All insights

Copilot Agents · 7 min read

Are Copilot Agents Secure? Where Your Data Goes

By James Wilkinson 7 August 2026

The long answer on Copilot agent security: where answers come from, what stays inside the Microsoft 365 service boundary and what your admins control.

TL;DR
  • Copilot agents are as secure as the Microsoft 365 tenant they run in, because that is where they run. Content stays inside the service boundary and is not used to train the models.
  • An agent can only surface what the person asking is already allowed to open. Permissions are inherited per person, per question.
  • The real security work is governance. Tidy permissions, named owners and agreed review points, using the Microsoft 365 controls you already have.

Copilot agents are secure to the extent your Microsoft 365 tenant is secure, because that is where they run. Your content stays inside the Microsoft 365 service boundary, it is not used to train the underlying models and an agent can only surface what the person asking is already allowed to open. No third-party AI tools are involved at any stage. The real security work is governance: tidy permissions, named owners and agreed review points.

The short version of that answer lives on the Agent Journey page, where it belongs next to the stages. This is the long version: what actually happens to a question, a document and an answer.

Where an agent’s answers come from

A Copilot agent is Copilot given one job, grounded on named knowledge sources such as a SharePoint site. Grounding means the agent retrieves from that content and answers with citations back to it. It does not mean the content is copied somewhere new. The documents stay in SharePoint or OneDrive, under the permissions, retention and audit arrangements they already have. The agent is a reader, not a new place your data lives.

That single fact settles most of the “where does our data go” worry: nowhere. It stays where you put it.

The service boundary, in plain English

When someone asks an agent a question, the prompt, the retrieved content and the generated answer are processed inside the Microsoft 365 service boundary: the same contractual and technical perimeter that already covers your email, files and Teams messages. Your Microsoft 365 agreement, your tenant’s data residency arrangements and Microsoft’s enterprise commitments apply to agent traffic the same way they apply to everything else in the tenant.

Two things follow. First, content is not used to train the underlying foundation models. Your engagement letters do not make the model cleverer for anyone else. Second, there is no third-party AI service in the path. Copilot, Copilot Studio and Microsoft 365 are the whole stack, which keeps the vendor list and the due diligence exactly as long as it already was.

Permissions: the inheritance rule

The rule is one sentence: an agent searches with the permissions of the person asking, per person and per question. If someone cannot open a document today, an agent will not show it to them tomorrow. There is no agent super-user account with sight of everything, and sharing an agent with a colleague does not share the content behind it, because the colleague’s own permissions apply when they ask.

The honest caveat is that agents make your existing permissions visible. A payroll spreadsheet shared with “Everyone” five years ago was always open. Once an agent starts answering questions, someone will find out. That is a reason to tidy permissions before rollout, not a reason to avoid agents, and it is standard SharePoint groundwork before grounding anything on a site.

What your admins control

Agents do not arrive outside your existing controls. Admins decide who can build and share agents and which agents are available to whom. Sensitivity labels, data loss prevention policies, retention and audit logging keep applying to the content agents read and the interactions people have with them. An agent that takes actions through Copilot Studio runs those actions through connectors your admins can see and manage, with agreed review points so a person approves anything that matters.

For firms that want a checklist for any agent, wherever it runs, the three governance questions are the right frame: what exactly can it do, which agent did what, and where is the record.

What this means for professional firms

For a practice holding client records under confidentiality duties, the position is straightforward to state to a partner or a client: agents run inside the firm’s own Microsoft 365 tenant, read only what the asking member of staff could already open, add no new vendor and leave the firm’s existing governance in force. The remaining work is the firm’s own: tidy sources, a named owner per agent and review points that match the risk of the job. The client data governance guide covers the wider Copilot picture, and the AI agents for accountancy firms page shows how the security answer sits alongside the named jobs.

If a security question is the thing standing between your firm and a first agent, a short call usually settles it.

Related reading

More on copilot agents

Copilot Agents Microsoft's Agent Governance Toolkit: Three Questions to Ask of Any Agent Microsoft's open-source Agent Governance Toolkit enforces agent rules in code, not prompts. Why that matters for firms that will never install it. Copilot Agents Copilot Agent Builder vs Copilot Studio: Which Do You Need? The plain-English difference between the agent builder in Copilot Chat and Copilot Studio, and the one question that decides between them. Copilot Agents What Is a Copilot Agent? A Plain-English Definition A plain-English definition of Microsoft Copilot agents: what they are made of, the jobs they do well, where they run and how firms go from one agent to a team. Capability map The Agent Journey Five stages from using your first Copilot agent to running a team of agents, with two doors at every stage. Copilot Governance Can You Use Microsoft Copilot with Client Data? A Practical Governance Guide Can you use Microsoft Copilot with client data? Yes, but only inside clear governance, approved tools and a review process built around risk levels. Agent builds AI agents for accountancy firms AI agents for UK accountancy firms, built in Copilot Studio: document intake, onboarding and records chasing, in your own Microsoft tenant, from £5,000. Copilot Readiness SharePoint Copilot Readiness: Preparing Your Files, Permissions and Knowledge Base SharePoint Copilot readiness is the foundation of safer AI. Fix permissions, content ownership and duplicates in the areas where Copilot will matter most. Next step Book a free consultation Share where you are now and what you want Microsoft 365 to help with next.

Common questions

Questions about Copilot agent security

Does Microsoft use our data to train its AI models?
No. Content in your Microsoft 365 tenant, including what agents read and the questions people ask them, is not used to train the underlying foundation models. Prompts and responses are processed within the Microsoft 365 service boundary under the same commitments that cover the rest of the service.
Can a Copilot agent leak documents to the wrong person?
An agent cannot show someone a document they could not already open, because it searches with the permissions of the person asking. What an agent can do is make existing oversharing visible, by answering from a document that was always too widely shared. That is a permissions problem surfacing, not a new leak, and tidying it is normal pre-agent groundwork.
Do Copilot agents need a security review before rollout?
A proportionate one, yes. For a declarative agent that only answers questions, the review is mostly about source content and audience. For a Copilot Studio agent that takes actions, review what each action can change, who approves it and how it is logged. Every agent should have a named owner and agreed review points before it is shared.
Where is the short version of this answer?
On the Agent Journey page, which carries the four security points every leader asks about first. This article is the long version, with the mechanics underneath each point.