Microsoft 365 Copilot — a governance playbook

How to roll out M365 Copilot without leaking sensitive content: tenant boundary, Restricted SharePoint Search, sensitivity labels, audit and DSR handling.

The data boundary you can rely on

  • Prompts, responses and grounding data stay inside the Microsoft 365 service boundary and are not used to train foundation models. Confirm in your contract (DPA + Product Terms).
  • For EU customers, EU Data Boundary commitments apply to Copilot processing.
  • Bing-grounded ("web") responses leave the boundary — treat them like any external web call: disable for high-sensitivity tenants or scope to specific roles.

Permissions hygiene — the real work

Copilot will only return what the prompting user can already see — but most tenants have years of over-sharing. Before broad rollout:

  1. Run SharePoint Advanced Management site access reviews on the top 100 sites by activity.
  2. Enable Restricted SharePoint Search (RSS) during pilot so Copilot only grounds on an allow-list of sites.
  3. Turn on Sensitivity labels (Purview Information Protection) with auto-labelling for the top sensitive content types (HR, M&A, source code, customer PII).
  4. Configure DLP policies for Copilot (Purview) to block prompts containing regulated data and to suppress responses citing labelled content above the user''s clearance.
  5. Disable personal OneDrive as a grounding source for users in regulated functions.

Audit and subject rights

  • Copilot interactions are logged in the Unified Audit Log (Microsoft Purview Audit). Verify retention meets your policy (default 180 days; longer with Audit Premium).
  • For GDPR Art. 15 DSARs, Copilot prompt/response history is in-scope. Use Purview eDiscovery (Premium) to collect.
  • For GDPR Art. 17 erasure, deleting the user''s mailbox / OneDrive removes the associated Copilot history.

Rollout pattern that works

  1. Pilot of 50–200 users in low-sensitivity functions.
  2. RSS on; allow-list expands monthly as labelling matures.
  3. Monthly Copilot-specific incident review at the AI Governance Forum.
  4. Broad rollout only after a clean labelling and DLP run.

Reviewer hot-buttons

  • Evidence of an access-review run before rollout, not just after.
  • Sensitivity labels present on the regulated content corpus.
  • DLP-for-Copilot rules live and tested with a synthetic prompt.
  • DSAR + erasure runbook explicitly covers Copilot.