VendorScore · AI assistant · Data-access posture

Can Microsoft read your Microsoft 365 Copilot data?

A plain-language answer from Microsoft Learn, Trust Center and licensing pages. Customer Key and Customer Lockbox add custody and approval; Copilot still processes your content in plaintext.

Get the full 5-dimension PDF — join the waitlist

Evidence dated 2026-10-07, public docs only, not legal advice.

Short answer

Yes, by design (with controls): Copilot processes your prompts and the Microsoft 365 content it retrieves in plaintext; Customer Key and Customer Lockbox add custody and approval, not zero access.

66 / 100 overall

Scored configuration: Commercial tenant with Purview Customer Key (multi-workload DEP covering Copilot interactions), Customer Lockbox, Purview sensitivity-label encryption and EU Data Boundary; AI subprocessors at their defaults.

Default setup without Customer Key and Customer Lockbox scores lower: Microsoft-managed keys and no customer approval of engineer access. Scored separately; the Microsoft 365 score isn't reused.

Report confidence: Medium-high.

Higher = more customer control / less inherent vendor read access for the scored configuration. A strong SOC 2 doesn't mean the vendor can't read your data.

Last reviewed: · Evidence date: (score, key findings and FAQ) · Sources

Key findings

Where public evidence is thin

Our report flags these gaps in Microsoft 365 Copilot's public documentation:

  • Microsoft's subprocessor list lives in the Service Trust Portal (a JavaScript app), so we couldn't read the list content.
  • The Trust Center says new subprocessors are published 'at least six months in advance', but OpenAI was listed 2026-06-23 and usable 2026-07-09; the footnote couldn't be read. Verify against the DPA.
  • Certifications for OpenAI-operated models are managed by OpenAI, not Microsoft.

In the full PDF

Get the full 5-dimension PDF — join the waitlist

PDFs aren't for sale yet. Join the waitlist and we'll email yours when it's ready. No calls.

FAQ: Microsoft 365 Copilot data access, AI training, GDPR and residency

Can Microsoft read your Microsoft 365 Copilot data?

Yes, by design (with controls): Copilot processes your prompts and the Microsoft 365 content it retrieves in plaintext; Customer Key and Customer Lockbox add custody and approval, not zero access. VendorScore rates Microsoft 365 Copilot 66/100 overall from public documentation (evidence dated 2026-10-07). Scored configuration: Commercial tenant with Purview Customer Key (multi-workload DEP covering Copilot interactions), Customer Lockbox, Purview sensitivity-label encryption and EU Data Boundary; AI subprocessors at their defaults.

Does Customer Key or Customer Lockbox stop Microsoft reading Copilot data?

No, they add custody and approval. Customer Key multi-workload data encryption policies encrypt Microsoft 365 Copilot interactions with root keys you supply in Azure Key Vault (Microsoft keeps an availability key), and "All Microsoft 365 Copilot interactions are covered by Customer Lockbox through the support available for Exchange Online." Copilot still has to decrypt content to work, prompts sent to OpenAI-operated or Anthropic models are processed outside that key story, and Microsoft makes no E2EE claim for Copilot.

Can Microsoft employees see my Copilot prompts?

Not by default. Microsoft says engineers have no default access to cloud customer data and access is granted under management oversight only when needed; Customer Lockbox lets you approve such requests for Copilot interactions. Microsoft also says: "While abuse monitoring, which includes human review of content, is available in Azure OpenAI, Microsoft Copilot services have opted out of it." The exception is opt-in Anthropic models with Data Retention, where Anthropic retains data under its own terms.

Does Microsoft 365 Copilot train on my data?

No foundation-model training. Microsoft says: "Prompts, responses, and data accessed through Microsoft Graph aren't used to train foundation LLMs, including those used by Microsoft Copilot." Optional feedback may be used to improve Copilot, which Microsoft says isn't used to train foundation LLMs, and admins can manage feedback. Opt-in Anthropic models with Data Retention fall under Anthropic's terms: retention up to 30 days, flagged content up to 2 years.

Is Microsoft 365 Copilot GDPR compliant? Where is the Microsoft DPA?

VendorScore doesn't certify compliance; Microsoft publishes a DPA at https://www.microsoft.com/licensing/docs/view/Microsoft-Products-and-Services-Data-Protection-Addendum-DPA. Microsoft's Copilot docs list Copilot under Microsoft's GDPR offerings. Check the DPA (May 2026 version) for subprocessor-notice terms; see the thin-evidence note above.

Who are Microsoft 365 Copilot's subprocessors? Do OpenAI or Anthropic see my prompts?

Microsoft publishes its Online Services Subprocessor List through the Service Trust Portal at https://servicetrust.microsoft.com/, a JavaScript app, so we couldn't read the list content. Microsoft's Copilot docs name the AI subprocessors that see prompts: OpenAI (OpenAI-operated models, on by default for eligible commercial tenants since 2026-07-24 unless admins select 'No users') and Anthropic (off by default in the EU/EFTA/UK and excluded from the EU Data Boundary). Microsoft says "Some AI subprocessors are enabled by default", so admins should check the setting.

Does Microsoft 365 Copilot keep data in the EU (EU Data Boundary)?

Mostly. Copilot is an EU Data Boundary service, so EU traffic stays in the EUDB, and Advanced Data Residency and Multi-Geo carry Copilot residency commitments. Anthropic models are excluded from the EUDB, and OpenAI-operated models are excluded from in-country processing commitments.

Compare Microsoft 365 Copilot

All comparisons

Sources

Every URL cited on this page. Score, key findings and FAQ: VendorScore report (microsoft-365-copilot.md), evidence dated 2026-10-07.