Episode 427: Copilot Cowork Hands-On Experiences

by [Scott](/content/author/scottmsclouditpro/ "Posts by Scott"/index.html) | May 7, 2026 | Podcast

Welcome to episode 427 of the Microsoft Cloud IT Pro podcast, recorded live on 04/30/2026. This is a show about Microsoft three sixty five and Azure from the perspective of IT pros and end users, where we discuss a topic or recent news and how it relates to you. In this episode, Ben and Scott open with a quick peek at Merrill's latest project, Yako, a browser extension to make navigating to your Microsoft three sixty five services quicker. Then they move into an extended follow-up on Copilot CoWork and some of the recent hands on hardships, artifact management, and integration with Anthropic, including a potential security risk related to sensitive data.

Start incorporating some video. I've been told we should do actually, nobody's told me we should do video. The SEO people and everybody that grows podcasts tell me we should do video. Our AI overlords are back. They're just gonna have us do this until we're done with it. We've tried it before and then quit. I don't know, Scott. Maybe this time it'll stick. Maybe Riverside will make it easier. The AI has definitely made some of it. It's compelling stuff here.

Yeah. Before we get into our topic, though, did you see Merrill's latest invention development project, etcetera? I have not. Okay. So go into whatever browser you use and go search for Yako, y a c o, or you can go to the website, get Yako, yaya, not c,yako,.com. It's a browser extension that changes the home page of your browser. So he created it for Edge, Chrome, and Firefox. And now when you click a new tab in your browser, it gives you a bunch of links that you can customize to whatever Office March well, Microsoft Cloud, really, Cloud links. So, like, mine, I hit a new tab, and I can pick OneDrive, Outlook, Loop, Copilot, Azure, Sentinel, Intune, Admin Center, all the different things. Then I can customize what I want on there. That's a nifty one. I can see how that would be helpful in a work context.

Yeah. I don't know that it's a personal one, but for work and, frankly, I don't really care about the news that normally pops up, and I know you can tweak it. And I don't really wanna set portal to office.com since that doesn't even get me to my apps anymore.

You're out of time. Copilot needs to be deployed ASAP, but is your tenant really ready for it? Years of data, permissions, and users lurk in its shadows, ready to be exposed by AI. Sharegate Protect sees it all, so you can find the exposure risks, fix them fast, and deploy AI with confidence.

Now we can get into our topic if you want. That was just a nifty thing that popped up in my feed the other day.

So last time we recorded, we kinda talked about the co work situation and Claude co work and CoPilot co work. And that definitely sent me down the path of, like, hey. Let me play a little bit more with CoPilot CoWork and kinda see how far I could get with some of the stuff we had talked about, like, maybe, like, the limitations of not being able to interact with your local desktop or local resources, all that kind of stuff.

Custom skills in Copilot Cowork are kind of broken right now. They're they're a little frustrating to to work with along the way. Definitely ran into the I'm very used to kinda prompting LLMs at this point or a lot of these tools with questions to kinda help me refine a prompt and come up with a way to generate, like, the artifacts that you want. So rather than saying go in and build me this, it's ask me a couple questions that are gonna help.

So in, like, in the case of, say, like, Claude Code or GitHub Copilot CLI, things like that, or GitHub Copilot chat, it's very easy to go in and say, I would like to build a new skill that does blah blah blah. And then it will actually kinda ask you a couple questions, and it will frame out the markdown for you, and it will write it to the right directory for you, like, to the point where it where you can do install to just my local session or install this globally kinda thing.

And Copilot Cowork kinda surprised me. It walked me in and it said, oh, you wanna create a new skill. This is great. I'll go create a new skill for you. What do you wanna call it? What do you want the description to be?

So, boom. Great. Click the go button, does its cheeky. I'm thinking about it and thinking and spinning the gears. And then it spits out an output for me, which is a skill quality report. So it gave me this very nice HTML file that said, I created your skill, and your skill has an 83, 84% score or whatever it is. Right? So it gave me this, like, nice dashboard that said, your skill is gonna be awesome and it passes.

Not so great that it didn't actually generate my skill. It didn't actually create a skill? Maybe it did. Maybe it's in someone else's OneDrive. That was number one. Number two is actually finally did get that skill created. I had to go do it manually, provision it into my OneDrive. It's a little weird in the cowork frontier agent today because sometimes it sees your skills in your OneDrive, and sometimes it does not.

So when you go and you do, like, slash commands in Copilot co work, you're presented with an interface of, like, people, skills, files, and these various things. So the very first time I created this skill, I went out there and I went and I just popped it into my OneDrive. I closed Copilot down, just the Copilot m three sixty five Copilot app. Loaded it back up, slash command. Oh, look. There's my skill. That's awesome.

So I did a quick chat with it just to see, like, okay. Does this work? Cool. It generated some output. Looks like it did the right thing that I wanted it to do. So then I spun up a new chat.

Now mind you, I didn't close m three sixty five chat down. I didn't change anything in my OneDrive. Just a new session. Just a new chat session because now I'm like, oh, cool. This still works. Let me actually go, like, fire off and do what I wanted to do. New chat?

I don't know about your skill. I've never seen this thing in the world, like, in my life. I I don't know what it is and what's going on. So you do the slash command, not there in the slash command. You actually could browse straight over to the skills tab from the slash command, not there.

But you I was able to say in my co work session, do you know about this skill? Can you please, like, use it when I put this what I wanna do in here? So it it eventually kinda wrangled itself. So I think that skills experience has a little bit of refinement to do, maybe something for folks to watch out for.

The other thing that's been, I think, kind of getting on my nerves a little bit is as you're in Copilot Cowork and you're generating artifacts, so like in that very first run where it generated a skill report for me or what I was trying to do with this custom skill that I spun out, it was ultimately spitting out some HTML files and some markdown for me as, like, an output.

So those all go into your session, and you see them kind of in the Cowork, in in the co work frontier agent interface, like, it has a little bit of a different interface than the chat interface, and it says, here's your inputs, here's your outputs, blah blah blah. Good luck.

Because well, at least in whatever build I'm on that's pushed out today or as of today, you cannot, like, right click those things and open in OneDrive. There is a little drop down like like an ellipsis there to click it and say open in OneDrive. Doesn't work for me at all.

So then you gotta go manually browse your OneDrive. So you go into your OneDrive, you go into your documents folder, you go into your co work folder. And then in your co work folder, well, you've got skills, which is where you load your custom skill, and then you've got sessions. And then each session is a GUID. So if you do multiple chats per day or anything more than, like, one or two with co work for the day, now you have these folders that are just GUIDs.

And, hopefully, you can figure out by timestamp which one is the right folder because you have to browse into that GUID folder, and then there's an outputs folder in there, and then that's where your artifacts end up. So it's it's got some rough edges and some friction today.

And it immediately drove me back to GitHub Copilot CLI, at least, because I I have access to that or GitHub Copilot, I guess. And the other thing is I was hoping that because Cowork is in the cloud ecosystem to start, that it would be able to get by some limitations that I potentially run into in my day to day being on the CLI or the desktop.

And probably one of the biggest ones is I often have, like, multiple artifacts, could be presentations, Word documents, excels, things like that, that I kinda wanna, like, iterate over and riff on and come out with those ideas and go back and forth on my thinking around them.

So on the desktop, I run into a lot of issues because I have my OneDrive and I have things synced and both my work OneDrive and then I use shortcuts a bunch too, so I have shortcuts back to SharePoint sites.

A lot of the content that I iterate on day over day and throughout my day is IRM ed. So it has some kind of information rights management or, like, MIP information protection. Encryption on the files.

So I was kinda hoping that, like, Cowork would maybe help solve that for me, and I could just rethink some of the skills I use in the cloud world. Cowork can't read my protected documents either. It just blows up and says, sorry. I can't do this.

Is it because it's sending it over to Anthropic into Claude versus when you use the GPT models that's staying in the Azure data centers and it's going to the models internally? That would be my assumption if that's the case because those MIP protected documents, I can use in things like Copilot notebooks when I'm in GPT mode.

And then, oh, yeah. We should also talk about so, Anthropic had an outage earlier this week on their API surface, and it happened to be when I was in the middle of one of my Copilot co work sessions, completely bombed out.

So that that was an interesting moment for me as well because I was trying to debug it. Like, what happened and what's going on? Is m three sixty five down right now?

So it was a good reminder for me of, like, that mental model of, like, when you're in Copilot Cowork, you are, I I guess, using just the anthropic APIs.

So a lot of that stuff does start to click then about, like, oh, hey. I can't read and or open that IRM document and all those kinds of things.

And so, like, I was playing around with that paste to markdown extension of Versus Code. Super cool, like I said, but you can do things like you can paste, say like an image from a website or from a document, and when you paste it in, it gets pasted as a base 64 encoded just native image in there.

So it it's not even like, if you had, like, sensitive data in a flowchart or something like that coming through, you could potentially leak that into an LLM or something like that. So def definitely some stuff to think about.

If you come back and listen to this, here's your thing. Right? We'll dump the transcript out, throw this through an LLM, and have this just write your next m three sixty five Copilot whatever security workshop for you.

Thanks, Scott. We'll talk to you later.