LearnMicrosoft 365 Copilot › 2 · The data plane

Web grounding: the one outbound edge

Every other grounding source lives inside your boundary; web grounding sends something OUT. Know exactly what leaves, who can toggle it, and how to hold a defensible position between 'useful' and 'leaky'.

The flow — what actually happens

Plain-language first; the packet-level view underneath each step is what you'd see in a Wireshark trace, and what healthy looks like.

  1. A prompt that needs the world

    'Compare our travel policy with current UK rail prices' — Copilot decides the second half needs the web. If web grounding is allowed, it formulates a SEARCH QUERY derived from the prompt — not the prompt itself, and not your documents.

    On the wire A generated query string goes to the search backend (Bing). The distinction that matters in reviews: derived query terms leave; the grounded tenant content and full conversation do not.
  2. Results come back and join the package

    Web snippets are added to the model package alongside any tenant content, the answer cites both kinds of source separately — your proof of what came from where.

    On the wire Search-service traffic is outside your tenant's audit surface; the CITATIONS in the response are your per-answer record of web use.

The control stack

Level Control
Org Admin center Copilot settings: web grounding allowed / off for work prompts
User Per-user toggle where org allows choice
Surface Copilot Chat's web vs work framing keeps the modes visible to users
Contract Web queries are handled under search terms, distinct from the M365 DPA — the fact your privacy review needs stated

Picking a stance (the three defensible positions)

  1. On for everyone — maximum utility; accept that derived query terms from work prompts reach the search service. Right for most commercial estates; document the derived-query fact and move on.
  2. Off for regulated groups, on elsewhere — the common landing zone; pair with comms so the regulated group understands WHY their Copilot feels less current.
  3. Off org-wide — the sovereign stance; Copilot becomes purely tenant-grounded. Honest cost: 'current events' prompts get worse, and users route around via consumer tools unless BYO-AI policy holds (alternatives concept).

The indefensible position is not knowing which stance you're in — this toggle is precisely the kind of quiet default that surfaces in a regulator questionnaire.

What to watch (proofs)

  • The stance as fact: the admin-center setting value, screenshot dated, + audit-log alerts on changes (control-system concept's lever list).
  • Per-answer evidence: citations distinguishing web vs tenant sources — train reviewers to read them; it settles 'did this answer use the web'.
  • The behaviour delta: same prompt with web on vs off (two test users) — the demo for the stance decision meeting.
  • Routing-around signal: consumer-AI usage telemetry (DSPM for AI) rising in the groups you toggled off — the cost of stance 2/3, measured.

The wire

  • Web grounding ON: derived search query -> Bing (not the raw prompt, not tenant content)
  • Citations mark web vs tenant sources per answer

Discussion

No messages yet — start the thread.

Sign in with your email to join the discussion — we send a one-time link, no password.