Microsoft 365 Copilot APIs: Does Enterprise Data Protection provide Zero Data Retention?

James Meehan 0 Reputation points
2026-10-03T04:56:15.26+00:00

Hello,

We have Microsoft 365 Copilot licenses and are evaluating Microsoft 365 Copilot APIs as a potential AI platform for a regulated business environment.

While reviewing Microsoft documentation, I found references to:

  • Microsoft 365 Copilot APIs
  • Enterprise Data Protection (EDP)
  • Interaction Export API
  • AI Interaction Notifications
  • Purview auditing and compliance controls

I am trying to understand the retention and compliance behavior of Copilot API interactions.

Service

  • Microsoft 365 Copilot
  • Microsoft 365 Copilot APIs
  • Copilot Chat API
  • Retrieval API
  • Search API
  • Microsoft Graph

Scenario

We are evaluating whether Microsoft 365 Copilot APIs provide a Zero Data Retention (ZDR) experience, or whether prompts and responses are stored within Microsoft's compliance boundary.

I understand that Microsoft states prompts and responses are not used to train foundation models. However, I am trying to determine whether interaction data is retained elsewhere for compliance, audit, logging, export, or operational purposes.

Questions

Does Enterprise Data Protection (EDP) provide Zero Data Retention (ZDR) for:

  • Copilot Chat API
    • Retrieval API
      • Search API
        • Meeting Insights API
        If EDP and ZDR are different concepts, what retention behavior applies to Copilot API requests? Are Copilot API prompts and responses retained anywhere within Microsoft 365? Are prompts and responses stored in any of the following:
              - Microsoft Purview
              
              
                 - Audit logs
              
                 
                    - Interaction Export data
              
                    
                       - Exchange Online
              
                       
                          - Other Microsoft compliance systems
              
                          
                          If prompts and responses are retained, what retention policy applies?
              
                          
                          Does the Interaction Export API exist because Copilot prompts and responses are persisted somewhere within Microsoft 365?
              
                          
                          Is there any Microsoft documentation that specifically explains retention behavior for Copilot API interactions versus Copilot user-interface interactions?
              ```### Goal
        
        

I am trying to understand whether Microsoft 365 Copilot APIs provide a Zero Data Retention experience, or whether Copilot API requests are retained within Microsoft's compliance and audit infrastructure while still being protected under Enterprise Data Protection.

Thank you for any clarification or documentation references.

Microsoft 365 and Office | Development | Other
0 comments No comments

2 answers

Sort by: Newest
  1. Julie Huynh 3,770 Reputation points Independent Advisor
    2026-10-03T07:18:49.3533333+00:00

    Dear James Meehan,

    Good day! Welcome to Microsoft Q&A forum!

    As a user myself, I find this topic quite interesting and thought-provoking. You can refer to the AI's answer; additionally, I have summarized a few key points below.

    Microsoft has not documented Microsoft 365 Copilot APIs as providing a Zero Data Retention (ZDR) model.

    Enterprise Data Protection (EDP) and Zero Data Retention are different concepts:

    • Enterprise Data Protection (EDP) ensures prompts, responses, and related interaction data are protected under Microsoft 365 enterprise privacy, security, compliance, and contractual commitments.
    • Prompts and responses are not used to train foundation models.
    • However, Microsoft documentation indicates that Copilot interaction data may be subject to auditing, eDiscovery, retention, and compliance management through Microsoft 365 and Microsoft Purview.

    In this situation, it should be viewed as operating within the Microsoft 365 compliance and governance boundary, protected by EDP, rather than as a Zero Data Retention service, unless Microsoft publishes explicit ZDR guarantees for those APIs in future documentation.

    These are some insights I gathered from Microsoft articles; however, for more precise information, I suggest contacting Microsoft directly to clarify the matter. You might consider opening a Unified Support ticket to seek confirmation from the development team.

    Thank you for your time and have a good day.

    Was this answer helpful?

    0 comments No comments

  2. AI answer

    2026-10-03T04:56:42.9033333+00:00

    Enterprise data protection (EDP) does not mean zero data retention.

    Supported documentation shows these points:

    • EDP is a set of contractual protections and controls under the Data Protection Addendum and Product Terms for Microsoft Copilot and Microsoft Copilot Chat.
    • With EDP, prompts and responses are protected under the same enterprise terms used for Microsoft 365 customer data.
    • Prompts and responses are not used to train foundation LLMs.
    • Copilot prompts, responses, and related interaction data can be stored, audited, discovered, retained, and deleted within Microsoft 365 compliance systems.

    For retention behavior, the documentation explicitly states:

    • Data about user interactions with Microsoft Copilot includes the user prompt and Copilot response, including citations.
    • This interaction data is stored and encrypted.
    • Admins can use Content search and Microsoft Purview to view and manage this stored data.
    • Admins can use Microsoft Purview retention policies for data related to chat interactions with Copilot.
    • Copilot interaction data is stored within Microsoft 365 services and can be discovered, audited, and retained using Microsoft Purview capabilities.
    • Microsoft 365 can capture audit records for Copilot prompts, responses, and referenced content.
    • Retention policies for AI apps include user prompts and responses for Microsoft 365 Copilot.
    • For Copilot Chat with enterprise data protection, prompts and responses are logged, and the same retention policies used for Microsoft Copilot can be used for Copilot Chat.

    For Copilot APIs specifically, the available documentation supports this narrower conclusion:

    • Compliance controls, audit logging, and monitoring apply to Copilot API interactions.
    • Audit logging for Copilot and AI interactions is available through Microsoft Purview.

    That means the documented behavior for Copilot APIs is aligned with retention/compliance infrastructure rather than a zero-data-retention model.

    What cannot be concluded from the available documentation:

    • No documentation here states that Microsoft 365 Copilot APIs provide a Zero Data Retention (ZDR) offering.
    • No documentation here provides API-by-API retention differences for Copilot Chat API, Retrieval API, Search API, or Meeting Insights API.
    • No documentation here explicitly maps Copilot API interaction storage to a specific substrate such as Exchange Online.
    • No documentation here explicitly explains whether an Interaction Export API exists because prompts and responses are persisted in a particular Microsoft 365 store.

    What is supported for policy behavior:

    • Retention policies for AI apps can automatically retain or delete user prompts and responses.
    • If multiple retention policies or holds apply, standard Microsoft Purview retention principles apply, including retaining data for the longest duration when conflicts exist.
    • Retention and deletion behavior follows configured Microsoft Purview retention policies.

    So, based on the available documentation, the clearest answer is:

    • EDP and ZDR are different concepts.
    • EDP protects prompts and responses under Microsoft 365 enterprise privacy, security, compliance, and audit controls.
    • Microsoft 365 Copilot and Copilot API interactions are documented as subject to logging, auditing, discovery, and retention in Microsoft 365/Purview.
    • A zero-data-retention guarantee for Microsoft 365 Copilot APIs is not documented here.

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.