Copilot Agents · 7 min read
Are Copilot Agents Secure? Where Your Data Goes
By James Wilkinson 7 August 2026
The long answer on Copilot agent security: where answers come from, what stays inside the Microsoft 365 service boundary and what your admins control.
TL;DR
- Copilot agents are as secure as the Microsoft 365 tenant they run in, because that is where they run. Content stays inside the service boundary and is not used to train the models.
- An agent can only surface what the person asking is already allowed to open. Permissions are inherited per person, per question.
- The real security work is governance. Tidy permissions, named owners and agreed review points, using the Microsoft 365 controls you already have.
Copilot agents are secure to the extent your Microsoft 365 tenant is secure, because that is where they run. Your content stays inside the Microsoft 365 service boundary, it is not used to train the underlying models and an agent can only surface what the person asking is already allowed to open. No third-party AI tools are involved at any stage. The real security work is governance: tidy permissions, named owners and agreed review points.
The short version of that answer lives on the Agent Journey page, where it belongs next to the stages. This is the long version: what actually happens to a question, a document and an answer.
Where an agent’s answers come from
A Copilot agent is Copilot given one job, grounded on named knowledge sources such as a SharePoint site. Grounding means the agent retrieves from that content and answers with citations back to it. It does not mean the content is copied somewhere new. The documents stay in SharePoint or OneDrive, under the permissions, retention and audit arrangements they already have. The agent is a reader, not a new place your data lives.
That single fact settles most of the “where does our data go” worry: nowhere. It stays where you put it.
The service boundary, in plain English
When someone asks an agent a question, the prompt, the retrieved content and the generated answer are processed inside the Microsoft 365 service boundary: the same contractual and technical perimeter that already covers your email, files and Teams messages. Your Microsoft 365 agreement, your tenant’s data residency arrangements and Microsoft’s enterprise commitments apply to agent traffic the same way they apply to everything else in the tenant.
Two things follow. First, content is not used to train the underlying foundation models. Your engagement letters do not make the model cleverer for anyone else. Second, there is no third-party AI service in the path. Copilot, Copilot Studio and Microsoft 365 are the whole stack, which keeps the vendor list and the due diligence exactly as long as it already was.
Permissions: the inheritance rule
The rule is one sentence: an agent searches with the permissions of the person asking, per person and per question. If someone cannot open a document today, an agent will not show it to them tomorrow. There is no agent super-user account with sight of everything, and sharing an agent with a colleague does not share the content behind it, because the colleague’s own permissions apply when they ask.
The honest caveat is that agents make your existing permissions visible. A payroll spreadsheet shared with “Everyone” five years ago was always open. Once an agent starts answering questions, someone will find out. That is a reason to tidy permissions before rollout, not a reason to avoid agents, and it is standard SharePoint groundwork before grounding anything on a site.
What your admins control
Agents do not arrive outside your existing controls. Admins decide who can build and share agents and which agents are available to whom. Sensitivity labels, data loss prevention policies, retention and audit logging keep applying to the content agents read and the interactions people have with them. An agent that takes actions through Copilot Studio runs those actions through connectors your admins can see and manage, with agreed review points so a person approves anything that matters.
For firms that want a checklist for any agent, wherever it runs, the three governance questions are the right frame: what exactly can it do, which agent did what, and where is the record.
What this means for professional firms
For a practice holding client records under confidentiality duties, the position is straightforward to state to a partner or a client: agents run inside the firm’s own Microsoft 365 tenant, read only what the asking member of staff could already open, add no new vendor and leave the firm’s existing governance in force. The remaining work is the firm’s own: tidy sources, a named owner per agent and review points that match the risk of the job. The client data governance guide covers the wider Copilot picture, and the AI agents for accountancy firms page shows how the security answer sits alongside the named jobs.
If a security question is the thing standing between your firm and a first agent, a short call usually settles it.
Related reading
More on copilot agents
Common questions