Microsoft 365, Teams, Office apps and Copilot

Research date: 4 October 2026
Edition: First Microsoft 365 baseline report
Method: Review of Microsoft's public documentation. No signed-in business account was inspected and no controls were tested in a live account.

Summary

Microsoft’s AI can work across business documents and communications. Its scope depends on the licence, application, policies and enabled agents.

  • By default: The report does not establish a universal Copilot default. Ordinary features such as text predictions, suggested replies, dictation and content analysis need separate consideration.
  • Beyond the default: Drafting and analysing documents, spreadsheets, presentations and email; meeting assistance; searching work information; and Outlook actions such as moving, deleting or categorising email and managing rules.
  • Outside the immediate app: Copilot can retrieve accessible information across email, files, calendars and chats. Web search can send search terms derived from prompts and relevant content to Bing. Connected agents can introduce external sources and actions.
  • Business exposure and learning: Broad existing file permissions can make sensitive information easier to discover. Bing-generated queries have different contractual and geographic protections from Microsoft 365 prompts and responses. Business Copilot has published foundation-model no-training protections, but diagnostics and third-party agents require separate assessment.
The main exposure: AI can combine information across the business and send derived queries outside the Microsoft 365 protection boundary. Action permissions require their own review.

Business finding

Microsoft 365 covers a family of applications and services, including Word, Excel, PowerPoint, Outlook, Teams, OneDrive and SharePoint. The business should record what its subscription actually includes; it should not assume every service or AI feature is included in every plan.

A business can restrict Copilot access, cloud-based content analysis, meeting assistance and agent availability. These controls have different scopes. This review did not establish one switch that makes the whole Microsoft 365 environment AI-free.

Three distinctions matter: a personal Microsoft account differs from a managed work account; Copilot Chat differs from the licensed business Copilot experience; and hiding a button differs from blocking access. Copilot Chat is available with eligible business subscriptions even without the additional Copilot licence.[1]

Microsoft's current documentation uses the shorter names Microsoft Copilot and Microsoft Copilot Chat, while some products and licences retain the Microsoft 365 names. This report uses “business Copilot” where needed to distinguish the managed service from other products with the same name.[2]

Where is AI operating?

Writing and analysis: Copilot helps produce and work with documents, spreadsheets, presentations and email. Microsoft's release notes also describe Outlook actions such as moving, deleting and categorising messages and managing inbox rules. The assessment therefore extends beyond the wording of an AI answer. Availability depends on licence, application and rollout.[3]

Teams: Copilot can identify discussion points and suggest follow-up tasks. Depending on the configuration, it works from a saved transcript or temporary speech-to-text processing during a meeting. The absence of a saved recording does not establish that speech was not processed by AI.[14]

Ordinary-looking features: Microsoft's content-analysis list includes Editor, suggested replies, text predictions, dictation, translation, PowerPoint Designer and Excel's Analyze Data. These are not all the same technology, but they are relevant to identifying processing that staff may use without opening Copilot.[5]

Business information and agents: Business Copilot can work with accessible emails, documents, calendars and chats. Agents can extend it with information sources and actions.[2][6]

Who controls it?

For managed work accounts, the business's administrators control relevant account policies, application access, Teams settings and file permissions. Responsibility may be divided between the people managing Office applications, Teams and SharePoint.[7][4][8]

For personal accounts, users have a different set of application and privacy settings. Microsoft's personal-account Copilot checkboxes should not be assumed available to employees signed in with work accounts.[9]

Record the account type, subscription, additional Copilot licences, app versions, devices and administrators. If an IT supplier manages the account, name the business contact who can require changes and the person who can implement them.

Also check which account staff actually use for Copilot. Microsoft says chats, files, permissions and protections remain separate between personal and work sign-ins. A business subscription does not automatically place an employee's personal Copilot session under the business's controls.[1]

What can the business switch off?

Managed Office applications

Administrators can use Microsoft's Cloud Policy or Group Policy controls, including Allow the use of connected experiences in Office that analyze content. The policies also apply to Microsoft 365 Apps for business.[7]

Microsoft says turning off content-analysis experiences disables Copilot features in current versions of Word, Excel, PowerPoint, Outlook and OneNote on the listed Windows, Mac, iOS and Android devices. That statement should not be extended to every browser, Teams meeting or external agent.[2]

Copilot Chat and agents

Microsoft documents blocking Copilot Chat for all or selected users across supported experiences. Administrators should use the current Copilot and app-management controls for their account. Unpinning Copilot Chat does not remove access.[1]

Review agents separately in the Microsoft 365 admin centre's Agent Registry. Microsoft documents enabling, assigning, blocking and removing agents. It also says Researcher and Analyst are core Copilot experiences and do not fall under agent-related settings.[6]

Teams meetings and calls

Use Teams admin centre → Meetings → Meeting policies → Recording & transcription → Copilot to review meeting policy. Microsoft's Off policy sets the organiser's default to Off, but organisers can change it. Treat it as a default rather than proof of a business-wide prohibition.[4]

Review call policies separately under Voice → Calling policies; meeting settings are not a complete assessment of Teams calls.[10]

Personal Microsoft accounts used for business work

On supported Windows desktop apps, use File → Options → Copilot, clear Enable Copilot, then restart the app. On Mac, use the application's Preferences → Authoring and Proofing Tools → Copilot. These settings apply separately to each app and device.[9]

For personal-account Outlook, Microsoft documents Settings → Copilot in new Outlook and the web version, and Copilot under Quick Settings on other listed platforms. Its guidance says the equivalent app checkbox is unavailable in web, iOS and Android versions of Word, Excel and PowerPoint.[9]

What information and actions can the business restrict?

Information or capability What to review
Emails, files, calendars and chats Existing permissions determine which business information Copilot can surface. Review access before relying on it as an AI safeguard.[2]
Copilot Chat information access Staff can supply files and text, use open content in supported apps, use connected agents, or obtain work context through Outlook. It is not always limited to public web information.[11]
SharePoint discovery Eligible accounts can restrict discovery of selected sites; this does not revoke existing file access.[8]
Web search Copilot can derive search terms from prompts and relevant content and send them to Bing. A separate administrator policy controls this route.[12]
Actions and external agents Check the agent's permissions, connections, provider terms and operations it can perform.[6]

Shared files

Review SharePoint and OneDrive sharing links, groups and permissions. As a practical implication, information shared too widely can also be surfaced too widely through AI assistance.

Where licensed, Restricted Content Discovery can be configured through SharePoint admin centre → Sites → Active sites → select a site → Settings → Restrict content from Microsoft Copilot. Microsoft describes this as a temporary discovery control. It does not apply to OneDrive sites or prevent every use of an already accessible document, including summarising an open file. Changes can take time to propagate.[8]

Web search and processing location

Review Allow web search in Copilot in Cloud Policy. Turning it off stops that Bing-query route, rather than switching off the underlying AI.[12]

Microsoft distinguishes Bing queries from prompts and responses held within Microsoft 365. Its documentation says the Microsoft 365 Data Protection Addendum and EU Data Boundary do not apply to generated web queries. For a business assessing where information goes, this is a separate route to record.[12]

Actions

Inspect what enabled tools can change as well as what they can read. Microsoft's Outlook release notes describe confirmation for bulk email actions and inbox-rule changes; they do not establish that every individual action across Microsoft 365 needs approval. A universal switch separating all reading from all actions was not established by this review.[3]

Can the business refuse use of its information for training?

Microsoft says business Copilot prompts, responses and information accessed through Microsoft Graph are not used to train foundation language models. Its work-account Copilot Chat guidance also says prompts and responses are not used to train foundation models. These are published protections, rather than participation the business must refuse through a training switch.[15]

For Copilot inside Microsoft 365 apps for home, Microsoft also says personal data collected through connected experiences is not used to train large language models. This should not be extended into a blanket statement about every consumer Microsoft service or external agent.[13]

“Not used to train foundation models” does not mean “not processed, stored or used for any improvement.” Microsoft separately says optional Office diagnostic data may be used in aggregate to train and improve machine-learning experiences, including text predictions and contextual help. Administrators can review Configure the level of client software diagnostic data sent by Office to Microsoft. Required service data remains a separate category.[7]

Check third-party agents' terms independently. The business should record the service, account and data route to which each protection applies.

How can the business check that its choices worked?

The following are proposed business checks, rather than claims of testing completed for this report:

  1. Record subscriptions, account types, app versions, assigned policies, affected users and dates.
  2. Check saved controls and policy assignments for each relevant user and device.
  3. Test Copilot Chat access through the app, browser, Outlook and Teams. A missing shortcut alone is insufficient.
  4. Use harmless files to test open-document assistance separately from searches across shared business information.
  5. Hold a test Teams meeting. Check what the organiser can change, whether another participant can activate assistance, and whether speech processing occurs without a saved transcript.
  6. Review enabled agents, connections and any scheduled or automated work. Use test records to check retained action capabilities.
  7. Where available, review usage reports, audit records and retention settings. Copilot Chat logs prompts and responses, but available controls depend on the subscription.[11][1]

Microsoft says meeting prompts and responses may remain under compliance retention even where recording and transcription are off. Include retained AI exchanges in the evidence review, rather than checking only for a recording file.[14]

These checks provide evidence about access and behaviour. They do not independently prove that every background AI process has stopped or that the provider's training protections have been implemented in every case.

What does the business lose, retain or need to replace?

Disabling Copilot assistance removes related drafting, analysis and summarising functions. Staff may need to produce documents, analyse figures, manage email and write meeting notes manually. These are proposed working alternatives; this report did not measure the resulting time or cost.

Disabling content-analysis experiences can also remove useful features beyond Copilot. Some basic Editor and text-prediction functions remain locally available in specified situations. Check actual app behaviour.[5]

Turning off all connected Office experiences is broader still: Microsoft says it affects functions such as co-authoring and online file storage. Outlook mailbox synchronisation, Teams and essential licensing services can continue. A broad privacy control therefore has different business consequences from restricting one AI feature.[7]

At meeting level, setting Copilot to Off also turns off recording and transcription for that meeting. Plan how the business will retain an agreed record if one is needed.[4]

Removing shared access or restricting discovery can make information harder to find. Assess the benefit of reduced exposure alongside the effect on legitimate work. For retained AI, measure useful time savings against checking effort, corrections and any additional licence or usage costs.

Control assessment

Requirement Finding
Disable Copilot in managed Office apps Documented content-analysis policies; app and device scope matters.
Block Copilot Chat Documented access controls; unpinning is insufficient.
Restrict meeting AI Separate Teams controls; policy Off is an organiser-adjustable default.
Restrict access to shared information Permissions are fundamental; discovery restrictions have limits.
Stop Bing web-query processing Separate documented web-search policy.
Restrict agents and actions Agent controls and permissions require separate review.
Prevent foundation-model training Published protections for the relevant Microsoft 365 services; other routes need checking.
Verify complete absence of AI processing Not established from published information reviewed.

Sources and scope

All sources below are official Microsoft documentation checked on 4 October 2026. This report covers Microsoft 365 applications, Teams, relevant SharePoint and OneDrive information access, business Copilot and Copilot Chat. It also distinguishes personal-account Office controls because small businesses may use those accounts.

It is not a complete audit of Windows AI, every Edge feature, Azure, Dynamics 365, Power Platform or external agents. Published features and release notes do not establish availability in a particular account. Provider statements are not independent verification of implementation.

  1. Manage Microsoft Copilot Chat
  2. Data, privacy and security for Microsoft Copilot
  3. Microsoft 365 Copilot release notes
  4. Manage Copilot in Teams meetings and events
  5. Connected experiences in Office
  6. Manage agents in the Microsoft 365 admin centre
  7. Manage privacy controls for Microsoft 365 Apps
  8. Restrict discovery of SharePoint sites and content
  9. Turn off Copilot in Microsoft 365 apps — personal accounts
  10. Manage Copilot in Teams calls
  11. Copilot Chat privacy and protections
  12. Data, privacy and security for Copilot web search
  13. Copilot in Microsoft 365 apps for home: data and privacy
  14. Use Copilot without transcribing or recording a Teams meeting or call
  15. Data protection for Copilot Chat used with a work or school account

Unresolved: account-specific rollout and policy availability; complete coverage of all access routes; universal separation of reading from action permissions; restrictions in externally organised meetings; independent verification of background processing and training protections.

Changes since previous Microsoft 365 report: None. This establishes the first Microsoft 365 baseline for subsequent monthly research.