Open-plan office worker with coffee watches a remote Cloud PC fill a spreadsheet and click a browser, hand near the mouse ready to take over
Enterprises are not buying a talkative model—they are buying a governance shell for handing over the mouse., AI-generated illustration, not a news photograph

Microsoft’s Support and Learn docs describe Project Opal (Frontier) without romance: a Copilot capability that runs task-based work via computer use on a secure Windows 365 Cloud PC (Entra-joined, Intune-enrolled), asynchronously in the background, with the user able to guide or take control.

This is not a model launch note. It is what an enterprise computer-use agent looks like once it sits inside a Copilot license and an admin toggle—Frontier early access plus a Copilot license, with admins required to enable Opal (Frontier) and finish the Opal Admin Portal.

[1][2]

Admins fill the form before the agent gets the mouse

The Admin Portal reads like a governance checklist: device groups and policy, Cloud PC pool, allow/block lists, tenant instructions, starters. Official use cases include security-group membership, audit-evidence collection, IT incident triage, compiling Excel into a financial close deck, timesheets, and more.

The security story is also from the docs: it uses the user’s identity; it will not enter passwords or submit forms without confirmation; browser-first by default; actions logged; up to three concurrent jobs. Skills target repeatable work; default website access is now allow-all with an optional blocklist (flipped from block-all); file interaction on the Cloud PC follows Intune policy updates.

[1][2]

The Cloud PC is both sandbox and product edge

Mechanically, Opal does not thrash the user’s laptop—it operates inside a managed Cloud PC, where identity, device compliance, policy, and logs already live in Microsoft’s enterprise stack. Users can dispatch work asynchronously or seize the mouse; the concurrency cap turns an “agent farm” into a bounded ticket queue.

The allow-all + blocklist flip matters: the product moved from “deny by default, then whitelist” to “useful by default, then blocklist,” admitting that computer use has to be usable first, with governance plugging holes second.

[2][1]

What it means for enterprise IT

For orgs that already buy Windows 365 and Copilot, Opal turns “let an agent touch the mouse” from a demo into a tenant feature with switches. Security groups, audit packs, and close materials get an official computer-use path—if admins complete the governance form.

Competitively, this is the enterprise answer to the naked agent: not who chats better, but who can bundle identity, device, logs, and confirmation into packaging buyers will ship. Computer use without an Admin Portal still struggles in regulated procurement.

[1][2]

Commentary

I read this as Microsoft selling supervised hands, not another chat skin. The Cloud PC, Entra, Intune, confirmation gates, and three-job cap are the product; the Frontier label mainly signals that enterprise tolerance is still being probed in early access.

Watch two things: whether admins actually leave allow-all in place, and the takeover rate—if everyone must stare at the Cloud PC desktop, the deskmate is just remote desktop with autoclick. Governance packaging only closes when people are willing to let go.

[1][2]