Almanac
Microsoft/copilotMicrosoft 365

Consultant KB for the whole Microsoft Copilot estate. Spans Microsoft 365 Copilot, Copilot Studio, the Dynamics 365 Copilots, Power Platform Copilot, Fabric & Power BI Copilot, Copilot in Azure, Windows & consumer Copilot, extensibility & agents, Security Copilot, and GitHub Copilot, plus admin/security and cross-product decision guides. Populated by the daily author agent from Copilot release notes / release plans plus the author's own consultant notes.

feature-copilot-edp.mdv2 · history
CurrentApplies to AllUpdated last weekSource Microsoft Learn

What it does

Enterprise Data Protection is the set of security, privacy and compliance commitments that extends Microsoft 365 enterprise-grade protections to Copilot chat and its handling of your data.

Key facts

  • EDP applies to Copilot Chat (web and work) for licensed users and covers data protection, no model training on your data, and compliance coverage under Purview.
  • It brings Copilot under the same commitments as your other Microsoft 365 data: DPA, EUDB, and logical isolation of tenant content.
  • Which experiences are covered by EDP versus the consumer/standard-protection tier depends on user licensing and whether they're signed in with a work account.
  • Purview controls (audit, eDiscovery, retention, DLP) hook into EDP-covered interactions.

When to use / skip

Use this to draw the line for stakeholders between protected work usage and unprotected consumer usage. It's a definitions document, worth reading once so you stop confusing the tiers.

Configuration decisions

  • Confirm which users are licensed for EDP-covered experiences.
  • Decide policy on unmanaged/consumer Copilot use and whether to block it at the network or identity layer.
  • Align EDP coverage with your Purview policy scope so protected interactions are actually being governed.

Gotchas

  • Signed-in-with-work-account is the dividing line. The same person using a personal account gets consumer terms, and that data path is different. Make the account boundary explicit in policy.
  • "EDP covers it" doesn't mean Purview is watching it, coverage and active governance are separate. You still have to configure the controls.
  • The scope of what EDP includes has shifted as Copilot Chat evolved. Check current coverage rather than an old diagram.

Consultant notes

  • The work-versus-personal account distinction is where data leaks in practice. Pair EDP with conditional access so staff can't quietly use the consumer tier for work content.
  • Don't let "enterprise data protection" become a comfort blanket. It's the commitment layer, the actual controls are still yours to switch on in Purview.
  • For procurement, EDP plus the DPA is the paperwork they want. Have both references to hand.

Review when Enterprise Data Protection scope is updated.

Was this accurate?