Insight · Microsoft Power BI

    Microsoft 365 Copilot in Power BI: What It Does and How to Control AI Access to Your Models

    Power BI answers in Microsoft 365 Copilot are GA; Microsoft 365 Copilot inside Power BI is in preview. What each does, the new per-model AI-access setting, and a rollout checklist.

    Nick de Vrye, CTOPublished 30 September 20267 min read
    Navy Solv Systems title card reading 'Microsoft 365 Copilot in Power BI' with a padlocked semantic model motif.

    In Short: Microsoft 365 Copilot in Power BI Is Two Features, Not One

    Microsoft announced at FabCon Europe 2026 (29 September 2026) two things that sound alike and are governed differently. Fabric IQ in Microsoft 365 Copilot Chat and Cowork brings Power BI answers into Microsoft 365 Copilot, and Microsoft says it is generally available. Microsoft 365 Copilot integrated into Power BI and Fabric brings the Microsoft 365 Copilot experience into Power BI, and it is in preview, behind a new admin setting that is off by default.

    Alongside both sits the control most organisations will care about: a per-semantic-model setting that decides whether read-only users can reach a model through Copilot and Microsoft's MCP tools at all. This post covers what each feature does, how the controls fit together, where Microsoft's own descriptions differ, and a practical rollout checklist. For the rest of the week's news, see our FabCon Europe 2026 recap.

    Power BI Answers Inside Microsoft 365 Copilot (Generally Available)

    The first feature is the outward direction. Users search for Power BI content, attach a report or paste a link, and ask questions in natural language from Microsoft 365 Copilot. Bogdan Crivat's post adds that Copilot can infer "which report or model is right for the question", and that in Cowork, Power BI content "participates directly in long running and asynchronous tasks". It is the grounding layer we described in what Fabric IQ means for Power BI users, now with production support.

    The Power BI September 2026 feature summary lists what came with general availability:

    • Coverage of organisational apps, with improvements to content discovery, large model handling, schema selection, Verified Answers and row-level value search
    • Existing permissions and row-level security decide which reports and models each user can reach
    • Purview DLP support: "Microsoft 365 Copilot now supports Microsoft Purview Data Loss Prevention (DLP) policies and information protection controls for this experience"
    • Citations and sensitivity labels surfaced in responses, per the feature summary

    One caution. The Learn page for the Cowork plugin, last updated on 23 September, still said Cowork did not include citations and that DLP "isn't currently supported in Cowork". The feature summary's DLP statement refers to Power BI answers in Microsoft 365 Copilot generally. Check the current Learn page before you rely on DLP or citations in Cowork specifically.

    On cost, Arun Ulag's FabCon post says Copilot customers can tap into Fabric insights "without additional AI token costs", and the Cowork documentation says no additional Fabric capacity or licence is needed for the plugin itself. Cowork uses usage-based billing of its own, so the phrase covers the Fabric side, not Cowork.

    Microsoft 365 Copilot Inside Power BI and Fabric (Preview)

    The second feature is the inward direction: the Microsoft 365 Copilot experience embedded in Power BI and Fabric, with shared conversation history across Microsoft 365 Copilot experiences. Microsoft's example is a sales leader using Fabric IQ to find regions behind plan, then Work IQ to connect that with customer emails, meetings and documents, then kicking off tasks in Cowork, all from inside Power BI. Microsoft says that work context "was not available in the standalone Power BI Copilot experience".

    The controls, as the feature summary describes them:

    • A new setting in the Fabric admin portal turns the entry point on or off in the navigation pane. It is off by default and can be disabled again to pause access
    • It is independent of the standalone Copilot setting. With both on, licensed users see both entry points and standalone Power BI Copilot stays on Home. With standalone Copilot off and this setting on, users see only the Microsoft 365 Copilot entry point
    • Initial preview requires a Microsoft 365 Copilot licence. Those users get the full Copilot Chat experience with Fabric IQ and Work IQ
    • A broader audience will follow, giving Fabric users without that licence an integrated experience "tailored to their available capabilities". Microsoft gives no date, and says it may differ from the full licensed offering

    Microsoft's wording is that the preview "will roll out", so the setting may not appear in every tenant yet. How we would pilot the existing Copilot is covered in our guide to Copilot in Power BI.

    The Fabric IQ Toggle in Report View

    Separately, report viewers can enable Fabric IQ from the Copilot pane. Copilot then takes a multi-step approach to the semantic model, shows its reasoning steps, generates Fabric visuals and provides the underlying DAX query and data table. The feature summary gives this item no preview or GA label. Seeing the DAX is the useful part: it gives analysts something to check.

    The Per-Model AI-Access Setting

    The new governance control sits on the semantic model. Users with write permission can block read-only users from reaching the model through AI. The feature summary quotes the setting as "Allow any person with read-only access to use AI (i.e. Copilot, Microsoft's MCP tools) on the model and its related reports"; the Learn page words it slightly differently and also places it under Explore and AI access on the full settings page.

    It applies to Power BI Copilot experiences, Microsoft 365 Copilot Chat and Cowork, data agents, and the remote Fabric and Power BI MCP servers. It is on by default to preserve current behaviour. Learn adds three details worth knowing:

    • In experiences that search across models, restricted models are excluded from search results for all users, including those with build and write permission, who can still attach them directly
    • Other eligible models keep working in the same experience
    • The setting is not inherited: a model built on another model needs configuring separately

    How It Relates to Restrict from Copilot

    Here Microsoft's sources describe the control differently. Bogdan Crivat's post says "Restrict from Copilot gives administrators control over which semantic models can participate in AI experiences". The feature summary and Learn describe a model-level setting managed by users with write permission, and neither uses the name Restrict from Copilot in its text. The feature summary's documentation link is aka.ms/restrict-copilot-read-only, which suggests they are the same control, but no source says so outright. Treat it as a model owner's setting unless Microsoft documents a separate administrator control.

    A Practical Rollout Checklist

    The pattern we recommend is the one Microsoft's own documentation implies: expose few models, prepare them properly, and widen on evidence.

    • Pick the first models deliberately. Two or three well-used models with clear owners and stable definitions, where a wrong answer would be noticed quickly
    • Favour certified or endorsed models. Learn suggests Copilot readiness as a criterion for promoted or certified status, or tags that mark models as ready
    • Fix naming and descriptions first. Business names, descriptions on every important measure, hidden technical columns. The full list is in preparing your semantic model for AI
    • Turn the AI-access setting off everywhere else. It is on by default, so unprepared models are reachable until someone changes it, and it is not inherited by models built on top
    • Check sensitivity labels. Answers carry the label of the content behind them, so unlabelled models are a gap. Our guide to Purview DSPM for AI covers the wider Copilot data security picture
    • Test row-level security as a viewer. Copilot queries as the signed-in user, so a flawed role becomes visible in chat. See our row-level security guide
    • Review the tenant settings together: the new Fabric admin portal setting for Microsoft 365 Copilot in Power BI (off by default); the standalone Copilot setting; Share Fabric data with your Microsoft 365 services in the Fabric admin portal, which controls whether Power BI content appears in Copilot search; and Fabric data in Microsoft Copilot in the Microsoft 365 admin center, which Learn says is enabled by default and can be scoped to groups

    Learn also notes that query data from Copilot is shared with Fabric and processed under the Fabric Product Terms, which is worth confirming with whoever signs off data processing.

    Where Solv Systems Comes In

    Most of the work here is not switching settings; it is deciding which models deserve to be answered from and getting them ready. Our Power BI consulting team audits semantic models for AI readiness, sets up endorsement, labels and RLS, and designs the staged rollout so the numbers Copilot gives match the reports people already trust.

    Sources and Further Reading

    Frequently asked

    Direction. Fabric IQ in Microsoft 365 Copilot Chat and Cowork brings Power BI answers into Microsoft 365 Copilot, and Microsoft says it is generally available. Microsoft 365 Copilot in Power BI and Fabric puts the Microsoft 365 Copilot experience, with Work IQ context and shared conversation history, inside Power BI. That one is in preview and controlled by a new admin setting that is off by default.

    During the initial preview, only users with a Microsoft 365 Copilot licence, and only once an administrator enables the new Fabric admin portal setting. Microsoft says support for a broader Fabric audience without that licence will follow, possibly with a different experience, but gives no date.

    No. Microsoft says it is independent. With both enabled, licensed users see both entry points and standalone Power BI Copilot stays on Home. With standalone Copilot disabled and Microsoft 365 Copilot enabled, users see only the Microsoft 365 Copilot entry point.

    Users with write permission on the model can turn off the Copilot setting that allows people with read-only access to use AI on the model and its related reports. When it is off, read-only users cannot reach that model through Power BI Copilot, Microsoft 365 Copilot Chat and Cowork, data agents or Microsoft's remote MCP tools. It is on by default.

    Microsoft does not say so explicitly. Bogdan Crivat's post describes Restrict from Copilot as giving administrators control over which semantic models participate in AI experiences, while the Power BI feature summary and Learn describe a model setting managed by users with write permission. The documentation short link is named restrict-copilot-read-only, which suggests they are one control, but check before relying on it.

    Microsoft's FabCon post says Copilot customers can use Fabric IQ insights without additional AI token costs, and the Cowork documentation says no extra Fabric capacity or licence is needed for the plugin itself. Cowork itself uses usage-based billing, and the in-product preview needs a Microsoft 365 Copilot licence. Check Microsoft 365 Copilot plans and pricing for your position.