Everything else follows from this, and it is on Microsoft's own semantic indexing page rather than in anybody's commentary. Copilot does not hand your sentence to a model. It uses your sentence to search, adds what it finds, and sends the result onward.
Modified prompt. Those are Microsoft's words, not a paraphrase. You never see the modification, and you never see what it failed to find. That is the whole reason a list of checkpoints is useful: each one is a place where the search comes back with less than you assumed, and none of them announce themselves in the answer.
All three are about reach. Not one of them is about the model being clever or stupid, which is why rewriting the prompt is the wrong first move when an answer is missing something you know exists.
There is no separate Copilot account with its own keys. It runs as you.
The consequence people trip over is not the rule, it is what the rule implies: the answer is not a property of the question. Two colleagues, same tenant, same afternoon, the same sentence word for word, and two different answers. Nothing has gone wrong. That is the security model working exactly as designed.
So when two of you compare notes, the first question is not which answer is right. It is which files each of you can see.
Where a sensitivity label applies encryption, Copilot needs usage rights on the file before it will work with the content. Microsoft states the requirement twice, and the two statements do not agree.
This one only applies if an administrator has configured a data loss prevention policy for the Microsoft 365 Copilot location with the sensitivity-labels condition. It is not out-of-the-box behaviour, and any version of this claim that implies otherwise is false. Where such a policy does exist, here is the state it leaves you in.
Whichever sentence is current, the useful consequence is the same and it is narrower than the internet version of it. The cited item is real. It exists. You can open it. The citation is real and the reading did not happen. That is not a fabricated source and it is not a hallucination, and calling it one gets the mechanism wrong.
Whether the interface marks such a citation is not written down anywhere on the page. Not that it does, not that it does not.
When an answer is missing something you know exists, the instinct is to rewrite the prompt. Do that fourth, not first.
Your permissions can be perfect and all three of these can still leave a document out of the answer. That is what makes them worth knowing: they fail quietly, and they fail in ways a prompt cannot fix.
Restricted Content Discovery is how an administrator takes a site out of organisation-wide search and Copilot experiences. Three sentences from the page decide what it actually does, and none of them say what the name suggests.
Put together: restrict a large site on Monday and Copilot can keep answering from it for over a week. Once the restriction does land, a document somebody already has open still gets summarised.
Web search is on by default, and an administrator can turn it off: "If the IT admin turns off web search, the Web content toggle is turned off and appears dimmed. Users can't turn on the toggle to use web search."
The more interesting half is what gets searched. Copilot does not send your sentence to Bing.
Microsoft's own worked example on that page is the clearest thing in this guide. The prompt "Who is my manager and what public information is available about them?" produces a generated query that is the manager's name. Copilot finds the name in Microsoft 365 data, then builds a Bing query from it. This is checkpoint zero made visible: the search that runs is not the sentence you wrote.
The least glamorous checkpoint on the list, which is exactly why it catches people. These are the published limits of the Microsoft Graph File Share connector, the connector that puts on-premises Windows file shares into Copilot.
Read plainly: on a connected file share, the back half of a long specification may as well not exist, and a scanned or image-based drawing reduces to a filename and some properties. The file name is in the index. What is drawn is not. Nothing in an answer tells you which of your files hit that ceiling.
The advice in circulation is right. The reason attached to it is wrong, and the wrong reason is why people abandon the advice the moment it stops working.
Go back to checkpoint zero. Your words are also the search, and a search has to match something. "Summarise my last meeting" gives a search nothing to grab: last according to whom, in which calendar, and does that calendar even hold the meeting you mean. "Summarise the Q3 budget preparation meeting" gives it a title. A title is findable, and it survives being rewritten. Ask like you are talking to a search box that has to find something first, because it is one.
The only signal you get about whether any of that worked is whether there are sources underneath the answer. And as checkpoint 3 shows, a citation is not a receipt.
Every reason below has been checked against a Microsoft page or against a filmed test. Three of these patterns circulate with reasons that are flatly false, and those are marked.
| Pattern | Instead of | Write | The real reason |
|---|---|---|---|
| 1. Anchor to a real object | VagueWhat were the key points from yesterday's meeting? | AnchoredSummarise the Teams meeting titled "Q3 Strategy" held on 12 August 2026, which I attended. Focus on action items assigned to me. | A title and a date are things that can be looked up. Microsoft's own worked example shows the derived query for "who is my manager" is the manager's name: the proper noun is what came through. That example is web search, and no page says tenant retrieval behaves identically, so treat it as the principle rather than the proof. |
| 2. Name the file and where it lives | VagueDraft an email about the new campaign. | AnchoredDraft an email about the "Summer 2026 Campaign" document in our SharePoint "Campaigns" folder. Include the budget highlights and ask for feedback by Friday. | Your prompt is rewritten before it reaches the model. Proper nouns survive a rewrite. Adjectives do not. |
| 3. Stay inside your own access | VagueShow me all customer feedback from last month. | AnchoredList the customer feedback emails in my "Client Feedback" Outlook folder from the last 30 days and summarise the top 3 recurring themes. | Documented, not folklore: "Copilot can only summarize or reference content that the user is authorized to access." Labels and DLP can subtract further, and quietly. |
| 4. Ask for the tool you will actually use | VagueCreate a project timeline in a Gantt chart. | AnchoredCreate a project timeline in Microsoft Planner for the "Product Launch" task list, using milestones from the "Timeline" Excel file in the same SharePoint folder. | Not because Copilot is restricted to Microsoft tools. It is not. This is about the output landing somewhere you can use it, which is a workflow reason rather than a permission one. |
| 5. Point at data, not at the future | VaguePredict how our sales will perform next quarter. | AnchoredAnalyse the "Q2 Sales Data" Excel file in our "Finance" SharePoint site and identify the top 3 trends. | Not because Copilot avoids speculation. It will speculate happily. The difference is that one answer is your data talking and the other is the model talking, and the interface does not label which. |
| 6. For automation, name the platform | VagueWrite a Python script to clean this dataset. | AnchoredCreate a Power Automate flow to extract "Customer Name" and "Order Value" from the "Sales Records" Excel file in our "Data" SharePoint folder. | The usual reason for this one is false and should not be repeated. Copilot writes and runs Python; that was tested. The real reason is durability: a flow persists and a script in a chat window does not. |
| 7. Start from a template that exists | VagueWrite a press release about our new product. | AnchoredDraft a press release using the "Press Release Template" in our "Templates" SharePoint folder, populated with details from the "Product Launch Plan" Word document. | Two retrieval anchors instead of zero, and the house format comes along for free. |
All three circulate in prompt packs and internal training decks. Each one is disproved in seconds, and each one takes the rest of the advice down with it.
A list of checkpoints reads as more certain than the evidence behind it, so here is the evidence's own boundary. These are limits of the sources, not hedging.
Six pages. All read 13 August 2026. Microsoft revises these without notice and none of them carry a version history, so check the date on the page against the date here before relying on a quote.
| Page | Page date when read | Used for |
|---|---|---|
| Semantic indexing for Microsoft 365 Copilot | updated 23 April 2026 | Checkpoint zero |
| Copilot architecture and data protection | updated 6 May 2026 | Checkpoints 1 and 2 |
| Learn about DLP for Microsoft 365 Copilot | updated 17 July 2026 | Checkpoints 2 and 3 |
| Restricted Content Discovery | updated 28 July 2026 | Checkpoint 4 |
| Manage public web access for Copilot | ms.date 15 July 2026 | Checkpoint 5 |
| Microsoft Graph File Share connector | updated 23 July 2026 | Checkpoint 6 |
Nothing in this guide, and nothing in the episode it accompanies, is a method for putting AI inside a safety authorisation decision. Permit to work, lock out tag out, confined space entry, job safety analysis, incident classification, inspection sign-off: those carry a named accountable human, and they stay that way.
The six checkpoints are the argument for that boundary rather than a caveat attached to it. A retrieval system that can miss a document because of a label, a policy that has not propagated yet, a restriction that takes a week, or a file share that stopped indexing a document at 4 MB, is a system that can return a confident and incomplete answer without saying so. AI prepares. Humans decide.