# GPT-6 Astra in Copilot, GitHub and Foundry: the admin map

GPT-6 Astra reached Microsoft tenants through four doors in 48 hours: Foundry, Copilot Cowork, Copilot Studio and GitHub Copilot, two of them on by default. Each door has a different operator, data path, meter and off switch, from OpenAI running as a Microsoft subprocessor inside the EU Data Boundary to GitHub billing at list price. Here is the map and the admin checklist for a Swedish tenant.

- Published: 2026-09-10 · Category: Security & Compliance · Tags: GPT-6 Astra, Microsoft Foundry, Microsoft 365 Copilot, Copilot Cowork, Copilot Studio, GitHub Copilot, EU Data Boundary, Data Residency, OpenAI, AI Governance
- Author: Technspire AB, Stockholm (https://technspire.com)
- Canonical: https://technspire.com/en/blog/gpt-6-astra-copilot-github-foundry-admin-map

GPT-6 Astra entered a typical Microsoft tenant through four separate doors within 48 hours of its 3 September release: Microsoft Foundry, Copilot Cowork, Copilot Studio and GitHub Copilot. Two of those doors are open by default and a third follows the same tenant-wide switch. Each one is run by a different operator, bills through a different meter and is switched off in a different admin console. The model behind them is the same, so the capability analysis from [yesterday's post](/en/blog/gpt-6-astra-capabilities-what-it-can-and-cannot-do) applies everywhere. The governance does not. A Swedish company that carefully decided to keep Astra off Foundry until an EU Data Zone exists may find that its developers have been using it in GitHub Copilot since Friday, at list price, and that its knowledge workers can pick it in Cowork today. Below is the map: what each door is, who operates the model behind it, where the tokens go, what it costs and which switch controls it.

## What changed in Foundry since launch week

Our [launch-day analysis](/en/blog/gpt-6-astra-foundry-price-gate-eu-gap) described a model gated behind the Foundry Limited Access Program with no reserved capacity. That was accurate on 3 September and stale by the next evening. Microsoft revised its Azure blog post on 4 September, and the URL itself now reads "now generally available". The body says Astra "is now generally available for all customers in Microsoft Foundry" and adds a second deployment option: Provisioned Throughput, in both Global and US Data Zone, with the US zone priced at a 10% premium over Global. The Limited Access wording is gone. What remains as a gate is quota: the Microsoft Learn model page notes that some quota tiers require a quota request for `gpt-6-astra`, while Tier 5 and Tier 6 subscriptions have quota by default.

Two things did not change. The Learn region table, last updated 3 September, lists Astra under Global Standard and Global Provisioned Managed for every European resource region including Sweden Central, and does not list it under Data Zone Standard, Data Zone Provisioned or either Batch type. GPT-5.6 Sol is listed in both EU Data Zone types. So the EU Data Zone gap is still open, and there is still no Batch discount on Azure for a model whose best work happens in queued jobs. The pay-as-you-go price sheet is unchanged at $10 input and $50 output per million tokens on Global, $11 and $55 in the US zone, doubling on input past 272,000 tokens.

The Learn page also carries operational constraints that the marketing post omits. Tool calling requires the Responses API. The model rejects the `none` reasoning effort level and ignores custom `temperature`, `top_p` and `logprobs`. Azure does not yet support mid-conversation effort changes or mid-turn steering for Astra. And a note worth reading twice: "in certain circumstances, Astra may apply enhanced safety controls when safety systems identify elevated risk," which may include changing classifier thresholds at inference time and "supplementing customer prompts with system-generated safety instructions." If your evaluation harness sees behaviour drift between runs, that clause is one candidate explanation before you blame your own prompt.

## The four doors in one table

| Door | Who runs the model | Where tokens are processed | Meter | Default state | Off switch |
| --- | --- | --- | --- | --- | --- |
| Microsoft Foundry | Microsoft (Azure OpenAI) | Global or US Data Zone. No EU zone. | Per token, or Provisioned Throughput | Off until someone deploys it (quota permitting) | Azure RBAC, quota, Azure Policy |
| Copilot Cowork | OpenAI, as a Microsoft subprocessor | Inside the EU Data Boundary, with a pseudonymised user ID stored in the US | Copilot credits, scaled by effort level | On for all users since 24 July 2026 | M365 admin center, AI providers operating as Microsoft subprocessors |
| Copilot Studio | OpenAI, as a Microsoft subprocessor | Same as Cowork, plus environment-level data movement rules | Copilot credits per message | Follows the M365 provider setting, plus Power Platform controls | M365 admin center and Power Platform admin center |
| GitHub Copilot | GitHub's model provider arrangement | GitHub's infrastructure, no EU pinning | AI credits at provider list price | On by default for Pro+, Max, Business and Enterprise | Copilot settings, model policy |

Read the second column before anything else. Only the Foundry door delivers Astra as an Azure OpenAI model operated by Microsoft. In Cowork and Copilot Studio the model runs under a different arrangement entirely, and that changes which contract terms, which compliance reports and which residency promises apply.

## Door 2: Copilot Cowork, and the subprocessor detail that matters

Microsoft announced Astra in Copilot Cowork and Copilot Studio on 4 September, and the Learn page for choosing a Cowork model, revised on 8 September, now lists "GPT 6 Astra" as the latest model for tough problems. The same table carries a note that most admins will skim past: the model is "provided by OpenAI as a subprocessor". So is GPT-5.6 Sol and Terra. GPT-5.5, by contrast, is marked "hosted in Azure AI Foundry". Inside one model picker, two OpenAI generations run under two different operating models.

The Learn article on OpenAI as a subprocessor spells out what that means. OpenAI was added to the Microsoft Online Services Subprocessors List on 23 June 2026 and became usable on 9 July. Since 24 July, OpenAI-operated models are enabled for all users of eligible commercial tenants unless an admin has explicitly selected "No users". The Product Terms and the Data Protection Addendum apply, use is covered by Microsoft's Enterprise Data Protection commitments, and the Responses API that Microsoft calls on OpenAI's side runs under Zero Data Retention, subject to OpenAI's feature-specific limitations. The EU Data Boundary documentation states that when these models are enabled, OpenAI "processes and stores a pseudonymized user ID in the United States for troubleshooting, debugging, and security purposes," while all other customer data "is processed within the EU Data Boundary and is not stored by OpenAI."

Then come the exclusions, and they are the part your compliance team needs in writing. OpenAI-operated models are "currently excluded from in-country processing commitments", are unavailable in sovereign and government clouds, and come without three attestations that Microsoft's own Azure OpenAI service carries: no PCI DSS Attestation of Compliance, no HITRUST CSF certification letter and no SOC 1 Type 2 report. For a bank, an insurer or a payment processor in Sweden, that last list can decide the question on its own, regardless of how good the model is.

Cost in Cowork is metered in credits rather than tokens, and the Learn page ties consumption to model choice, context volume, orchestration and tools. Effort levels run from Light through Medium, High and Extra High to Max, with Medium as the default. That is the same effort ladder we analysed yesterday, now exposed to every licensed user as a dropdown. Nothing in the documentation lets an admin cap effort per user. If Max effort on Astra becomes the office habit, the credit bill will say so before anyone else does.

## Door 3: Copilot Studio, two layers of switches and a documentation lag

Copilot Studio inherits the tenant-level OpenAI subprocessor setting from the Microsoft 365 admin center and adds its own layer in the Power Platform admin center, where an environment must allow external large language models before makers can choose them. Preview and experimental models require a separate environment setting, and cross-geo models require the "Move data across regions" setting. Those switches compose: an admin can block external models while allowing previews, or the reverse.

One caution on timing. The Learn page for selecting a Copilot Studio primary model, revised on 5 September, still does not list GPT-6 Astra in its regional availability table. GPT-5.5 Chat is the newest OpenAI model shown there, and every non-US entry carries the cross-geo tag. The 4 September announcement says Astra is rolling out to Copilot Studio and that "availability may vary by region and organization." Treat that as the operative statement: check your own environment's model dropdown rather than the docs, and expect a cross-geo tag when it appears. For a Swedish environment, cross-geo means the data movement setting decides whether the model is reachable at all.

## Door 4: GitHub Copilot, on by default at list price

GitHub's changelog of 4 September made Astra generally available to Copilot Pro+, Max, Business and Enterprise across every surface: VS Code, Visual Studio, JetBrains, Xcode, Eclipse, the CLI, the coding agent, github.com and mobile. Two sentences in that changelog carry the governance load. New models "activate by default" unless an admin has disabled the global default or turned off this specific model in the model policy. And Astra is "billed at provider list pricing under usage-based billing," which since 1 June 2026 means tokens drawn from GitHub AI Credits at one credit per cent.

The GitHub pricing reference confirms the rate: $10 per million input tokens, $1 cached, $50 output, doubling past 272,000 tokens of context. GPT-5.6 Sol on the same page is $4, $0.40 and $20. So a coding-agent run that consumes a million input tokens and produces a hundred thousand output tokens costs $15 on Astra and $6 on Sol, before caching. Multiply by the number of developers who will select the newest model simply because it is newest, and the pooled credit allowance of a Business plan drains two and a half times faster than it does on Sol. The GitHub pricing page is the one place in this map where Astra and Claude Fable 5.1 meet on identical terms, at $10 and $50, with Fable's cached input at $0.25 against Astra's $1.00.

Residency is the weakest of the four here. GitHub Copilot's model routing does not offer an EU Data Zone equivalent, and none of the GitHub material describes where Astra inference runs. If source code with personal data or trade secrets is in scope, the GitHub door needs the same data classification review as the other three, and it is the one most likely to have been skipped because developers, not admins, own the model picker.

## The Swedish and EU angle

The map produces a paradox for a Swedish enterprise. On Foundry, the door where Microsoft operates the model, Astra cannot be pinned inside the EU because no Data Zone deployment exists. In Cowork and Copilot Studio, the doors where OpenAI operates the model, Microsoft states that customer data stays inside the EU Data Boundary apart from a pseudonymised identifier. Azure gives the stronger contractual and audit coverage, Microsoft 365 gives the stronger residency, and neither matches the position GPT-5.6 Sol holds in the EU Data Zone today, which is why we still recommend Sol in the EU zone for anything that must process inside the Union, at the [20% premium](/en/blog/foundry-eu-data-zone-premium-doubles-swedish-cost-math) that came in on 1 September.

In-country processing deserves its own line. Microsoft's November 2025 announcement listed Sweden among eleven countries due to receive in-country Copilot processing during 2026. The April 2026 update to that post names five countries for the end of 2026, then Canada in 2027 and Japan in 2028, and gives no date for Sweden. Even when it arrives, the subprocessor article says OpenAI-operated models are excluded from in-country commitments. So Astra in Cowork will be an EU Data Boundary workload, not a Sweden workload, for the foreseeable future.

Two paperwork items follow. OpenAI as a subprocessor is a new entry for your records of processing and, if your DPA review process tracks subprocessor changes, a June 2026 change that many teams missed over the summer. And an AI Act deployer who has documented which model sits behind a high-risk workflow now needs to record that the same model name can mean two operators depending on the door. The system card and Microsoft's Foundry documentation cover the Azure path; the subprocessor article and the EU Data Boundary transfer note cover the Microsoft 365 path. Cite the right pair.

## The admin checklist for this week

1. **Decide the tenant position on OpenAI-operated models.** In the Microsoft 365 admin center, open Copilot, Settings, View all, then AI providers operating as Microsoft subprocessors, select OpenAI and choose All users, specific groups or No users. Groups are the right answer for most: a pilot population, not the whole company.
2. **Check who already used it.** The setting has been on since 24 July for every OpenAI-operated model. Cowork shows a model badge on each response, and the admin center's Copilot usage reports show which users are active. Assume some Astra traffic already exists.
3. **Set the GitHub Copilot model policy.** In Copilot settings for the organisation or enterprise, review the model policy and decide whether new models activate by default. Astra at list price is the first model where that default has a visible budget consequence.
4. **Gate Copilot Studio at the environment level.** Confirm the external-model and data-movement settings per environment group in the Power Platform admin center, and log which production agents are allowed to switch primary model.
5. **Treat Foundry as the controlled path.** If you want Astra for agentic workloads with Azure's audit coverage, deploy it deliberately on Global Standard or Provisioned Throughput in a subscription with quota, with the same identity, egress and token budget controls we set out for [coding-agent isolation](/en/blog/coding-agent-sandboxing-auto-mode-break). Keep EU-resident data on Sol in the EU Data Zone until Microsoft lists Astra there.
6. **Update the records.** Add OpenAI as a subprocessor to the records of processing, note the missing PCI, HITRUST and SOC 1 attestations where they matter, and record which door each Astra use case goes through.

**Need the four doors mapped for your own tenant?** We audit Copilot, Copilot Studio, GitHub Copilot and Foundry settings together, so model choice, cost and residency are decided once instead of four times.

[See our Azure OpenAI integration offers →](/en/services/azure-openai-integration#offers)

## Sources

- [Microsoft Azure Blog: GPT-6 Astra now generally available in Microsoft Foundry (revised 4 September 2026; Standard and Provisioned Throughput, Global and US Data Zone, price sheet)](https://azure.microsoft.com/en-us/blog/gpt-6-astra-frontier-intelligence-for-work-now-generally-available-in-microsoft-foundry/)
- [Microsoft Learn: Foundry Models sold by Azure, GPT-6 section (quota tiers, Responses API requirement, unsupported parameters, enhanced safety controls note)](https://learn.microsoft.com/en-us/azure/foundry/foundry-models/concepts/models-sold-directly-by-azure)
- [Microsoft Learn: Region availability for Foundry Models sold by Azure (Astra in Global Standard and Global Provisioned; absent from Data Zone and Batch)](https://learn.microsoft.com/en-us/azure/foundry/foundry-models/concepts/models-sold-directly-by-azure-region-availability)
- [Microsoft Tech Community: Available today, OpenAI GPT-6 Astra in Microsoft Copilot (Cowork and Copilot Studio rollout, admin center control)](https://techcommunity.microsoft.com/blog/microsoft-copilot-blog/available-today-openai-gpt-6-astra-in-microsoft-copilot/4552808)
- [Microsoft Learn: Choose a model for Copilot Cowork (model table with operator notes, effort levels, admin controls)](https://learn.microsoft.com/en-us/microsoft-365/copilot/cowork/cowork-models)
- [Microsoft Learn: OpenAI as a subprocessor in Microsoft Online Services (dates, default-on setting, admin steps, exclusions, Zero Data Retention)](https://learn.microsoft.com/en-us/microsoft-365/copilot/openai-subprocessor)
- [Microsoft Learn: EU Data Boundary ongoing partial transfers (OpenAI operated models, pseudonymised user ID in the US)](https://learn.microsoft.com/en-us/privacy/eudb/eu-data-boundary-ongoing-partial-transfers)
- [Microsoft Learn: Select a primary AI model for your Copilot Studio agent (regional availability table, cross-geo tags, admin controls)](https://learn.microsoft.com/en-us/microsoft-copilot-studio/authoring-select-agent-model)
- [GitHub Changelog: GPT-6 Astra is generally available in GitHub Copilot (plans, surfaces, default activation, provider list pricing)](https://github.blog/changelog/2026-09-04-gpt-6-astra-is-generally-available-in-github-copilot/)
- [GitHub Docs: Models and pricing for GitHub Copilot (per-token rates for Astra, Sol, Fable 5.1 and Sonnet 5; credit conversion)](https://docs.github.com/en/copilot/reference/copilot-billing/models-and-pricing)
- [Microsoft 365 Blog: In-country data processing for Microsoft 365 Copilot (original country list and April 2026 timeline update)](https://www.microsoft.com/en-us/microsoft-365/blog/2025/11/04/microsoft-offers-in-country-data-processing-to-15-countries-to-strengthen-sovereign-controls-for-microsoft-365-copilot/)

---

Technspire AB builds AI agents, Azure OpenAI solutions, and production web platforms for Swedish and EU enterprises. Book a call: https://calendly.com/technspire · hello@technspire.com · More articles: https://technspire.com/en/blog · Site overview for agents: https://technspire.com/llms.txt
