You are not buying a search box. You are buying an access-control decision that will outlive the vendor, the contract and probably the org chart. Glean, Microsoft 365 Copilot and Dust will all answer a question with three tidy citations in a demo. Where they genuinely differ is who is allowed to see what, and that is the expensive part.
Every demo of an enterprise assistant looks the same: someone types "what did we decide about the Q3 pricing change," and a paragraph appears with three citations. All three products in this comparison do that. What separates them is what happens to your permissions on the way there — and that difference is permanent, expensive to reverse, and almost never covered in the evaluation.
Here is the verdict. If your organisation runs Microsoft 365, start with Microsoft 365 Copilot, because Copilot Search now comes with the seat you are probably already buying and reaches over 100 connectors at no extra indexing cost. Buy Glean when you can name ten high-value systems Microsoft cannot reach, or when you need the index inside your own cloud account. Do not buy Dust as your enterprise search layer — it has twelve connectors and governs access by its own workspace model rather than by your source systems' permissions. Dust is a capable agent-building platform. It is the wrong answer to this question.
| Microsoft 365 Copilot | Glean | Dust | |
|---|---|---|---|
| Published price (checked 29 Aug 2026) | $30 per user/month, paid yearly | None — contact sales | $24 per seat/month, Pro, billed yearly |
| Native connectors | 100+ in the Microsoft catalog | 275+ | 12 |
| Permission model | Microsoft Graph identity; only content the user already has view rights to | Mirrors each source's ACLs at query time | Dust spaces — admin picks what syncs, membership decides who reads it |
| Runs in your cloud | No | Yes — customer-hosted on AWS or GCP | No — EU data residency is a workspace option |
| Metered on top of the seat | Copilot Studio / pay-as-you-go agent usage | FlexCredits past 100 thinking-mode queries per user per week | 8,000 credits/month on Pro, 40,000 on Max |
| Skip it if | Your highest-value knowledge lives outside Microsoft | You cannot name what Microsoft cannot reach | You need per-document permissions from the source |
The Permission Model Is the Product
An enterprise assistant is a permissions engine with a language model bolted on, and the three products resolve permissions in three genuinely different places.
Glean's index carries a copy of each source system's access-control list. Glean's own documentation states the rule plainly: "If a user can't open a document in the source system, that document can't be used as context, returned as a search result, or surfaced as a citation," and permission changes are reflected as soon as they happen in the source. That is the expensive, correct answer. It is also the reason Glean needs 275 connectors rather than 275 API clients — each connector has to understand a foreign permission model, not just fetch documents.
Microsoft resolves permissions by never leaving its own identity plane. Copilot "only surfaces organizational data to which individual users have at least view permissions," and the semantic index "honors the user identity-based access boundary." For content that lives in SharePoint, Exchange and Teams, that is a stronger guarantee than mirroring, because there is nothing to mirror — it is the same authorization check the file already uses. For content outside Microsoft, the guarantee is only as good as the connector you configured.
Dust does something categorically different, and a CIO needs to see it before signing. Access is governed by Dust spaces: an admin chooses which Slack channels, Notion pages or Drive folders sync, and then users "can interact with agents created with the data of the spaces users are a member of." Source-system ACLs do not follow the document in. Space membership replaces them.
That is a defensible design for a team building agents on a curated corpus. It is a bad design for "search everything the company knows," because it means an admin decision — made once, at sync time, by someone who does not know who is on which HR mailing list — becomes the access boundary for content that used to be governed by fifty different owners. Steel-manning it: this is arguably safer than a badly configured ACL mirror, because nothing is exposed unless a human deliberately syncs it. But it does not scale to forty systems, and it makes an access review a manual audit of space membership rather than a query against your identity provider.
What Microsoft Started Giving Away in 2026
Microsoft Copilot Search is now a full unified search product bundled into a Copilot licence at no additional cost, and that is the single biggest change to this market since Glean was founded.
Microsoft's own documentation is unambiguous: Copilot Search "is available to users with an eligible Microsoft Copilot license at no additional cost," it does semantic rather than keyword ranking, and it covers "over 100 connectors now in the Microsoft Catalog, support for custom connectors, and hundreds of connectors from integrated software vendors." The comparison table on that page is worth reading closely, because Microsoft is explicit that the free Microsoft Search tier gets keyword matching with no semantic search, while the paid tier gets "instant support for all tenant-enabled connectors with semantic search and personalization."
The connector economics changed too. Indexing synced connector data "incurs no extra cost for tenants with Microsoft 365 licenses," which retires the old per-licence index quota that used to make Graph connectors a budget line. There is a real catch: federated connectors — the ones that query a source live instead of indexing it — require a Copilot add-on licence for every user who queries that source, and are not available on Copilot Studio licences or pay-as-you-go.
The widely repeated claim that "Copilot can't search Salesforce, Confluence or Slack" was true in 2024 and is not true now. Confluence, ServiceNow and Google Drive ship as prebuilt synced connectors. If your evaluation deck still carries that line, it is arguing against a product that no longer exists.
None of which means Copilot is winning on adoption. Microsoft reported over 30 million paid Microsoft 365 Copilot seats in its FY26 Q4 results — a genuinely large number, and still a minority of the Microsoft 365 base. Gartner's 2025 Microsoft 365 and Copilot survey of 187 IT and CSS leaders found 40% piloting and 5% of those who had finished a pilot moving to a larger deployment that year, with analyst Dan Wilson noting that deployment plans assumed "a clean data environment, which is rarely the case." That was reported in June 2025 and counts deployments happening within 2025, so it is a snapshot of how slowly the first wave converted rather than a standing conversion rate — which is exactly why the 30 million figure and the 5% figure are both true.
Glean's Moat Narrowed on March 3, 2026
The most decision-relevant fact about Glean this year is not its valuation — it is that Salesforce took Slack's index away, and the fix is a downgrade.
In May 2025 Salesforce rewrote the Slack API terms to prohibit bulk export of Slack data and bar its use for training LLMs, pushing third parties onto a new Real-Time Search API instead. Glean's own retirement notice records the consequence: Glean "discontinued use of the Slack Discovery APIs on March 3, 2026 and now supports Slack through a Real-Time Search–based integration."
Read the replacement connector's documentation and the trade becomes concrete. Slack Real Time Search is a federated connector that "does not crawl or index Slack message content"; message bodies are "retrieved live from Slack at query time via the RTS API and processed in memory only. They are not written into an index in RTS-only mode." Only identity metadata — users, channels, workspaces, memberships — is stored. Admins are told to expect "a low 'Items synced' count" and "no docbuilder activity."
That is not a bug, and Glean handled it about as well as anyone could. But it matters to a buyer for one specific reason: the pitch for a unified index is that everything sits in one ranked, cross-referenced knowledge graph. A federated source is queried, not ranked alongside everything else. If your institutional memory really does live in Slack threads — and for a lot of engineering organisations it does — you should test that path specifically, not the demo corpus.
The strategic point generalises beyond Slack. Glean's differentiation depends on source systems permitting a third party to hold a permanent copy of their content. Salesforce owns Slack. Microsoft owns Teams, SharePoint and Exchange. Google owns Workspace. Every one of them now sells a competing assistant. Glean CEO Arvind Jain has been clear that he does not see the model vendors as competition: "I don't see OpenAI, Anthropic, or Google as competition, but rather as partners," he told TechCrunch, arguing that enterprises would rather have a neutral infrastructure layer than be locked into a single model or productivity suite. The vertical integration of the platform companies is the harder question, and the March cutover is what it looks like in a change log.
What Each One Actually Costs at 10,000 Seats
Normalise to one workload — 10,000 seats, roughly 40 source systems, employees in both the EU and the US — and only one of the three lets you calculate the bill before the call.
Microsoft is the arithmetic case. At $30 per user per month paid yearly, 10,000 seats is $3.6M a year on top of the Microsoft 365 base you already pay. Copilot Search is included. Synced connector indexing is included. Below 300 users, Microsoft 365 Copilot Business is $18 per user/month paid yearly on promotional pricing through December 2026, with a $21 standard price — the cheapest legitimate way to run a real pilot.
Glean publishes nothing. Its pricing page is a demo request, and its Enterprise Flex documentation describes the metering model without a single dollar figure: fast-mode queries unlimited, thinking mode "included, up to 100/user/week. Excess usage consumes FlexCredits," with Deep Research, agent runs, slide generation, meeting notes and client API calls all metered. For real transaction data, procurement platform Vendr reports a median annual contract value of $98,890 for Glean across 55 deals, ranging from $29,880 to $208,897, while Sacra reports that Fortune 500 deals can exceed $5M annually. A 10,000-seat deployment is at the top of that distribution, not the middle. Budget accordingly, and get the FlexCredit rate card in writing before you sign — a consumption meter you cannot price is a consumption meter you cannot cap.
Dust is the cheapest and the most conditional. Pro seats are $30 per month, or $24 billed yearly, with 8,000 credits per month; Max is $150, or $120 yearly, with 40,000. Credits are consumed as token credits plus action credits — advanced actions such as data retrieval and external integrations cost 3 credits each, and unused credits "do not carry over to the following month". At 10,000 Pro seats that is $2.88M a year, which looks like a bargain until you notice you are comparing a twelve-connector product to a hundred-connector one.
Two alternatives belong in the same spreadsheet. Amazon Q Business is $20 per user/month for Pro and $3 for Lite, plus an index charged hourly — $0.264 per hour per Enterprise index unit, covering 20,000 documents or 200 MB of extracted text, which is the only genuinely usage-shaped model of the group. Google's Gemini Enterprise publishes editions but not prices, and its documented storage quotas are small enough to matter: 25 GiB pooled on Business, 30 GiB on Standard, 75 GiB on Plus. Check that against your corpus before you get to a price discussion.
Where Your Prompts Actually Get Processed
Every vendor in this category will tell you your data stays in region. Read the exceptions, because they are written down and they are specific.
Microsoft's documentation states that "Copilot calls to the LLM are routed to the closest data centers in the region, but also can call into other regions where capacity is available during high utilization periods," with EU traffic kept inside the EU Data Boundary. Two exceptions sit in the same page and both are load-bearing: worldwide traffic can be sent to the EU and other regions for LLM processing, and "models provided by Anthropic as a subprocessor are currently excluded from the EU Data Boundary." If your legal team approved Copilot on the strength of the EU Data Boundary, they approved a commitment with a named model-vendor carve-out. Go and check which models your tenant has enabled.
Glean offers the strongest structural answer available here, and it is the reason regulated buyers pay its premium. In the customer-hosted model, "Glean deploys its tenant as a managed service in isolation within your own cloud environment (GCP, AWS)," giving "full data residency guarantees — data doesn't leave your organizational boundaries." The trade is written down too: "Glean doesn't support manually deploying or patching the Glean services, or altering any part of the Glean architecture." You own the account, not the operations.
Dust does not run in your cloud at all. EU data residency exists as a workspace option rather than a published feature of the $24 Pro seat, so get in writing which tier carries it before you price the deal.
Nobody Is Good at This Yet
Do not let a vendor bench you against a demo corpus, because the best available research says multi-hop enterprise retrieval is an unsolved problem before you get to any particular product.
Salesforce AI Research built HERB, a benchmark for "Deep Search" over a retrieval pool of 39,190 enterprise artifacts — documents, meeting transcripts, Slack messages, GitHub content and URLs — and found that "even the best-performing agentic RAG methods achieve an average performance score of 32.96." Two caveats belong with that number before you quote it at a vendor. The corpus is synthetic: the authors "build it using a synthetic data pipeline that simulates business workflows," so it is a realistic simulation of an enterprise, not one. And the systems tested are research agentic-RAG methods and long-context models — HERB did not evaluate Glean, Copilot or Dust, so the score is not a report card on any of them. Salesforce, which published it, also owns Slack.
What generalises is the diagnosis rather than the score, and it is the one that should shape your evaluation: retrieval is the bottleneck, not reasoning. Systems "struggle to conduct deep searches and retrieve all necessary evidence," and then reason confidently over the incomplete set. That is a property of the problem all three vendors are attacking, and nothing any of them publishes claims it is solved.
An enterprise assistant evaluation is therefore a retrieval evaluation. Build a set of 100 questions whose answers you already know, drawn from your own corpus, and weight them toward the hard cases: a decision that changed twice, a number that appears differently in three systems, a question whose correct answer is "that document is not in scope for you." Score recall of the evidence, not the fluency of the paragraph. Every vendor will pass the fluency test.
Who Should Not Buy Each One
Microsoft 365 Copilot is the wrong purchase if your highest-value knowledge genuinely sits outside Microsoft — a services firm running on Salesforce, Slack and Confluence, or an engineering organisation whose real documentation is in GitHub and Linear. It is also wrong if you have never audited SharePoint permissions. Copilot does not create oversharing, it makes existing oversharing searchable in one sentence.
Glean is the wrong purchase if you cannot list ten systems it reaches that Microsoft does not, with real users and real content in each. It is also wrong if your buying case rests on Slack being deeply indexed, which since March is no longer how it works. And at a six-to-seven-figure ACV with an unpriced consumption meter attached, it is wrong for anyone who cannot get FlexCredit rates into the contract.
Dust is the wrong purchase as a company-wide search layer, full stop — twelve connectors and space-based permissions cannot answer "search everything" for a 10,000-person company. It is a reasonable purchase as a cheap, fast agent platform for teams that already know which corpus they want, which is the job it raised $40M to do.
Your Existing Intranet Search Has a Deadline
One dated item belongs on the plan of anyone taking the Microsoft path, and it is not on most vendor slides.
Restricted SharePoint Search — the tenant-wide control many organisations switched on precisely so they could roll out Copilot while a permissions review ran — is being retired. Microsoft's message centre notice sets new enablement blocked from July 31, 2026, full retirement on January 31, 2027, and PowerShell cmdlet retirement on February 28, 2027. The replacement is Restricted Content Discovery, and the line that matters is this: "Microsoft will not automatically migrate RSS configurations to Restricted Content Discovery."
If you used RSS as your guardrail, doing nothing means previously restricted content becomes discoverable when enforcement stops. That is a migration project with a hard date, and it belongs in the same budget cycle as the Copilot decision, not after it.
How to Decide
The criteria that predict regret are not the ones on the scorecard.
This month:
- Count what fraction of your last 200 real internal questions could be answered from Microsoft 365 alone. If it is above roughly 70%, Copilot plus Graph connectors is your baseline and Glean has to beat it on the remainder, not in the abstract.
- Build the 100-question retrieval set described above, including at least ten questions whose correct answer is a refusal. Run it against every finalist with a real employee's identity, not an admin account.
- Pull your SharePoint oversharing report. Whatever you buy, this is the work that determines whether it is safe.
Before you sign:
- Get every consumption meter priced in the contract — FlexCredits, Dust credits, Copilot pay-as-you-go agent rates — with an annual cap. A meter you cannot price is a meter you cannot budget, and that is the standing rule for every consumption-priced AI contract.
- Ask each vendor, in writing, which of your sources are federated rather than indexed, and what happens to answer quality on those. Slack is the current example. It will not be the last.
Before the next renewal cycle:
- Put the Restricted SharePoint Search migration on the roadmap with its January 2027 date attached.
What changes the answer: if a major source system you depend on cuts off third-party indexing the way Salesforce did, the neutral-index thesis weakens further and the platform vendor's assistant gets relatively better. If Microsoft's connector catalogue stalls below 150 while Glean's stays above 275, the reverse.
The Bottom Line
The last cycle that looked like this was enterprise search in the 2000s, when a specialist index across everything was worth real money until the platforms bundled a good-enough one. Glean is a better product than Microsoft Search ever was, its business is growing fast — Sacra reports $300M ARR in May 2026, up from $208M at the end of 2025 — and the customer-hosted deployment is a genuine capability nobody else in this comparison offers. But its differentiation is being squeezed from both ends: bundled by the platforms above it, and rate-limited by the source systems beneath it.
Buy the assistant your identity provider already governs. Pay the premium for a neutral index only where you can name the systems it reaches and the questions it answers that the bundled one cannot. And write the consumption cap into the contract before anyone sees the demo again.
The seat price is the number in the deck. The permission model is the number you live with.
Continue Reading
RAG Build vs Buy: Buy the Index. Build the Eval Set. Best RAG Platforms for Regulated Industries: Permissions First What RAG Actually Costs: $1,308 a Month at 10M Tokens/Day Agentic AI Pricing: Don't Buy Consumption Without a Cap Copilot Memory Survives Your Password Reset. Go Purge It. The 2026 Agentic AI Stack: 8 Layers, 3 You Can Skip Vector Database Pricing: Only pgvector Publishes a Rate Single-Player AI Is Dead: Dust Raises $40M to Prove It
