The Core Principle: Context is Everything
The most important thing to understand about Copilot is that it operates within strict boundaries defined by your user identity and the application you are currently using. When you use Copilot in a Word document opened from your work OneDrive, it operates with the permissions
and context of your work account. Conversely, if you're drafting a party plan in a document saved to your personal OneDrive, Copilot uses your personal account context. The system is designed to prevent data from unintentionally leaking between your different digital lives. Your prompts, the data Copilot accesses, and the responses it generates all remain within the Microsoft 365 service boundary tied to the account associated with the file.
Data Protection is Based on the File's Home
Microsoft has emphasized that data protection policies are always based on the identity used to access the file, not the account that provides the Copilot license. This ensures that even if you're using a personal Copilot Pro license, your company's data protection rules are still enforced when you work on a corporate document. Copilot respects all existing security frameworks, including access controls and sensitivity labels. It can only surface content that a user already has permission to see. This means Copilot cannot be used to bypass existing permissions; if you can't access a file directly, neither can Copilot on your behalf.
Understanding 'Multiple Account Access'
Microsoft has a feature called "multiple account access" for Copilot in apps like Word, Excel, and PowerPoint. This allows a Copilot license from one account (e.g., your personal subscription) to be used on documents owned by a different signed-in account (e.g., your work account). However, this doesn't mean your personal AI is reading your work files without restriction. The work account's security and privacy settings still apply to the work document. It’s more of a licensing convenience. Company administrators have the ability to disable this feature for their organization if they want to ensure only company-provided Copilot licenses can be used on work documents.
Switching Between Worlds
To reduce confusion, Microsoft has been working to unify the Copilot experience and make it easier to see which account is active. Recent updates include an account switcher directly within the Copilot side pane in apps like the new Outlook for Windows. This allows you to explicitly see and change which account context Copilot is using without needing to sign out and back in. This is especially helpful for consultants or IT admins who manage multiple work tenants. For a cleaner separation, some users find it helpful to use different browser profiles for their work and personal accounts, and then install Copilot as a separate app for each profile.
What About Data Training?
A common concern with AI is whether personal or company data is used to train the models. For commercial customers signed in with a work or school account, Microsoft states that prompts, responses, and data accessed through Microsoft Graph are not used to train the foundation large language models (LLMs). Your company’s data stays within your company's Microsoft 365 tenant. For personal accounts, users have privacy controls to opt out of having their conversation activity used for model training. The key is that work and personal data streams are designed to remain separate.














