More governance controls for Copilot data in Microsoft Purview

As Microsoft 365 Copilot becomes a larger part of everyday work, governance and compliance requirements are evolving alongside it. Recent Microsoft Purview announcements focus less on new Copilot capabilities and more on the policies, retention controls, and user guidance needed to support enterprise adoption.

In this post, we'll look at three updates that affect how organizations manage Copilot data, apply retention policies, and help users understand why access to certain content may be restricted.

Retention support arrives for Microsoft 365 Copilot Memory

As Microsoft 365 Copilot becomes more personalized, organizations are also facing new questions around governance, retention, and discoverability of that information. Microsoft is now addressing part of that challenge by bringing Copilot Memory into Microsoft Purview Data Lifecycle Management.

Copilot Memory includes saved memories, details inferred from previous interactions, and custom instructions that help tailor the Copilot experience to individual users. With this update, organizations will be able to retain historical versions of memory items when they are modified or deleted.

The change is particularly relevant for organizations with regulatory, legal, or records-management requirements. Historical versions can be preserved according to retention settings and made available for compliance activities, eDiscovery, and internal investigations, extending governance capabilities to a part of Copilot that was previously outside the scope of Microsoft Purview retention policies and retention labels.

Retained memory versions will be stored in a hidden folder within the user's Exchange Online mailbox and inherit existing mailbox security protections. Authorized administrators will also be able to use Microsoft Purview eDiscovery to search and investigate this content.

Rollout is expected to begin in late September 2026 and complete by mid-October 2026. As always, Microsoft timelines may change.

More information:

Legacy Teams retention policies will no longer apply to Copilot interactions

Some organizations currently rely on Teams retention policies to govern both Teams conversations and Copilot interactions. Microsoft is now updating that behavior by separating Teams and Copilot retention controls.

Some existing Microsoft Purview retention policies that currently govern both Teams content and Copilot interactions will be treated as Teams-only policies following this change. While retention behavior for Teams content remains unchanged, those same policies will no longer implicitly retain or delete Copilot interactions.

Organizations that currently rely on Teams retention policies to govern Copilot interactions should review their configuration before the rollout. Microsoft states that retention and deletion requirements for Copilot must be managed through policies specifically configured for the Copilot workload.

The announcement follows Microsoft's recent introduction of retention support for Copilot Memory, another step in building compliance and governance capabilities specifically for Copilot data.

Rollout is expected to begin in late October 2026 and complete by mid-November 2026. As always, Microsoft timelines may change.

More information:

Organizations can now provide custom guidance when Copilot access is blocked

Governance controls are most effective when users understand why they're encountering them. Microsoft is introducing a new Microsoft Purview Data Loss Prevention (DLP) capability that allows organizations to replace the default documentation link shown in Copilot data access messages with a destination of their own.

Today, when a DLP policy prevents Microsoft 365 Copilot from accessing or processing content, users are presented with a message explaining that access has been restricted by organizational policy. The included Learn about access restrictions link currently directs users to Microsoft's DLP documentation. With this update, organizations can instead direct users to internal compliance guidance, governance documentation, support resources, or help desk processes.

The message itself remains unchanged, including its wording and localization. Organizations that do not configure a compliance URL will continue using Microsoft's default documentation.

This is a small but important technical change, as it may help reduce confusion when users encounter policy restrictions in Copilot. Rather than being sent to generic documentation, users can be directed to guidance that reflects their organization's policies and support processes.

The feature is not enabled automatically. A compliance URL must be configured within the applicable DLP rule before users will see an organization-specific destination. Where multiple DLP policies apply, only the URL associated with the winning policy tip will be displayed.

Rollout began in late September 2026 and is expected to complete by mid-October 2026 across all supported environments. As always, Microsoft timelines may change.

More information:

While new Copilot features often receive the most attention, effective adoption also depends on the controls that sit behind the experience. Retention, eDiscovery, data lifecycle management, and user guidance all play an important role in helping organizations use AI while meeting compliance and governance requirements.

Taken together, these announcements suggest Microsoft is continuing to treat Copilot as a distinct workload within Microsoft 365, with dedicated controls and policies rather than relying on functionality originally designed for other services. For organizations investing in Copilot, that is likely to become increasingly important as adoption grows.

If you'd like to stay up to date with Microsoft 365, Copilot, Teams, security, compliance, and AI-related announcements, you can follow me on LinkedIn:

Comments