
Explanation:
Box 1: No
No - Microsoft 365 Copilot uses your business data to train underlying AI models.
No Training on Customer Data: Microsoft does not use customer data, prompts, or interactions with the Microsoft Graph (emails, documents, chat history) to train the foundation Large Language Models (LLMs) that power Microsoft 365 Copilot.
Data Stays within Tenant: Your data, prompts, and Copilot's responses remain within your Microsoft 365 service boundary, adhering to your organization's existing privacy, security, and compliance policies.
Enterprise Data Protection (EDP): For users with an organizational Entra ID account, Copilot operates with EDP, ensuring that prompt and response data are not used for model training and are not accessed by Microsoft employees without explicit permission.
Respects Permissions: Copilot only accesses data that a specific user already has permission to view within their Microsoft 365 environment (SharePoint, OneDrive, etc.).
Exceptions (Consumer vs. Commercial): While commercial data (Entra ID) is excluded from training, Microsoft may use data from consumer Copilot services (like free Bing/MSN interactions) to train models, but users can opt out.
Box 2: No
No - Microsoft 365 Copilot automatically assigns permissions to resources, so that users can find information more easily.
Microsoft 365 Copilot is designed to strictly respect existing permissions and security, compliance, and privacy policies already established within an organization's Microsoft 365 environment.
Here is a breakdown of how Copilot handles permissions:
Respects Current Access Controls: Copilot only accesses data (emails, chats, documents) that an individual user is already authorized to view, based on existing role-based access controls (RBAC), SharePoint permissions, and OneDrive settings.
No Automatic Permission Changes: Copilot does not change, assign, or create new permissions for files to make them easier to find. It operates within the bounds of what is already shared with the user.
Oversharing Risk: Because Copilot relies on existing permissions, if files have been improperly or overly shared in the past, Copilot will allow users to find that information. It is not a tool to manage or "fix" permissions automatically, but rather to access data based on them.
Data Security: Copilot respects sensitivity labels and encryption (like Microsoft Purview), meaning it will not expose content that is locked down.
Box 3: Yes
Yes - Microsoft 365 Copilot uses the same underlying data access controls as other Microsoft
365 services to ensure that users are presented with only information to which they have access.
Microsoft 365 Copilot is designed to inherit and strictly adhere to the existing security, compliance, and data privacy policies established within your Microsoft 365 tenant.
Here is how Microsoft 365 Copilot ensures users only access information they are authorized to see:
Microsoft Graph Integration: Copilot uses Microsoft Graph to access user data (emails, chats, documents) only within the user's unique context and based on their existing permissions.
Permission Model Inheritance: Copilot honors SharePoint, OneDrive, and Microsoft Entra (formerly Azure AD) permissions. If a user does not have access to a document, Copilot cannot access or summarize it for them.
Data Protection Mechanisms: Copilot respects sensitivity labels and data loss prevention (DLP) policies, ensuring that sensitive data is handled appropriately.
Secure Scope: Copilot operates within the Microsoft 365 service boundary, meaning user prompts and data do not leave the secure environment to train the foundation models.
Zero Trust Approach: Copilot treats input prompts as potentially unsafe, using a zero-trust architecture to prevent data leaks.