AI-powered assistant that helps security teams detect, investigate, and respond to threats
Supported facts differ by product.
For Microsoft 365 Copilot:
- How uploaded or accessed data is processed and protected
- Microsoft 365 Copilot operates within the Microsoft 365 service boundary.
- It uses content in Microsoft Graph that the user already has permission to access.
- It honors the existing permissions model in the tenant, so it presents only data the individual user can access.
- It also honors Microsoft Purview Information Protection usage rights, including sensitivity labels and IRM-based restricted permissions.
- Microsoft states that customer content is protected with tenant isolation, role-based access control, encryption at rest and in transit, and physical and logical security controls.
- Use for model training
- Prompts, responses, and data accessed through Microsoft Graph aren’t used to train foundation LLMs, including those used by Microsoft 365 Copilot.
- Who can access files, prompts, and responses
- The available documentation states that Copilot only accesses data users are authorized to access and that auditing and compliance capabilities apply.
- The provided material does not specify a detailed list of Microsoft personnel roles that can access uploaded files, prompts, or responses.
- Retention
- The provided Microsoft 365 Copilot documentation states that Copilot supports audit of interactions and follows retention policies, but the returned material does not provide a specific retention duration for prompts, conversations, or uploaded files.
- Security controls, encryption, and compliance
- Encryption at rest and in transit.
- Technologies cited include BitLocker, per-file encryption, TLS, and IPsec.
- Tenant isolation through Microsoft Entra authorization and role-based access control.
- Compliance commitments cited include GDPR, EU Data Boundary, ISO/IEC 27018, Microsoft Product Terms, and the Data Protection Addendum.
- Built-in protections include blocking harmful content, detecting protected material, and blocking prompt injections.
- Additional governance and investigation controls are available through Microsoft Purview, including eDiscovery, sensitivity labels, DLP for Microsoft 365 Copilot and agents, Insider Risk Management, and DSPM for AI, depending on licensing.
- Differences between consumer Copilot / Copilot Pro / Microsoft 365 Copilot
- The provided material supports these distinctions:
- Microsoft 365 Copilot has enterprise data protection, inherits Microsoft 365 tenant permissions, compliance, retention, audit, and sensitivity labeling controls.
- For consumer Copilot, the provided FAQ states that if a file is shared with Copilot, the file is stored securely for up to 18 months and then automatically deleted, and the file and related conversations are subject to choices about model training and personalization.
- For Copilot Vision in the consumer FAQ, screenshots and camera images shared with Vision aren’t stored after the session ends, while text transcripts may be saved and can be deleted.
- The provided context does not contain product-specific security distinctions for Copilot Pro.
- The provided material supports these distinctions:
- What sensitive information Microsoft recommends not to upload
- The provided material does not include a general Microsoft recommendation listing categories of sensitive information that should never be uploaded.
- For consumer image scenarios, the FAQ says not to share images of others without their consent.
For consumer Copilot based on the provided FAQ:
- If a file is uploaded to Copilot, it is stored securely for up to 18 months and then automatically deleted.
- The file and related conversations are treated like other conversations and are subject to user choices about model training and personalization.
- For Copilot Vision, captured screenshots and camera images are processed only to respond to the request, aren’t used to train AI models or personalize the experience, and aren’t stored after the session ends.
- Text transcripts of Vision interactions may be saved so they can be revisited later and to help monitor for abuse, and they can be deleted.
References:
- Data, Privacy, and Security for Microsoft 365 Copilot
- Privacy FAQ for Microsoft Copilot
- Security for Microsoft 365 Copilot
- How data is protected and audited in Microsoft 365 and Microsoft 365 Copilot
- Copilot Control System security and governance
- Enterprise data protection in Microsoft 365 Copilot and Microsoft 365 Copilot Chat