Security & privacy
How Copilot Insights protects your data — read-only, activity-metadata-only, tenant-isolated, and Microsoft Graph native.
Security isn't a feature bolted on afterwards — it's how Copilot Insights is built. Because it is read-only and reads activity metadata only, the blast radius of any incident is low by construction. This page explains the guarantees; the legal detail lives in the Privacy Notice.
Read-only by design
Copilot Insights observes; it never writes to your tenant. It cannot reassign licences, alter or delete agents, or change any setting. Every action in the product is analysis or a recommendation — you stay in control of what actually changes.
Activity metadata only — never content
Copilot Insights reads licence assignment, usage signals and an inventory of agents. It does not access the content of Copilot prompts, chat messages, emails or files.
What it never sees
Prompt text, chat and message bodies, email contents, and document contents. If a report can be produced from metadata, that's all Copilot Insights uses.
Microsoft Graph permissions
- Connection uses standard, auditable Microsoft Graph consent — nothing to install in your tenant.
- Scopes are read-only: licence and usage reporting, plus directory read to inventory Copilot Studio agents.
- No write permissions, ever. You can revoke access from Microsoft Entra at any time, which immediately cuts Copilot Insights off from your tenant.
Tenant isolation
Every query is scoped to a single tenant, so one customer's data is never visible to another. On Enterprise and Partner plans you can self-host Copilot Insights entirely within your own Azure subscription, which isolates your data completely — see Multi-tenant.
Data anonymisation
User names in reports can be anonymised so that analysis and sharing don't expose individual identities, while still surfacing the licence and adoption insights you need. If Microsoft returns anonymised usage data, Copilot Insights shows a Names anonymised banner — the numbers remain accurate.
Hosting & your data controls
- Copilot Insights runs on Microsoft Azure (App Service + Azure SQL).
- Disconnect at any time to revoke access instantly.
- Delete your organisation and all its scan data whenever you want.
- Full detail — retention, sub-processors, your rights — is in the Privacy Notice.
Frequently asked questions
Does Copilot Insights read our users' Copilot prompts?
No. It reads activity metadata and inventory only — licence assignment, usage signals and the list of agents. Prompt, chat and file content is never accessed or stored.
Can Copilot Insights change anything in our tenant?
No. Access is read-only through Microsoft Graph, so it cannot reassign licences, alter agents or change any setting.
Can we host it in our own Azure subscription?
Yes. On Enterprise and Partner plans, Copilot Insights can be deployed entirely within your own Azure tenant, keeping all data under your governance.
