Microsoft Copilots commercial data protection now for Office 365
Microsoft Copilot
Feb 29, 2024 1:00 AM

Protect Office 365 with Microsoft Copilots commercial data protection now in E1, E3, E5, F3, Business Basic at no extra cost!

Key insights


  • Commercial Data Protection (CDP) for Microsoft Copilot is now available in Office 365 E1, E3, E5, Microsoft 365 F3, and Microsoft 365 Business Basic, enhancing security at no extra cost.
  • Microsoft Copilot, powered by GPT-4 and DALL-E 3, offers AI-driven chat capabilities across the web, providing access to current information and creative solutions while aligning with AI principles.
  • Commercial data protection ensures user and organizational data are safeguarded by not saving prompts and responses, prohibiting visual access by Microsoft, and not using chat data for model training.
  • Differences in Copilot features with commercial data protection include no chat history retention and no support for 3rd-party plugins/actions to protect commercial data.
  • Accessibility of Copilot with commercial data protection is extended to users with eligible work or school accounts, demonstrating Microsoft's commitment to data security across its services.

Understanding Microsoft Copilot and Its Commercial Data Protection

Microsoft Copilot stands out as an innovative AI companion designed to streamline daily tasks and promote creativity across various fields. Harnessing the power of advanced AI models like GPT-4 and DALL-E 3, it offers users unique capabilities to analyze data, search for information, and generate creative content. Copilot is integrated into a wide array of platforms, including its own web service, Microsoft Edge, and Windows, as well as through mobile apps, making it highly accessible.

The introduction of Commercial Data Protection (CDP) into Microsoft Copilot for users of Office 365 E1, E3, E5, and other Microsoft 365 suites marks a significant advancement in how data security is handled within AI-powered services. This protection ensures that sensitive user and organizational data are kept secure, adhering to the highest standards of privacy and confidentiality. CDP's implementation addresses potential security concerns by preventing the storage of prompts and responses, restricting Microsoft's access to the data, and ensuring that commercial information is not used to refine AI models further.

The impact of CDP on feature availability within Copilot should also be noted. With CDP, users experience some temporary changes, like the absence of chat history and third-party integrations, underscoring a robust approach to data protection. Despite these differences, the core functionality of Copilot remains a vital asset for users seeking efficient, AI-powered assistance in their daily digital interactions.

In light of these developments, Microsoft Copilot with Commercial Data Protection emerges not just as a tool for enhanced productivity and creativity but also as a benchmark for privacy and security in the use of AI technologies. It mirrors Microsoft's commitment to innovating responsibly, ensuring that users across all sectors can leverage the benefits of AI while confidently knowing their data is protected.


Commercial data protection for Microsoft Copilot for Office 365 is now available across Office 365 E1, E3, and E5; Microsoft 365 F3; and Microsoft 365 Business Basic. This enhanced protection ensures that by simply using enterprise credentials, users can activate this feature. Importantly, it secures data without storing any prompts or responses, blocking Microsoft from visual access and restricting the use of chat data for model training.

It is notable that this protection is provided at no extra cost across all key Office 365 product tiers. An overview of Copilot with commercial data protection reveals that Microsoft Copilot, previously known as Bing Chat Enterprise, serves as an AI companion. It aids in various tasks such as industry research, data analysis, and sourcing inspiration, ensuring users find better answers, improved efficiency, and new creative avenues.

Microsoft Copilot is powered by GPT-4 and DALL-E 3, providing up-to-date, transparent responses based on the Bing search index. Its design adheres to Microsoft’s AI principles, making it broadly accessible through multiple platforms. When business or educational organizations utilize commercial data protection, they assure both user and organizational data’s safety. Notably, this includes no saving of prompts or responses, no Microsoft access, and no use of data to train large language models.

There are distinct feature differences when using Copilot with commercial data protection, such as no chat history and the non-support of 3rd-party plugins/actions. These measures are put in place to ensure the highest level of data security for users. While some features are temporarily limited, the overall intent is to provide robust data protection within the Copilot experience.


"How secure is Microsoft 365 Copilot?"

Microsoft 365 Copilot adheres to the stringent privacy, security, and compliance frameworks applied to Microsoft 365 commercial customers. This includes adherence to the General Data Protection Regulation (GDPR) and the establishment of a European Union (EU) Data Boundary.

"What is commercial data protection for Microsoft Copilot?"

Copilot ensures the protection of user and business data, preventing any leakage outside an organization. Microsoft guarantees that chat data within Copilot is not recorded, and they do not have the ability to access this data directly. Additionally, this chat data is not utilized for the training of their underlying models.

"Does Microsoft Copilot use my data?"

Microsoft 365 Copilot utilizes content and context via Microsoft Graph, connecting Large Language Models (LLMs) to an organization's data to deliver its functionality. Despite this access, Microsoft clarifies that customer data is not employed in the training processes of their large language models.

"Is Microsoft Copilot Hipaa compliant?"

The deployment of Microsoft Copilot Studio is fully recognized under the Health Insurance Portability and Accountability Act (HIPAA) through the Business Associate Agreement (BAA), ensuring adherence to relevant regulations.



