Forum Discussion
deactivate the Microsoft Copilot Consumer App
You can manage the consumer Copilot app separately from Microsoft 365 Copilot, but scope controls to the exact app rather than a broad Copilot domain block. Inventory the installed consumer package and determine whether users also access its website. For managed Windows, pilot an Intune uninstall assignment or Windows App Control policy targeting only that package. If web access must be blocked, use your approved filtering control and retest Microsoft 365 Copilot. In Defender for Cloud Apps, connector apps can appear automatically sanctioned. Marking one unsanctioned is primarily a discovery/governance action; automatic blocking requires Defender for Endpoint integration with Network Protection or another supported stream. Do not unsanction shared Microsoft dependencies. Test a small device group, then verify work-account Copilot in Microsoft 365 apps, Teams, and the web before expanding. Narrow targeting should leave Microsoft 365 Copilot unaffected because its packages and endpoints are excluded