Microsoft details what Copilot can access and retain

Microsoft updated its detailed Data, Privacy, and Security for Microsoft Copilot guidance on 18 August. It says Copilot only surfaces organisational data a user can already access, while administrators decide which agents are allowed and can review their permissions and data access. The guidance also says prompts, responses, and their citations form Copilot activity history. Administrators can use Microsoft Purview to search those interactions and set retention policies; sensitivity labels and encryption apply to organisational content, with stated limitations for some external data used through agents and Graph connectors.
Before teams add Copilot to routine work, their existing Microsoft 365 permissions already determine much of what it can find. That makes ordinary sharing, external access, and oversharing reviews part of the AI rollout rather than a separate IT clean-up. The practical control is not a manager telling people to be careful in a blank chat. It is a repeatable tenant decision about approved agents, the data they can reach, and how long interaction records should be retained and reviewed.
Analysis
Ask IT for a one-page Copilot control map: the permissions review owner, the agents approved for the tenant, their external data access, and the Purview retention policy for Copilot interactions. Test one labelled, least-privilege workflow before asking teams to reuse company context.
Source note
Pulse published by Collab365 Spaces, reviewed by Helen Jones on . Cite as "Microsoft details what Copilot can access and retain", Collab365 Spaces. 2 sources referenced.