Share via

for adding copilot to a biz license

Javi Alcocer 0 Reputation points
2026-03-19T16:14:06.8733333+00:00
  • Does Copilot keep data inside tenant only? 

Is data used to train external models? 

  • is there Compliance (HIPAA-like, SOC, etc.) 
  • Does Copilot keep all data inside our tenant or send anything externally? 
  • Permissions behavior – like can Copilot access anything the user normally can’t? 
Microsoft Copilot | Microsoft 365 Copilot | Development
0 comments No comments

1 answer

Sort by: Most helpful
  1. Q&A Assist
    2026-03-19T16:14:22.7766667+00:00
    AI generated content. This question contains an answer created with AI from Q&A Assist. Learn more

    • Data location / tenant boundary Microsoft 365 Copilot operates within the existing Microsoft 365/Office 365 trust boundary. Customer data, including Copilot prompts and responses, is stored within the Microsoft Cloud trust boundary and is logically isolated per tenant using Microsoft Entra authorization and role-based access control.

    For Microsoft 365 Copilot specifically, Copilot presents only data that each individual is already authorized to access, using the same underlying access controls as other Microsoft 365 services. Semantic Index and grounding honor user identity–based access boundaries.

    In some scenarios (for example, features powered by Bing or third‑party plug-ins), customer data can be transmitted outside the Microsoft Cloud trust boundary, but core Microsoft 365 Copilot runs within the Microsoft cloud.

    • Use of data for training models Prompts and responses in Microsoft 365 Copilot are not used to train the foundation models used by Copilot.

    For Dynamics 365 and Power Platform Copilot features, prompts and outputs:

    1. Are not available to other customers.
    2. Are not used to train or improve any third‑party products or services (such as OpenAI models).
    3. Are not used to train or improve Microsoft AI models unless the tenant admin explicitly opts in to optional data sharing.

    • Compliance posture (HIPAA-like, SOC, etc.) Microsoft 365 Copilot and Dynamics 365/Power Platform Copilot are built on Microsoft’s existing enterprise security, privacy, and compliance framework. Copilot inherits Microsoft 365 and Dynamics 365/Power Platform security, privacy, and compliance controls, including:

    • Logical isolation of customer content per tenant.
    • Multi-layered encryption at rest and in transit (BitLocker, per-file encryption, TLS, IPsec, etc.).
    • Support for Microsoft Purview Information Protection (sensitivity labels, rights management) with Copilot honoring usage rights.
    • Microsoft’s commitments to broadly applicable privacy laws (such as GDPR) and privacy standards (such as ISO/IEC 27018).

    These services are designed to align with the same compliance boundary as the underlying Microsoft 365 services; detailed mappings to specific frameworks (HIPAA, SOC, etc.) are provided in Microsoft’s compliance documentation outside this context.

    • Does Copilot send data externally? Within Microsoft 365 and Dynamics 365/Power Platform, Copilot operates inside the Microsoft Cloud trust boundary. Data transfers between Dynamics 365, Power Platform, and Azure OpenAI occur over the Microsoft backbone network and are encrypted in transit.

    The documentation notes that in some scenarios, such as features powered by Bing and third‑party copilot plug-ins, customer data might be transmitted outside the Microsoft Cloud trust boundary. For core Microsoft 365 Copilot experiences, data remains within the Microsoft cloud and is governed by existing Microsoft 365 data protection controls.

    • Permissions behavior (can Copilot see more than the user?) Copilot does not elevate permissions. It can only access and surface content that the current user is already authorized to access:

    • Microsoft 365 Copilot uses the same permissions model as Microsoft 365. It presents only data each individual can access, and the Semantic Index honors user identity–based access boundaries.
    • For encrypted content protected by Microsoft Purview Information Protection, Copilot honors the usage rights granted to the user. If the user does not have rights to open or use the content, Copilot cannot use it.
    • For Dynamics 365 and Power Platform, data is provided to Copilot based on the access level of the current user. If a user has access to encrypted data and provides it to Copilot, Copilot can access it; otherwise, it cannot.

    Authentication and authorization mechanisms segregate requests to shared models among tenants, and Copilot utilizes only data that the requesting user can access.


    References:

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.