Where does Copilot send your data?
What stays in your tenant, what doesn't, and how to check the boundary.
Updated 31 Jul 2026 fast-moving — check a current source
Behaviour per Microsoft 365 Copilot documentation, checked late July 2026. Copilot ships changes monthly — verify current before relying on it.
Microsoft 365 Copilot processes your prompts and the files it reads inside your organisation’s service boundary. It doesn’t use that content to train the underlying model. That single fact is the thing most staff get wrong, in both directions — some assume it’s training on their documents, others assume “inside the tenant” means nothing ever leaves their control. The truth is more specific.
What stays inside the tenant
Your prompts, the files and emails Copilot reads to answer you, and the responses it generates are handled within your Microsoft 365 service boundary, under the same commitments as the rest of your tenant data. Copilot respects existing permissions: it can only surface content the asking user already has access to. It does not, by default, feed your business data back into model training.
What crosses a boundary
The model itself runs in Microsoft-managed infrastructure, so the prompt and the relevant grounded content are sent to that service to be processed — they don’t stay on your device. Web queries (when Copilot looks something up online) leave the tenant by design. Connected third-party plugins or agents may send data to those providers under their own terms, which are not Microsoft’s.
The boundary protects you from training and from other tenants. It does not mean the data never moves — it means it moves under contract, not into a public model.
”Copilot” is no longer one model
A development worth knowing about: Microsoft has begun offering a choice of frontier models inside Copilot, including models from both OpenAI and Anthropic in some applications. Excel is the clearest example, where either can be selected.
This does not change the tenant boundary — the commitments above are Microsoft’s and apply regardless of whose model does the work. But it does change two practical things. Answers may differ between models for the same prompt, so “Copilot said” is now an ambiguous statement. And if your governance documentation names a specific model provider, it may quietly have become inaccurate. Check which models are enabled for your tenant rather than assuming.
How to check, rather than assume
- Confirm your tenant’s Copilot data-handling terms in the Microsoft 365 admin centre, not from a blog post — the specifics change.
- Audit which plugins and connectors are enabled; each is a separate data path.
- Check that permissions are tight: Copilot inherits oversharing. If a sensitive file is readable by “everyone”, Copilot can surface it to everyone.
- Decide your stance on web search and enterprise data protection settings deliberately, rather than leaving defaults.
Why this matters for governance
Knowing the boundary is the prerequisite for the harder questions — data loss prevention and the shadow-AI problem of staff using tools that have no boundary at all.
Sources
Everything above was checked against these on 31 Jul 2026. Providers change things without notice — if a detail matters to a decision, follow the link.