Kesslernity · Companion guide to the two-part episode

The Six Checkpoints Your Question Passes

What enterprise Copilot does to your prompt before a model sees it.
In a chat window you opened yourself, your words are an instruction. In Microsoft 365 Copilot they are an instruction and a search query at the same time, and that search has to get past six checkpoints before anything reaches a model. Every checkpoint below is on a Microsoft page. So is every edge, and the edges are the part nobody puts on the slide.
Checkpoints Six, plus checkpoint zero
Sources Six Microsoft pages, quoted verbatim
All pages read 13 August 2026
Published by kesslernity.com
Part one · Checkpoints 1 to 3
What you can reach
Permissions, the label on the file, and the policy your administrator wrote. Three gates that decide whether a document is available to your question at all.
Part two · Checkpoints 4 to 6
Whether it was ever findable
Discovery restrictions, the web and who decides, and whether the file was readable in the first place. These three are not about your permissions.
Read this before the list
This was never a scoreboard. No competitor product appears in the episode or in this guide. ChatGPT Business and Enterprise ship admin consoles, SSO and a compliance API; Google Workspace ships DLP. They all have enterprise controls of their own, and comparing them is a different piece of work. The only comparative statement here is definitional: a chat window you opened yourself has no Microsoft 365 tenant behind it, so none of these six checkpoints exist there to be passed or failed.

Everything else follows from this, and it is on Microsoft's own semantic indexing page rather than in anybody's commentary. Copilot does not hand your sentence to a model. It uses your sentence to search, adds what it finds, and sends the result onward.

Semantic indexing works by "appending additional information to your Microsoft Copilot prompt". Semantic indexing for Microsoft 365 Copilot
And then, in the same five-step flow: "Copilot sends the modified prompt to the Large Language Model." Semantic indexing for Microsoft 365 Copilot

Modified prompt. Those are Microsoft's words, not a paraphrase. You never see the modification, and you never see what it failed to find. That is the whole reason a list of checkpoints is useful: each one is a place where the search comes back with less than you assumed, and none of them announce themselves in the answer.

Part one · Checkpoints 1 to 3
What you can reach

All three are about reach. Not one of them is about the model being clever or stupid, which is why rewriting the prompt is the wrong first move when an answer is missing something you know exists.

1
Copilot only sees what you can already open

There is no separate Copilot account with its own keys. It runs as you.

"Copilot can only summarize or reference content that the user is authorized to access." Copilot architecture and data protection · updated 6 May 2026

The consequence people trip over is not the rule, it is what the rule implies: the answer is not a property of the question. Two colleagues, same tenant, same afternoon, the same sentence word for word, and two different answers. Nothing has gone wrong. That is the security model working exactly as designed.

So when two of you compare notes, the first question is not which answer is right. It is which files each of you can see.

2
The label on the file

Where a sensitivity label applies encryption, Copilot needs usage rights on the file before it will work with the content. Microsoft states the requirement twice, and the two statements do not agree.

One bullet
"When encryption is applied, the user must have EXTRACT and VIEW usage rights for Copilot to interact with the content."
The next bullet
"Items encrypted by Azure Rights Management without a sensitivity label still require EXTRACT or VIEW usage rights for the user for Copilot to summarize the content."
Same page, one bullet apart, and neither sentence carries a version number. This guide is not going to tell you which one is current, because there is no way to know from the page. What both versions agree on is the practical test: the right to copy from the file. Build your expectations on that and you are safe under either reading.
The second edge on this checkpoint
In Word, Excel and PowerPoint the policy that prevents Copilot from processing content is "evaluated at file open". If a sensitivity label is applied mid-session, it is enforced "the next time the file is opened". A document can be relabelled while it sits on your screen and nothing changes until you close it and reopen it.
3
The policy your administrator wrote

This one only applies if an administrator has configured a data loss prevention policy for the Microsoft 365 Copilot location with the sensitivity-labels condition. It is not out-of-the-box behaviour, and any version of this claim that implies otherwise is false. Where such a policy does exist, here is the state it leaves you in.

Body of the page
"Identified items still appear in the citations of the response."
Conditions table, same page
"The content of the item is not processed by Copilot or used in the response summary", though "the item could be available in the citations of the response."
Two different promises about the same feature, and the disagreement sits on the thing that tells you whether your document was used. This guide uses the weaker wording throughout: a citation can appear, never always appears.

Whichever sentence is current, the useful consequence is the same and it is narrower than the internet version of it. The cited item is real. It exists. You can open it. The citation is real and the reading did not happen. That is not a fabricated source and it is not a hallucination, and calling it one gets the mechanism wrong.

Whether the interface marks such a citation is not written down anywhere on the page. Not that it does, not that it does not.

Two more edges from the same page
Uploads are a different path: "DLP can't scan the contents of files that you upload directly into prompts, so evaluation of the uploaded file for sensitive data doesn't occur. DLP only checks the text you type into the prompt itself." And policy changes are not immediate: "Updates to a DLP policy can take up to four hours to reflect in Microsoft 365 Copilot and Copilot Chat experience." Which turns "we fixed it in Purview" into "we fixed it in Purview, and it is still the old behaviour until this afternoon".
What was not done to test this
None of checkpoint 3 was demonstrated on a live tenant. Configuring Purview DLP policies in a real company tenant to find out what happens is not something anyone should do for a video, in simulation mode or otherwise. The documentation is the exhibit, and in this case it is the stronger exhibit, because it carries Microsoft's own conditions table and its own disagreement with itself.

When an answer is missing something you know exists, the instinct is to rewrite the prompt. Do that fourth, not first.

Part two · Checkpoints 4 to 6
Whether it was ever findable

Your permissions can be perfect and all three of these can still leave a document out of the answer. That is what makes them worth knowing: they fail quietly, and they fail in ways a prompt cannot fix.

4
Content somebody pulled out of reach

Restricted Content Discovery is how an administrator takes a site out of organisation-wide search and Copilot experiences. Three sentences from the page decide what it actually does, and none of them say what the name suggests.

"The feature doesn't remove content from the Microsoft 365 search index." Also on the page: "eDiscovery and auto-labeling continue to function." Restricted Content Discovery · updated 28 July 2026
"For sites with more than 500,000 items, an update to Restricted Content Discovery could take more than a week to fully process and reflect in search and Copilot experiences." Restricted Content Discovery
It "doesn't affect experiences that operate on content that's already in use by the user, such as summarizing an open document." Restricted Content Discovery

Put together: restrict a large site on Monday and Copilot can keep answering from it for over a week. Once the restriction does land, a document somebody already has open still gets summarised.

The governance sentence to get right
Restricted Content Discovery is a discovery control, not an access control, and Microsoft says so on the page. The mistake it invites is reading "restricted from Copilot" as "Copilot cannot see it". Permissions are unchanged; users who already have access keep it.
5
The web, and who decides whether you get it

Web search is on by default, and an administrator can turn it off: "If the IT admin turns off web search, the Web content toggle is turned off and appears dimmed. Users can't turn on the toggle to use web search."

The more interesting half is what gets searched. Copilot does not send your sentence to Bing.

"This generated search query is different from the user's original prompt, it consists of a few words informed by the user's prompt." Manage public web access for Copilot · ms.date 15 July 2026

Microsoft's own worked example on that page is the clearest thing in this guide. The prompt "Who is my manager and what public information is available about them?" produces a generated query that is the manager's name. Copilot finds the name in Microsoft 365 data, then builds a Bing query from it. This is checkpoint zero made visible: the search that runs is not the sentence you wrote.

What you can see
The exact derived queries, in the chat thread, for 24 hours. Not in the Copilot pane inside Word or PowerPoint, where citations for web queries are not available at all.
What your administrator can see
"Search, audit, and eDiscovery on the exact web search queries Copilot derived from the user's prompt." The page gives no retention period, so this guide does not state one.
Credit where it is due: Copilot showing you the queries it derived is real transparency, and most tools do not. The asymmetry is worth knowing anyway, because the two windows are not the same length.
Read this one exactly as written, and no further
The same page says: "The Microsoft Products and Services Data Protection Addendum (DPA) doesn't apply to the use of generated web search queries in Microsoft 365 Copilot, Microsoft 365 Copilot Chat, or the Bing search service. Also, HIPAA compliance and the EU Data Boundary don't apply to generated search queries."

That is a statement about which agreements cover the derived query. It is not a statement about what the query contains or where it goes, and it must not be repeated as one. The same page also says prompts and responses stay within the Microsoft 365 service boundary "without customer direction". Those are two different sentences about two different things, and merging them produces a claim neither one supports.
6
Was the file ever readable

The least glamorous checkpoint on the list, which is exactly why it catches people. These are the published limits of the Microsoft Graph File Share connector, the connector that puts on-premises Windows file shares into Copilot.

"The maximum supported file size is 100 MB. Files that exceed 100 MB aren't indexed. The maximum post-processed size limit is 4 MB. Processing stops when a file's size reaches 4 MB. Therefore, some phrases present in the file might not work for search." Microsoft Graph File Share connector · updated 23 July 2026
"Only the textual content of these formats is indexed, and all multimedia content is ignored. For multimedia and other file types, only metadata is indexed." Microsoft Graph File Share connector

Read plainly: on a connected file share, the back half of a long specification may as well not exist, and a scanned or image-based drawing reduces to a filename and some properties. The file name is in the index. What is drawn is not. Nothing in an answer tells you which of your files hit that ceiling.

Scope, and this one matters
4 MB is the File Share connector's post-processed limit. It is not a Copilot-wide file limit. "Copilot only reads the first 4 MB of your documents" is false, it is the easiest mistake to make with this number, and it is worth correcting whenever you see it. The claim only holds where the connector is the path to the file.
One inconsistency on that page
GIF, JPEG, JPG and PNG appear in the indexable-formats list under Capabilities, and the very next sentence says multimedia content is ignored and only metadata is indexed. Read together, images are indexed for metadata only. Do not quote the format list without the sentence that follows it.
The technique
And it is not what you have been told

A list of checkpoints reads as more certain than the evidence behind it, so here is the evidence's own boundary. These are limits of the sources, not hedging.

Six pages. All read 13 August 2026. Microsoft revises these without notice and none of them carry a version history, so check the date on the page against the date here before relying on a quote.

PagePage date when readUsed for
Semantic indexing for Microsoft 365 Copilotupdated 23 April 2026Checkpoint zero
Copilot architecture and data protectionupdated 6 May 2026Checkpoints 1 and 2
Learn about DLP for Microsoft 365 Copilotupdated 17 July 2026Checkpoints 2 and 3
Restricted Content Discoveryupdated 28 July 2026Checkpoint 4
Manage public web access for Copilotms.date 15 July 2026Checkpoint 5
Microsoft Graph File Share connectorupdated 23 July 2026Checkpoint 6
Where all of this stops

Nothing in this guide, and nothing in the episode it accompanies, is a method for putting AI inside a safety authorisation decision. Permit to work, lock out tag out, confined space entry, job safety analysis, incident classification, inspection sign-off: those carry a named accountable human, and they stay that way.

The six checkpoints are the argument for that boundary rather than a caveat attached to it. A retrieval system that can miss a document because of a label, a policy that has not propagated yet, a restriction that takes a week, or a file share that stopped indexing a document at 4 MB, is a system that can return a confident and incomplete answer without saying so. AI prepares. Humans decide.

If you are the one answering for this

This guide explains what the checkpoints are. It does not cover the part that lands on whoever owns the rollout: the operating model, the 90-day plan with owners and decision gates, the governance checklist, and the ROI case for a finance team that has already said no once.

That is the M365 Copilot Deployment Kit. One payment, no subscription.

See what is in the Deployment Kit →