Aller au contenu principal

Configure Microsoft 365 Copilot memory controls

Implementation Effort: Low – A targeted administrative decision to set the tenant and group-level personalization control, review the retention and deletion behavior, and confirm how data subject requests will be handled.
User Impact: Low – The control is set by an administrator; where memory is left enabled, users keep their existing personalization experience, and where it is disabled, the personalization surfaces are turned off for the affected users.

Overview

Microsoft 365 Copilot can personalize responses by remembering details a user saves, details it infers from chat history, and custom instructions. This memory is governed by the Enhanced personalization control, which is turned on by default and draws on a user's Microsoft 365 communication data — such as Teams chats and Outlook mail — to make Copilot more useful to that individual. Because memory is on by default and is built from personal communication data, an organization needs to make a deliberate decision about whether that personalization is appropriate for the whole tenant or only for specific groups, rather than letting the default stand unexamined. This activity is that decision: configuring the personalization control at the tenant or group level and understanding the behavior that comes with it, including that memories are stored in a hidden folder in the user's Exchange mailbox and inherit mailbox protections like Customer Lockbox and encryption at rest, and that turning the control off stops Copilot from applying memories but does not delete them.

This supports Use least privilege access because it lets the organization limit which populations have a Copilot experience built from private communication data, keeping personalization scoped to where it is wanted rather than broadly enabled by default. It supports Assume breach by requiring administrators to understand the retention and deletion model up front — including that Purview retention policies do not apply to Copilot personalization memory and that data subject requests for this memory are served through eDiscovery and Microsoft Graph — so deletion and investigation paths are known before they are needed. The risk of not making this decision is that a personalization store derived from users' confidential communications is enabled tenant-wide without review, its data lands outside the retention controls administrators assume are covering it, and the organization discovers the gap only when it must respond to a deletion or investigation request it is not prepared to handle.

Reference