Microsoft 365 Copilot Cowork Explained with Bas Brekelmans, Software Engineer at Microsoft

Bas Brekelmans is the Microsoft software engineer who started the Microsoft 365 Copilot Cowork project, having previously worked on Copilot Studio, Power Virtual Agents and Dynamics. He walks through Cowork's cloud-only architecture, its use of Anthropic's Sonnet and Opus models, skills and MCP exte

Microsoft 365 Copilot Cowork Explained with Bas Brekelmans, Software Engineer at Microsoft

Prefer audio?

Who should listen: Microsoft 365 service owners, Copilot administrators and IT architects evaluating agentic AI tooling for enterprise rollout — particularly anyone weighing cloud-hosted agents against local or container-based alternatives, or planning MCP-based integration with line-of-business systems.

Guest: Bas Brekelmans — Software Engineer, Microsoft 365 Copilot Cowork, Microsoft

Bas Brekelmans is the Microsoft software engineer who started the Microsoft 365 Copilot Cowork project, having previously worked on Copilot Studio, Power Virtual Agents and Dynamics. He walks through Cowork's cloud-only architecture, its use of Anthropic's Sonnet and Opus models, skills and MCP extensibility, and the audit and compliance work that makes it viable for enterprises.

Many thanks to Crestron, sponsor of this episode.

Key insights

  • Cowork's current codebase was rebooted in mid-to-late January and had only been in development around three months at the time of recording, so expect a fast, iterative release cadence rather than a settled product. ▶ 5:36
  • Cowork exclusively uses Anthropic's Sonnet and Opus today, but the stated strategy is to run each workload on whichever model performs best — the provider is not fixed, and first-party models could be routed into the 'auto' setting for specific task types. ▶ 4:34
  • The deliberate architectural decision was to run entirely in the cloud rather than on a local machine or container, because audit, security and DLP guarantees are extremely hard to deliver from an endpoint — device management policy routes get complex fast, and IT departments generally won't let users spin up cloud VMs anyway. ▶ 8:39
  • Running server-side forces trade-offs an on-device agent never faces: tool approvals (e.g. 'send this email?') must survive the VM being torn down and respun when the user returns hours later, so state has to persist independently of the compute. ▶ 11:12
  • Tooling is predominantly Graph API-based, with a proprietary AI optimisation layer tuned from telemetry — Brekelmans cites fixing paging failures where the model listed only the first page of mail folders and missed the eleventh. ▶ 12:44
  • Extensibility comes in two forms: markdown-style skills (built-in ones for Word, PowerPoint, Excel and PDF generation plus calendar management, alongside personal and third-party store skills) and remote MCP servers — so an in-house line-of-business app with an MCP wrapper can be driven from Cowork, including returning CSV or JSON for analysis. ▶ 21:01
  • Built-in skills keep their own per-user memory file: the calendar management skill records why you prioritised one meeting over another and applies that reasoning to future conflict recommendations, without the user creating a custom skill. ▶ 18:24
  • Recent drops have focused on hardening rather than features — richer audit logs, Purview surfacing and eDiscovery support — and Brekelmans expects compliance and control to remain the main focus for the coming weeks and months. ▶ 26:07
  • Practical framing for adoption: the baseline for judging output is not perfection but how well the user would have done it manually; Brekelmans reckons roughly half his inbound email can be handed straight to Cowork, and status reports that took three hours are now review-only. ▶ 31:43

Insights summarised by AI from the episode transcript, reviewed by the Empowering.Cloud team.

Listen: Apple Podcasts · Spotify · Other platforms