Manage web search for Copilot and Copilot Chat

Completed

Settings in the Copilot settings catalog usually live in separate corners of the admin center—self-service purchases sits on its own tab, and image generation is a distinct control from video generation. That pattern sets up a reasonable prediction: web search probably follows the same rule, with one switch for Microsoft 365 Copilot and a second, independent switch for Copilot Chat. Take a guess before you read further.

One policy governs both experiences

The guess is wrong. Web search for Microsoft 365 Copilot and Copilot Chat comes from a single policy: Allow web search in Copilot. Configure it once, and the setting reaches both experiences at the same time—there's no separate Copilot Chat switch to hunt for, and no reason to configure the same protection twice.

The Copilot settings page in the Microsoft 365 admin center lists an entry named Web search for Microsoft 365 Copilot and Microsoft 365 Copilot Chat, under the Data access tab. That entry isn't the control itself—it's a shortcut link. Select it, and it takes you to the Cloud Policy service for Microsoft 365, inside the Microsoft 365 Apps admin center at config.office.com. That's where you actually create and configure the Allow web search in Copilot policy. If you look for an actual toggle on the Copilot settings page itself, you don't find one—the real control lives one admin center over.

Choose one of three policy states

The Allow web search in Copilot policy resolves to one of three states. The only real complexity is that Microsoft 365 Copilot has two modes the policy can treat differently—Work mode (grounded in tenant content) and Web mode:

Policy state Copilot Work mode Copilot Web mode Copilot Chat
Enabled Web search on Web search on Web search on
Disabled Off Off Off
Split (Work off, Web on) Off—tenant content only Web search on Web search on

That third state is the only real split this policy offers, and it's a split within Microsoft 365 Copilot itself—between its Work mode and its Web mode—not a split between Copilot and Copilot Chat.

If you don't configure this policy at all, web search defaults to available in both experiences. A separate policy, Allow the use of additional optional connected experiences in Office, can still restrict multiple Microsoft 365 experiences at once when it's set to disabled, but it isn't specific to web search. One exception applies to US Government tenants (GCC and DoD): web search stays off by default until you explicitly configure the policy.

Guiding question: Woodgrove Bank's regulated posture calls for tight control over what leaves the tenant. Which of the three policy states fits that posture best, and what capability does Relecloud give up by choosing it?

Distinguish the policy from the personal Web content toggle

One control genuinely is separate from the policy: the Web content toggle. It lives only inside Microsoft 365 Copilot's work chat experience—Copilot Chat doesn't have it at all. It's personal, not tenant-wide: each user sets it for themselves rather than you setting it for the tenant.

When you enable the Allow web search in Copilot policy, the Web content toggle defaults to on, but a Relecloud user can still turn it off for their own sessions without your involvement. When you disable the policy, the toggle becomes unavailable—it appears dimmed in the interface, and the user can't turn it on no matter what they try.

So two layers govern web search together: your policy decision sets the ceiling for the tenant, and the Web content toggle lets individual Microsoft 365 Copilot users lower that ceiling for themselves. Neither layer lets a user raise it above what your policy allows.

Weigh capability against exposure

Web search extends Copilot's reach past Relecloud's tenant boundary and into public content, so every state you choose trades assistant capability for exposure beyond what governance already reviews. That trade is the same one you make with every other setting in this catalog—more capability for Relecloud's users, or a tighter boundary around what Copilot can reach.

The next unit turns to a different kind of reach. Copilot Search grounds answers in Relecloud's own content instead of the public web, and it needs to understand Relecloud's internal shorthand—its acronyms and internal terms—before it's actually useful.