Craig Stanley
Home / Capabilities / Copilot Chat / What Copilot Chat can see, and what it can't

What Copilot Chat can see, and what it can't

Copilot Chat is grounded in the web by default. Here's how organisational data gets in, what protections apply, and what that means for decisions.

· 3 min read · Craig Stanley
In short, explained

The free work helper mostly reads the internet. It only reads your work files if you show them to it, open them next to it, or use it inside your email.

Copilot Chat comes with most work Microsoft 365 plans at no extra cost. It answers from the web unless you give it your own content: by uploading a file, using it beside a document you have open, using it in Outlook, or using a paid-per-use agent that can reach company data.

Copilot Chat (Basic) grounds in web data and has no Microsoft Graph access. Organisational content enters via the prompt (paste, upload, / file reference), open content in the Word, Excel and PowerPoint agents or Edge, Copilot Chat in Outlook (lexical indexing), or agents grounded in shared tenant data. Enterprise data protection applies; prompts and responses are logged for audit and eDiscovery and aren't used to train foundation models. Access to some capabilities is "standard", subject to capacity.

What it is

Microsoft Copilot Chat is the AI chat included with eligible Microsoft 365 work plans. Microsoft's documentation now calls it Microsoft Copilot Chat, after a rename from Microsoft 365 Copilot Chat. People reach it in the Copilot app, in the Edge sidebar, and inside Outlook and Teams.

For anyone deciding whether Copilot Chat is enough for a team, the most useful thing to understand is what it can see.

By default, the web

Microsoft's privacy page says Copilot Chat "is not grounded in organizational content like files, emails, or chats as part of the chat experience", and that it's grounded in web data. When web grounding is on, Copilot sends short search queries generated from the prompt to Bing, without user or tenant identifiers.

So a question like "what's our travel policy?" won't be answered from your intranet unless the policy has been given to it some other way.

How work content gets in

Microsoft lists four routes. People can include content in the prompt by pasting it, uploading a file, or picking a file by typing "/". They can use Copilot Chat with open content, for example in the Word, Excel and PowerPoint agents, where it can see only the file that's open. They can use Copilot Chat in Outlook, where Microsoft says it can access the user's emails, calendar, meetings, chats and a limited set of files, such as files shared with them or ones they've recently worked on. Or they can use an agent grounded in shared tenant data, such as a SharePoint site.

The paid Microsoft 365 Copilot licence is different: it grounds answers in work data automatically through Microsoft Graph and Work IQ. See What the paid Copilot licence adds.

The protections

Microsoft says Copilot Chat has enterprise data protection when people sign in with a work account, shown by a green shield in the interface. Prompts and responses are processed within the Microsoft 365 service boundary, logged and stored for audit and eDiscovery, and not used to train the underlying foundation models. Your sensitivity labels and retention policies apply.

Microsoft's overview also notes that Copilot Chat has "standard" access to features such as file upload, image generation and some models, which depends on service capacity. Licensed users get priority access.

What this means for decisions

Copilot Chat is a good fit for the find-and-summarise job when the information is public or when someone deliberately hands it the relevant document. It's weaker when the decision needs context spread across many internal files that the person wouldn't think to upload.

There's a governance upside to that. Because Copilot Chat only sees work content when it's handed over or open, the oversharing risk that comes with automatic Graph grounding is smaller. People still need to know not to paste content they shouldn't, and data loss prevention policies are the control for that.

A worked example

This scenario is illustrative. A procurement officer is choosing between two shortlisted suppliers. In Copilot Chat, they upload both tender responses and ask for a side-by-side comparison against the published criteria, then ask it to check each supplier's public news from the last year. Both tasks fit Copilot Chat well. If they wanted it to also check past emails with each supplier, they'd need to ask from Copilot Chat in Outlook or use a licensed Copilot.

What I'm still checking

I'd like to confirm how the new Home experience, which merges Chat and Cowork, changes what unlicensed Copilot Chat users see. Microsoft's pricing table currently shows Cowork as unavailable in Copilot Chat and metered for licensed users, but the experience is changing quickly.

Sources

Read next

A question to take awayWhich of these do you already pay for and not use?

About me

Craig Stanley

Microsoft AI consultant and technical architect, based in Whitley Bay. Over the last few years I've delivered Microsoft 365 Copilot, Copilot Studio agents, Microsoft Foundry (formerly Azure AI Foundry) work and governance for UK public sector and financial services organisations.

What interests me is the decision underneath the tool: what it costs, what it risks, and whether a small, transparent model can make it better. I write the methods up here and on Substack so anyone can use them.

I write this site to learn in public: explaining each idea simply is how I check I understand it. Why I write this site.

Find me