Microsoft 365 Copilot agents and the data they can reach
The new Copilot agents build documents, spreadsheets and presentations from a single prompt. For a business in a regulated sector, the question worth asking is what those agents are allowed to see.
Microsoft has moved Copilot from suggesting to acting. Through 2026, dedicated Word, Excel and PowerPoint agents have appeared in Copilot Chat, each able to turn a plain-language request into a finished draft, a working spreadsheet or a complete deck. The in-app version, Agent Mode, reached general availability on 22 April 2026, and a Planner agent has joined the set.
The productivity gain is plain. In a regulated business the question that repays attention is governance: what these agents are permitted to reach, and whether you can show, on demand, that the limits hold.
To build something useful, an agent reads across your Microsoft 365 environment, drawing on the mailboxes, the SharePoint sites and the files in OneDrive that the user already has the right to open. Microsoft is explicit that Copilot and its agents can reach data held in Exchange Online, SharePoint and OneDrive. That access goes through Microsoft Graph, the part of Microsoft 365 that connects Copilot to an organisation’s data and enforces the same permissions that apply to the user, so an agent can open only what that person could already open. Files the agents create in OneDrive inherit the organisation’s retention rules and sensitivity labels.
So an agent does not widen who can see what. What it changes is speed and reach: a person’s existing access becomes a polished, shareable file in seconds rather than hours. That shift is the thing to govern.
Two controls carry most of the load, and both are already available. Microsoft Purview can read a prompt as it is typed and, where it finds defined sensitive information such as account numbers or flagged project terms, stop the prompt from being processed at all: no response is generated, and none of your data is read to answer it. That control applies to the prebuilt agents as well as to chat. The second works from sensitivity labels: a policy can keep Copilot from drawing on labelled files, so a document marked confidential stays outside an agent’s reach.
Neither control sets itself. Each rests on labelling that is accurate and consistently applied, and on a policy that someone has written, scoped and tested.
For a compliance officer the boundary matters less than the proof of it. A regulator or auditor asking how client and regulated data is protected expects more than an assurance that Copilot has been set up sensibly. These controls supply that proof: a Purview policy is a written, testable rule, and the sensitivity labels it reads are visible and reportable. The weak position is an arrangement nobody can point to.
That is where to look. The capability is already present in your Microsoft 365 environment, open to licensed and unlicensed users alike once an administrator switches it on. For a regulated business holding client and sensitive data, the test is simpler than the technology. Can you say, today, what your Copilot agents are allowed to reach, and who drew that line?
For Penta clients, those controls – prompt-level data loss prevention, label-based restriction and the labelling beneath them – are configured, managed and evidenced as part of the service. There is nothing to action. For anyone else, the question stands: if you cannot name who has set those limits in your Microsoft 365 environment, that is the gap we fill.
Jonathan Da Dalto is Compliance Manager at Penta. He advises financial institutions on regulatory compliance, IT governance, and cyber resilience, with a focus on FINMA’s evolving supervisory requirements. Jonathan has extensive experience guiding boards and senior management teams in Geneva and across Switzerland to align technology risk management with business strategy and regulatory expectations.
We all seem to use many Microsoft products, from Teams to Word. Well, now, Microsoft is releasing a new tool to increase productivity by linking the...