Security of Sensitive Information Uploaded to Microsoft Copilot

Jess B 0 Reputation points
2026-07-22T16:40:53.6666667+00:00

Hello,

I would like clarification regarding the security and privacy of sensitive information uploaded to Microsoft Copilot.

Specifically:

  1. If I upload sensitive or confidential information to Copilot, how is that information stored, processed, and protected?
  2. Is uploaded content used to train Microsoft AI models or foundation models?
  3. Who within Microsoft can access uploaded files, prompts, and generated responses?
  4. How long are prompts, conversations, and uploaded files retained?
  5. What security controls, encryption standards, and compliance certifications protect sensitive data?
  6. Are there differences in data protection between the consumer version of Copilot, Copilot Pro, and Microsoft 365 Copilot?
  7. What types of sensitive information, if any, does Microsoft recommend users not upload to Copilot?

I would appreciate a response from a Microsoft representative or Copilot security/privacy specialist and any official documentation you can provide.

Thank you.

Microsoft Copilot | Microsoft Security Copilot
0 comments No comments

2 answers

Sort by: Most helpful
  1. Jess B 0 Reputation points
    2026-07-22T16:45:33.1333333+00:00

    Can I get a non AI response?

    Was this answer helpful?

    0 comments No comments

  2. AI answer

    2026-07-22T16:41:26.9166667+00:00

    Supported facts differ by product.

    For Microsoft 365 Copilot:

    1. How uploaded or accessed data is processed and protected
      • Microsoft 365 Copilot operates within the Microsoft 365 service boundary.
      • It uses content in Microsoft Graph that the user already has permission to access.
      • It honors the existing permissions model in the tenant, so it presents only data the individual user can access.
      • It also honors Microsoft Purview Information Protection usage rights, including sensitivity labels and IRM-based restricted permissions.
      • Microsoft states that customer content is protected with tenant isolation, role-based access control, encryption at rest and in transit, and physical and logical security controls.
    2. Use for model training
      • Prompts, responses, and data accessed through Microsoft Graph aren’t used to train foundation LLMs, including those used by Microsoft 365 Copilot.
    3. Who can access files, prompts, and responses
      • The available documentation states that Copilot only accesses data users are authorized to access and that auditing and compliance capabilities apply.
      • The provided material does not specify a detailed list of Microsoft personnel roles that can access uploaded files, prompts, or responses.
    4. Retention
      • The provided Microsoft 365 Copilot documentation states that Copilot supports audit of interactions and follows retention policies, but the returned material does not provide a specific retention duration for prompts, conversations, or uploaded files.
    5. Security controls, encryption, and compliance
      • Encryption at rest and in transit.
      • Technologies cited include BitLocker, per-file encryption, TLS, and IPsec.
      • Tenant isolation through Microsoft Entra authorization and role-based access control.
      • Compliance commitments cited include GDPR, EU Data Boundary, ISO/IEC 27018, Microsoft Product Terms, and the Data Protection Addendum.
      • Built-in protections include blocking harmful content, detecting protected material, and blocking prompt injections.
      • Additional governance and investigation controls are available through Microsoft Purview, including eDiscovery, sensitivity labels, DLP for Microsoft 365 Copilot and agents, Insider Risk Management, and DSPM for AI, depending on licensing.
    6. Differences between consumer Copilot / Copilot Pro / Microsoft 365 Copilot
      • The provided material supports these distinctions:
        • Microsoft 365 Copilot has enterprise data protection, inherits Microsoft 365 tenant permissions, compliance, retention, audit, and sensitivity labeling controls.
        • For consumer Copilot, the provided FAQ states that if a file is shared with Copilot, the file is stored securely for up to 18 months and then automatically deleted, and the file and related conversations are subject to choices about model training and personalization.
        • For Copilot Vision in the consumer FAQ, screenshots and camera images shared with Vision aren’t stored after the session ends, while text transcripts may be saved and can be deleted.
      • The provided context does not contain product-specific security distinctions for Copilot Pro.
    7. What sensitive information Microsoft recommends not to upload
      • The provided material does not include a general Microsoft recommendation listing categories of sensitive information that should never be uploaded.
      • For consumer image scenarios, the FAQ says not to share images of others without their consent.

    For consumer Copilot based on the provided FAQ:

    • If a file is uploaded to Copilot, it is stored securely for up to 18 months and then automatically deleted.
    • The file and related conversations are treated like other conversations and are subject to user choices about model training and personalization.
    • For Copilot Vision, captured screenshots and camera images are processed only to respond to the request, aren’t used to train AI models or personalize the experience, and aren’t stored after the session ends.
    • Text transcripts of Vision interactions may be saved so they can be revisited later and to help monitor for abuse, and they can be deleted.

    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.