AI engineering

Control Web Search in Microsoft 365 Copilot and Copilot Chat: Admin Guide

Allow, restrict or disable Bing web grounding for Copilot and Copilot Chat with the Cloud Policy setting, and understand exactly what leaves the tenant.

11 min read
On this page

You control web search in Microsoft 365 Copilot (now named Microsoft Copilot) and Copilot Chat with one setting: the Allow web search in Copilot policy in the Cloud Policy service for Microsoft 365, which can enable web search in both, disable it in both, or disable it only in Copilot Work mode. When web search is on, Copilot sends Bing a short generated query of a few words with user and tenant identifiers removed; prompts and responses stay inside Microsoft 365, but those generated queries fall outside the Data Protection Addendum and the EU Data Boundary.

Who this is for and what you will have at the end

This guide is for Microsoft 365 administrators, privacy officers and security teams who need a defensible decision on web grounding before or during a Copilot rollout. Some organizations want web results for general research but not mixed into answers about internal documents, and some regulated tenants need web search off entirely.

At the end you will have:

  • A clear picture of what Copilot sends to Bing and which contractual terms cover it.
  • A Cloud Policy configuration that sets web search per group, with priorities that resolve overlaps.
  • An understanding of the user-level Web content toggle and how it interacts with your policy.
  • A way to audit the web queries Copilot generated, and a checklist for Copilot Studio agents that have their own web setting.

How web search works in Copilot

When web search is enabled and information from the web would improve a response, Copilot parses the prompt, identifies the terms that need web data, and generates a search query for the Bing search service. The query isn't the prompt. It's a few words informed by the prompt.

These items aren't included in the generated query:

  • The user's entire prompt, unless the prompt is very short, such as "local weather".
  • Entire Microsoft 365 files, such as emails or documents, or files uploaded into Copilot.
  • Entire web pages or PDFs summarized by Copilot Chat in Microsoft Edge.
  • Identifying information from the user's Microsoft Entra account, such as username, domain or tenant ID.

In licensed Copilot, organizational content can still inform the query in two cases: when the user prompts Copilot inside an app with a relevant document open, and when the user explicitly references a document. Microsoft's example: a user asks Copilot to summarize an internal clean energy strategy and check whether Fabrikam announced something similar. The query sent to Bing is along the lines of "Fabrikam clean energy policy announcements". The document itself isn't sent, but a theme from it is.

That last point is the one to explain to your privacy team. Web search doesn't upload documents, but a generated query can carry a word or phrase derived from internal content.

What leaves the tenant and under which terms

DataWhere it goesTerms that applyMicrosoft's role
Prompts and responsesStored in Microsoft 365, inside the service boundaryEnterprise data protection, Data Protection Addendum, Product TermsData processor
Generated web search queriesBing search service, identifiers removedProduct Terms commitments, which supersede the Microsoft Services Agreement and Microsoft Privacy Statement where they conflictData controller

The Product Terms add these commitments for the generated queries:

  • Microsoft has no rights to them other than as needed to provide the service.
  • They aren't used to improve Bing, to build advertising profiles or to track users.
  • They aren't shared with advertisers or used to train generative AI foundation models.
  • They're treated as customer confidential information.

They also don't affect Bing search ranking, rich captions, or social features such as autosuggest and trending.

The exclusions matter as much as the commitments. The Microsoft Products and Services Data Protection Addendum doesn't apply to generated web search queries, and neither do HIPAA compliance or the EU Data Boundary. If any of those is a hard requirement for a user population, web search has to be off for that population.

Prerequisites

ItemRequirement
Admin roleOffice Apps Administrator (recommended), Security Administrator or Global Administrator
PortalMicrosoft 365 Apps admin center at config.office.com, or Intune admin center Apps > Policy > Policies for Office apps
LicensingA Microsoft 365 plan that includes Microsoft 365 Apps; Microsoft 365 operated by 21Vianet isn't supported
GroupsMicrosoft Entra groups of user objects; device objects are ignored; nesting up to three levels
CloudGCC High uses config.office365.us; DoD uses config.apps.mil

Choose the policy value

The Allow web search in Copilot policy is available only in Cloud Policy and applies to both Microsoft Copilot and Copilot Chat.

Policy stateMicrosoft CopilotCopilot ChatUser toggle
Enabled: Enabled in Microsoft Copilot and Microsoft Copilot ChatWeb search onWeb search onOn by default; users can turn it off
Enabled: Disabled in Microsoft Copilot and Microsoft Copilot ChatOffOffOff and dimmed
Enabled: Disabled in Microsoft Copilot Work mode; Enabled in Microsoft Copilot Web mode and Microsoft Copilot ChatOff in Work mode, on in Web modeOnAvailable where web search is allowed; users can turn it off
Not configured (commercial)On, unless optional connected experiences are disabledOn, unless optional connected experiences are disabledOn by default
Not configured (GCC, DoD)OffOffOff

Two details change real outcomes:

  • The split option (Disabled in Microsoft Copilot Work mode; Enabled in Microsoft Copilot Web mode and Microsoft Copilot Chat) also disables web search in Researcher and Cowork. Microsoft recommends web search for getting the most value from Researcher, Analyst and Cowork, so tell users who rely on them.
  • Disabling Allow the use of additional optional connected experiences in Office also stops web search when the Copilot policy isn't configured, but it restricts Copilot Chat, Copilot and many other Microsoft 365 experiences. Use the dedicated Copilot policy instead.

Step 1: Create the tenant-wide configuration

  1. Sign in to config.office.com and accept the terms if this is your first visit.
  2. Under Customization, select Policy Management, then Create.
  3. On Start with the basics, enter a name such as Copilot web search - default and a description, then select Next.
  4. On Choose the scope, select the users this applies to. For the baseline, choose all users. Select Next.
  5. On Configure Settings, search for Allow web search in Copilot. Open it, set it to Enabled, choose the option you decided on, and save.
  6. Select Next, review, and select Create.

A common baseline is Disabled in Microsoft Copilot Work mode; Enabled in Microsoft Copilot Web mode and Microsoft Copilot Chat, which keeps web results separate from answers grounded in organizational data. Regulated tenants usually choose Disabled for everyone as the baseline.

Step 2: Add exceptions for specific groups

  1. Select Create again and name the configuration for its purpose, for example Copilot web search - research team or Copilot web search - off for clinical staff.
  2. On Choose the scope, select Add Groups and pick the Entra groups. One configuration can target several groups.
  3. Configure Allow web search in Copilot with the value for that group and create the configuration.
  4. On the Policy configurations page, select Reorder priority. When a user is in several targeted groups with conflicting values, the configuration with the highest priority wins, and 0 is the highest. Put your restrictive exceptions above the baseline.

Cloud Policy settings take precedence over Group Policy and local settings. Microsoft doesn't publish a specific propagation time for this Copilot policy. For Office apps, Cloud Policy check-ins happen every 90 minutes for users in targeted groups (every 24 hours otherwise), and app policies apply when the app restarts, so allow time before testing.

Step 3: Tell users about the Web content toggle

When web search is allowed, users have a Web content toggle that's on by default. Turning it off removes web content from their responses, and the preference persists across sessions, clients and devices. In the Microsoft Copilot app, users find it under Settings > Personalization > Advanced > Web search.

The toggle can only restrict. If your policy disables web search, the toggle is off and dimmed and users can't turn it on. The user-level privacy setting for optional connected experiences in Word, Excel or Teams has no effect on Copilot web search.

Step 4: Cover Copilot Studio agents separately

Agents built in Copilot Studio have their own Use information from the web setting (shown as Web Search on the agent's Overview page), which uses Grounding with Bing Search and searches all public sites indexed by Bing. The Cloud Policy setting governs Copilot and Copilot Chat; makers control the agent setting.

To find agents with web search turned on, use the Copilot Studio agent inventory in the Power Platform admin center. Its knowledge properties include IsWebSearchEnabledForKnowledge, which is true when the agent can use web search as a knowledge source. Agents grounded on internal content usually shouldn't have it; the SharePoint knowledge source guide explains turning it off to keep answers inside a filtered source.

Audit the queries Copilot sends

Turning web search on doesn't mean losing visibility:

  • Citations for users. In Copilot Chat, the citation section of a response shows the exact web search queries sent to Bing. These are available in the chat thread for 24 hours and aren't shown in the Copilot pane inside Word or PowerPoint.
  • Audit and eDiscovery. Web search queries are logged, so you can search, audit and run eDiscovery on them with the same tools you use for Copilot prompts and responses.
  • DSPM for AI. Activity explorer in Microsoft Purview Data Security Posture Management for AI shows the web search terms alongside the prompt, response and supporting resources.
  • Policy changes. Cloud Policy creation, deletion, setting changes and priority changes are recorded in the Microsoft Purview audit log when auditing is on.

Verify the configuration

  1. Sign in as a test user in each targeted group and open Copilot Chat.
  2. Check the Web content toggle. For disabled groups it should be off and dimmed.
  3. Ask a question that needs current public information. For enabled groups, the response should include web citations with the generated queries; for disabled groups, it shouldn't.
  4. In Copilot, test Work mode and Web mode separately if you used the split option.
  5. In Purview, search for the test user's Copilot activity and confirm the web queries appear.

Troubleshooting

SymptomLikely causeFix
Web results still appear after disablingPolicy not yet applied, or a higher-priority configuration enables it for the userWait for check-in and restart the app; review Reorder priority
Policy doesn't apply to a groupGroup contains devices, not users, or nesting deeper than three levelsTarget user objects; flatten the group
Researcher no longer uses the webSplit option disables web search in Researcher and CoworkGive those users a higher-priority configuration with web search enabled
Web search off for everyone in a GCC tenantDefault in GCC and DoDConfigure the policy to enable it where approved
Many Office features stopped workingOptional connected experiences disabled to stop web searchRe-enable them and use the Copilot web search policy
A user turned the toggle on but gets no web resultsAdmin policy disables web searchExpected; the toggle can't override the policy

Closing checklist

  • Privacy review done on generated queries: no DPA, HIPAA or EU Data Boundary coverage.
  • Baseline Allow web search in Copilot configuration created for all users.
  • Exception configurations created for specific groups and ordered by priority.
  • Optional connected experiences left enabled.
  • Users told about the Web content toggle and the Researcher impact of the split option.
  • Copilot Studio agents with IsWebSearchEnabledForKnowledge reviewed.
  • Web queries visible in Purview Audit and DSPM for AI.

If you're still preparing the rollout itself, the Copilot license assignment checklist covers prerequisites and licensing.

References

Questions people ask

How do I turn off web search in Microsoft 365 Copilot?

Create a policy configuration in the Cloud Policy service for Microsoft 365, enable the Allow web search in Copilot policy, and choose Disabled in Microsoft Copilot and Microsoft Copilot Chat. Users in scope then see the Web content toggle turned off and dimmed.

Is web search on by default in Copilot Chat?

In commercial tenants, yes. If you don't configure the Allow web search in Copilot policy, web search is available unless the Allow the use of additional optional connected experiences in Office policy is disabled. In GCC and DoD, web search is off by default until you enable the policy.

What data does Copilot send to Bing?

A short generated search query of a few words derived from the prompt, with user and tenant identifiers removed. The full prompt, whole files, whole web pages summarized in Edge and Entra identity information aren't sent, except that a very short prompt can be the query itself.

Does the Data Protection Addendum cover Copilot web search queries?

No. The DPA, HIPAA compliance and the EU Data Boundary don't apply to the generated search queries sent to Bing. Microsoft acts as a data controller for them, with additional commitments in the Product Terms, while prompts and responses stay under enterprise data protection.

Microsoft 365 CopilotCopilot ChatCloud Policy ServiceBingMicrosoft Purview
  1. Audit, Retain and Search Microsoft 365 Copilot Prompts with Purview

    Find Copilot interactions in the Purview audit log, keep or delete prompts and responses with a retention policy, and search or purge them with eDiscovery when something goes wrong.

    AI engineering11 min read
  2. Prepare a Tenant for Microsoft 365 Copilot by Fixing Oversharing First

    Find overshared SharePoint and OneDrive content with Data access governance reports and DSPM, contain it with RCD and RAC, then hand cleanup to site owners before Copilot rollout.

    AI engineering14 min read
  3. Set Up Microsoft Purview DSPM for AI to Audit and Govern Copilot Interactions

    Turn on auditing, activate the DSPM for AI one-click policies, run data risk assessments and read Copilot prompts and responses in activity explorer and the unified audit log.

    AI engineering11 min read