LearnMicrosoft 365 Copilot › 3 · Governance & the Copilot Control System

The Copilot Control System: the admin command centre

Microsoft's answer to 'where do I govern all this?' is a named framework spanning three portals. Here is what lives where, what each lever really does, and the gaps the framework doesn't close by itself.

The three-portal reality

The Copilot Control System is a framework over surfaces you already know:

  1. M365 admin center — Copilot pages: the product levers. Web grounding stance, feature enablement (memory, experiments), agent availability and deployment approvals, usage dashboards, Copilot Chat pinning. This is where "is X on for whom" gets answered.
  2. Microsoft Purview: the data levers. DSPM for AI (posture assessments, AI-specific risk reports), DLP for Copilot, sensitivity-label interactions, audit/eDiscovery/retention of interactions, communication compliance on Copilot conversations (security module).
  3. SharePoint admin + SAM: the content levers (the oversharing concept's entire toolkit).

Plus the fourth that pretends not to be one: Entra — because agents now have identities (Agent IDs) with Conditional Access and RBAC (agent governance concept), and because every Copilot session rides your CA policies anyway.

The levers that matter most, ranked

  1. Agent deployment approval flow — whether agents reach users through a governed pipeline or a wild west (module 5).
  2. Web grounding stance — the boundary edge (data-boundary concept).
  3. DSPM for AI assessments — the recurring posture scan; treat its findings like vulnerability reports with owners and SLAs.
  4. DLP for Copilot policies — the durable content control.
  5. Usage/adoption dashboards — because unused seats are the CFO's favourite Copilot fact (operations module).

What the framework does NOT do by itself

It doesn't fix oversharing (runbook required), doesn't review agent manifests (humans required), doesn't make interaction retention decisions (records programme required), and doesn't stop a determined user pasting secrets into a consumer AI on their phone (that's endpoint DLP + policy, outside Copilot entirely). The Control System is instrumentation and levers — the operating model is still yours to run.

What to watch (proofs)

  • One page per portal, exported quarterly: Copilot settings snapshot, DSPM assessment results, SAM report — the governance pack auditors accept.
  • Lever drift: admin-center Copilot setting changes land in the unified audit log with actors — alert on the web-grounding and agent-approval toggles.
  • The gap list, maintained: what the framework doesn't cover in YOUR estate (BYO-AI usage, unlabeled legacy shares) — honesty here is the serv365 house style for a reason.

Discussion

No messages yet — start the thread.

Sign in with your email to join the discussion — we send a one-time link, no password.