← Back to insights

Managed service providers · 19 August 2026 · 4 min

Copilot credits turn group hygiene into a budget question

Microsoft's spending policies for Copilot credits are governed exclusively through security groups. That makes your client's AI budget exactly as reliable as the group memberships behind it — and those are rarely as clean as anyone believes.

Consumption-based AI is becoming a cost line of its own at your clients. Microsoft has built a real governance apparatus for it: spending policies in the Microsoft 365 admin center provide caps at tenant, group and user level, different payment methods per department, threshold alerts and consumption reporting — and hard enforcement, where a user who hits the cap loses access to agents and services for the rest of the month. You should know this apparatus, and you should not pretend it does not exist.

But read the mechanics closely, because two things in there matter to an MSP.

The first: assigning a spending policy to individual users happens exclusively via security groups. There is no other route. The consequence is that the entire budget control inherits the quality of the group memberships — and group memberships, in most environments that have never had systematic governance over them, are historical sediment: people who changed departments two years ago, consultants added "temporarily," groups nobody remembers the purpose of. Until now, a wrong group membership was an access problem. With spending policies, it is also a budget problem: the wrong person in the wrong group is the wrong person on the wrong spending cap.

The second: conflict resolution is fail-open. If a user lands in multiple policies for the same service, they are assigned the highest per-user cap. Messy group structure does not produce random budget errors — it produces systematically higher caps than intended.

This is why AI cost governance at your clients begins with identity governance, not with AI. Entra Logic's home ground is precisely group hygiene: the continuously synchronised copy makes every group membership in every client tenant visible and queryable, every membership change passes through order and approval instead of direct editing, and the audit trail shows why each member is there. The default posture is, moreover, the opposite of Microsoft's conflict rule: governed by default, not open by default. When the groups are right, spending policies are a precise instrument. When they are not, they are a precise enforcement of the wrong thing.

In addition, Entra Logic has built-in entitlement management, metering and billing data for Copilot and other products, allocated per company and client in the same cost reporting as the rest of the M365 estate — so AI consumption at your clients does not become a detached cost line beside everything else. [VERIFY the exact functional scope with the product team before publication, and separate delivered functionality from planned — allocation mechanisms that are on the roadmap must not be described in the present tense.]

The advice to your clients can be simple and honest: use Microsoft's spending policies — they are good. But do not attach them to groups you do not trust. Offer a review of the group landscape in the client's tenant before the policies are switched on; it is a concrete, bounded deliverable with a findings count at the end. And the findings count tends, as always with groups, to surprise.

RELEVANT SOLUTION

See how this is handled in practice:

Norwegian version: Les artikkelen på norsk