Microsoft 365 Copilot deployment: the four control planes of a secure rollout
Securing a Microsoft 365 Copilot deployment means operating four control planes: data, through Purview DLP for the Copilot location; labels and encryption, where usage rights decide what Copilot may read; identity, which since 1 May 2026 includes identities for agents themselves; and evidence, through audit, eDiscovery and retention. The fourth is the one enterprises assume is automatic and it is not. This guide covers what each plane blocks, which controls were generally available and which were still in preview, and where interaction data physically goes under load.
01 / 09
What changed on 1 May 2026
Three things reached general availability on the same day, and together they moved the goalposts for what a secure Microsoft 365 Copilot deployment means.
Microsoft Entra Agent ID became generally available — an identity framework that extends Entra to AI agents, with agent identity blueprints, parent-child identity relationships and Conditional Access. Microsoft Agent 365 became generally available for commercial customers on a per-user basis, giving a central registry, lifecycle management and policy enforcement across agents. And Microsoft 365 E7 shipped, a strict superset of E5 that bundles Copilot, the full Entra Suite and Agent 365 together.
Read those three as one event. Before it, securing Copilot was a content problem: which files can this person reach, and which of them should be off limits. After it, there is a second question with a much less obvious answer — which non-human thing is asking, on whose behalf, and who signed off on it existing?
Every Copilot deployment runbook written before May 2026 is missing that plane entirely. That is the gap this guide is organised around.
02 / 09
Plane one — what Purview DLP for Copilot actually blocks
The Copilot location in Purview DLP is the control most people mean when they say they have secured Copilot. It is worth knowing precisely what it does, because two of its four protections were still in preview at the time of writing.
- Three limits worth designing around, all documented: you cannot use a sensitive-information-type condition and a sensitivity-label condition in the same rule; DLP cannot scan the contents of a file a user uploads directly into a prompt, only the text they type; and a policy change can take up to four hours to take effect in Copilot.
- That upload limitation is the one to think hardest about. A user who cannot get Copilot to read a restricted document can often just attach it to the prompt instead.
| Protection | What it does | Status as at 11 July 2026 |
|---|---|---|
| Block labelled files and emails as grounding | Items with a given sensitivity label still appear in citations, but their content is not used in the response. | Generally available. Rolled out from mid-April, completing end of June 2026. |
| Block sensitive information types in web search | Stops a prompt containing an SIT from being sent to web grounding. | Generally available, having been in preview from late March 2026. |
| Block sensitive information types in prompts | Blocks the prompt itself when it contains a matching SIT. | Preview, rolling out to tenants with Copilot and Copilot Chat. |
| Block external email as grounding | Evaluates sender-domain metadata only — not the body of the email. | Preview. |
03 / 09
Plane two — the encryption rule that surprises people
Sensitivity labels do two jobs here. The first is inheritance: when Copilot generates content from labelled sources, the highest-priority label is inherited along with its protection settings. That part behaves as you would hope.
The second is the one that generates support tickets. Where a label applies encryption, the user must have EXTRACT and VIEW usage rights for Copilot to interact with the content. Rights that let a person open and read a document do not necessarily let Copilot summarise it. The same applies to items encrypted by Azure Rights Management without a label.
And a sharper edge: Copilot agents cannot read files carrying user-defined sensitivity label permissions at all. If your organisation encourages ad-hoc protection, you have created a class of documents that agents will silently never see — which reads to users as the product being unreliable rather than as the control working.
04 / 09
Plane three — identity, and the boundary that moved
This is the plane that changed, and the controls are real but unevenly mature.
At the Microsoft 365 admin center you can configure who may access agents and which types they can install, disable the Agent Builder entry point tenant-wide, and restrict org-wide agent sharing to specific groups. In the Power Platform admin center you can turn off the ability to publish agents that use generative AI features across the entire tenant, and use environment routing to give makers a contained place to build.
SharePoint agents deserve separate attention because of how they are created. They are .agent files sitting in a site's Site Assets library, and anyone who can create a file on a site can create one. You can inventory them with Get-SPOCopilotAgentInsightsReport. But note Microsoft's own caveat on blocking them: blocking an agent only affects its availability in Copilot Chat. It doesn't yet apply to OneDrive, SharePoint, or Teams. An admin who blocks an agent and believes it is gone has been misled by the word.
- Copilot Frontier is not a feature set, it is a pre-release channel. Microsoft describes Frontier features as preview and subject to change. It defaults to no access; scope it to a named pilot group and keep it there.
- Agent 365 and Entra Agent ID are both generally available as products while named capabilities inside each remain in preview — agent identity blueprints and access packages for agent identities among them. Product GA is not capability GA, and procurement conversations rarely make that distinction.
- No single Microsoft page reconciles which admin centre owns which agent control. A complete picture currently requires the Microsoft 365, Entra and Power Platform admin centres side by side.
05 / 09
Plane four — evidence, which is never automatic
Copilot user and admin activity lands in the unified audit log, including administrative events such as tenant setting updates and plugin creation and deletion. Prompts and responses are discoverable through eDiscovery — they live in the user's mailbox, and the query is against ItemClass for IPM.SkypeTeams.Message.Copilot.*.
Retention is where assumptions get expensive. Retention for AI apps is its own set of locations — Microsoft Copilot experiences, enterprise AI apps, and other AI apps each configured separately. A tenant with mature Exchange and Teams retention has not thereby retained anything about Copilot.
For regulated organisations, Compliance Manager carries assessment templates for the EU Artificial Intelligence Act, ISO/IEC 42001:2023, ISO/IEC 23894:2023 and the NIST AI Risk Management Framework, classified as premium regulations. Two adjacent facts are worth knowing before you promise a regulator anything: Microsoft 365 Copilot and Copilot Chat are listed in scope for the Microsoft HIPAA Business Associate Agreement, and the Cohasset assessment covering SEC 17a-4, SEC 18a-6, FINRA 4511 and CFTC 1.31 was expanded in December 2024 to include Copilot.
The gap in that list is worth naming rather than glossing. Microsoft's own 23 NYCRR Part 500 compliance page enumerates the in-scope Microsoft 365 services and does not mention Copilot. That is not a statement that Copilot is non-compliant — it is an absence of published coverage, and if you are a covered entity under NYDFS it is a question to put to your account team in writing rather than an inference to make.
06 / 09
Where the data actually goes when the region is busy
Residency is the question every enterprise security review reaches, and the honest answer has two halves that get conflated.
At rest, the commitment is strong. Advanced Data Residency covers the content of interactions — the prompt, the response and the citations — plus Copilot interaction history. Two conditions to plan for: ADR requires that 100% of paid licences in the tenant are covered, not merely the Copilot users, and Microsoft commits reasonable efforts to complete the migration within twelve months. If you have Multi-Geo, data may still be stored in multiple geographies even with ADR.
In inference, the answer is different. Flex routing lets EU and EFTA tenants allow LLM inferencing outside the EU Data Boundary during peak demand, with that inferencing occurring in the United States, Canada or Australia. It is on by default for eligible tenants created after 25 March 2026; older tenants are told to check their Message Center for their own default. An AI Administrator can switch it off, and Microsoft states the residency commitments continue to apply either way. Multi-Geo tenants are excluded and never see the setting.
Separately, Anthropic models used inside Microsoft's Copilot experiences are excluded from the EU Data Boundary entirely, and are off by default in the EU, EFTA and the UK. That is a distinct carve-out from flex routing, not the same one described twice.
07 / 09
The commitment that is easy to state and worth stating precisely
Microsoft's enterprise data protection terms say that prompts, responses and data accessed through Microsoft Graph are not used to train foundation models, and that commitment sits under the Data Protection Addendum and Product Terms rather than in marketing copy. It carries one documented exclusion: web search queries sent to Bing.
That exclusion is small and it is the whole reason the web-grounding toggle matters. Turning off web search is not only a data-leakage control, it is the boundary of the training commitment. In government clouds it is off by default already.
08 / 09
A deployment order
The sequence below is ours rather than Microsoft's, and it is ordered by lead time rather than by importance — the slow items are not the hard ones, they are the ones with other people in them.
- Weeks one to two, in parallel: decide the residency posture and check the flex routing default for your tenant, since that is a written answer someone will demand later; and start the Purview data risk assessment, which runs weekly across your top hundred SharePoint sites by usage without being asked.
- Weeks two to four: stand up the DLP policies you actually intend to keep, remembering the four-hour propagation and the one-condition-per-rule constraint. Confirm that the labels those policies depend on are applied in reality, not just published.
- Before any broad enablement: set the agent posture. Who may build, who may share, whether generative agents can be published at all, and whether Frontier is scoped to a named group. This is cheap to do first and expensive to retrofit once people have built things.
- Before go-live, not after: configure retention for the AI app locations and confirm audit is capturing what your evidence obligations require. This is the plane that is assumed to be automatic and is not.
09 / 09
What we would do, and what we sell
For most enterprises the binding constraint is not the technology, it is that the four planes have four different owners — the data team, the compliance team, identity, and whoever ends up responsible for agents, which is often nobody. A deployment stalls at whichever plane has no name against it. Assigning those four names is worth more than any single control on this page.
The disclosure, plainly: we sell this work. Copilot Pilot in a Box covers governance policy and a scoped pilot, and our security practice covers the Purview and identity side. Everything described here is documented publicly and you can run all of it yourself.
One note on freshness, because this area moves faster than almost anything else in Microsoft 365. The status column above is accurate as at 11 July 2026, and the claims in this article were re-checked against Microsoft's documentation on 19 August 2026. Preview features become generally available, and occasionally the reverse — verify status against Microsoft's own pages before you put any of it in a control document.
Primary sources
- Microsoft — Microsoft Agent 365 overview (generally available 1 May 2026)
- Microsoft — What is Microsoft Entra Agent ID
- Microsoft — What's new in Microsoft Entra Agent ID (GA and preview markers)
- Microsoft — Compare E3, E5 and E7 licence features for Microsoft 365 Copilot
- Microsoft Purview — DLP for the Microsoft 365 Copilot location (protections, statuses and limits)
- Microsoft — Copilot architecture, data protection and auditing (label inheritance, EXTRACT and VIEW rights)
- Microsoft Purview — Data Security Posture Management
- Microsoft Purview — Insider risk management policy templates (Risky AI usage, Risky agents)
- Microsoft Purview — Communication compliance for Copilot
- Microsoft Purview — Audit logs for Copilot and AI activities
- Microsoft Purview — Retention for Copilot and AI apps
- Microsoft Purview — Compliance Manager regulations list (EU AI Act, ISO 42001, ISO 23894, NIST AI RMF)
- Microsoft — Manage access to agents in SharePoint
- Microsoft Copilot Studio — Security and governance
- Microsoft — Get started with the Microsoft Frontier program
- Microsoft — Flex routing for the EU and EFTA
- Microsoft — Advanced data residency overview
- Microsoft — Data residency for Microsoft 365 Copilot and Copilot Chat
- Microsoft — Anthropic models in Microsoft online services (EU Data Boundary exclusion)
- Microsoft — Enterprise data protection in Copilot (no training on customer data)
- Microsoft — HIPAA and HITECH compliance offering
- Microsoft — 23 NYCRR Part 500 compliance offering (Copilot is not listed among in-scope services)