Best AI Agent Security Software for Copilot Cowork and Microsoft Copilot Cowork Plugins
Try it live
Watch AgentShield block an attack in real time.
Pick a scenario and drive the inspection lane yourself. No signup needed.
Run a request
Runs the live engine on your text. Nothing is stored, no account needed.
Inspection lane
INSPECTINGPolicy trace
High-risk action held for approval
Audit trail
- § · → → →
For most US companies on Microsoft 365, the best AI agent security software for Copilot Cowork is the set of controls they already own: spending policies scoped to a security group, Purview labels and DLP, the unified audit log, and plugin allow lists. Add a gate only where Cowork writes to finance, CRM or ticketing systems through plugins your organization builds, and where an auditor will ask who besides the requester approved the action.
We sell that gate, so opening with "Microsoft's controls may be enough" is deliberate. For a team that uses Cowork to draft decks, summarize threads and schedule meetings, it is the right answer.
Why teams are reviewing Copilot Cowork security now
Copilot Cowork became generally available on June 16, 2026, and billing moved to Copilot Credits. Since then it has gained local browser use, edits to existing Office files, plugins from partners such as Salesforce, ServiceNow, SAP ERP and Workday, and event-driven tasks that start when a matching email or Teams message arrives. Each of those widened what a single user's agent can do while nobody watches. We cover the platform in depth on our Copilot Cowork security page. Four facts from Microsoft's documentation shape every option below:
- Access moved. Access is granted "only through a spending policy that selects Cowork." The agent entry admins configured during Frontier "has no effect on who can use Cowork."
- Approvals are personal. The user who owns the session approves its actions, can release every pending one with Approve All, and can skip prompts for similar actions for the rest of the session.
- Outsiders can start runs. Event-driven tasks fire on a matching email, and "users can pre-authorize actions when they create a task."
- Plugin tools are dynamic. Cowork "calls initialize and tools/list at runtime to discover available tools automatically," so the tool list can change after an admin approved the plugin.
Six options compared
| Option | What it covers | Where it stops | Best for |
|---|---|---|---|
| Microsoft native controls | Spending policies, user approvals, Edge policies, plugin allow and block, Purview labels, DLP and audit | No second approver, no rules on plugin call arguments | Every tenant, as the baseline |
| Controls in the target system | Dual control and roles inside the ERP, CRM or ticketing system the plugin writes to | Only where that system supports it, one system at a time | A few high-risk writes in one system |
| Purview Insider Risk and Defender alerts | Detection of risky AI usage, including prompt injection attempts, after the fact | Alerts, does not hold an action | Security teams with a SOC already on Purview |
| SaaS and AI discovery tools | Inventory of agents, plugins, connectors and owners across tools | Tells you what exists, does not decide a call | Large estates where nobody knows what is connected |
| Build your own MCP gateway | Exactly the rules you want on plugins you build | Approval routing, audit storage and upkeep are yours | Platform teams with spare capacity |
| AgentShield MCP gateway | Per-tool, per-argument policy on calls from your own plugins, named approvers, injection checks, audit trail | Cannot sit in front of partner or Microsoft plugins, does not govern email or Teams actions | Custom plugins that write to money or customer records |
Option 1, Microsoft's native controls
Start here whatever else you buy. Put the people who should have Cowork into an Entra security group and scope a spending policy to it. Remember Microsoft's warning that "a spending policy is an access control, not only a budget," so a tiny credit limit still grants access. Keep Cowork Browsing off until a team needs it; it is disabled by default. Enable sensitivity labels for SharePoint and OneDrive, extend DLP to Copilot, and allow plugins per team rather than tenant-wide.
The approval dialog is a good control for personal actions. Microsoft calls it "Cowork's primary safety mechanism," medium and high risk prompts carry a risk indicator, and approvals "don't persist across conversations." The gap is structural: the approver is the requester. For a vendor bank change or a refund, that is a self-approval.
Option 2, controls in the system the plugin writes to
This is often the cheapest real fix and it means buying nothing. If Cowork updates vendor records through an ERP plugin, the strongest control for a bank detail change is dual approval on the vendor master inside the ERP, which most US mid-market and enterprise systems support. If it closes tickets in ServiceNow or updates opportunities in Salesforce, the plugin can only do what the user's role there allows, because connector consent is per user and cannot be granted on a user's behalf.
The limit is coverage. You configure it system by system, and many write actions, such as an outbound email with a file attached, have no target-system control at all. For payment changes, keep the downstream backstop too: matching each payment against its invoice in reconciliation software catches a misdirected transfer within days instead of at quarter end.
Option 3, Purview Insider Risk and Defender alerts
Microsoft's Purview page for Cowork lists Insider Risk Management as supported, and the Risky AI usage policy template detects risky usage that includes prompt injection attacks, with insights flowing into Defender XDR. If your SOC already lives in Defender, turn it on. Two caveats from the same page: Cowork interactions appear in activity explorer but not in the DSPM Apps and agents dashboard or the AI observability page, and data classification and Compliance Manager are not supported for Cowork. Detection tells you an action happened. It does not stop one.
Option 4, SaaS and AI discovery tools
Discovery and posture tools inventory which agents, plugins and connectors exist, who owns them and which ones are overprivileged. That matters in a tenant where users can share uploaded plugins with colleagues, since Microsoft notes "there's currently no single tenant setting that turns off plugin sharing for every user." If you already run one, check whether it sees Cowork plugins. It answers what is connected. It does not decide whether a particular call should run.
Option 5, build the gateway yourself
Plugins you build declare a remote MCP server URL in their manifest, so you can point that URL at your own proxy and evaluate each call. The rules engine is the easy part. The work is approval routing to a person who is not the requester, timeouts for event-driven runs, an audit store the agent cannot touch, and keeping rules current as the MCP server's tool list changes at runtime. Teams with spare platform capacity do this well. Our MCP gateway page lists what a complete build needs.
Option 6, AgentShield as the MCP gateway
You set your plugin's MCP server URL to an AgentShield gateway endpoint, and the gateway holds the real credential to the downstream system. Every call is evaluated against per-tool, per-argument permissions: which tools a plugin may call, which records, which amounts, which destinations. A bank detail change or a payment above a threshold waits for a named approver who is not the requester, with the triggering email attached. Inputs are checked for injected instructions, and each decision lands in an AI agent audit trail outside the Cowork session.
What it does not do: sit in front of partner App Store plugins or Microsoft's own Dynamics 365 plugins, whose URLs belong to their publishers, or govern email, Teams and calendar actions. For those, use Options 1 and 2. Pricing for the gateway is on our AI security pricing page.
Which option fits your situation
| Situation | Pick | Buy anything new |
|---|---|---|
| Cowork drafts documents and research, no plugins | Option 1 | No |
| Email, Teams and calendar work in interactive sessions | Option 1, plus user training on Approve All | No |
| One or two risky writes in a single ERP or CRM | Options 1 and 2 | No |
| SOC already on Defender and Purview | Add Option 3 | Usually licensed already |
| Custom plugins that write, platform team has capacity | Option 5 | Engineering time |
| Custom plugins that move money or change customer records, auditor asks who approved | Option 6 | Yes |
Four of six situations buy nothing new. That ratio shifts as teams move more back-office work into event-driven tasks and custom plugins, which is where the approval stops being personal.
How much does Copilot Cowork security cost
The Microsoft side is mostly licensed already. Cowork requires the Microsoft 365 Copilot user license, and Cowork usage is billed in Copilot Credits at 0.01 USD per credit on pay as you go, per Microsoft's June 16, 2026 announcement, with each task priced from model use, context retrieval, tool calls and runtime. Purview audit Standard captures Copilot activities at no extra cost. The variable is the gate. A self-built gateway costs engineering time and on-call ownership; a hosted one is a subscription. Either way, scope it to the plugins that write, not to every Cowork user.
Frequently asked questions
Is Copilot Cowork safe for finance teams?
It is safe for drafting, research and personal email work, because sensitive actions pause for the user's approval and every task runs with the user's own permissions. For vendor changes, payments or refunds through plugins, add dual control in the target system or a gate with a second approver, because Cowork's approval is a self-approval.
Can an email trigger Copilot Cowork to take an action?
Yes. Event-driven tasks run when a matching email or Teams message arrives. By default Cowork asks the user before an automated task sends, posts or changes a shared system, but users can pre-authorize actions when they create the task. Do not allow pre-authorized writes on tasks triggered by external email.
Does AgentShield replace Microsoft Purview for Cowork?
No. Purview governs data: labels, DLP, audit, eDiscovery and insider risk. AgentShield governs actions on the plugins you route through it: which calls run, with which arguments, and who approves the risky ones. Most teams that need both keep Purview as the data layer and add the gate only for write plugins.
See the firewall block an attack live.
Drive the Threat Console and watch a real prompt injection get stopped, then put AgentShield in front of your own agents.
Keep reading