Risk · 01
One window is not one account
The updated Copilot app can hold a personal sign-in and a work or school sign-in at once. Microsoft's account guidance says the accounts, and the data behind them, stay separate. A shared window is not permission to mix a home chat with the company's files.
What the worker actually opens
Someone new to this will tap the same icon they use at home. The work side is a Microsoft Entra ID account. Microsoft Learn lists that account as a requirement for Microsoft Copilot and for Copilot Chat. If the personal account is the one signed in, the work files are not in the conversation.
What September did not change
On 25 September 2026 Microsoft set Copilot around Home, Code and Autopilot. That is a change of shelf, not a change of identity. The support note is plain: one interface, not a blend of corporate and personal context.
A fictional method uses the same rule
The FrontierOrg method is a fictional simulation, not a client and not a case study. Its mock intranet is marked simulated. It does not treat a personal login as a work identity, and it does not provision tens of thousands of real directory accounts in order to tell the story. The boundary is the point of the exercise.
Monday
Ask three people which account is signed in when they open Copilot. Write down every wrong answer. That list is the first lesson, not a new policy document.
If a colleague pastes a work paragraph into the personal account, who is supposed to notice, and when?
Sources: Microsoft Support, Copilot app updates for personal, work and school accounts (opens in a new tab). Microsoft blog, 25 September 2026, Introducing the new Copilot with Home, Code and Autopilot (opens in a new tab). Microsoft Learn, Microsoft Copilot requirements (opens in a new tab).
Where this note mentions FrontierOrg, that is a fictional method for rehearsing a decision. It is not a company, not a client, and not a case study.