Insights

Microsoft 365 Copilot agents and the data they can reach

Written by Jonathan Da Dalto | Jul 22, 2026 11:43:47 AM

Microsoft has moved Copilot from suggesting to acting. Through 2026, dedicated Word, Excel and PowerPoint agents have appeared in Copilot Chat, each able to turn a plain-language request into a finished draft, a working spreadsheet or a complete deck. The in-app version, Agent Mode, reached general availability on 22 April 2026, and a Planner agent has joined the set.

The productivity gain is plain. In a regulated business the question that repays attention is governance: what these agents are permitted to reach, and whether you can show, on demand, that the limits hold.

To build something useful, an agent reads across your Microsoft 365 environment, drawing on the mailboxes, the SharePoint sites and the files in OneDrive that the user already has the right to open. Microsoft is explicit that Copilot and its agents can reach data held in Exchange Online, SharePoint and OneDrive. That access goes through Microsoft Graph, the part of Microsoft 365 that connects Copilot to an organisation’s data and enforces the same permissions that apply to the user, so an agent can open only what that person could already open. Files the agents create in OneDrive inherit the organisation’s retention rules and sensitivity labels.

So an agent does not widen who can see what. What it changes is speed and reach: a person’s existing access becomes a polished, shareable file in seconds rather than hours. That shift is the thing to govern.

Two controls carry most of the load, and both are already available. Microsoft Purview can read a prompt as it is typed and, where it finds defined sensitive information such as account numbers or flagged project terms, stop the prompt from being processed at all: no response is generated, and none of your data is read to answer it. That control applies to the prebuilt agents as well as to chat. The second works from sensitivity labels: a policy can keep Copilot from drawing on labelled files, so a document marked confidential stays outside an agent’s reach.

What sets a Copilot agent’s reach

  1. 1

    Existing permissions: an agent can open only what the user can already open, through Microsoft 365’s own permission checks.

  2. 2

    Sensitivity labels: a Purview policy can keep labelled files from being used.

  3. 3

    Prompt-level DLP: Purview can block a prompt carrying sensitive information before it is processed, prebuilt agents included.

Neither control sets itself. Each rests on labelling that is accurate and consistently applied, and on a policy that someone has written, scoped and tested.

For a compliance officer the boundary matters less than the proof of it. A regulator or auditor asking how client and regulated data is protected expects more than an assurance that Copilot has been set up sensibly. These controls supply that proof: a Purview policy is a written, testable rule, and the sensitivity labels it reads are visible and reportable. The weak position is an arrangement nobody can point to.

Regulatory note

What a regulator can be shown

In a regulated business, controls over client and personal data have to be demonstrable. A Purview DLP policy and the sensitivity labels it reads are auditable artefacts: a written rule and a reportable state. An undocumented arrangement is not.

That is where to look. The capability is already present in your Microsoft 365 environment, open to licensed and unlicensed users alike once an administrator switches it on. For a regulated business holding client and sensitive data, the test is simpler than the technology. Can you say, today, what your Copilot agents are allowed to reach, and who drew that line?

For Penta clients, those controls – prompt-level data loss prevention, label-based restriction and the labelling beneath them – are configured, managed and evidenced as part of the service. There is nothing to action. For anyone else, the question stands: if you cannot name who has set those limits in your Microsoft 365 environment, that is the gap we fill.

 

References

  1. Microsoft 365 Blog – Copilot’s agentic capabilities in Word, Excel and PowerPoint are generally available, 22 April 2026. https://www.microsoft.com/en-us/microsoft-365/blog/2026/04/22/copilots-agentic-capabilities-in-word-excel-and-powerpoint-are-generally-available/
  2. Microsoft Learn – Create files with Word, Excel, and PowerPoint Agents in Microsoft 365 Copilot. https://learn.microsoft.com/en-us/microsoft-365/copilot/wordexcelppt-agents
  3. Microsoft Learn – Learn about using Microsoft Purview Data Loss Prevention to protect interactions with Microsoft 365 Copilot and Copilot Chat. https://learn.microsoft.com/en-us/purview/dlp-microsoft365-copilot-location-learn-about
  4. Microsoft Learn – Use Microsoft Purview to manage data security and compliance for Microsoft 365 Copilot and Copilot Chat. https://learn.microsoft.com/en-us/purview/ai-m365-copilot
  5. Microsoft Community Hub – Introducing Word, Excel and PowerPoint Agents in Microsoft 365 Copilot, 18 November 2025. https://techcommunity.microsoft.com/blog/microsoft365copilotblog/introducing-word-excel-and-powerpoint-agents-in-microsoft-365-copilot/4470604
  6. Microsoft Security Blog – Safeguarding sensitive data in Microsoft 365 Copilot interactions: DLP for Microsoft 365 Copilot, 21 April 2026. https://techcommunity.microsoft.com/blog/microsoft-security-blog/safeguarding-sensitive-data-in-microsoft-365-copilot-interactions-dlp-for-micros/4512497