Almanac
Microsoft/copilotMicrosoft 365

Consultant KB for the whole Microsoft Copilot estate. Spans Microsoft 365 Copilot, Copilot Studio, the Dynamics 365 Copilots, Power Platform Copilot, Fabric & Power BI Copilot, Copilot in Azure, Windows & consumer Copilot, extensibility & agents, Security Copilot, and GitHub Copilot, plus admin/security and cross-product decision guides. Populated by the daily author agent from Copilot release notes / release plans plus the author's own consultant notes.

feature-copilot-data-protection.mdv2 · history
CurrentApplies to AllUpdated last weekSource Microsoft Learn

What it does

Sets out how Microsoft 365 Copilot handles your tenant data: what it can see, where prompts and responses go, and what Microsoft does and doesn't do with them.

Key facts

  • Copilot only surfaces content the user already has permission to open. It respects existing SharePoint, OneDrive, Exchange and Teams access.
  • Prompts, retrieved data and responses stay inside the Microsoft 365 service boundary and are not used to train the foundation models.
  • Interactions are protected by the same commitments as your other Microsoft 365 data, including the Data Protection Addendum.
  • Grounding data pulled via Microsoft Graph inherits the source item's sensitivity and permissions.

When to use / skip

This isn't something you switch on. It's the baseline you explain to security stakeholders before they'll sign off on a rollout. Read it, then move straight to oversharing and labelling work.

Configuration decisions

  • Whether users can turn on optional connected experiences and web-grounded queries.
  • Whether plugins and third-party connectors are allowed, since those extend the data path.

Gotchas

  • "Copilot respects permissions" is true and misleading. It respects current permissions, which in most tenants are far too broad. The privacy model doesn't fix your sharing sprawl.
  • Bing web queries are handled under separate terms from the tenant boundary. Don't conflate the two when briefing legal.

Consultant notes

  • The privacy model is your easy win in the security review, but it lulls people. Follow it immediately with a permissions audit or you'll be firefighting oversharing later.
  • Get legal to read the DPA and EU Data Boundary commitments early. They ask the same three questions every time and it's better answered on paper.
  • Don't let anyone treat "not used for training" as the end of the data-governance conversation. It's the start.

Review when the Copilot privacy documentation is next refreshed.

Was this accurate?