Microsoft + ClaudeOne partner for the cloud you run and the AI you put on top of it.
Avalon Web ServicesMicrosoft · Claude · Security

Microsoft Copilot security: what actually happens to your business data

Microsoft 365 Copilot answers using data the signed-in user can already reach, and Microsoft commits under the Data Protection Addendum that prompts, responses and Microsoft Graph data are not used to train foundation models. Prompts and responses are kept in a hidden folder in the user's own mailbox. Two things most security reviews miss: since July 2026 some Copilot models are operated by OpenAI as a Microsoft subprocessor rather than by Microsoft, and several certifications people cite for Copilot do not name it in scope at all.

Written by
Arif Ali Mughal
Published
Reading time
9 min

01 / 09

The question behind the question

Nobody asks is Microsoft 365 Copilot secure in the abstract. They ask because a customer sent a security questionnaire, or a board member read something, or a regulator wants to know where the data goes. The useful answer is not a yes. It is a trace: what happens to a prompt, what is kept, who can read it, what Microsoft has promised in writing, and which of those promises are contractual rather than marketing.

That trace has four stages, and Microsoft documents them — though not consistently. The main architecture page describes four steps. A separate page on the semantic index describes five, adding a post-processing pass back against Microsoft Graph after the model responds. Both pages are current. Neither references the other.

ONE PROMPT, END TO END — AND WHAT SURVIVES IT 01 PROMPT 02 GROUNDING 03 MODEL 04 RESPONSE What the user types Graph and semantic index Where it leaves the apps Returned with citations TWO MODEL PATHS SINCE JULY 2026 Azure OpenAI — models operated by Microsoft OpenAI — as a Microsoft subprocessor, on by default for eligible commercial tenants WHAT PERSISTS AFTERWARDS Prompt and response, in a hidden folder in the user’s own mailbox Then SubstrateHolds, until retention expires Microsoft says the data stays inside the Microsoft 365 service boundary. Its pages never define that boundary against stage 03.
Stage 03 is the one that changed in July 2026, and the one Microsoft's own architecture pages describe least precisely. Everything to the right of it persists in a mailbox folder neither the user nor the administrator browses directly.

02 / 09

Where your data physically lives afterwards

Microsoft calls the prompt and the response, together with the citations used to ground it, the content of interactions. The running record is the user's Copilot activity history.

The storage location is more specific than most people expect, and it is worth knowing before you answer a data-mapping question. Prompts and responses are stored in a hidden folder in the mailbox of the user who ran the AI app — a folder Microsoft states “isn’t designed to be directly accessible to users or administrators”, existing so that compliance administrators can reach it with eDiscovery. When retention expires, items move to another hidden folder, SubstrateHolds, before permanent deletion.

Two practical consequences. A user can delete their own Copilot activity history from the My Account portal — but a retention policy still governs the underlying copy, so deletion by the user is not deletion from the tenant. And there is no published default retention period. Retention for AI apps is something an administrator configures; if nobody has configured it, do not assume you know the answer, and do not tell a regulator you do.

03 / 09

What Microsoft commits, and where the commitment lives

The strongest claim is also the most quoted: prompts, responses and data accessed through Microsoft Graph are not used to train foundation models. What matters for a questionnaire is not the sentence but its address. Microsoft describes enterprise data protection as controls and commitments under the Data Protection Addendum and Product Terms, with Microsoft acting as a data processor. That makes it a contractual undertaking rather than a documentation promise, which is the distinction your legal reviewer will care about.

Two carve-outs belong in an honest answer. Customer feedback is optional, and Microsoft may use it to improve Copilot — while stating explicitly that feedback is not used to train the foundation models. And web-grounding queries go to Bing with user and tenant identifiers removed; Microsoft states they are not shared with advertisers and not used to train the models. Neither carve-out is alarming. Both are the sort of detail that looks like concealment if a customer finds it after you have said “none of our data leaves”.

04 / 09

The change most security reviews have not caught up with

This is the part worth reading twice, because it is recent enough that most published Copilot security assessments predate it.

Until 2026, the model layer behind Copilot was Azure OpenAI — OpenAI's models, operated by Microsoft, inside Microsoft's own infrastructure. That is no longer the only path. Microsoft now documents a distinction between OpenAI models operated by Microsoft (Azure OpenAI) and OpenAI models operated by OpenAI, provided by OpenAI as a subprocessor.

The dates are specific. OpenAI was added to the Microsoft Online Services Subprocessors List on 23 June 2026. The subprocessor path became available on 9 July 2026. And as of 24 July 2026, OpenAI-operated models are enabled for all users at eligible commercial customers unless an administrator disables them. Only an AI Administrator or Global Administrator can turn it off.

  • Microsoft states this path is excluded from in-country processing commitments where those apply, and is unavailable in GCC, GCC High, DoD and sovereign clouds. It is included in the EU Data Boundary, except as that documentation otherwise notes.
  • Microsoft states OpenAI offers Zero Data Retention for the Responses API it uses, subject to that API's documented limitations.
  • The gap worth naming: the page documenting this path does not restate the no-training commitment or the abuse-monitoring position described below. The page carrying those statements predates this rollout. We could not find any Microsoft page confirming they extend to the OpenAI-operated path — so if that matters to your regulator, get it answered in writing rather than assumed.

05 / 09

Human review, and the sentence people get wrong

A recurring question in vendor assessments is whether a human at the vendor might read a prompt. For Copilot the documented answer is unusually clean, and it is better than most people assume.

Microsoft states: while abuse monitoring, which includes human review of content, is available in Azure OpenAI, Microsoft Copilot services have opted out of it. Note what that says. It is not a customer-configurable toggle you need to go and switch off. The service itself is excluded, so there is nothing for a tenant to opt out of.

Be careful not to import Azure OpenAI's general abuse-monitoring documentation — including its retention windows — into a Copilot answer. Those pages describe a programme Copilot has explicitly opted out of, and quoting them would understate your own position.

06 / 09

The certifications that name Copilot, and the ones that do not

Here is the finding most likely to change what you send a customer. Vendor questionnaires routinely answer is Copilot ISO 27001 certified? with a yes. Microsoft's own in-scope service tables do not support that answer as written.

We checked each framework's published list of in-scope services, as at 21 August 2026.

  • None of this says Copilot is uncertified or unsafe. It says the scope statement you attach to a certification has to be accurate, because a customer's auditor can open the same in-scope table you did.
  • The underlying audit reports live on the Microsoft Service Trust Portal, behind sign-in and an NDA covering compliance materials. It carries an AI Resources section covering Copilot and Azure OpenAI.
FrameworkIs Microsoft 365 Copilot named in scope?How to answer honestly
ISO/IEC 42001:2023 (AI management systems)Yes — explicitly listed among the Microsoft AI services in scope.Cite it directly. This is the strongest Copilot-specific certification claim available.
FedRAMPYes — but only in the GCC, GCC High and DoD tables, not commercial.Only claim it for a government cloud tenant.
ISO/IEC 27001, 27017, 27018, 27701No — Copilot does not appear in the in-scope tables.Say coverage is inherited from the underlying Microsoft 365 services Copilot runs on, not that Copilot is separately certified.
SOC 1 Type 2No.Same inherited-coverage wording.
SOC 2 Type 2Partially — Copilot Studio appears; Microsoft 365 Copilot does not.Do not let the Copilot Studio line item stand in for Copilot itself.
IRAP (Australia)Contradictory — absent from the general offering page, but the ANZ blueprint states Microsoft 365 with Copilot is in scope at PROTECTED.Cite the ANZ blueprint and flag the inconsistency rather than picking one.
HITRUST, C5 (Germany)No evidence found naming Copilot.Do not claim it.

07 / 09

Prompt injection, and the public disclosure record

Prompt injection is the attack class specific to this product, and Microsoft now documents it directly. Its prompt-defense page — revised on 18 August 2026 — separates direct injection, where the user types something coercive, from indirect injection, where the malicious instruction is hidden in a file, image, code or encoded text that Copilot reads.

What actually ships against it: jailbreak and cross-prompt injection attack classifiers that analyse inputs and block high-risk prompts before model execution, with Microsoft's own caveat that these may not be available in all Microsoft Copilot scenarios. Grounding excludes spam mail and chats. Defender for Office 365 Plan 2 detects prompt-injection content in inbound email before it reaches a user or an AI assistant. Hidden Unicode obfuscation in pasted text is detected and sanitised — a control that maps directly onto a published 2024 attack. And the audit log records a JailbreakDetected flag.

One inconsistency worth knowing: Microsoft's Transparency Note for Copilot covers responsible-AI limitations at length but does not name prompt injection as a discrete risk category, while the prompt-defense page treats it as the main event. If your reviewer reads only the Transparency Note, they will conclude less work has been done here than actually has.

PUBLICLY DISCLOSED COPILOT VULNERABILITIES — AND WHO FIXED THEM AUG 2024 JUN 2025 JUN 2026 ASCII SMUGGLING ECHOLEAK SEARCHLEAK Indirect injection via email, exfiltration through invisible Unicode in a rendered link. Reported Jan 2024, fixed before Aug 2024 disclosure. CVE-2025-32711. Zero-click indirect prompt injection, no user interaction needed. Patched server-side before public disclosure. CVE-2026-42824. One-click chain using a search parameter and an image-fetch endpoint. Mitigated on the backend; severity ratings differ by source. The pattern, not the count, is the finding: every one was fixed service-side. No tenant admin could have patched any of them.
Three disclosures in two years is neither reassuring nor alarming on its own. The useful reading is that all three were remediated service-side before or without customer action — which is what buying a managed service actually buys, and also what it costs you in control.

08 / 09

What an administrator can and cannot see

A question that comes up in works-council and employee-privacy discussions, and one where the answer is more nuanced than admins see everything.

  • Broadly available: that an interaction happened, when, in which app, and which files were referenced — all captured in the unified audit log.
  • Restricted: the literal text of prompts and responses. Reading that requires a specific Purview role, or an eDiscovery case against the user's mailbox. It is not something a general administrator sees by default.
  • User-side: a user can delete their own Copilot activity history, which does not defeat a retention policy.
  • For risky behaviour rather than content, the Purview insider-risk template for AI usage covers prompt-injection attempts and access to protected material, and feeds Defender XDR.

09 / 09

How we would answer the questionnaire, and what we sell

Our advice, and it is an opinion rather than vendor guidance: answer with the contract, the scope statement and the configuration, in that order. The contract is the DPA and Product Terms and it is strong. The scope statement is where most answers quietly overclaim, and it is the easiest thing for a customer's auditor to check. The configuration — retention, the model-path setting, web grounding, DLP — is the part that is actually yours to get wrong.

One more caution on sources. Several further Copilot CVEs were reported during 2026 that we could not verify against Microsoft's own advisories, and at least one widely-shared 2026 vulnerability affects Microsoft Copilot Personal, the consumer product, not Microsoft 365 Copilot. Check the product name before either of them reaches a risk register.

The disclosure, plainly: we sell this work. A Cloud Health Check reviews identity, endpoints, data protection and monitoring across a Microsoft tenant and produces ranked findings and a plan you own, whether or not you engage us further. Everything above is public and you can verify all of it yourself — the pages are linked below. Every claim here was checked against Microsoft's documentation on 21 August 2026; this surface moves monthly, and the July 2026 change described above is exactly the kind of thing that will be out of date faster than you expect.

Primary sources

Want us to run this for you?

Start here

Tell us what'skeeping you upat night.

Most engagements start with a Cloud Health Check — one week, full audit, top-10 findings, 90-day roadmap. Many turn into a longer engagement; either way, you walk away with a prioritized plan you own.