (and everything that comes with it) to now delivering cutting edge content delivery platforms, I have extensive knowledge when it comes to People, Process and Technology. Data is at the heart of everything we do and I love taking our customers on a journey that exploits all the amazing capabilities Microsoft 365 and Microsoft Purview has to offer them in mitigating risk and being ever more compliant.

Get Industry Insights

Subscribe to stay up to date with Microsoft 365 news and technology

Go to Top