Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
As a Compliance Manager or IT administrator, it's crucial to stay up-to-date on the latest governance, data lifecycle, and compliance posture for the software solutions being used in your organization. This article details the capabilities available and not available yet for Copilot Pages and Copilot Notebooks.
At a glance
| Capability | Status |
|---|---|
| Admin policy | ✅ Available - Cloud Policy |
| GDPR / EUDB | ✅ Supported |
| Conditional Access | ◐ App-level only (entire Microsoft Copilot app) |
| Information Barriers | ❌ Not supported |
| Customer Lockbox | ✅ Supported |
| eDiscovery | ✅ Supported |
| Legal Hold | ✅ Supported; selecting the container in the custodian data source picker is rolling out (expected October 2026) |
| Retention policies | ✅ Supported via "All SharePoint Sites" |
| Retention labels | ◐ Limited manual application |
| Sensitivity labels | ✅ Copilot Pages only |
| DLP | ✅ Supported with policy tips |
| Recycle bin | ❌ No end-user recycle bin for Copilot Notebooks |
SharePoint Embedded
Copilot Pages and Copilot Notebooks content are stored in SharePoint Embedded. Content stored in SharePoint Embedded containers follows the SharePoint Embedded security and compliance documentation. The sections below outline governance, lifecycle, and compliance capabilities applicable to all Copilot Pages and Copilot Notebooks storage types.
Foundations
- Admin policy: Use Cloud Policy to turn on or off creation of Copilot Pages and Copilot Notebooks. Copilot Pages can also be shared as Loop components in supporting apps. See relationship to Loop components.
- GDPR: Data subject requests can be serviced through the Microsoft Purview portal and Purview eDiscovery workflows.
- EUDB: Compliance is supported. See What is the EU Data Boundary?
Data security and devices
- Intune: Device Management Support is available for the Microsoft 365 app and Teams app on iOS and Android.
- Conditional Access: Only applies at the app level. Because Copilot Pages and Copilot Notebooks are features of the Microsoft Copilot app, Conditional Access applies to the entire app at m365.cloud.microsoft. Use admin policies to block creation of new content.
- Information Barriers: Not supported. See admin policies for available controls.
Important
Information Barriers are not supported for content stored in SharePoint Embedded containers. Copilot Pages and Copilot Notebooks use SharePoint Embedded for storage. If your organization requires Information Barriers, consider using admin policies to disable Copilot Pages and Copilot Notebooks.
- Customer Lockbox: Supported.
- Guest app access: Available for Copilot Pages and Copilot Notebooks containers. Enables third-party export/eDiscovery tools, migration tools, and developer APIs. Use PowerShell to Get and Set guest app permissions.
Data lifecycle
- Scenario: user leaves the organization. The container follows the same OneDrive deletion lifecycle as the rest of Microsoft 365, with one manual handoff step at departure (access and notification aren't automatic) and the option to permanently reassign the container to a new owner. For the full process, options, and comparison with OneDrive, see Grant access to containers. To preserve content before departure, export it using Purview or the Graph API, or add the container to a retention policy.
- Storage: Copilot Pages and Copilot Notebooks are stored together in a single user-owned SharePoint Embedded container, which is also shared by Loop My workspace. Storage counts against your organization's SharePoint quota. See storage for the full explanation of the shared container and Managing SharePoint Embedded containers for admin tooling.
- Limitation: There's no admin control to set quota limits on individual containers.
- Admin control note: To prevent the container from being created, disable both the Copilot Pages and Copilot Notebooks policy and the Loop Create Loop workspaces in Loop policy for the same user.
- Multi-Geo: Supported. The container is created in the geo matching the user's preferred data location.
- Known issue: Some operations might not work correctly after moving containers across geos. Microsoft is working on a fix.
- Recycle bin: No end-user recycle bin exists.
- Limitation: Neither administrators nor end users can recover individually deleted Copilot Notebooks.
- Version History: Export in Purview or via Graph API. 50 major versions per file by default, configurable via PowerShell per application.
- Audit logs: Available for all events. Retained, exportable, and streamable to third-party tools. Search in Purview for "page" and filter by
"SourceFileExtension":"page". Copilot Notebooks create and update.podfiles to manage content.
eDiscovery
- Purview eDiscovery: Supported for search/collection, review (Premium license required), and export as HTML (Premium license required) or original format. Download and reupload files to OneDrive to view in native format.
- Graph API export: Supported for third-party tools. Use PowerShell to Get and Set guest application permissions.
- Legal Hold: Supported. Content is stored in the Preservation Hold Library.
- When you add a user as a custodian in Purview eDiscovery, selecting their user-owned SharePoint Embedded container as a data source in the same experience where you select the user's OneDrive and Exchange mailbox is rolling out and expected in October 2026.
- Until then, retrieve the user-owned container URL using PowerShell or the SharePoint admin center, then add it as a data source manually. For instructions, see Retrieving the container URL for Purview.
Microsoft 365 retention and deletion
Retention policies from Microsoft Purview Data Lifecycle Management configured for all SharePoint sites are enforced for all Copilot Pages and Copilot Notebooks.
- For more information on how to configure specific Copilot Notebooks, see Purview and SharePoint Embedded.
Retention labels from Microsoft Purview Data Lifecycle Management and Microsoft Purview Records Management are supported for Copilot Pages (.page files) and Copilot Pages in Copilot Notebooks by applying published labels in OneDrive or SharePoint, or automatically applying the labels. There's limited support for manually applying retention labels.
- Retention labels can't be viewed or applied directly from a Copilot Page. Instead, the user must navigate to the Copilot Page within the Loop app to view or apply a retention label on a Copilot Page.
- Retention labels that mark the content as a record or regulatory record can't be manually applied in either the Copilot Page or when the content is opened in the Loop app. If content is automatically labeled as a record, locking and unlocking this record is not yet available.
Information protection
- Sensitivity labels: Available for Copilot Pages. Copilot Notebooks don't have container sensitivity labels because they share a container with all Copilot Pages.
- Data Loss Prevention (DLP): Rules enforced with end-user policy tip support.