They arrive in the same sales conversation, so buyers assume one covers the other. One executes work inside the apps, the other governs agents as identities across the tenant. What separates them, how each bills, and why the order you buy them in decides the cost.
These two get compared because they arrive in the same sales conversation, not because they do the same job. Cowork is about execution. Agent 365 is about control.
The distinction matters commercially, because they bill on different mechanisms and an estate that scales agents usually ends up paying for both.
Cowork is where agents carry out multi step work inside the Microsoft 365 apps. Its output is completed tasks, and its cost tracks how much work you move onto it.
Agent 365 treats agents as managed identities rather than features. It is the registry, the access model, and the audit trail for agents operating in your tenant, and it runs at tenant level.
That is a governance problem, not a productivity one. It becomes urgent at the point where you can no longer name every agent running in your estate.
Across the Microsoft agent engagements Morten Andersen reviewed between 2025 and 2026, most estates over licensed the per user assignment and under sized the message pool, which is the exact inverse of where the cost lands.
The reason is structural rather than careless. Per user is the line a licence count can produce, and the message pool needs usage data nobody has yet on the day the order is signed.
Agent 365 is not one line. Per user assignment covers agents running in a single user's context and stacks with Copilot per user pricing. Per agent metered covers autonomous, asynchronous, scheduled and multi user agents, billed per message unit in prepaid packs. The Agent 365 plan runs the governance layer at tenant level.
A simple query is one message. Multi step reasoning is three to five. Each tool call adds one, an agent to agent handoff costs two at each agent, and long context retrieval carries a surcharge.
That compounding is why forecasts break. A nightly compliance agent over two thousand records, at three reasoning steps and two tool calls each, runs roughly ten thousand messages a night and 3.6 million a year, around $360,000 at typical rates before discount. From one agent.
| Dimension | Copilot Cowork | Agent 365 |
|---|---|---|
| Question it answers | Can this work get done? | Who is accountable for the agent that did it? |
| Scope | Execution inside the Microsoft 365 apps | Agent identity and governance at tenant level |
| Billing basis | Consumption, through credits | Three SKUs: per user, per agent metered, tenant plan |
| Where estates get it wrong | Budgeting the license and not the meter | Over licensing per user, under sizing the message pool |
| Becomes urgent when | You want throughput on a repeatable process | You can no longer name every agent running |
The common advice is to govern first and execute later, which sounds prudent and inverts the cost. Governance sized against an agent estate you have not built yet is guesswork, and it is guesswork you pay for per managed agent.
Run the execution pilot first, on a named set of tasks, then size governance against the agents that survive it. You will license a real estate rather than a projected one, and the message pool will be sized on measured behaviour instead of a vendor worked example.
Source: Redress Compliance advisory engagement file, 2025 to 2026. Microsoft agent and Copilot engagements only.
Related reading: the Agent 365 licensing guide for the SKU map and the worked meter, Cowork pricing and the two layer bill, and Cowork against the Microsoft 365 Copilot seat.
Primary sources: the Microsoft 365 Copilot product page, the Microsoft 365 Copilot documentation, Copilot Studio billing and licensing, and the Microsoft Product Terms.
No. Cowork is an execution layer where agents carry out multi step work inside the Microsoft 365 apps. Agent 365 is a governance layer that treats agents as managed identities with a registry, an access model and an audit trail. Neither answers the other's question, and an estate running agents at scale generally needs both.
No. Agent 365 governs agents, it does not perform the work. Assuming governance includes execution, or that execution includes governance, is the most common and most expensive misreading of these two lines.
Through three SKUs covering three populations. Per user assignment covers agents running in a single user's context and stacks with Copilot per user pricing. Per agent metered covers autonomous, asynchronous, scheduled and multi user agents, billed per message unit in prepaid packs. The Agent 365 plan runs governance at tenant level with per managed agent elements.
Because the message meter compounds by construction rather than scaling linearly. A simple query is one message, multi step reasoning is three to five, each tool call adds one, an agent to agent handoff costs two at each agent, and long context retrieval carries a surcharge. Forecasting on an average message count misses all of that.
Run a narrow execution pilot first, then size governance against the agents that survive it. Governance sized against a projected estate is guesswork you pay for per managed agent, and the message pool sized on a vendor worked example rather than your own behaviour will be wrong in one direction or the other.
The per user assignment. It is the line a licence count can generate on day one, so it gets sized confidently, while the message pool needs usage data nobody has when the order is signed. The result is over licensing the predictable line and under sizing the one that actually carries the cost.
Estates license the line they can count and under size the line that bills. The per user number is knowable on day one. The meter is the one that decides the year.
Independent buyer side advisory on Microsoft agent and Copilot spend: separating execution from governance, modelling the message meter with its compounding rules, right sizing the three Agent 365 SKUs, and keeping the pool resizable mid term.
Independent. Buyer side. Written for CIOs, CFOs, and procurement leaders carrying Microsoft contracts. No vendor influence. No reseller margin.
Talk to the Microsoft buyer side practice. No obligation.
See Microsoft Advisory →Independent buyer side advisory. No vendor influence. No reseller margin. We sit on your side of the table when you negotiate with Anthropic and the GenAI vendors.
Monthly. One email. Zero noise.