You control web search in Microsoft 365 Copilot (now named Microsoft Copilot) and Copilot Chat with one setting: the Allow web search in Copilot policy in the Cloud Policy service for Microsoft 365, which can enable web search in both, disable it in both, or disable it only in Copilot Work mode. When web search is on, Copilot sends Bing a short generated query of a few words with user and tenant identifiers removed; prompts and responses stay inside Microsoft 365, but those generated queries fall outside the Data Protection Addendum and the EU Data Boundary.
Who this is for and what you will have at the end
This guide is for Microsoft 365 administrators, privacy officers and security teams who need a defensible decision on web grounding before or during a Copilot rollout. Some organizations want web results for general research but not mixed into answers about internal documents, and some regulated tenants need web search off entirely.
At the end you will have:
- A clear picture of what Copilot sends to Bing and which contractual terms cover it.
- A Cloud Policy configuration that sets web search per group, with priorities that resolve overlaps.
- An understanding of the user-level Web content toggle and how it interacts with your policy.
- A way to audit the web queries Copilot generated, and a checklist for Copilot Studio agents that have their own web setting.
How web search works in Copilot
When web search is enabled and information from the web would improve a response, Copilot parses the prompt, identifies the terms that need web data, and generates a search query for the Bing search service. The query isn't the prompt. It's a few words informed by the prompt.
These items aren't included in the generated query:
- The user's entire prompt, unless the prompt is very short, such as "local weather".
- Entire Microsoft 365 files, such as emails or documents, or files uploaded into Copilot.
- Entire web pages or PDFs summarized by Copilot Chat in Microsoft Edge.
- Identifying information from the user's Microsoft Entra account, such as username, domain or tenant ID.
In licensed Copilot, organizational content can still inform the query in two cases: when the user prompts Copilot inside an app with a relevant document open, and when the user explicitly references a document. Microsoft's example: a user asks Copilot to summarize an internal clean energy strategy and check whether Fabrikam announced something similar. The query sent to Bing is along the lines of "Fabrikam clean energy policy announcements". The document itself isn't sent, but a theme from it is.
That last point is the one to explain to your privacy team. Web search doesn't upload documents, but a generated query can carry a word or phrase derived from internal content.
What leaves the tenant and under which terms
| Data | Where it goes | Terms that apply | Microsoft's role |
|---|---|---|---|
| Prompts and responses | Stored in Microsoft 365, inside the service boundary | Enterprise data protection, Data Protection Addendum, Product Terms | Data processor |
| Generated web search queries | Bing search service, identifiers removed | Product Terms commitments, which supersede the Microsoft Services Agreement and Microsoft Privacy Statement where they conflict | Data controller |
The Product Terms add these commitments for the generated queries:
- Microsoft has no rights to them other than as needed to provide the service.
- They aren't used to improve Bing, to build advertising profiles or to track users.
- They aren't shared with advertisers or used to train generative AI foundation models.
- They're treated as customer confidential information.
They also don't affect Bing search ranking, rich captions, or social features such as autosuggest and trending.
The exclusions matter as much as the commitments. The Microsoft Products and Services Data Protection Addendum doesn't apply to generated web search queries, and neither do HIPAA compliance or the EU Data Boundary. If any of those is a hard requirement for a user population, web search has to be off for that population.
Prerequisites
| Item | Requirement |
|---|---|
| Admin role | Office Apps Administrator (recommended), Security Administrator or Global Administrator |
| Portal | Microsoft 365 Apps admin center at config.office.com, or Intune admin center Apps > Policy > Policies for Office apps |
| Licensing | A Microsoft 365 plan that includes Microsoft 365 Apps; Microsoft 365 operated by 21Vianet isn't supported |
| Groups | Microsoft Entra groups of user objects; device objects are ignored; nesting up to three levels |
| Cloud | GCC High uses config.office365.us; DoD uses config.apps.mil |
Choose the policy value
The Allow web search in Copilot policy is available only in Cloud Policy and applies to both Microsoft Copilot and Copilot Chat.
| Policy state | Microsoft Copilot | Copilot Chat | User toggle |
|---|---|---|---|
| Enabled: Enabled in Microsoft Copilot and Microsoft Copilot Chat | Web search on | Web search on | On by default; users can turn it off |
| Enabled: Disabled in Microsoft Copilot and Microsoft Copilot Chat | Off | Off | Off and dimmed |
| Enabled: Disabled in Microsoft Copilot Work mode; Enabled in Microsoft Copilot Web mode and Microsoft Copilot Chat | Off in Work mode, on in Web mode | On | Available where web search is allowed; users can turn it off |
| Not configured (commercial) | On, unless optional connected experiences are disabled | On, unless optional connected experiences are disabled | On by default |
| Not configured (GCC, DoD) | Off | Off | Off |
Two details change real outcomes:
- The split option (Disabled in Microsoft Copilot Work mode; Enabled in Microsoft Copilot Web mode and Microsoft Copilot Chat) also disables web search in Researcher and Cowork. Microsoft recommends web search for getting the most value from Researcher, Analyst and Cowork, so tell users who rely on them.
- Disabling Allow the use of additional optional connected experiences in Office also stops web search when the Copilot policy isn't configured, but it restricts Copilot Chat, Copilot and many other Microsoft 365 experiences. Use the dedicated Copilot policy instead.
Step 1: Create the tenant-wide configuration
- Sign in to
config.office.comand accept the terms if this is your first visit. - Under Customization, select Policy Management, then Create.
- On Start with the basics, enter a name such as
Copilot web search - defaultand a description, then select Next. - On Choose the scope, select the users this applies to. For the baseline, choose all users. Select Next.
- On Configure Settings, search for
Allow web search in Copilot. Open it, set it to Enabled, choose the option you decided on, and save. - Select Next, review, and select Create.
A common baseline is Disabled in Microsoft Copilot Work mode; Enabled in Microsoft Copilot Web mode and Microsoft Copilot Chat, which keeps web results separate from answers grounded in organizational data. Regulated tenants usually choose Disabled for everyone as the baseline.
Step 2: Add exceptions for specific groups
- Select Create again and name the configuration for its purpose, for example
Copilot web search - research teamorCopilot web search - off for clinical staff. - On Choose the scope, select Add Groups and pick the Entra groups. One configuration can target several groups.
- Configure Allow web search in Copilot with the value for that group and create the configuration.
- On the Policy configurations page, select Reorder priority. When a user is in several targeted groups with conflicting values, the configuration with the highest priority wins, and
0is the highest. Put your restrictive exceptions above the baseline.
Cloud Policy settings take precedence over Group Policy and local settings. Microsoft doesn't publish a specific propagation time for this Copilot policy. For Office apps, Cloud Policy check-ins happen every 90 minutes for users in targeted groups (every 24 hours otherwise), and app policies apply when the app restarts, so allow time before testing.
Step 3: Tell users about the Web content toggle
When web search is allowed, users have a Web content toggle that's on by default. Turning it off removes web content from their responses, and the preference persists across sessions, clients and devices. In the Microsoft Copilot app, users find it under Settings > Personalization > Advanced > Web search.
The toggle can only restrict. If your policy disables web search, the toggle is off and dimmed and users can't turn it on. The user-level privacy setting for optional connected experiences in Word, Excel or Teams has no effect on Copilot web search.
Step 4: Cover Copilot Studio agents separately
Agents built in Copilot Studio have their own Use information from the web setting (shown as Web Search on the agent's Overview page), which uses Grounding with Bing Search and searches all public sites indexed by Bing. The Cloud Policy setting governs Copilot and Copilot Chat; makers control the agent setting.
To find agents with web search turned on, use the Copilot Studio agent inventory in the Power Platform admin center. Its knowledge properties include IsWebSearchEnabledForKnowledge, which is true when the agent can use web search as a knowledge source. Agents grounded on internal content usually shouldn't have it; the SharePoint knowledge source guide explains turning it off to keep answers inside a filtered source.
Audit the queries Copilot sends
Turning web search on doesn't mean losing visibility:
- Citations for users. In Copilot Chat, the citation section of a response shows the exact web search queries sent to Bing. These are available in the chat thread for 24 hours and aren't shown in the Copilot pane inside Word or PowerPoint.
- Audit and eDiscovery. Web search queries are logged, so you can search, audit and run eDiscovery on them with the same tools you use for Copilot prompts and responses.
- DSPM for AI. Activity explorer in Microsoft Purview Data Security Posture Management for AI shows the web search terms alongside the prompt, response and supporting resources.
- Policy changes. Cloud Policy creation, deletion, setting changes and priority changes are recorded in the Microsoft Purview audit log when auditing is on.
Verify the configuration
- Sign in as a test user in each targeted group and open Copilot Chat.
- Check the Web content toggle. For disabled groups it should be off and dimmed.
- Ask a question that needs current public information. For enabled groups, the response should include web citations with the generated queries; for disabled groups, it shouldn't.
- In Copilot, test Work mode and Web mode separately if you used the split option.
- In Purview, search for the test user's Copilot activity and confirm the web queries appear.
Troubleshooting
| Symptom | Likely cause | Fix |
|---|---|---|
| Web results still appear after disabling | Policy not yet applied, or a higher-priority configuration enables it for the user | Wait for check-in and restart the app; review Reorder priority |
| Policy doesn't apply to a group | Group contains devices, not users, or nesting deeper than three levels | Target user objects; flatten the group |
| Researcher no longer uses the web | Split option disables web search in Researcher and Cowork | Give those users a higher-priority configuration with web search enabled |
| Web search off for everyone in a GCC tenant | Default in GCC and DoD | Configure the policy to enable it where approved |
| Many Office features stopped working | Optional connected experiences disabled to stop web search | Re-enable them and use the Copilot web search policy |
| A user turned the toggle on but gets no web results | Admin policy disables web search | Expected; the toggle can't override the policy |
Closing checklist
- Privacy review done on generated queries: no DPA, HIPAA or EU Data Boundary coverage.
- Baseline Allow web search in Copilot configuration created for all users.
- Exception configurations created for specific groups and ordered by priority.
- Optional connected experiences left enabled.
- Users told about the Web content toggle and the Researcher impact of the split option.
- Copilot Studio agents with
IsWebSearchEnabledForKnowledgereviewed. - Web queries visible in Purview Audit and DSPM for AI.
If you're still preparing the rollout itself, the Copilot license assignment checklist covers prerequisites and licensing.
References
- Data, privacy, and security for web search in Microsoft Copilot and Microsoft Copilot Chat
- Microsoft Copilot Chat privacy and protections
- Overview of Cloud Policy service for Microsoft 365
- Microsoft Copilot requirements
- Knowledge sources summary - Microsoft Copilot Studio
- Microsoft Copilot Studio agent inventory schema