AI engineering

Audit, Retain and Search Microsoft 365 Copilot Prompts with Purview

Find Copilot interactions in the Purview audit log, keep or delete prompts and responses with a retention policy, and search or purge them with eDiscovery when something goes wrong.

11 min read
On this page

To govern Microsoft 365 Copilot interactions with Microsoft Purview, use three tools together: the audit log, where every interaction creates a CopilotInteraction record showing who used Copilot, in which app, and which files and labels it touched; a retention policy on the Microsoft Copilot experiences location, which keeps or deletes the prompts and responses stored in each user's mailbox; and eDiscovery, which searches those prompts and responses by item class and can purge them during a data spillage. Auditing is on by default; retention and eDiscovery need to be configured before you need them.

Who this is for and what you will have at the end

This guide is for compliance, security and Microsoft 365 administrators who have rolled out, or are about to roll out, Microsoft 365 Copilot and need to answer three questions: what are people doing with it, how long do we keep it, and how do we find or remove a specific conversation.

At the end you will have:

  • A repeatable audit search and a PowerShell export of Copilot activity, including web search use and labelled files accessed.
  • A decision on audit record retention.
  • A retention policy for Copilot prompts and responses, separated from Teams chat.
  • An eDiscovery search pattern for Copilot data and a tested purge procedure for spillage events.

If you haven't yet reduced oversharing in SharePoint, do that first; auditing tells you what Copilot accessed, but it doesn't stop it accessing overshared content. See Prepare a tenant for Microsoft 365 Copilot by fixing oversharing first.

Where Copilot interaction data lives

Two different records are created for each interaction, and they answer different questions:

Audit recordPrompt and response messages
Where it is storedUnified audit logHidden folder in the user's Exchange Online mailbox
What it containsUser, time, AppHost, contexts, accessed resources with sensitivity label IDs, plugins (including web search), message IDs, model detailsThe text of user prompts and Copilot responses, including links and references
How you find itPurview Audit, Search-UnifiedAuditLog, Management Activity APIPurview eDiscovery
How long it's kept180 days by default; longer with Audit (Premium) policiesUntil a retention policy, user action or purge removes it
Governed byAudit log retention policiesRetention policies and eDiscovery holds

Messages from Microsoft 365 Copilot and Copilot Studio are captured without extra setup. Prompts and responses for other AI apps are captured only when a Purview collection policy with the setting to capture content covers them.

Prerequisites

  • Audit search: the Audit Logs or View-Only Audit Logs role in the Microsoft Purview portal, and the same roles in the Exchange admin center to run audit cmdlets.
  • Retention policies: permissions for data lifecycle management in Purview.
  • eDiscovery: membership of the eDiscovery Manager role group to create cases and searches; the Search And Purge role to delete data (included by default in the Data Investigator and Organization Management role groups).
  • Licensing: Audit (Standard) for 180-day audit records; Audit (Premium) for audit log retention policies; Microsoft Copilot interactions are included in Audit (Standard). Audit records for non-Microsoft AI apps use pay-as-you-go billing.
  • PowerShell: the Exchange Online PowerShell module, and Security & Compliance PowerShell for retention cmdlets.

Step 1: Confirm auditing is on

Audit log search is on by default for enterprise organizations, but confirm it in Exchange Online PowerShell. Run this in Exchange Online PowerShell specifically; in Security & Compliance PowerShell the property always shows False.

Connect-ExchangeOnline -UserPrincipalName admin@contoso.com
Get-AdminAuditLogConfig | Format-List UnifiedAuditLogIngestionEnabled

True means audit search is on. Audit records for core services are typically available 60 to 90 minutes after the event, and Microsoft doesn't commit to a specific time.

Step 2: Search Copilot activity in the audit log

In the Purview portal

  1. Sign in to the Microsoft Purview portal and open the Audit solution.
  2. Set the Date and time range (UTC). The maximum range is 180 days.
  3. In Activities - operations names, enter CopilotInteraction exactly as written; misspelled operation names return no results. Alternatively, select Copilot under Workloads.
  4. Optionally add Users, then select Search.
  5. Open the job when it completes and select Export. Export supports up to 50,000 rows with Audit (Standard) and up to 1,000,000 rows with Audit (Premium).

Each account can run up to 10 search jobs at once, completed jobs are kept for 30 days, and broad searches in large tenants can take up to 48 hours.

With PowerShell

For a scheduled report, page through results with a session ID until no more records return, then flatten the fields you care about from AuditData. Copilot-specific properties sit under CopilotEventData.

$start = (Get-Date).AddDays(-7).ToUniversalTime()
$end   = (Get-Date).ToUniversalTime()
$all   = @()
 
do {
    $page = Search-UnifiedAuditLog -StartDate $start -EndDate $end -RecordType CopilotInteraction `
        -SessionId "copilot-weekly" -SessionCommand ReturnLargeSet -ResultSize 5000
    $all += $page
} while ($page.Count -gt 0)
 
$all | ForEach-Object {
    $data = $_.AuditData | ConvertFrom-Json
    $ev   = $data.CopilotEventData
    [pscustomobject]@{
        TimeUtc    = $data.CreationTime
        User       = $data.UserId
        AppHost    = $ev.AppHost
        WebSearch  = ($ev.AISystemPlugin.Id -contains 'BingWebSearch')
        Files      = ($ev.AccessedResources.Name -join '; ')
        LabelIds   = (($ev.AccessedResources.SensitivityLabelId | Where-Object { $_ }) | Sort-Object -Unique) -join '; '
    }
} | Export-Csv -Path "C:\Audit\copilot-weekly.csv" -NoTypeInformation

ReturnLargeSet returns unsorted data and allows up to 50,000 results per session. Always use the same SessionCommand value for a session ID; mixing values limits output to 10,000 results. For larger volumes or continuous export to a SIEM, Microsoft recommends the Office 365 Management Activity API instead of scripting this cmdlet.

Fields worth reviewing

  • AppHost: where the interaction happened, for example BizChat (Microsoft 365 Copilot Chat), Word, Excel, Outlook, Teams or SharePoint.
  • AccessedResources: every file, email or site Copilot read to answer, with SensitivityLabelId, Action and, when a policy blocked access, PolicyDetails. Use this to find interactions that touched content labelled Highly Confidential.
  • AISystemPlugin.Id = BingWebSearch: Copilot used the public web via Bing for that prompt.
  • Messages: message IDs, an isPrompt flag and a JailbreakDetected flag for prompts identified as jailbreak attempts.
  • XPIADetected on an accessed resource: a cross-prompt injection attack was detected in content Copilot read.
  • AgentId and AgentName: interactions with declarative or custom-engine agents, for example those built in Copilot Studio.
  • DLPEvaluationDeferred: a bitmask showing that DLP evaluation of the prompt, response, grounding or web grounding was deferred, with the reason in DLPEvaluationDeferredReason.

Step 3: Decide how long to keep audit records

Audit (Standard) keeps records for 180 days. Under Audit (Premium), Microsoft Entra ID, Exchange, OneDrive and SharePoint records are kept for one year by default, but records for other services, including Copilot, stay at 180 days unless you create an audit log retention policy. Policies can target a service, specific activities or specific users, for up to one year, or 10 years for users with the 10-year audit log retention add-on.

If your regulator or internal policy asks for longer than 180 days of Copilot activity, either create that policy or stream records to a SIEM through the Management Activity API.

Step 4: Create a retention policy for Copilot interactions

Retention for Copilot used to share the Teams chats and Copilot interactions location. New policies use separate locations: Microsoft Copilot experiences (Microsoft 365 Copilot, Security Copilot, Copilot in Fabric, Copilot Studio), Enterprise AI apps (Entra-registered AI apps, ChatGPT Enterprise, Microsoft Foundry) and Other AI apps.

  1. In the Microsoft Purview portal, go to Solutions > Data Lifecycle Management > Policies > Retention policies.
  2. Select New retention policy and name it, for example "Copilot interactions - retain 3 years then delete".
  3. On Assign admin units, keep Full directory; admin units aren't supported for this policy.
  4. Choose Adaptive (you need an existing user adaptive scope) or Static.
  5. Select Microsoft Copilot experiences. By default all users are included; use Choose or Exclude to refine.
  6. Choose whether to retain, retain then delete, or delete only, and set the period.
  7. Save. The policy can take up to seven days to apply.

If you still have a combined policy, split it with Security & Compliance PowerShell. To turn an existing older-style policy into a Teams-chat-only policy:

Connect-IPPSSession -UserPrincipalName admin@contoso.com
Set-RetentionCompliancePolicy -Identity "Teams chats and Copilot" -Applications "User:TeamsChatUserInteractions"

To add Microsoft 365 Copilot interactions to an existing policy that uses the newer locations:

Set-AppRetentionCompliancePolicy -Identity "Copilot and Viva Engage retention" -Applications "User:M365Copilot"

Existing combined policies keep working but can't be edited once your tenant supports the separate locations.

How deletion actually happens

An Exchange timer job evaluates the hidden folder, typically every 1-7 days. Expired items move to the hidden SubstrateHolds folder, stay there for at least one day, and are permanently deleted on the next timer run. Microsoft's worked example of a delete-after-one-day policy takes 16 days to reach permanent deletion. Permanent deletion is suspended if another retention policy, Litigation Hold, delay hold or an eDiscovery hold applies to the mailbox. When a user leaves and their mailbox becomes inactive, their Copilot messages remain under the retention policy that applied before.

What users still see in Copilot isn't a reliable indicator of what is retained or deleted for compliance. Verify with eDiscovery.

Step 5: Find prompts and responses with eDiscovery

  1. Create an eDiscovery case.
  2. Create a search, add the user mailboxes as data sources, and use the Item class condition with the Copilot activity option to include all Copilot and AI app data. Narrow it with a date range and keywords.
  3. To target one experience, use its item class, for example:
ExperienceItem class
Microsoft 365 Copilot (all)IPM.SkypeTeams.Message.Copilot.*
Microsoft 365 Copilot ChatIPM.SkypeTeams.Message.Copilot.BizChat
Copilot in WordIPM.SkypeTeams.Message.Copilot.Word
Copilot in Teams chat, channel or meetingIPM.SkypeTeams.Message.Copilot.Teams
Copilot StudioIPM.SkypeTeams.Message.Copilot.Studio.*
Entra-registered AI appsIPM.SkypeTeams.Message.ConnectedAIApp.Entra.<AppID>

In results and exports, a prompt appears with the user as From and the Copilot application identity (such as "Microsoft 365 Chat") as To; responses appear the other way round. Copilot memories are stored as IPM.Contact items, and deleting a conversation doesn't delete an associated memory.

Step 6: Purge Copilot data after a spillage

If a prompt or response contains data that must be removed, for example a pasted password or regulated data, use the search-and-purge workflow:

  1. Build and review the search so it returns only the items to delete. Check the Top Locations statistics to list affected mailboxes.
  2. Remove any holds and retention policies on those mailboxes, and record them so you can reapply them. Otherwise the data is retained.
  3. With an account that has Search And Purge, get the case ID and search ID, then call purgeData through Microsoft Graph, for example in Graph Explorer:
GET  https://graph.microsoft.com/v1.0/security/cases/ediscoveryCases
GET  https://graph.microsoft.com/v1.0/security/cases/ediscoveryCases/{ediscoveryCaseID}/searches
POST https://graph.microsoft.com/v1.0/security/cases/ediscoveryCases/{ediscoveryCaseID}/searches/{ediscoverySearchID}/purgeData
  1. Reapply the holds and retention policies.

Up to 10 items per mailbox are removed per run. Purged items go to SubstrateHolds for at least a day and are permanently deleted on the next timer run, typically within 1-7 days. Users don't receive any notification.

Verify

  1. Use Copilot Chat with a pilot account, then search the audit log after about 90 minutes for CopilotInteraction by that user.
  2. Confirm your export flags web search and labelled files correctly by testing a prompt that uses web results and one that grounds on a labelled document.
  3. Open the retention policy in Data Lifecycle Management and confirm the distribution status shows success for Microsoft Copilot experiences.
  4. Run an eDiscovery search with the Copilot activity item class for the pilot user and confirm the prompt and response appear.

Troubleshooting

SymptomCause and fix
No CopilotInteraction recordsCheck UnifiedAuditLogIngestionEnabled in Exchange Online PowerShell, the operation name spelling, and allow time for ingestion.
PowerShell returns only 100 recordsWithout -SessionCommand, the cmdlet returns up to 100 results. Use ReturnLargeSet and page with a session ID.
Output capped at 10,000 resultsReturnLargeSet and ReturnNextPreviewPage were mixed in one session. Use one value per session ID.
Retention policy shows an error statusRetry distribution with Set-AppRetentionCompliancePolicy -Identity <policy> -RetryDistribution or Set-RetentionCompliancePolicy -Identity <policy> -RetryDistribution, depending on the policy type.
Can't edit an old "Teams chats and Copilot interactions" policyExpected once separate locations exist. Split it with PowerShell or create new policies.
Deleted Copilot messages still found in eDiscoveryThey are in SubstrateHolds or under a hold. Wait for the timer job, and check for other policies and holds.
Purge removed fewer items than expectedThe limit is 10 items per mailbox per run. Repeat the purge.
ChatGPT Enterprise or Entra app prompts not retainedThose apps need a collection policy that captures content before retention applies.

Closing checklist

  • Audit ingestion confirmed; weekly CopilotInteraction export scheduled.
  • Web search, labelled-file access, jailbreak and XPIA flags reviewed in the export.
  • Audit retention beyond 180 days decided: Audit (Premium) policy or SIEM.
  • Retention policy on Microsoft Copilot experiences created and distributed; old combined policy split.
  • eDiscovery search with the Copilot activity item class saved in a standing case.
  • Purge procedure documented, including removing and reapplying holds.

References

Questions people ask

Where are Microsoft 365 Copilot prompts and responses stored?

They are stored in a hidden folder in the Exchange Online mailbox of the user who used Copilot. Users and administrators can't open that folder directly; compliance administrators find the messages with eDiscovery, and retention policies for Copilot act on them there.

Does the audit log contain the text of Copilot prompts?

The CopilotInteraction audit record describes the interaction: who, when, which app hosted it, which files and sites Copilot accessed and their sensitivity labels, whether web search was used, and message IDs. The prompt and response text itself is found through eDiscovery, because it is stored in the user's mailbox.

How long are Copilot audit records kept?

Audit (Standard) keeps audit records for 180 days. With Audit (Premium) you can create audit log retention policies to keep records for other services, such as Copilot, for up to one year, and up to 10 years for users who also have the 10-year audit log retention add-on.

If I set a Copilot retention policy to delete after one day, when is the data gone?

Not after one day. Deletion runs through timer jobs that typically take 1-7 days, and items sit in the SubstrateHolds folder for at least a day before permanent deletion. Microsoft's own example shows a delete-after-one-day policy can take 16 days before a message stops appearing in eDiscovery.

Microsoft 365 CopilotMicrosoft PurvieweDiscoveryAuditData Lifecycle Management
  1. Set Up Microsoft Purview DSPM for AI to Audit and Govern Copilot Interactions

    Turn on auditing, activate the DSPM for AI one-click policies, run data risk assessments and read Copilot prompts and responses in activity explorer and the unified audit log.

    AI engineering11 min read
  2. Control Web Search in Microsoft 365 Copilot and Copilot Chat: Admin Guide

    Allow, restrict or disable Bing web grounding for Copilot and Copilot Chat with the Cloud Policy setting, and understand exactly what leaves the tenant.

    AI engineering11 min read
  3. Prepare a Tenant for Microsoft 365 Copilot by Fixing Oversharing First

    Find overshared SharePoint and OneDrive content with Data access governance reports and DSPM, contain it with RCD and RAC, then hand cleanup to site owners before Copilot rollout.

    AI engineering14 min read