Blog Post

Microsoft 365 Copilot Blog
3 MIN READ

Updates to Microsoft Copilot to bring enterprise data protection to more organizations

Seth_Patton's avatar
Seth_Patton
Icon for Microsoft rankMicrosoft
Aug 15, 2024

Next month, we are making several updates to the free Microsoft Copilot service for users with a Microsoft Entra account to enhance data security, privacy, and compliance and simplify the user experience. For users signed in with an Entra account, Microsoft Copilot will offer enterprise data protection (EDP) and redirect users to a new simplified, ad-free user interface designed for work and education.

 

Enterprise data protection 
For users signed in with an Entra account [1], Microsoft Copilot will offer enterprise data protection. EDP will be available for these users at no additional cost. EDP refers to controls [2] and commitments, under the Data Protection Addendum and Product Terms, that apply to customer data for users of Copilot for Microsoft 365 and Microsoft Copilot [3]. This means that security, privacy, and compliance controls and commitments available for Copilot for Microsoft 365 will extend to Microsoft Copilot prompts and responses. Prompts and responses are protected by the same terms and commitments that are widely trusted by our customers—not only for Copilot for Microsoft 365, but also for emails in Exchange and files in SharePoint. 

 

With EDP in Microsoft Copilot:  

  • We secure your data: We help protect your data with encryption, at rest and in transit, rigorous physical security controls, and data isolation between tenants.  
  • Your data is private: We won’t use your data except as you instruct. Our commitments to privacy include support for GDPR, ISO/IEC 27018 [4], and the Data Protection Addendum.

  • Your access controls and policies apply to Copilot [5]: Prompts and responses are logged, retained, and available for audit, eDiscovery, and advanced Microsoft Purview capabilities. The specific controls will vary depending on the underlying subscription plan. 
  • You are protected against AI security risks: We help safeguard against AI-focused risks such as harmful content and prompt injections.   
  • Your data isn’t used to train foundation models: Prompts and responses are not used to train foundation models 

 

Simplified experience 

We’ve also responded to customer feedback with a new simplified, ad-free Copilot user interface designed for work and education. And to help people get started quickly, we’re introducing prompt examples relevant to work and education scenarios. 

 

Starting in mid-September, you will be able to experience Microsoft Copilot at Microsoft.com/copilot and in the Microsoft 365 app, and it will be coming soon to Microsoft Teams and Outlook. To ensure people across your organization have easy access to Microsoft Copilot and can benefit from the security and experience updates to Copilot, enable in-app access today.

 

The option to pin Copilot can be found under Settings on the Copilot page in the Microsoft 365 admin center (Global Admin permissions required).

Image of a settings page with options to agree or disagree pinning. The page includes toggle switches for each option, allowing the user to select their preference.

 

 To learn more about these updates, head to our FAQ. And be sure to check back here for more announcements and updates in the weeks to come. 

 

________________________________________________________________________________________________

[1] Government cloud customers and students under 18 are not yet eligible.

[2] The specific controls will vary depending on the underlying subscription plan.

[3] The use of the term EDP is not meant to limit the benefits offered under the Data Protection Addendum and Product Terms. The specific controls will vary depending on the underlying subscription plan.

[4] Microsoft Copilot for Microsoft 365 runs on the ISO 27018 certified Microsoft 365 platform. Microsoft Copilot will start rolling out to the same platform in the second half of September 2024 for users signed in with a Microsoft Entra account.

[5] EDP experience may vary based on your Entra account service SKU.

Updated Aug 15, 2024
Version 1.0

36 Comments

  • JonKilner's avatar
    JonKilner
    Brass Contributor

    When we deployed Copilot we implemented HTTP Header Injection to ensure all visits to Copilot require CDP https://learn.microsoft.com/en-us/copilot/manage#require-commercial-data-protection-in-

     

    Are there any additional sites that we need to add HTTP Headers to in order to 'Require Enterprise Data Protection'? 

  • TANDA151's avatar
    TANDA151
    Copper Contributor

    Hi Seth, this is great news. Will it also apply to the Web content plug-in for Copilot M365, that is also using the Copilot/Bing experience ?

  • TobiasAT's avatar
    TobiasAT
    Iron Contributor

    What is the behavior of users who do not have a Copilot for Microsoft 365 license, e.g. if the app is pinned in Outlook, Microsoft 365 Apps, and other apps where a Copilot for Microsoft 365 license is necessary? Does the user get the usual message he should ask for a license? 
    Second, what happens if the Copilot service plan is disabled for an account and the app is pinned for the users?


    As noted in the documentation:

    If you choose to pin Microsoft Copilot for all users, it will be pinned in the Microsoft 365 app for desktop, mobile, and web starting mid-September. Microsoft Copilot will be pinned in Microsoft Teams, Microsoft Outlook, and the Microsoft 365 web app soon after.

     

     

  • koolhand_k's avatar
    koolhand_k
    Brass Contributor

    Thanks Greg_C_Gilbert picking up the distinction.

     

    And TranissaCreme_PMM  thanks for that clarification.

    I'd strongly recommend that it is set out clearly in a single page in the documentation. I think most people won't note the distinction, or understand implementation.

    The only place where the comparison between "Commercial Data Protection" and "Enterprise Data Protection" is clarified is here in your comment - there doesn't appear to be any official documentation with both terms on it. 

    As a customer, it was already very difficult to read the tea leaves for how CDP worked on its own

    • vaguely contradictory statements in different places
    • alarming DNS-based implementation
    • pieces of information spread between InTune, Windows, Edge, Copilot, Copilot M365 and Purview documentation

    Then by adding EDP over the top - I think most people won't even quite realise those are two mechanisms, and when they do, it's hard to understand the differences.

    I think it will really help customers if that's all laid out on a single page, for clarity, with a table setting out differences between treatment for

    • non-M365 customers
    • non-Copilot-for-M365 customers
    • M365 customers with CDP DNS hackaround implemented
    • M365 customers with EDP implemented (are implementation steps even required?)

    with ticks and crosses for what & what doesn't happen in each scenario.

    The clarifying what's needed for implementation:

    • does EDP require the CDP implementation steps
    • if not, what is CDP on its own
    • do users need to be told to log in, for it to even take effect
    • etc

    That would make a world of difference for customers. Thanks for your consideration.

  • Greg_C_Gilbert - With EDP, Microsoft Copilot customers will receive the following benefits (compared to what is currently offered with commercial data protection)

    • Prompts and responses will stay within the Microsoft 365 service boundary, and all associated data handling commitments will apply—including support for GDPR, and ISO/IEC 27018 (Copilot for Microsoft 365 runs on the ISO 27018 certified Microsoft 365 platform)  
    • Prompts and responses can be logged and have retention policies applied to them 
    • Prompt and responses will be available for eDiscovery and other Purview capabilities 
    • Commercial use of Microsoft Copilot will be covered by the Data Protection Addendum for all prompts and responses 
    • Ads will not be displayed in Copilot chat web scope 

    For a full definition of EDP, review the EDP public documentation.

  • What is the difference between Enterprise Data Protection and Commercial Data Protection which has been in the product since it was Bing Chat Enterprise?