# SharePoint agents without Copilot licences: what they cost, and the four ways to switch them off

> Agents in SharePoint were never something you turn on, and people without a Copilot licence can use them for about 12 cents a question. Here are the numbers, what an agent can actually see, and the four ways to switch it off, including the one that does not work the way admins expect.

[Home](https://tenantcraft.ca/)  [Insights](https://tenantcraft.ca/insights)  Copilot

Govern Aug 3, 2026  16 min read

Geri Crroj

Microsoft 365 consultant, Niagara, Ontario

An Agent icon turned up in the header of your SharePoint sites. Nobody in IT switched it on. Nobody bought anything.

A week later a director asks whether you can “use the AI on our files” without buying Copilot for all 80 staff.

Those are the same question. Microsoft’s answer to the second one is yes, at about twelve cents a question.

One line in the docs explains the icon: _“Agents in SharePoint don’t require activation.”_ There was never a switch to leave off. What you get to control is who may use agents, what they can reach, and where they show up. That is the whole list.

The five minute version

-   **Agents are already there.** There is no activation step. Any site member who can create files can create an agent, and the .agent file’s permissions decide who can open it.
-   **Two ways to be allowed to use one:** a Microsoft 365 Copilot licence, or pay-as-you-go billing through an Azure subscription, tied to a named security group.
-   **Pay-as-you-go is $0.01 USD a message, and a hard question costs 12 messages**, so about **$0.12 USD a question**. Microsoft’s [consumption-based pricing announcement](https://techcommunity.microsoft.com/blog/spblog/consumption-based-pricing-for-agents-built-in-sharepoint/4389591) splits the 12 into 2 messages for the answer and 10 for tenant graph grounding. Against a $21 USD Microsoft 365 Copilot Business seat you break even at about 175 questions a month, or 8 a working day.
-   **An agent does not get round permissions.** Answers are filtered by the permissions of whoever asked. It is a permissions amplifier, which is worse if your permissions are messy.
-   **Four off-switches**, and the one in the Microsoft 365 admin centre only blocks the agent in Copilot Chat, not in SharePoint.

## What an agent in SharePoint is, and the four things it is not

Most of the confusion here comes from four different products all being called agents. Different makers, different billing, different admin centres.

| Thing | What it is | Who makes one | What an unlicensed user pays | Managed from |
| --- | --- | --- | --- | --- |
| **Agent in SharePoint** | An `.agent` file on a site, grounded in that site’s pages and libraries | Any site member who can create files | $0.12 USD per complex question, via pay-as-you-go | SharePoint admin centre + Microsoft 365 admin centre |
| **Microsoft 365 Copilot Chat** | The chat experience in the Copilot app, web-grounded by default | Nobody, it ships as-is | Nothing for the chat itself; agent usage inside it is metered | Microsoft 365 admin centre |
| **Copilot Studio agent** | A purpose-built agent with custom knowledge, tools, and actions | A maker with Copilot Studio access | Copilot Credits: 2 per generative answer, 10 for tenant graph grounding, 5 per agent action | Power Platform admin centre |
| **Microsoft Agent 365** | A per-user governance and security control plane for all agents, generally available since May 1, 2026 | Not an authoring tool | Not applicable, it’s licensed per user and works best on E5 | Microsoft 365 admin centre |

Almost everything written about “governing SharePoint agents” is really about the last two rows. Agent 365 sits in the Microsoft 365 E7 bundle next to E5, Copilot and Entra Suite, which puts it well out of reach of a 90-person nonprofit.

The first row is the one that showed up in your tenant without a purchase order. That is the one this post is about.

One detail to hold on to. On September 1, 2025 Copilot Studio renamed its billing unit from _messages_ to _Copilot Credits_. The rate did not change. The SharePoint docs still say messages. Same unit.

## Do you need a Copilot licence to use SharePoint agents?

No. But you need one of exactly two things.

**Option one is a Microsoft 365 Copilot licence.** When a licensed person uses generative answers and tenant graph grounding inside Microsoft 365 apps, it is included. Their questions never touch the meter.

Two different seats hide behind the word Copilot, and which one you can buy depends on what you already own.

**Microsoft 365 Copilot Business** is the add-on for tenants on a Microsoft 365 Business plan, and it needs one. It lists at USD $21 per user per month on an annual commitment, currently on promotion at USD $18 until September 30, 2026. **Microsoft 365 Copilot**, the enterprise add-on, lists at USD $30 per user per month annual. Canadian list prices checked August 3, 2026: Copilot Business CAD $28.50, promotional CAD $24.43; Business Premium with Copilot bundled, CAD $43.40.

If you are a 10 to 500 user Ontario organization on Business Premium, the $21 seat is the one that lands on your quote. Not the $30 one. That difference moves the break-even numbers below by about 30%, so check which line your reseller actually gave you before you trust anyone’s figures. Mine included.

**Option two is pay-as-you-go billing.** You register SharePoint agents as a resource in Azure, create a billing policy in the Microsoft 365 admin centre under **Copilot** then **Billing & usage**, and attach a security group. Microsoft’s wording on that last bit is the part that matters:

> Only users in the security group assigned to the billing policy have access to SharePoint agents.

Microsoft Learn, Set up SharePoint agents for pay-as-you-go billing

That sentence does two jobs at once. It controls the bill and it controls access. No Copilot licence and not in the group means no agent access, whatever the icon in the header suggests.

The setup needs two different sets of rights, written up on two different doc pages, which is where people get stuck. Registering SharePoint agents as an Azure resource needs a SharePoint administrator, plus Owner or Contributor on the Azure subscription and the resource group. Microsoft notes you only need those Azure roles while you set it up. Creating the billing policy is a separate job, and it needs Billing Administrator, AI Administrator, or Global Administrator. A SharePoint admin working alone gets halfway and stops.

The tenant also needs “at least one SharePoint license, or a license that includes SharePoint”, which in practice means every tenant already qualifies. You pick a region while creating the policy, and that choice decides where the tenant ID and usage data live. In Ontario public sector that is the first question anyone will ask.

Current limits: one security group per billing policy, up to 10 policies. Microsoft says support for more groups per policy is coming, which is a polite way of saying it is not here yet.

## What do SharePoint agents cost per use?

The published rate, from the Microsoft 365 pay-as-you-go pricing table:

| Service | What’s counted | Billed (USD) |
| --- | --- | --- |
| Agents in SharePoint | Number of messages used | $0.01 per message |

And the number that makes it real:

> Each interaction includes a question and an answer. A successful interaction uses 12 messages.

Microsoft Learn, Microsoft 365 pay-as-you-go pricing

The billing page for SharePoint agents splits that 12 for you: 10 messages for tenant graph grounding, 2 for the answer itself. SharePoint agents are always grounded in the tenant graph, so you cannot trim the 10 off. That gives you **$0.12 USD a hard question** for someone without a licence.

Now hold it against a seat. Take Microsoft 365 Copilot Business at $21 USD, the seat a small business on a Business plan actually buys. At $0.12 a question, $21 buys 175 questions in a month. That is about 8 a working day, every working day, without a break. On the $30 enterprise seat you get 250 questions, about 12 a day.

Both are a high bar. Most people asking a document library questions do it in bursts, a few times a week, when they need to find one specific thing.

Worked example, 40 staff, all figures USD per month:

| Scenario | Monthly cost |
| --- | --- |
| 40 people, 5 questions each per working day, 21 days: 4,200 interactions | **$504** |
| 40 people, 1 question each per working day: 840 interactions | **$101** |
| 40 Microsoft 365 Copilot Business seats at $21 | **$840** |
| 40 Microsoft 365 Copilot seats at $30 | **$1,200** |

Look at what the top row survives. Even at five questions per person per working day, which is heavier than most document libraries ever see, paying per use still comes in under the cheaper seat.

Two warnings before anyone takes that into a budget meeting. The rate is published in US dollars and Azure bills in your subscription’s currency, so use your own exchange rate, not mine. And pay-as-you-go has no spending ceiling unless you set one, which is what the budget section below is for.

There is a middle option if usage settles into something steady. Copilot Studio capacity packs list at $200 USD per pack per month for 25,000 Copilot Credits. That is $0.008 per credit, and roughly 2,080 SharePoint agent interactions per pack. Cheaper per unit, and Microsoft is clear that unused credits do not roll into next month.

One catch before anyone buys a pack. The credits do cover SharePoint agent use. But the thing that scopes credits to particular people, the Copilot credit policy, only works in Copilot Chat right now: _“For SharePoint agents, continue using pay-as-you-go billing as described in the existing setup process.”_ A pack buys you a cheaper rate and one shared pool. It does not buy you per-department control. If capping one team’s spend was the whole point, the pay-as-you-go billing policy is still the only thing that does it.

## Who can create an agent, and what can it see?

Agents in SharePoint are ordinary files. That one design decision answers most of the permission questions.

> The permissions on the .agent file determine who can access or edit the agent. Only users who can create or access files on a SharePoint site can create or access agents.

Microsoft Learn, Manage access to agents in SharePoint

So there is no separate agent permission model to learn, and no approval step. Microsoft’s own user documentation is blunt: all site members can create their own agents and use them. Agents show up in no published list. People find the `.agent` file the way they would find a Word document, or they use the one a site owner pinned to the Agent icon in the header.

The question everyone really wants answered is whether an agent leaks. Directly, no:

What Microsoft says about agent answers and permissions

“For users who access and use an agent in SharePoint, the agent’s responses depend on each user’s permissions to the agent’s data sources. For instance, if a user has access to the agent but not to the site or document library it references, the agent’s responses for this user don’t include content from those restricted sources.”

Two people can open the same agent and get different answers, because they have different access. Nobody reads a file through an agent that they could not have opened directly.

So the security line holds. What is left standing is the governance problem.

Every permission an agent uses was already granted to somebody. What changes is how easily those grants get used. Say someone was given Contribute on the finance library by mistake in 2022 and never once clicked into it. That grant has sat dormant for four years. Give that person an agent and it wakes up. They now have a tireless reader working through everything the mistake allows.

Pay-as-you-go makes doing this at scale cheaper than it has ever been. Adding 200 people to a security group costs nothing until they ask a question.

If you have not done a permissions pass, do it before you widen the group, not after. [Turn on Copilot without leaking your HR folder](https://tenantcraft.ca/insights/copilot-without-leaking-hr) has the order to work in.

One gap worth knowing: you cannot yet put a sensitivity label on a `.agent` file. Microsoft’s workaround is to write Purview DLP conditions against the `.agent` extension instead. For content, a DLP policy using **Content contains** then **Sensitivity labels** keeps items out of processing. The behaviour is specific: the citations in the answer still list the item, but its content is not used.

## The four places you can switch agents off

| # | Control | Scope | What it stops | What it also stops |
| --- | --- | --- | --- | --- |
| 1 | ”Microsoft 365 Copilot for SharePoint” service plan | One licensed user | That user’s use of agents in SharePoint | Copilot in OneDrive and SharePoint page authoring Copilot for that user |
| 2 | Pay-as-you-go billing policy security group | Unlicensed users | All agent access for anyone not in the group | Nothing else |
| 3 | Restricted content discovery | One site | The Agent icon, agent creation, and that site’s content in any other agent | The site’s content in org-wide search and Copilot generally |
| 4 | Copilot Control System, Agents section | One agent | That agent, in Copilot Chat | Nothing, and that’s the problem |

**1\. The service plan.** On the Microsoft 365 Copilot licence details page in the admin centre you can switch _Microsoft 365 Copilot for SharePoint_ on or off per user. Someone could keep Copilot in Teams and lose agents in SharePoint. There is a real trade though: the same toggle also kills Copilot in OneDrive and the page authoring Copilot for that person. One switch, three things.

**2\. The billing policy group.** For anyone without a licence, this is the whole access model. Keep the group small and named, review it like any other access group, and do not reach for “All users” because it was quicker.

**3\. Restricted content discovery.** The site-level kill switch, and the broadest of the four. Flag a site and people stop seeing the Agent icon in the header there, cannot create agents on it, and cannot pull that site’s content into any other agent. Microsoft’s RCD page describes a wider effect than agents alone: the Copilot button, the AI actions menus, and **Create pages with AI** all vanish from that site. The command:

```
Set-SPOSite -Identity <site-url> -RestrictContentOrgWideSearch $true
```

RCD does a good deal more than block agents. It also pulls the site out of org-wide search and Copilot answers, and Microsoft’s warning about leaning on it too hard still stands. [The full read on where RCD helps and where it quietly hurts](https://tenantcraft.ca/insights/restricted-content-discovery-copilot) covers that trade.

RCD may not be available to you if you go pure pay-as-you-go

RCD is a SharePoint Advanced Management feature, and SAM has two gates, not one.

The base subscription has to be Office 365 E3/E5/A5, Microsoft 365 E1/E3/E5/A5, or a government SKU. Business Premium is not on that list. On top of that you need one of three things: at least one Microsoft 365 Copilot licence assigned to somebody in the tenant, or SharePoint K/P1/P2 in the subscription plus the SharePoint Advanced Management Plan 1 add-on, or Microsoft 365 E7.

The RCD documentation says the Copilot part outright rather than making you work it out from the SAM page: “Ensure your organization has a Microsoft 365 Copilot license.” Its own FAQ defines who qualifies as “customers who are licensed for Copilot and have SharePoint Advanced Management available to them.”

So a tenant that takes up agents purely through pay-as-you-go, with no Copilot licences assigned at all, can lose the per-site kill switch at the very moment it opens agents to everyone. On a qualifying base subscription, keeping one assigned Copilot seat is the cheapest way to hold on to RCD and the SAM oversharing reports. On Business Premium there is no SAM route at all short of changing base subscription, so your controls are the billing policy group, file permissions, and deleting the `.agent` file.

**4\. The Copilot Control System.** Tenant admins and AI admins get a list of agents under **Agents** in the Copilot Control System (the section that used to be called integrated apps) in the Microsoft 365 admin centre, with block and unblock on each one. This is the control most admins reach for first. It is also the one that will mislead you.

Blocking an agent there does not block it in SharePoint

Straight from the Microsoft Learn page on managing access to agents in SharePoint, last updated June 25, 2026:

“Currently, blocking an agent only affects its availability in Copilot Chat. It doesn’t yet apply to OneDrive, SharePoint, or Teams.”

Block an agent in the admin centre, then check it in Copilot Chat, and you will see exactly what you expected and reach the wrong conclusion. The agent is still live on its SharePoint site for everyone who can reach the `.agent` file. To stop an agent in SharePoint you need control 1, 2, or 3, or you delete the file.

## Keeping the bill and the damage predictable

Pay per use has one failure mode: nobody notices until the invoice lands. Three things worth doing on day one.

**Put a budget on the billing policy.** The Microsoft 365 admin centre lets you set a limit as you create the policy, choose whether it resets monthly, quarterly or yearly, and send alerts at percentage marks to named groups. The default alert is at 100%, which is too late. Add 50% and 75%. Alerts can take up to 24 hours to arrive, so treat them as a trend signal, not a trip switch.

**Know where the charge lands.** Agent use bills under the **Copilot Studio** meter on your Azure invoice, not under anything called SharePoint. Microsoft Cost Management shows the breakdown by feature, but whoever checks the invoice needs telling, or that first line becomes a mystery.

**Start the group small and grow it on purpose.** One department, four weeks. Then look at the real interaction count against the $0.12 figure before you widen it. Microsoft’s own advice for controlling spend is to limit who can reach sites that have agents, which is the same advice as tidying permissions, arriving from the finance department instead.

That third one is where the two halves of this post meet. Every person you add to the billing group is a person whose whole existing access becomes easy to search. Twelve cents a question is a rounding error on any budget you are likely to have. A staff member reading a colleague’s performance review because a 2019 sharing link was never cleaned up is not, and no budget alert will ever tell you it happened.

Working out whether your tenant is ready for agents?

Copilot Readiness Governance Checklist

PDF · 7 pages · 44 checkpoints

[Email me the PDF](https://tenantcraft.ca/resources/guides/copilot-readiness-governance)

## Frequently asked

01 Can users create agents without me enabling anything?

Yes. Microsoft's documentation states that **agents in SharePoint don't require activation**. Any site member who can create files on a site can create an agent there, because agents are `.agent` files. What you control is who is _allowed to use_ one: a Microsoft 365 Copilot licence, or membership of the security group attached to your pay-as-you-go billing policy. Without one of those, a user can see the icon but can't use the agent.

02 Can an agent see files the asking user can't open?

No. Responses are filtered by each user's own permissions to the underlying content. Microsoft's example: a user with access to the agent but not to the site or library it references gets responses that exclude content from those sources. Two people using the same agent can get different answers. No new access is created. What changes is that dormant wrong permissions become easy to exercise.

03 How do I stop agents on one site only?

Apply **restricted content discovery** to the site, either from the site's Settings tab in the SharePoint admin centre or with `Set-SPOSite -Identity <site-url> -RestrictContentOrgWideSearch $true`. Users then don't see the Agent icon in the global header on that site, can't create agents there, and can't add that site's content to any other agent. Note that it also removes the site from organization-wide search and Copilot, and it needs SharePoint Advanced Management.

04 Does blocking an agent in the Microsoft 365 admin centre stop it everywhere?

No. As of the June 25, 2026 documentation update, blocking an agent in the Agents section of the Copilot Control System _"only affects its availability in Copilot Chat. It doesn't yet apply to OneDrive, SharePoint, or Teams."_ The agent keeps working on its SharePoint site. Use the service plan toggle, the billing policy group, restricted content discovery, or delete the `.agent` file.

05 Can I put a sensitivity label on a .agent file?

Not yet. Microsoft says you can't add a sensitivity label directly to an `.agent` file, and recommends writing Purview DLP conditions against the `.agent` extension instead. For the content an agent reads, a DLP policy on **Content contains > Sensitivity labels** excludes items from processing; the citation still appears in the response but the item's content isn't used.

## What to actually do this week

If you want a solid answer for the director who asked, it is four short jobs and none of them need a project.

1.  **Check whether pay-as-you-go is already connected.** Microsoft 365 admin centre, **Copilot** then **Billing & usage**, **Pay-as-you-go services**. If SharePoint agents is connected to a policy, find out which security group is on it and when somebody decided that.
2.  **Pick the pilot group before you pick the budget.** One team, named group, four weeks. The interaction count you get back is worth more than any estimate, mine included.
3.  **Run the oversharing reports first if you have SAM.** Data Access Governance and the content management assessment exist so that you do not find out what is overshared by watching an agent tell somebody.
4.  **Write down which of the four off-switches you would use, before you need one.** The wrong answer under pressure is the admin centre block, because it looks like it worked.

On cost, my honest read. If a dozen people occasionally need to find something in a document library, pay-as-you-go beats seats by a wide margin. It keeps beating them right up until somebody starts using an agent as their main way of working. At that point they have earned a licence, and the invoice will tell you exactly who they are. That is a better signal than any rollout plan built on guesses.

On risk, the picture is less comfortable. The icon is already there. The file permissions already decide everything. The only reason any of this feels new is that agents make old permission mistakes useful, and fixing those was on the list well before agents turned up. If Restricted SharePoint Search was your holding measure, [that option closed on July 31, 2026](https://tenantcraft.ca/insights/restricted-sharepoint-search-retirement), so the permissions work is now the way through rather than one of two.

TWENTY MINUTES, NO PITCH

## Tell me what is stuck. I will tell you what it takes.

Same consultant from the first email to the last cutover. If I am not the right fit, I will refer you to someone who is.

[Book a 20-min call](https://tenantcraft.ca/contact) [See published rates](https://tenantcraft.ca/pricing)

---

_Canonical HTML: https://tenantcraft.ca/insights/sharepoint-agents-without-copilot-licences · Agent guide: https://tenantcraft.ca/llms.txt · Site map: https://tenantcraft.ca/sitemap-index.xml_
