AB-900 - Understand data protection and governance tasks for Microsoft 365 and Copilot - Section 2.2

Understand how Copilot accesses data and the controls that constrain what it can surface.

How Copilot accesses data, how Microsoft Graph influences Copilot responses, how Copilot honours existing permissions and Purview and Defender controls, and responsible AI principles. The central idea is that Copilot inherits the user's existing permissions, so an oversharing problem becomes a Copilot problem.

Microsoft GraphCopilot honours existing permissionssemantic indexresponsible AI principlesCopilot data residency and boundaries

Practice question for this objective

Free sampleUnderstand data protection and governance tasks for Microsoft 365 and Copilothard

During a data residency review, an organisation in the European Union must confirm where Microsoft 365 Copilot processes the tenant's data. Which statement correctly describes how Copilot handles data location and boundaries?

  • ACopilot copies the tenant's data to a shared public model for training before returning any response.
  • BCopilot processes the request within the Microsoft 365 service boundary and honours the tenant's data residency commitments. Correct
  • CCopilot stores every prompt indefinitely in a region chosen at random to balance load.
  • DCopilot bypasses tenant residency settings because generative processing must occur in the United States.
Microsoft 365 Copilot processes data inside the Microsoft 365 service boundary and honours the tenant's data residency commitments. Copilot grounds its answers on tenant content accessed through Microsoft Graph and runs within the Microsoft 365 trust boundary, so it inherits the same residency and compliance commitments as the tenant and does not train foundation models on customer data.

Why A is wrong: Tempting because people worry generative AI trains on their content, but Microsoft states that tenant data is not used to train the foundation models, so this describes a boundary violation that does not occur.

Why B is correct: Correct: Copilot operates inside the Microsoft 365 trust and compliance boundary, grounding responses on tenant content through Microsoft Graph while honouring the tenant's data residency commitments, which is what the residency review needs to confirm.

Why C is wrong: Tempting because load balancing is real in cloud services, but Copilot does not place customer data in random regions or retain prompts outside governed compliance and residency controls, so this contradicts the data boundary model.

Why D is wrong: Tempting because some early cloud services centralised processing, but Copilot is bound by the same Microsoft 365 residency commitments as the rest of the service, so it does not override them by forcing processing to one country.

See more AB-900 practice questions, answers explained.

More in this domain

Back to all Understand data protection and governance tasks for Microsoft 365 and Copilot objectives, or the AB-900 cert hub.

Examworthy is not affiliated with or endorsed by Microsoft. Original, blueprint-aligned practice material only.