Copilot Agents · 8 min read
Microsoft Copilot Autopilot Explained: What Scout Became and What a Firm Should Sort First
By James Wilkinson 26 September 2026
Microsoft has renamed Scout to Autopilot and moved it into the cloud with its own identity in your tenant. What an autopilot is, what it costs and the five things to sort before one arrives.
TL;DR
- Scout, Microsoft's first autopilot, is now called Autopilot and moves from a desktop app you install to a cloud-hosted agent that lives in your tenant with its own identity, memory and workspace. Private preview from the end of September.
- The definition that matters: an autopilot gets its own account, like a new starter, so it can act as itself in Teams and Outlook, work with a whole team and respond to things that happen when nobody is at a keyboard.
- Nothing for a firm to install this month. Plenty to decide: who manages it, what it can reach, what it costs and who answers when it gets something wrong.
In June we wrote about Microsoft Scout twice: once on what autopilots mean for professional services and once on what accountancy and law firms need to know. On 25 September Microsoft renamed Scout to Autopilot as part of the new Copilot app, and the description changed along with the name.
Below: what changed, what “its own identity” now means, what it costs and the five things to sort before one arrives. The wider announcement is in the new Copilot explained.
Scout has a new name, and a new address
Scout was announced at Build on 2 June 2026. What Microsoft documented in June was a desktop application you installed on Windows 11 or macOS 12 and later, working on files on that machine. Autopilot is cloud-hosted instead. It lives in your tenant, your organisation’s own Microsoft 365 environment, with its own identity, memory, computer and workspace, so it keeps working while you sleep.
It shows up where people already work: Teams, Outlook, chats, channels and documents. You @mention it like a colleague.
Three practical notes.
The admin screens will lag. Microsoft’s Learn documentation still carries the Scout name and is marked prerelease, so expect the old name in admin screens for a while. Some templates in Intune, Microsoft’s device management service, even show the internal name Clawpilot.
It is not Windows Autopilot. Windows Autopilot is the device setup service, and the two are unrelated. Tell your IT provider now so they do not get muddled in a ticket.
The June data question still stands. Our June posts noted that Scout’s processing ran through the GitHub Copilot SDK, possibly with external subprocessors. That described the desktop app documented in June. Microsoft has not restated the data-flow position for the cloud-hosted Autopilot, so the June question stands until it does.
What “its own identity” actually means
This is the part our June posts could not write, because the documentation now exists.
Microsoft defines an autopilot as a type of agent that works under its own identity as a persistent, named member of the organisation. It holds a standing role rather than answering one request at a time. It has its own security profile in the tenant and a manager who is responsible for it.
The mechanism sits in Microsoft Entra, the sign-in and identity service behind Microsoft 365. Every agent gets an Entra agent identity. What makes an autopilot different is that it also gets an Entra agent user account. That gives it its own email, calendar, OneDrive, Teams presence and a place in the organisation chart. It also lets it act in Microsoft 365 as itself.
Without its own account, an agent can only act on behalf of a signed-in user, and that breaks in two everyday cases. An agent triggered by an event, such as an email arriving, has no user to act for. And in a group chat the agent has to guess whose permissions to use, so actions get attributed to someone who did not ask and people can be shown content they cannot access. An agent user account fixes both.
Governance follows from identity. Conditional Access, the rules that decide who can sign in and under what conditions, applies to agent identities the way it applies to people, and so do lifecycle policies. Agents authenticate without passwords or multi-factor authentication, so they are governed by policy instead.
The plain-English version: it gets a login, a mailbox and a line manager. Treat it like onboarding a new starter, including what you would do on their last day.
One catch: agents with their own user account are only available to tenants in the Frontier programme. That is Microsoft’s opt-in early-access programme, managed in the Microsoft 365 admin centre, off by default and entirely preview.
What it does
Give it a name, a role and a goal. It watches channels, follows up on threads, runs recurring work and picks a project back up days later without waiting for a prompt. Microsoft’s example is running a supplier review end to end: the schedule, the workback plan, the prep, the meetings, the follow-ups and chasing stakeholders for updates. It is built on Microsoft IQ, Microsoft’s context platform, so it understands how the organisation works.
Microsoft has not published an Autopilot feature list. It has documented what Scout could do in June, and most of that is likely to carry over:
- Read, write and search files.
- Run commands.
- Drive a browser to fill in forms and log into sites.
- Work with Outlook mail and calendar, Teams messages and meetings, SharePoint lists and OneDrive files.
- Launch sub-agents to work on several things in parallel.
- A heartbeat mode that runs a standing instruction every 15 minutes to 2 hours, within set working days and hours.
- Scheduled and condition-triggered automations.
- Memory across sessions.
- A three-tier permission system for commands (auto-approve, prompt, deny) and the ability to mark sensitive paths.
- Tracking of sensitivity labels, so labelled content is not written to unprotected places.
Heartbeat had its own stricter permissions, because nobody is there to approve anything. Outbound messages used generic content only, and actions that would normally prompt were skipped. The design already assumes you are not watching.
Where a practice would use one
Think of it as a teammate with a manager. Each example has a point where the work comes back to a person.
Chasing missing records. Ahead of year-end or a VAT quarter, it watches the client folder and the email thread, sends the reminder and escalates to the manager after two goes. The person decides what happens after that.
Month-end work in progress and billing follow-ups. It nudges fee earners for time, flags matters over budget and prepares the list for the partner meeting. The partner still makes the call.
Client onboarding. It picks up the engagement from the moment the letter is signed, opens the Teams channel, requests documents and tracks what has arrived. Anti-money laundering sign-off stays with the money laundering reporting officer.
Five admin jobs an agent can take off a 30-person accountancy firm and where an agent fits in a 20-person law firm draw the line in the same place.
What it costs, as far as anyone knows
Autopilot is billed on usage in Copilot Credits, on top of the Copilot licence, like Cowork and Code. A Copilot Credit is Microsoft’s usage currency for AI work the per-user licence does not cover. Microsoft has not published rates for Autopilot.
What we can set out is the shape of the stack. The June Scout preview required Frontier enrolment, a Copilot licence (business or enterprise), an Intune policy on the device, an admin attestation form and a GitHub account for the user. A GitHub Copilot licence alone did not grant access.
The closest published requirements for agents with their own accounts sit in Agent 365, Microsoft’s admin and governance layer for agents. Its preview features in Frontier need at least one Microsoft 365 E7 or Agent 365 licence and come with a 25-seat “Frontier for AI Teammates” preview subscription. Microsoft has not said whether Autopilot’s private preview uses this route, so treat these as the nearest documented requirements, not Autopilot’s.
The one firm rule is on spending. Usage-based services stay off until an admin sets a spending policy, and nothing bills before that. For Autopilot this matters more than for Cowork, because it runs continuously. Set a budget, a reset period and alert recipients before the first one is switched on. A billing policy in the Microsoft 365 admin centre supports a budget cap, a monthly, quarterly or yearly reset and alerts at the percentages you choose. The same rule applies to Copilot Code, which runs on the same meter.
Availability, and why a 30-person firm is not in the queue
Autopilot is in private preview from the end of September 2026, for selected customers. Microsoft has said a consumer version is planned, with no date. General availability has not been announced.
The honest line: a firm of 10 to 200 staff without an IT team is unlikely to be in this preview, and that is fine. The foundations are the same ones our June posts described, and they have not changed.
Five things to sort before it arrives
This is the same minimum we set out in why every agent needs an owner, and it applies to an autopilot with more force, not less.
- A named manager. One person, not a committee. Microsoft’s own model gives every autopilot a manager, so decide who it is.
- A one-page written scope. Name, role, goal and what it must never do.
- Data on least privilege. Which SharePoint sites, mailboxes and Teams channels it can reach, decided before it is created.
- Transcripts and audit on, with a ten-minute weekly review. Scout already kept heartbeat and automation logs. The review habit should start now, with the agents you already run.
- A kill switch and a test set. Known questions it must answer correctly before any change goes live.
A data protection impact assessment, an AI policy and staff training still happen. Using Copilot with client data sets out the staff rules and review standards, and three questions to ask of any agent explains why every agent needs an identity of its own, which is exactly what an autopilot now has.
The bottom line
Autopilot is Scout grown up: a cloud teammate with its own account, its own manager and its own meter. The firms that get value from it will be the ones that decided owner, scope and access before it arrived. That is the same work that makes a Copilot Studio agent safe today. If you want that work done against your own processes, Discover is the fixed first step.
Sources checked
Last checked: 26 September 2026.
- Microsoft Official Blog, “Introducing the new Copilot with Home, Code and Autopilot”, 25 September 2026
- Microsoft Tech Community, “Evolution of the Copilot pricing model”, 24 September 2026
- Microsoft Learn, “Use Microsoft Scout” (prerelease)
- Microsoft Learn, “Admin access overview for Microsoft Scout”
- Microsoft Learn, “What is an autopilot in Microsoft Foundry?”
- Microsoft Learn, “Agent 365 identity”
- Microsoft Learn, “Preview Microsoft Agent 365 features through the Frontier program”
- Microsoft Learn, “Set up pay-as-you-go”
Want to know what your firm would need in place before an autopilot could safely join the team? That is the work FiveForward does. Book a free consultation and we will start from the agents and processes you already run.
Related reading
More on Copilot Agents
Common questions