Comparison guide
Microsoft 365 Copilot vs ChatGPT Enterprise: which suits a Microsoft 365 organisation?
On each vendor's own documentation, read on 30 September 2026, the choice for a Microsoft 365 organisation turns on three things. Where the assistant works: Microsoft 365 Copilot sits inside Word, Excel, PowerPoint, Outlook and Teams and answers from Microsoft Graph, while ChatGPT Enterprise is a separate workspace that reaches SharePoint, email and calendars through plugins and joins Teams as @ChatGPT. How it is paid for: Copilot is US$30 a user a month on a yearly plan, added to a qualifying Microsoft 365 licence, with Copilot Cowork and some agent use metered in Copilot Credits; ChatGPT Enterprise is priced by OpenAI's sales team, with credits for heavier work. Whose permissions it follows: Copilot shows each person only what they can already open, so an overshared SharePoint site becomes a Copilot answer, and a ChatGPT plugin works with whatever the connected account can reach. The SharePoint permissions work comes first either way.
Workplace AI assistant. An AI assistant sold to a whole organisation, such as Microsoft 365 Copilot or ChatGPT Enterprise, that answers questions and produces work from company data under the organisation's identity, access and audit controls.
1AYM is an OpenAI Select Partner. Its founder holds personal Claude certifications. 1AYM is not an Anthropic partner. It resells no licences.
Checked . Every vendor fact below was read on Microsoft's and OpenAI's own pages and documentation. Prices are US list prices in US dollars: Microsoft says the price shown can vary by country and currency, and OpenAI's page states no tax basis. Vendors change prices, plans and features without notice. Not legal advice.
Microsoft 365 Copilot and ChatGPT Enterprise side by side
What Microsoft and OpenAI each publish about their own product, read on the same day; the numbers in brackets point to the sources at the foot of the page.
One naming note before the table. Microsoft now calls the product Microsoft Copilot, and Copilot Chat is now Microsoft Copilot Chat; its price pages and licences still say Microsoft 365 Copilot during the change, so this guide does too [3, 4].
| Dimension | Microsoft 365 Copilot | ChatGPT Enterprise |
|---|---|---|
| What you buy [1, 3, 10] | An add-on licence on top of a qualifying Microsoft 365 or Office 365 plan, such as E3, E5, Business Standard or Business Premium. Microsoft 365 E7 includes it | A separate ChatGPT workspace, sold through OpenAI's sales team. ChatGPT Business is the self-serve plan below it |
| List price, US dollars [1, 2, 10] | US$30 a user a month, paid yearly. Microsoft 365 Copilot Business, for up to 300 users: US$21 paid yearly (US$18 for the first year under a promotion shown when read) or US$25.20 monthly | Quote-only. ChatGPT Business is US$20 a user a month billed annually or US$25 monthly, from 2 users |
| Usage on top of the seat [1, 9, 10, 19] | Copilot Cowork, and agents used by staff without a Copilot licence, are metered in Copilot Credits: US$0.01 a credit on pay-as-you-go, or discounted through a yearly pre-purchase plan. Licensed users run assistive custom agents at no extra cost | Workspaces on flexible pricing buy credits to keep working past the included limits. ChatGPT Work and Codex share one allowance, and Enterprise admins can set monthly credit limits per user |
| Staff without the paid licence [1, 3] | Copilot Chat, grounded on the web, comes at no extra cost with an eligible Microsoft 365 subscription. Answers from work data need the Copilot licence | The OpenAI pages cited here describe no free tier inside an Enterprise workspace |
| Where people use it [1, 14, 18] | Inside Outlook, Word, Excel, PowerPoint, OneNote and Teams, and in the Microsoft Copilot app | ChatGPT on the web, desktop and mobile. In Teams as @ChatGPT, set up by a Teams admin and a ChatGPT admin together |
| Microsoft 365 content [4, 13, 14, 18] | Grounded in Microsoft Graph: mail, chats, meetings, calendar and documents, limited to what each user has at least view permission to | Through plugins for SharePoint, email and calendars, working with what the connected account can already open. @ChatGPT in Teams uses the connections an admin sets up, not the asking person's own access |
| Other systems [1, 4, 12, 19] | Copilot connectors bring in outside sources: included with the licence, metered for Copilot Chat users. Connector results reach only users with access to them | Plugins and MCP servers from a directory the admin controls, by role. Where a connection supports it, admins allow only read-only actions or an approved set |
| Agents [1, 9, 13, 18] | Researcher, Analyst and Facilitator included. Custom agents built in Agent Builder and Copilot Studio. Copilot Cowork for multi-step work, metered | ChatGPT Work for multi-step tasks that end in a brief, a deck, an analysis or a file to review. Plugins are replacing custom GPTs, which OpenAI is retiring |
| Where data is stored [4, 5, 10, 11] | Covered by Microsoft's data residency commitments for data at rest since 1 March 2024, with Advanced Data Residency and Multi-Geo on top. Copilot Cowork stores prompts and responses in the tenant's country for 15 countries, the UK and the UAE among them | Data residency controls on Enterprise and Edu, not on Business. OpenAI says residency covers only eligible content, workloads, regions and configurations |
| Where prompts are processed [4, 6, 11] | The nearest data centres, or other regions at busy times. EU traffic stays inside the EU Data Boundary; elsewhere, prompts may be processed in the US, the EU or other regions. Microsoft's timeline, revised in April 2026, expects in-country processing in Australia, India, the UAE, the UK and the US by the end of 2026, Canada in 2027 and Japan in 2028 | Inference residency is offered for supported regions and configurations. ChatGPT Work is not supported with UAE inference residency |
| Models from other vendors [1, 4, 7, 10] | OpenAI models, and Anthropic's Claude models as a Microsoft subprocessor. Claude is on by default in most commercial tenants, off by default in the EU, EFTA and UK, and outside the EU Data Boundary and in-country processing commitments | OpenAI's own models |
| Identity and joiners and leavers [3, 7, 10, 15, 16] | Microsoft Entra work accounts, with licences assigned in the Microsoft 365 admin center. Access to Claude models can be limited to named users or security groups | SAML SSO on Business and Enterprise. SCIM directory sync and custom roles by group on Enterprise, Edu and Healthcare. SCIM grants no permissions in connected systems |
| Audit and retention [4, 8, 17] | Prompts and responses are stored with the rest of your Microsoft 365 content, found through Content search and eDiscovery, and kept or deleted by Microsoft Purview retention policies | The Compliance API streams an append-only log for export to a SIEM or an eDiscovery workflow. OpenAI says its own retention window does not replace your retention policy |
| Keeping sensitive content out [8, 12, 19] | Restricted Content Discovery, data loss prevention for Copilot, sensitivity labels and site access reviews. SharePoint Advanced Management is included with Copilot licences | Admins choose which plugins each role may use and whether their actions are read-only. What a plugin can reach is set in the source system |
| Training on your data [4, 10] | Prompts, responses and Graph data are not used to train foundation models | No training on business data by default |
Which regions OpenAI offers for storage and for inference, and what each covers, is set out in the ChatGPT and Claude plan comparison, alongside UK seat prices for the plans below Enterprise.
Why SharePoint permissions decide the rollout
Microsoft's line that Copilot only surfaces data a user already has permission to view [4] is true, and it is the reason rollouts go wrong. Permission to view includes every site shared with everyone in the company years ago, every folder whose inheritance was broken for a project that ended, and every site whose owner has left. Nobody found those files before because nobody searched for them. Copilot searches for them on every prompt.
Microsoft's own deployment guidance treats this as step one. Before guardrails and before compliance work, it says to remediate oversharing: find the overshared, ownerless and inactive sites, put interim protections on the worst of them, then fix the access itself [8]. I would not switch Copilot on for a whole company before that is done, and I would not accept a rollout plan that leaves it for later.
ChatGPT Enterprise does not escape the problem. A ChatGPT plugin works with the documents the connected account can already open [13], so an overshared library is overshared to ChatGPT too. And @ChatGPT in Teams uses the connections an admin configures, which may reach more, or less, than the person asking could reach alone [14]. The clean-up is the same job whichever assistant you buy.
- Find the exposure
- Microsoft Purview's data risk assessments show overshared sites holding sensitive data, and the SharePoint Advanced Management content assessment flags sites with oversized audiences, company-wide sharing, broken inheritance, no owner or no activity [8].
- Put interim guards on
- Restricted Content Discovery keeps named sites out of Copilot's reach, and data loss prevention for Copilot keeps labelled content out of its answers, while the real fix runs [8].
- Fix the access
- Site access reviews let each site's owner remove excess users, groups and company-wide links; broken inheritance gets corrected, and every site gets an accountable owner [8].
- Stop it coming back
- Restricted access control on business-critical sites from the day they are created, limits on company-wide and Anyone links, and a sensitivity label required on every new site [8].
- Check the licences cover it
- Microsoft lists Microsoft 365 E3 or E5 for the Purview foundations, with some features needing E5, and includes SharePoint Advanced Management with Copilot licences [8].
Which fits which situation
I would not pick between these two on a feature list. Both answer questions, draft documents and run agents, and both keep adding features. What separates them for a Microsoft 365 firm is where people work, where the data has to stay, how the bill behaves and which audit trail your security team already reads. Start from the situation that looks most like yours.
- Staff spend the day in Outlook, Teams and Office documents
- Microsoft 365 Copilot works inside those apps and answers from mail, meetings and files through Microsoft Graph [1, 4]. The question is whether US$30 a seat a month [1] pays back for each role, so license the roles whose day is mail, meetings and documents first, and give everyone else Copilot Chat, which comes with eligible Microsoft 365 plans at no extra cost [3].
- The heavy work is analysis, research and writing outside Office
- ChatGPT Enterprise is a workspace of its own, and ChatGPT Work takes a multi-step job through to a finished brief, deck or analysis for review [18]. Plugins bring SharePoint and mail into it with the connected account's access [18, 13].
- Teams already rely on custom GPTs
- OpenAI is moving custom GPTs to plugins and will retire GPTs, which then stop running [13]. Put the migration in the rollout plan, with an owner for each GPT worth keeping.
- Data has to stay in the UK or the Gulf
- Copilot's stored data follows Microsoft's residency commitments, and Microsoft expects in-country processing of prompts in the UK and the UAE by the end of 2026 [5, 6]. Claude models inside Copilot sit outside those in-country commitments and are on by default for most commercial tenants outside the EU, EFTA and the UK [7], so in a Gulf tenant they are usually on until an admin decides otherwise. OpenAI's residency controls are Enterprise-only, and ChatGPT Work is not supported with UAE inference residency [10, 11]. The Gulf AI data-residency guide sets out what each Gulf regime asks for.
- Finance wants a predictable bill
- Copilot's seat is fixed, but Copilot Cowork and agents used by unlicensed staff draw Copilot Credits at US$0.01 each on pay-as-you-go [9]. ChatGPT Enterprise is quote-only, and heavier use draws workspace credits, capped by per-user monthly limits [10, 19]. Ask each vendor for the rate card before you sign, not after the first invoice.
- Security wants one audit trail
- Copilot's prompts and responses sit in Microsoft 365 alongside your other content, under the Purview retention and eDiscovery your team may already run [4]. ChatGPT Enterprise's records leave through the Compliance API into your SIEM or eDiscovery tooling [17], which is another feed to build and watch.
- You want both
- That is a reasonable answer: Copilot for the roles that live in Office, ChatGPT Enterprise for the people doing heavier analysis. It means two contracts, two admin consoles and two audit feeds, under one set of permission and data rules.
What a year costs at list price
Seat arithmetic is simple for Copilot and impossible for ChatGPT Enterprise, because OpenAI publishes no Enterprise price. At Microsoft's list price, 500 Copilot seats cost US$180,000 a year on top of the Microsoft 365 licences they sit on [1, 3]. Copilot Cowork and metered agents come on top of that, billed by credit [9].
For ChatGPT Enterprise, ask OpenAI for three numbers: the seat price, the credit rate card and what happens when a user reaches the limit. ChatGPT Business's list price, US$20 a user a month billed annually [10], is a reference point for the conversation, not a forecast of the quote.
The number I would budget against is neither list price. It is a two-week pilot on your own work, with usage per person recorded, because a few heavy users decide the bill on any metered plan.
What to test in a two-week pilot
Vendor documentation will not tell you how either product behaves on your tenant. Give both the same people and the same work for two weeks, time the work before either touches it, and collect evidence on each point below.
- A permissions probe
- Before anyone else gets a licence, have a pilot user ask each assistant for something they should not see: salary files, board papers, a closed deal. If either answers, stop and fix the access [4, 8].
- One workflow people repeat
- A weekly report, a meeting pack or a client brief, run by the same people in both products with the documents they really use.
- Usage per person
- Record credits and metered agent use per user, then project them across a year [9, 10].
- Joiners and leavers
- Connect SCIM where the plan has it, and check that access ends when someone leaves the directory [15, 16]. The 90-day ChatGPT Enterprise rollout plan puts this step before the first broad invite.
- The records your auditors will ask for
- Pull the pilot's prompts and responses from Purview and from the Compliance API, and check they hold what your auditors will ask for [4, 17].
Where 1AYM fits
1AYM rolls out both. On a Microsoft 365 estate the first job is the same either way: we clean up SharePoint and OneDrive permissions before Copilot goes live, so the assistant answers from what people should see rather than what they happen to be able to open. That is our AI governance implementation work: access reviews, sensitivity labels, Restricted Content Discovery and data loss prevention for Copilot, built into the rollout rather than left as a follow-up. We then run the pilot above, set up identity and SCIM, and put spend limits and audit collection in place on whichever product you choose.
We resell neither product, so the recommendation is not tied to a licence margin. We have rolled out Claude Enterprise for a client, and we roll out ChatGPT Enterprise and Microsoft 365 Copilot. The documented case, engagement file D-01, listed below, is the AI platform work at a large international marketing agency. If the choice between the two is still open, the AI Opportunity & Feasibility Sprint settles it with a scored recommendation.
A fixed-scope rollout can start within a day of the scope being signed, and a rollout you have already scoped can be resourced on contract from the collective of associates who work with 1AYM, held to the same standard. 1AYM will tailor the project to your budget and timeframe, and your account manager will make sure expectations are set from the first conversation. Book a call from the end of this page, or email tayyeb@1aym.com.
For engineers and security reviewers: grounding, models, identity and logs
The table shows what each vendor publishes at plan level. These are the details behind it that a security review asks about, each with its source.
- Grounding respects identity
- Copilot's Semantic Index honours the user's identity-based access boundary, so grounding only reaches content the current user is authorised to access; connector content is returned only if the user has permission to it [4].
- Encrypted content
- Copilot honours the usage rights on content encrypted by Purview Information Protection, through sensitivity labels or Information Rights Management, and that encryption can exclude programmatic access, which keeps agents out of it [4].
- Data loss prevention on prompts
- Purview DLP for Copilot can block processing of labelled files and emails, and a second policy can stop Copilot responding to prompts that contain named sensitive information types, or allow them for work grounding while blocking them from web grounding [8].
- Claude inside Copilot
- Anthropic models run as a Microsoft subprocessor under Microsoft's Product Terms and Data Protection Addendum. An AI Administrator or Global Administrator enables or disables them under Copilot settings and can assign them to users or security groups. Models labelled 'Anthropic models with Data Retention' are off for everyone until an admin opts in, and then Anthropic, not Microsoft, keeps most inputs and outputs for up to 30 days [7].
- Plugin identity in ChatGPT
- A member can use an MCP server only when the plugin and server are available to their role and the authenticated account can reach the connected service. With a shared credential, the external account can differ from the member's own [12].
- SCIM behaviour
- For synchronised groups the identity provider is the membership source, and later provisioning can overwrite changes made in the workspace [15]. OpenAI advises against enabling Automatic Account Creation and SCIM together [16].
- Compliance API
- An append-only log stream with scripted download of JSONL files, for collection into a SIEM or data lake. OpenAI names the Admin API reference as the source of truth for event coverage, schemas and retention [17].
- Residency switches
- If enforce_residency is set in any cloud policy, local computer access is disabled for both ChatGPT Work and dots. That safeguard does not itself configure workspace residency [11].
Sources
- [1]Microsoft, Microsoft Copilot pricing for enterprise (US), read 30 September 2026
- [2]Microsoft, Microsoft Copilot pricing for business (US), read 30 September 2026
- [3]Microsoft Learn, License options for Microsoft Copilot (updated 28 September 2026), read 30 September 2026
- [4]Microsoft Learn, Data, privacy and security for Microsoft Copilot (updated 18 August 2026), read 30 September 2026
- [5]Microsoft Learn, Data residency for Microsoft 365 Copilot and Copilot Chat (updated 11 September 2026), read 30 September 2026
- [6]Microsoft, In-country data processing for Microsoft 365 Copilot (dated 4 November 2025, timeline revised 3 April 2026), read 30 September 2026
- [7]Microsoft Learn, Anthropic models in Microsoft Online Services (updated 18 September 2026), read 30 September 2026
- [8]Microsoft Learn, Configure a secure and governed foundation for Microsoft Copilot (updated 7 September 2026), read 30 September 2026
- [9]Microsoft, Copilot Credits licensing guide (August 2026), read 30 September 2026
- [10]OpenAI, ChatGPT Work and Codex pricing (learn.chatgpt.com), read 30 September 2026
- [11]OpenAI, Admin rollout guide (learn.chatgpt.com), read 30 September 2026
- [12]OpenAI, Plugin controls (learn.chatgpt.com), read 30 September 2026
- [13]OpenAI, Moving your custom GPT workflows to plugins (learn.chatgpt.com), read 30 September 2026
- [14]OpenAI, Set up and manage @ChatGPT in Slack and Microsoft Teams (learn.chatgpt.com), read 30 September 2026
- [15]OpenAI, Groups and provisioning (learn.chatgpt.com), read 30 September 2026
- [16]OpenAI, User lifecycle management (learn.chatgpt.com), read 30 September 2026
- [17]OpenAI, Compliance API and audit events (learn.chatgpt.com), read 30 September 2026
- [18]OpenAI, Get started with ChatGPT Work (learn.chatgpt.com), read 30 September 2026
- [19]OpenAI, ChatGPT Work admin FAQ (learn.chatgpt.com), read 30 September 2026
Common questions
Is Microsoft 365 Copilot the same thing as Microsoft Copilot?
Yes. Microsoft has renamed Microsoft 365 Copilot to Microsoft Copilot, and Microsoft 365 Copilot Chat to Microsoft Copilot Chat. Licences, price pages and some admin screens still use the old names during the change, and Microsoft says security, compliance and privacy commitments are unchanged.
How much does Microsoft 365 Copilot cost?
On Microsoft's US pricing pages, read on 30 September 2026, Microsoft 365 Copilot is US$30 a user a month paid yearly, added to a qualifying Microsoft 365 plan. Microsoft 365 Copilot Business, for up to 300 users, is US$21 a user a month paid yearly or US$25.20 monthly. Copilot Cowork and some agent use are billed separately in Copilot Credits.
How much does ChatGPT Enterprise cost?
OpenAI does not publish a price for ChatGPT Enterprise; its sales team quotes it. As read on 30 September 2026, ChatGPT Business is US$20 a user a month billed annually or US$25 monthly, for 2 users or more. Workspaces on flexible pricing buy credits for use past the included limits.
Does Microsoft 365 Copilot use OpenAI's models?
Among others. Microsoft's pricing page lists OpenAI models in Copilot, and Microsoft also runs Anthropic's Claude models in Copilot as a subprocessor, which admins can switch on or off and limit to chosen users or groups.
Can ChatGPT Enterprise read our SharePoint?
Through a plugin, yes, where the admin makes it available. It works with the documents the connected account can already open, so overshared SharePoint sites are exposed to ChatGPT in the same way they are to Copilot.
Do we need to fix SharePoint permissions before a ChatGPT Enterprise rollout?
If ChatGPT will connect to SharePoint, yes. The risk is the same as with Copilot: an assistant that searches everything a user can open will find files that were shared too widely years ago. Microsoft's own Copilot deployment guidance makes that clean-up its first step.
Which one should we choose?
Choose by situation, not by vendor loyalty: where your staff work, where the data has to stay, how finance wants usage billed and which audit trail your security team reads. Fix the permissions, then run both on the same real work for two weeks and compare the results and the usage per person.
More in this topic
- ChatGPT Work vs Claude CoworkComparison guide
The agent layer of the same choice, with a section on Microsoft's Copilot Cowork and how it is metered.
Further
- AI Opportunity & Feasibility Sprint · Settles which assistant to buy, and for whom, with a scored recommendation behind it.
- Engagement file D-01 · The documented case: platform engineering under an agency's organisation-wide AI programme.
- Engagement file D-04 · Access that ends with the HR record: the joiner and leaver work an assistant rollout depends on.
- 1AYM's OpenAI partner status · What the company status covers, and what it does not.
We build these systems for a living. See the engagement files for what that looks like in practice, or write to us if yours is the next one.
Last reviewed · 1AYM