Microsoft 365 Copilot Memory is on by default, and admins still cannot restrict what information gets added to memory. That is the part engineers and tenant admins should care about here, not the marketing line about more relevant responses.
The roadmap item says Copilot now uses Microsoft 365 activity to provide more contextual responses, with updated settings to manage what it remembers. In practice, this builds on Copilot memory and enhanced personalization: Microsoft says personalization can use private communication data connected to Microsoft 365, including Teams chats, Outlook emails, transcripts, and data from connectors. It also uses Microsoft Graph context, which is exactly why the results can feel smarter.
That part is real. If you already use Microsoft Copilot and AI agents, better per-user context usually means fewer repetitive prompts and less prompt babysitting. For busy knowledge workers, that is useful.
What is actually changing?
According to Microsoft documentation, enhanced personalization is the tenant control behind Copilot memory, and it is turned on by default. When enabled, Copilot memory can use saved memories, inferred details from chat history, custom instructions, and work data from Microsoft 365 communications.
Microsoft also states that memories are stored in the user's Exchange mailbox in a hidden folder, and that prompts, responses, and data accessed through Microsoft Graph are not used to train foundation LLMs. So this is not the usual public-model data training concern.
The issue is governance, not model training.
Where the admin gap is
This is the part I would not gloss over:
- Admins cannot restrict what type of information is added to Copilot memory.
- Purview retention policies and retention labels do not apply to Copilot memory.
- Saved memories are retained until the user explicitly deletes them.
- Turning off enhanced personalization stops Copilot from using saved memories, but it does not remove those saved memories.
- Memory and personalization actions do not generate audit log entries in Purview.
That combination is awkward. You get more personalization, but not the level of lifecycle control, auditability, and retention enforcement most security teams would expect. If you care about least privilege, this is a real limitation. An assistant should not quietly accumulate durable user-specific context with weaker admin guardrails than the rest of the platform.
For most orgs, this is not an emergency. But if you built a strict compliance posture around retention, audit trails, or controlled use of employee communications, verify this before broad rollout. This is also where an AI and automation audit is more useful than another adoption workshop.
What this means in practice
The upside is obvious: more relevant Copilot answers with less repeated context. The second-order effect is less obvious: users will start treating Copilot like a persistent work assistant, which means memory quality, deletion behavior, and support processes suddenly matter.
I'd watch three things:
First, oversharing risk does not disappear just because Graph permissions are honored. Microsoft is clear that Copilot only shows what a user can access, but if your tenant already has messy permissions, memory makes that mess feel more personal and more trusted.
Second, connector-based grounding deserves extra scrutiny. Microsoft says enhanced personalization can use data from connectors, and Graph connectors bring external data into Microsoft Graph. If you are extending Copilot with custom integrations or AI workflow automation, be deliberate about what external content becomes available for grounding.
Third, support and privacy teams will get new questions: what is remembered, where is it stored, how is it deleted, and why is there no audit trail for certain actions? Those are operational questions, not product trivia.
My take
This feature is genuinely useful, but the governance story is behind the capability. I like the user value. I do not like that it is on by default while admin controls are still this thin.
If you run Microsoft 365 Copilot, do not block this automatically, but do not wave it through either. Review the enhanced personalization setting, test user deletion flows, validate Purview expectations, and document the support position before users discover memory on their own.




