To govern Microsoft 365 Copilot interactions with Microsoft Purview, use three tools together: the audit log, where every interaction creates a CopilotInteraction record showing who used Copilot, in which app, and which files and labels it touched; a retention policy on the Microsoft Copilot experiences location, which keeps or deletes the prompts and responses stored in each user's mailbox; and eDiscovery, which searches those prompts and responses by item class and can purge them during a data spillage. Auditing is on by default; retention and eDiscovery need to be configured before you need them.
Who this is for and what you will have at the end
This guide is for compliance, security and Microsoft 365 administrators who have rolled out, or are about to roll out, Microsoft 365 Copilot and need to answer three questions: what are people doing with it, how long do we keep it, and how do we find or remove a specific conversation.
At the end you will have:
- A repeatable audit search and a PowerShell export of Copilot activity, including web search use and labelled files accessed.
- A decision on audit record retention.
- A retention policy for Copilot prompts and responses, separated from Teams chat.
- An eDiscovery search pattern for Copilot data and a tested purge procedure for spillage events.
If you haven't yet reduced oversharing in SharePoint, do that first; auditing tells you what Copilot accessed, but it doesn't stop it accessing overshared content. See Prepare a tenant for Microsoft 365 Copilot by fixing oversharing first.
Where Copilot interaction data lives
Two different records are created for each interaction, and they answer different questions:
| Audit record | Prompt and response messages | |
|---|---|---|
| Where it is stored | Unified audit log | Hidden folder in the user's Exchange Online mailbox |
| What it contains | User, time, AppHost, contexts, accessed resources with sensitivity label IDs, plugins (including web search), message IDs, model details | The text of user prompts and Copilot responses, including links and references |
| How you find it | Purview Audit, Search-UnifiedAuditLog, Management Activity API | Purview eDiscovery |
| How long it's kept | 180 days by default; longer with Audit (Premium) policies | Until a retention policy, user action or purge removes it |
| Governed by | Audit log retention policies | Retention policies and eDiscovery holds |
Messages from Microsoft 365 Copilot and Copilot Studio are captured without extra setup. Prompts and responses for other AI apps are captured only when a Purview collection policy with the setting to capture content covers them.
Prerequisites
- Audit search: the Audit Logs or View-Only Audit Logs role in the Microsoft Purview portal, and the same roles in the Exchange admin center to run audit cmdlets.
- Retention policies: permissions for data lifecycle management in Purview.
- eDiscovery: membership of the eDiscovery Manager role group to create cases and searches; the Search And Purge role to delete data (included by default in the Data Investigator and Organization Management role groups).
- Licensing: Audit (Standard) for 180-day audit records; Audit (Premium) for audit log retention policies; Microsoft Copilot interactions are included in Audit (Standard). Audit records for non-Microsoft AI apps use pay-as-you-go billing.
- PowerShell: the Exchange Online PowerShell module, and Security & Compliance PowerShell for retention cmdlets.
Step 1: Confirm auditing is on
Audit log search is on by default for enterprise organizations, but confirm it in Exchange Online PowerShell. Run this in Exchange Online PowerShell specifically; in Security & Compliance PowerShell the property always shows False.
Connect-ExchangeOnline -UserPrincipalName admin@contoso.com
Get-AdminAuditLogConfig | Format-List UnifiedAuditLogIngestionEnabledTrue means audit search is on. Audit records for core services are typically available 60 to 90 minutes after the event, and Microsoft doesn't commit to a specific time.
Step 2: Search Copilot activity in the audit log
In the Purview portal
- Sign in to the Microsoft Purview portal and open the Audit solution.
- Set the Date and time range (UTC). The maximum range is 180 days.
- In Activities - operations names, enter
CopilotInteractionexactly as written; misspelled operation names return no results. Alternatively, select Copilot under Workloads. - Optionally add Users, then select Search.
- Open the job when it completes and select Export. Export supports up to 50,000 rows with Audit (Standard) and up to 1,000,000 rows with Audit (Premium).
Each account can run up to 10 search jobs at once, completed jobs are kept for 30 days, and broad searches in large tenants can take up to 48 hours.
With PowerShell
For a scheduled report, page through results with a session ID until no more records return, then flatten the fields you care about from AuditData. Copilot-specific properties sit under CopilotEventData.
$start = (Get-Date).AddDays(-7).ToUniversalTime()
$end = (Get-Date).ToUniversalTime()
$all = @()
do {
$page = Search-UnifiedAuditLog -StartDate $start -EndDate $end -RecordType CopilotInteraction `
-SessionId "copilot-weekly" -SessionCommand ReturnLargeSet -ResultSize 5000
$all += $page
} while ($page.Count -gt 0)
$all | ForEach-Object {
$data = $_.AuditData | ConvertFrom-Json
$ev = $data.CopilotEventData
[pscustomobject]@{
TimeUtc = $data.CreationTime
User = $data.UserId
AppHost = $ev.AppHost
WebSearch = ($ev.AISystemPlugin.Id -contains 'BingWebSearch')
Files = ($ev.AccessedResources.Name -join '; ')
LabelIds = (($ev.AccessedResources.SensitivityLabelId | Where-Object { $_ }) | Sort-Object -Unique) -join '; '
}
} | Export-Csv -Path "C:\Audit\copilot-weekly.csv" -NoTypeInformationReturnLargeSet returns unsorted data and allows up to 50,000 results per session. Always use the same SessionCommand value for a session ID; mixing values limits output to 10,000 results. For larger volumes or continuous export to a SIEM, Microsoft recommends the Office 365 Management Activity API instead of scripting this cmdlet.
Fields worth reviewing
- AppHost: where the interaction happened, for example
BizChat(Microsoft 365 Copilot Chat),Word,Excel,Outlook,TeamsorSharePoint. - AccessedResources: every file, email or site Copilot read to answer, with
SensitivityLabelId,Actionand, when a policy blocked access,PolicyDetails. Use this to find interactions that touched content labelled Highly Confidential. - AISystemPlugin.Id =
BingWebSearch: Copilot used the public web via Bing for that prompt. - Messages: message IDs, an
isPromptflag and aJailbreakDetectedflag for prompts identified as jailbreak attempts. - XPIADetected on an accessed resource: a cross-prompt injection attack was detected in content Copilot read.
- AgentId and AgentName: interactions with declarative or custom-engine agents, for example those built in Copilot Studio.
- DLPEvaluationDeferred: a bitmask showing that DLP evaluation of the prompt, response, grounding or web grounding was deferred, with the reason in
DLPEvaluationDeferredReason.
Step 3: Decide how long to keep audit records
Audit (Standard) keeps records for 180 days. Under Audit (Premium), Microsoft Entra ID, Exchange, OneDrive and SharePoint records are kept for one year by default, but records for other services, including Copilot, stay at 180 days unless you create an audit log retention policy. Policies can target a service, specific activities or specific users, for up to one year, or 10 years for users with the 10-year audit log retention add-on.
If your regulator or internal policy asks for longer than 180 days of Copilot activity, either create that policy or stream records to a SIEM through the Management Activity API.
Step 4: Create a retention policy for Copilot interactions
Retention for Copilot used to share the Teams chats and Copilot interactions location. New policies use separate locations: Microsoft Copilot experiences (Microsoft 365 Copilot, Security Copilot, Copilot in Fabric, Copilot Studio), Enterprise AI apps (Entra-registered AI apps, ChatGPT Enterprise, Microsoft Foundry) and Other AI apps.
- In the Microsoft Purview portal, go to Solutions > Data Lifecycle Management > Policies > Retention policies.
- Select New retention policy and name it, for example "Copilot interactions - retain 3 years then delete".
- On Assign admin units, keep Full directory; admin units aren't supported for this policy.
- Choose Adaptive (you need an existing user adaptive scope) or Static.
- Select Microsoft Copilot experiences. By default all users are included; use Choose or Exclude to refine.
- Choose whether to retain, retain then delete, or delete only, and set the period.
- Save. The policy can take up to seven days to apply.
If you still have a combined policy, split it with Security & Compliance PowerShell. To turn an existing older-style policy into a Teams-chat-only policy:
Connect-IPPSSession -UserPrincipalName admin@contoso.com
Set-RetentionCompliancePolicy -Identity "Teams chats and Copilot" -Applications "User:TeamsChatUserInteractions"To add Microsoft 365 Copilot interactions to an existing policy that uses the newer locations:
Set-AppRetentionCompliancePolicy -Identity "Copilot and Viva Engage retention" -Applications "User:M365Copilot"Existing combined policies keep working but can't be edited once your tenant supports the separate locations.
How deletion actually happens
An Exchange timer job evaluates the hidden folder, typically every 1-7 days. Expired items move to the hidden SubstrateHolds folder, stay there for at least one day, and are permanently deleted on the next timer run. Microsoft's worked example of a delete-after-one-day policy takes 16 days to reach permanent deletion. Permanent deletion is suspended if another retention policy, Litigation Hold, delay hold or an eDiscovery hold applies to the mailbox. When a user leaves and their mailbox becomes inactive, their Copilot messages remain under the retention policy that applied before.
What users still see in Copilot isn't a reliable indicator of what is retained or deleted for compliance. Verify with eDiscovery.
Step 5: Find prompts and responses with eDiscovery
- Create an eDiscovery case.
- Create a search, add the user mailboxes as data sources, and use the Item class condition with the Copilot activity option to include all Copilot and AI app data. Narrow it with a date range and keywords.
- To target one experience, use its item class, for example:
| Experience | Item class |
|---|---|
| Microsoft 365 Copilot (all) | IPM.SkypeTeams.Message.Copilot.* |
| Microsoft 365 Copilot Chat | IPM.SkypeTeams.Message.Copilot.BizChat |
| Copilot in Word | IPM.SkypeTeams.Message.Copilot.Word |
| Copilot in Teams chat, channel or meeting | IPM.SkypeTeams.Message.Copilot.Teams |
| Copilot Studio | IPM.SkypeTeams.Message.Copilot.Studio.* |
| Entra-registered AI apps | IPM.SkypeTeams.Message.ConnectedAIApp.Entra.<AppID> |
In results and exports, a prompt appears with the user as From and the Copilot application identity (such as "Microsoft 365 Chat") as To; responses appear the other way round. Copilot memories are stored as IPM.Contact items, and deleting a conversation doesn't delete an associated memory.
Step 6: Purge Copilot data after a spillage
If a prompt or response contains data that must be removed, for example a pasted password or regulated data, use the search-and-purge workflow:
- Build and review the search so it returns only the items to delete. Check the Top Locations statistics to list affected mailboxes.
- Remove any holds and retention policies on those mailboxes, and record them so you can reapply them. Otherwise the data is retained.
- With an account that has Search And Purge, get the case ID and search ID, then call
purgeDatathrough Microsoft Graph, for example in Graph Explorer:
GET https://graph.microsoft.com/v1.0/security/cases/ediscoveryCases
GET https://graph.microsoft.com/v1.0/security/cases/ediscoveryCases/{ediscoveryCaseID}/searches
POST https://graph.microsoft.com/v1.0/security/cases/ediscoveryCases/{ediscoveryCaseID}/searches/{ediscoverySearchID}/purgeData- Reapply the holds and retention policies.
Up to 10 items per mailbox are removed per run. Purged items go to SubstrateHolds for at least a day and are permanently deleted on the next timer run, typically within 1-7 days. Users don't receive any notification.
Verify
- Use Copilot Chat with a pilot account, then search the audit log after about 90 minutes for
CopilotInteractionby that user. - Confirm your export flags web search and labelled files correctly by testing a prompt that uses web results and one that grounds on a labelled document.
- Open the retention policy in Data Lifecycle Management and confirm the distribution status shows success for Microsoft Copilot experiences.
- Run an eDiscovery search with the Copilot activity item class for the pilot user and confirm the prompt and response appear.
Troubleshooting
| Symptom | Cause and fix |
|---|---|
No CopilotInteraction records | Check UnifiedAuditLogIngestionEnabled in Exchange Online PowerShell, the operation name spelling, and allow time for ingestion. |
| PowerShell returns only 100 records | Without -SessionCommand, the cmdlet returns up to 100 results. Use ReturnLargeSet and page with a session ID. |
| Output capped at 10,000 results | ReturnLargeSet and ReturnNextPreviewPage were mixed in one session. Use one value per session ID. |
| Retention policy shows an error status | Retry distribution with Set-AppRetentionCompliancePolicy -Identity <policy> -RetryDistribution or Set-RetentionCompliancePolicy -Identity <policy> -RetryDistribution, depending on the policy type. |
| Can't edit an old "Teams chats and Copilot interactions" policy | Expected once separate locations exist. Split it with PowerShell or create new policies. |
| Deleted Copilot messages still found in eDiscovery | They are in SubstrateHolds or under a hold. Wait for the timer job, and check for other policies and holds. |
| Purge removed fewer items than expected | The limit is 10 items per mailbox per run. Repeat the purge. |
| ChatGPT Enterprise or Entra app prompts not retained | Those apps need a collection policy that captures content before retention applies. |
Closing checklist
- Audit ingestion confirmed; weekly
CopilotInteractionexport scheduled. - Web search, labelled-file access, jailbreak and XPIA flags reviewed in the export.
- Audit retention beyond 180 days decided: Audit (Premium) policy or SIEM.
- Retention policy on Microsoft Copilot experiences created and distributed; old combined policy split.
- eDiscovery search with the Copilot activity item class saved in a standing case.
- Purge procedure documented, including removing and reapplying holds.
References
- https://learn.microsoft.com/en-us/purview/audit-copilot
- https://learn.microsoft.com/en-us/office/office-365-management-api/copilot-schema
- https://learn.microsoft.com/en-us/purview/audit-search
- https://learn.microsoft.com/en-us/purview/audit-solutions-overview
- https://learn.microsoft.com/en-us/powershell/module/exchangepowershell/search-unifiedauditlog
- https://learn.microsoft.com/en-us/office/office-365-management-api/office-365-management-activity-api-schema
- https://learn.microsoft.com/en-us/purview/retention-policies-copilot
- https://learn.microsoft.com/en-us/purview/create-retention-policies
- https://learn.microsoft.com/en-us/purview/edisc-search-copilot-data