How Copilot Accesses Data
Microsoft 365 Copilot retrieves only the work content a user already has permission to access, grounded through Microsoft Graph and the semantic index.
Microsoft 365 Copilot grounds responses in data retrieved through Microsoft Graph, querying only content the signed-in user already has permission to open. It inherits the user’s existing SharePoint, Exchange, and Teams permissions at query time rather than keeping a separate store. Sensitivity labels and encryption applied via Microsoft Purview travel with documents, so Copilot cannot summarize content whose usage rights block the user. The exam nuance: Copilot will surface content a user can access even if overshared, so reducing exposure means fixing upstream permissions, not reconfiguring Copilot.
PlayPrepHQ study notes are written and reviewed against primary exam sources. How we create & review content →