Microsoft 365 Copilot Multi-Model Routing and Purview Controls
TL;DR: Microsoft documents Anthropic as a Microsoft subprocessor under the DPA, but excludes it from EU Data Boundary commitments. Purview DLP, labels, audit and retention are documented for Microsoft 365 Copilot generally; Learn does not state model-by-model behaviour. This skill audits toggles and evidence, read-only.
How is this different from the other Copilot DLP skills?
This skill audits the model-provider layer: which non-Microsoft models Microsoft 365 Copilot may use in your tenant, who can reach them, and which Microsoft Purview controls Microsoft documents for those interactions. Copilot DLP Impact and Simulation forecasts what a DLP policy would block, Copilot Interaction Compliance Audit analyses what users actually did, and DSPM for AI Remediation plans oversharing clean-up. This page sits upstream of all three. Status statements are per Microsoft Learn as at 2026-09-30.
What does Microsoft document about Anthropic models in Microsoft 365 Copilot?
Per Microsoft Learn, Anthropic has onboarded as a Microsoft subprocessor, so the Microsoft Product Terms and Data Protection Addendum (DPA) apply unless a model is labelled “Anthropic models with Data Retention”. Learn states this use is also covered by Enterprise Data Protection and, for products covered by it, the Customer Copyright Commitment.
| Question | Position per Microsoft Learn (as at 2026-09-30) |
|---|---|
| Is Anthropic a Microsoft subprocessor? | Yes. Learn states Anthropic operates as a subprocessor under Microsoft oversight and contractual safeguards. |
| Which terms apply? | Microsoft Product Terms and DPA, unless the model is labelled “Anthropic models with Data Retention”. |
| Where can Anthropic models appear? | Learn lists Microsoft Copilot, Researcher, Copilot Studio, Power Platform and Copilot in Microsoft 365 apps. |
| Default state | On by default for most commercial cloud customers, excluding EU/EFTA and UK, where the default is off. |
| EU Data Boundary | Anthropic models are currently excluded from the EU Data Boundary and, when applicable, in-country processing commitments. |
| Government and sovereign clouds | Not available for federal customers in GCC, or in GCC High, DoD and other sovereign clouds. Non-federal GCC has a separate setting from 22 July 2026. |
| Training | Learn’s Copilot Cowork application card states prompts, responses and Microsoft Graph data are not used to train foundation LLMs. |
Which Purview controls apply when a prompt goes to a non-Microsoft model?
Microsoft Learn documents Purview controls for Microsoft 365 Copilot as a product. The pages read do not publish a per-model matrix, so for a prompt routed to Anthropic the position is documented for some controls and not documented for others.
| Purview control | Documented for Microsoft 365 Copilot | Stated for Anthropic-routed prompts? |
|---|---|---|
| DLP for the Microsoft 365 Copilot and Copilot Chat location | Yes (labels, sensitive info types in prompts, web search, external email preview) | Not documented |
| Sensitivity labels and EXTRACT usage right | Yes | Partly: Word, Excel and PowerPoint Agents page says labels and compliance policies are “fully respected” and Microsoft performs the searches |
| DSPM and DSPM for AI (classic) | Yes | Not documented |
| Audit (unified audit log) | Yes | Not documented |
| Retention (Microsoft Copilot Experiences location) | Yes | Not documented |
| eDiscovery, Insider Risk, Communication compliance | Yes | Not documented |
Treat “Not documented” as a gap to confirm with your Microsoft account team, not as a yes or a no.
What can admins toggle?
Admins control model reach through the settings below, and none of them is a Purview setting.
| Control | Where | Who | Effect per Learn |
|---|---|---|---|
| AI providers operating as Microsoft subprocessors | Microsoft 365 admin center, Copilot > Settings > View all | AI Administrator or Global Administrator | Enable or disable Anthropic; scope to All users, specific users or Microsoft Entra security groups; enforced across Microsoft Copilot and Copilot Studio |
| Copilot in Microsoft 365 apps with Anthropic models | Microsoft 365 admin center | AI Administrator | Word, Excel and PowerPoint only; on by default for EU/EFTA/UK tenants created after 25 March 2026 |
| Enable External Models | Power Platform admin center (environment or environment group rule) | Not stated on the page read | Copilot Studio and Power Platform; needs the Microsoft 365 admin center setting enabled first |
| Anthropic models with Data Retention | Microsoft 365 admin center | Tenant admin | Off by default for all scenarios; needs explicit opt-in and acceptance of Anthropic’s terms |
Disabling Anthropic removes dependent features. Learn states Word, Excel and PowerPoint Agents use Anthropic models exclusively and are hidden when Anthropic is disabled.
Does data still fall under Microsoft’s data-handling commitments?
Only for models that stay inside Microsoft’s subprocessor terms. Learn states that “Anthropic models with Data Retention” are stored by Anthropic, are not subject to your Microsoft Customer Agreement (including the Product Terms and DPA), and are governed by Anthropic’s Commercial Terms and Data Protection Addendum, with Anthropic acting as an independent processor.
| Model class | Governing terms | Retention position per Learn |
|---|---|---|
| Microsoft-hosted models (for example Azure OpenAI) | Microsoft DPA and Product Terms | Data does not leave Microsoft |
| Anthropic as subprocessor | Microsoft DPA and Product Terms | Learn states that for certain organisations Fable 5.1 is available with Anthropic as subprocessor and Anthropic does not retain customer content; retention for other models is not stated on the page read |
| Anthropic models with Data Retention | Anthropic Commercial Terms and DPA | Anthropic stores most inputs and outputs for up to 30 days; it may retain flagged content for up to two years and classification scores for up to seven years |
Learn also lists Copilot Studio exclusions: FedRAMP is not achieved for Anthropic or xAI models, and PCI DSS is not applicable to Anthropic or xAI models for cardholder data. Learn does not state an Australia-specific residency position.
When should you run this skill?
- “Which non-Microsoft AI models can our Microsoft 365 Copilot users reach today?”
- “Is Anthropic enabled for everyone, or only a pilot group?”
- “Do we meet our data-residency obligations if Copilot routes to Anthropic?”
- “Which Purview controls can we evidence for Anthropic-routed prompts?”
- “Has anyone enabled the Data Retention models?”
- “What should we ask Microsoft before enabling Anthropic?”
How this skill works, step by step
- Record the tenant’s region and cloud (commercial, EU/EFTA/UK, GCC or sovereign) to establish the documented default.
- Read the AI providers operating as Microsoft subprocessors setting: state per provider and user or group scope.
- Read the Copilot in Microsoft 365 apps with Anthropic models setting where it appears.
- Read the Enable External Models settings for each Power Platform environment and environment group.
- Check whether Anthropic models with Data Retention are enabled and for whom.
- List DLP policies scoped to the Microsoft 365 Copilot and Copilot Chat location, with mode, conditions and actions.
- Confirm auditing is on and a retention policy covers Microsoft Copilot Experiences.
- Populate the control matrix, marking each Purview control as Documented, Not documented or Not enabled for the model path.
- Produce the findings table and open questions for the Microsoft account team, without changing any setting.
Output format
| Area | Setting or control | Current state | Documented for Anthropic path | Finding |
|---|---|---|---|---|
| Model reach | Anthropic subprocessor | On, All users | Yes (DPA applies) | Scope to pilot group |
| Model reach | Data Retention models | Off | Yes | Compliant |
| Residency | EU Data Boundary | Not applicable to Anthropic | Excluded per Learn | Record risk acceptance |
| Purview DLP | Copilot location, label rule | Enforce | Not documented | Ask Microsoft |
| Purview audit | Copilot interactions | On | Not documented | Ask Microsoft |
Summary metrics:
- Providers enabled and the user or group scope for each.
- Whether any model outside the Microsoft DPA is enabled.
- Count of Purview controls marked Not documented.
- Residency exclusions that apply to your region.
Prerequisites
- Confirmed tenant region and cloud environment.
- An account able to view the Microsoft 365 admin center Copilot settings and Power Platform admin center environments.
- Access to the Microsoft Purview portal for DLP policies, audit and retention.
- Agreed list of Purview controls your organisation needs evidenced for AI interactions.
Scope and safety
This skill is read-only by default and makes no changes to your tenant. It reads provider settings, policy definitions and audit configuration only.
This skill does NOT:
- Enable, disable or rescope Anthropic or any other AI provider.
- Create, modify or delete any DLP policy, label or retention policy.
- Read or export the body of prompts, files or Copilot responses.
- Infer that a Purview control applies to a routed model where Microsoft Learn does not say so.
Licensing and permissions
Licences and add-ons
| Capability used | Licence position per Microsoft Learn |
|---|---|
| Microsoft 365 Copilot experiences | Word, Excel and PowerPoint Agents require a paid Microsoft 365 Copilot licence |
| Purview DLP for the Copilot location | The Learn page points to Microsoft 365 licensing guidance and does not state a tier |
| Anthropic models via subprocessor setting | No separate licence stated on the pages read |
Least-privilege roles
- AI Administrator or Global Administrator to change AI provider settings (per Learn, for the opt-in and disable tasks). A view-only role is not stated on the pages read.
- Roles Learn lists for creating or editing Copilot-location DLP policies include Purview Data Security AI Admin, Compliance Administrator and Security Administrator. A read-only role is not stated on the pages read.
Interfaces used
Provider settings are administered in the Microsoft 365 admin center and Power Platform admin center. Learn does not document an API for them on the pages read, so this skill reads them through the admin centres.
Related skills
- Governing Microsoft 365 Copilot with Microsoft Purview: pillar guide to the Purview controls documented for Microsoft 365 Copilot
- Copilot DLP Impact and Simulation: run to predict which prompts and files DLP policies scoped to Copilot would block
- Copilot Interaction Compliance Audit: run after to check where Copilot prompts and responses touched sensitive data
- Australian Compliance for Microsoft 365 Copilot and AI: pillar guide to Australian compliance for Microsoft 365 Copilot
- Microsoft 365 Copilot Readiness Guide for SharePoint and Data: read first to fix oversharing before Copilot activation
Notes
Preview and general availability status changes often. As at 2026-09-30, per Microsoft Learn: blocking sensitive information types in prompts is described as preview and rolling out; label-based file and email exclusion and web-search blocking are described without a preview flag; external email blocking is preview. Microsoft’s security blog dated 20 March 2026 announced expanded Copilot DLP for prompts as generally available on 31 March, so confirm the current status in your tenant.
Related skills: Tenant DLP Coverage Audit, Purview Label Coverage, Purview AI Activity Explorer, Retention and Records Management Audit, Shadow AI App Discovery.
Sources
- Anthropic models in Microsoft Online Services
- Understanding AI functionality and models in Microsoft Online Services
- Enterprise data protection in Microsoft Copilot
- Copilot in Microsoft 365 apps with Anthropic models
- Word, Excel, and PowerPoint Agents in Microsoft Copilot
- Allow external language models for generative responses
- Use Microsoft Purview to manage data security and compliance for Microsoft 365 Copilot
- Learn about DLP for Microsoft 365 Copilot and Copilot Chat
- Application card: Microsoft Copilot Cowork
- Secure agentic AI end to end (Microsoft Security blog, 20 March 2026)
Licensed under CC BY 4.0 by EDUC4TE .
SKILL.md— paste into Microsoft 365 Copilot or ClaudeDownload▸ View skill file▾ Hide skill file
How to use this skill
- Get the file. Download or copy the
SKILL.mdfrom the SKILL.md panel on this page. - Load it into your host:
- Microsoft 365 Copilot / Copilot Studio — add it as the instructions of a declarative agent or Copilot Studio agent.
- Claude (Cowork / Claude Code) — drop the file into your skills folder; it loads as an Agent Skill automatically.
- Any chat host — paste the file contents as your prompt.
- Grant read-only access. Assign the least-privilege roles and Microsoft Graph scopes listed in Licensing and permissions section of this article.
- Provide your tenant scope and run it (a site, a collection, or the whole tenant).
- Review the report and action the risk-ranked recommendations.
This skill is read-only by default — it inspects and reports, and never changes your tenant.
Last reviewed 2026-09-30