Skip to the main content.
Microsoft Copilot App Update
Arrives August 18, 2026New work and personal account indicators in the Copilot app

Your team is already using Copilot. Do you know which one?

Microsoft is adding labels to the Copilot app so people can tell their work account from their personal one, because right now a lot of them genuinely cannot. The labels will help. They will not stop anyone. Here is the difference between the two accounts, and the four controls that decide whether that difference costs you anything.

  • Two Copilots, two URLs, and almost identical screens
  • Microsoft Purview files the personal one next to ChatGPT, not next to yours
  • Four Microsoft controls, and which two of them actually stop it
60-second version
What happens when someone asks the wrong Copilot
Aug 18, 2026
Microsoft starts adding work and personal account indicators to the Copilot app
Microsoft Partner Center announcement
Unchanged
Security, compliance, and governance controls after the update, in Microsoft's own words
Microsoft Partner Center announcement
1,200+
Generative AI sites Microsoft Purview can watch, with personal Copilot among them
Microsoft Learn, supported AI sites list
3
Ways to enforce tenant restrictions, two of which need no corporate proxy
Microsoft Learn, Microsoft Entra ID

What is changing in the Copilot app?

On August 18, 2026, Microsoft begins rolling out an updated Copilot experience across web, desktop, and mobile. The stated purpose is simple and worth reading twice: to make it easier for users to distinguish between their work and personal accounts.

Three things arrive together. Account indicators appear in the interface, including account labels, a green shield for Microsoft Entra work accounts, and different backgrounds for each account type. The app name and icon get simplified. And the web address moves, from m365.cloud.microsoft to copilot.cloud.microsoft, with users redirected automatically unless the new address happens to be blocked inside their organization.

The date is a start rather than a switch. Microsoft describes the updated Windows and Mac desktop app as an early preview on August 18, with broad deployment beginning in mid-September. If your people see it at different times over several weeks, that is the plan working, not a problem.

If the network side of that URL move is what brought you here, that is a different job with a different answer, and we have written it up separately in the network fix for the cloud.microsoft migration. This page is about the account question underneath it.

"Security, compliance, and governance controls remain unchanged."

Microsoft Partner Center, August 2026 announcements, section "Microsoft Copilot app update", dated August 14, 2026

A label tells people. It does not stop them.

That one sentence from Microsoft is the most important thing in the announcement, and it is the easiest to skim past.

Read it plainly. Everything an employee could do with a personal Microsoft account on August 17 is still possible on August 19. The green shield is a helpful piece of interface design that reduces honest mistakes. It is not a boundary, it is not a policy, and it does not report anything to your administrators.

This matters because Microsoft has effectively confirmed the underlying problem by shipping a fix for it. You do not build account labels, colored backgrounds, and a shield icon into a product used by hundreds of millions of people unless a meaningful number of them are losing track of which account they are in. The confusion is real enough to justify engineering effort.

Now put that in a credit union, a bank, or a mortgage company. Somebody drafting a hardship letter, summarizing a loan file, or cleaning up notes from a member call has two Copilots within one click of each other. One of them sits inside your tenant, under your data protection. The other is a consumer product signed in with an account you do not own, do not administer, and cannot search.

The employee is not doing anything malicious in this story. That is the point. They are trying to get work done faster, which is exactly what you bought Copilot for. The failure mode is a productive person in the wrong window.

The uncomfortable version

If your answer to "has anyone here put member data into a personal Copilot account?" is "probably not", that is not an answer. It is the absence of one. The controls further down this page turn that into something you can actually check.

Find out what your tenant can actually see

ABT runs a free security assessment against your Microsoft 365 tenant. Part of it is this exact question: which AI accounts your people can reach, what your tooling records when they do, and which of the four controls below you already have.

Two URLs. Two completely different governance worlds.

The clearest evidence of how differently Microsoft treats these two accounts is buried in a Microsoft Purview documentation page most people never open.

Work
copilot.cloud.microsoft

Signed in with a Microsoft Entra ID work account. Governed natively as a Microsoft 365 Copilot experience inside your tenant, with your data protection, your retention, and your administrators.

Personal
copilot.microsoft.com

Signed in with a personal Microsoft account. Treated by Microsoft Purview as a third-party generative AI site, in the same list and the same category as ChatGPT, Claude, and Gemini.

Microsoft Purview publishes a list of generative AI sites it can monitor for data security and compliance. It runs to more than 1,200 domains, and it is the list your Purview policies draw on when you want to know who is pasting what into an AI tool.

The consumer Copilot address is on that list. It sits alphabetically among the other AI destinations an organization might want to watch, categorized by Purview as an "Other AI app" rather than as a Copilot experience. Meanwhile cloud.microsoft, the work Copilot, does not appear on the list at all, because it does not need to. It is governed from the inside.

Read those two facts next to each other and the picture is unambiguous. Microsoft's own data security tooling does not consider personal-account Copilot to be your Copilot. It considers it somebody else's AI product that your staff happen to be using, which is precisely what it is.

And there is a second catch

Seeing any of those third-party AI sites is not automatic. Microsoft's own documentation lists two prerequisites for third-party AI site visibility in Data Security Posture Management for AI: install the Microsoft Purview browser extension, and onboard devices to Microsoft Purview. A tenant that switched on the AI dashboards without doing both has clear visibility into the Copilot that was never the risk, and none into the one that is. The dashboard looks healthy exactly where it is blind.

Comparison infographic showing work Copilot at copilot.cloud.microsoft governed inside the Microsoft 365 tenant versus personal Copilot at copilot.microsoft.com treated by Microsoft Purview as a third-party AI app
Two Copilots, two governance worlds. Sources: Microsoft Partner Center and Microsoft Learn, verified August 2026.

What actually differs between the two accounts

Same brand, same assistant, same general shape on screen. Everything that matters to a regulated institution is on this table.

  Work account Personal account
Signs in with A Microsoft Entra ID account your organization owns and administers A personal Microsoft account the individual owns, created outside your tenant
Web address copilot.cloud.microsoft, moving there from m365.cloud.microsoft copilot.microsoft.com
New visual indicator Green shield plus a work account label, arriving from August 18, 2026 Personal account label and a different background, same rollout
How Microsoft Purview categorizes it A Copilot experience, governed natively An "Other AI app", one of more than 1,200 third-party generative AI sites
What it takes to see it at all Nothing extra beyond auditing being on The Microsoft Purview browser extension and onboarded devices, both listed as prerequisites
Who administers the account Your administrators The employee
Where it lives when they leave In your tenant, under your control, after the account is disabled With them, in an account you never had access to
What constrains it Not applicable, this is the one you want them in Microsoft Entra ID tenant restrictions v2, plus Microsoft Purview Endpoint DLP on the paste

Every row is sourced to Microsoft's own documentation, verified in August 2026. Check them yourself: the Partner Center August 2026 announcements for the rollout and the controls-unchanged statement, the Microsoft Purview supported AI sites list for the categorization, Data Security Posture Management for AI for the visibility prerequisites, and Microsoft Entra ID tenant restrictions v2 for the enforcement options. Categorization reflects Microsoft's published supported-sites list at the time of writing; Microsoft states that the list grows over time.

Four controls, and only two of them actually stop anything

It would be easy to call all four of these controls and move on. They are not the same thing, and the difference is the whole argument of this page, so each one below is labeled for what it genuinely does: enforce, detect, or inform. You need all four. Only two of them will stop a person mid-action.

1

Block the sign-in with tenant restrictions v2

Enforces

This is the only one of the four that stops the sign-in itself. Microsoft Entra ID tenant restrictions v2 governs Microsoft account authentication on both the identity and the data plane. The important architectural point, and the one most write-ups get wrong, is that version 2 is configured as a server-side cross-tenant access policy in Microsoft Entra ID rather than as a header injected by a proxy. You create a partner tenant policy for the Microsoft account tenant, and Microsoft's guidance is explicit that if you are still running the legacy version 1 mechanism you should remove its sec-Restrict-Tenant-Access-Policy header from your corporate proxy once version 2 is in place, because the two will otherwise conflict.

There are three ways to apply the policy: universal tenant restrictions through Global Secure Access, which needs no corporate proxy and covers all browsers and platforms; signaling through a corporate proxy, which covers the authentication plane only; or Windows Group Policy on corporate-owned devices, which covers both planes with no proxy required and reaches Microsoft Edge and every website in it.

Know this before you promise it. Microsoft lists per-user tenant restrictions for Microsoft accounts as an unsupported scenario, so the policy applies to all Microsoft accounts rather than to selected people. Application-level granularity is available, which is how organizations carve out a genuinely needed consumer service. Consumer OneDrive is also unsupported and needs a separate proxy-level block, and blocking the Microsoft account tenant does not block business-to-business authentication of consumer accounts.
2

Turn on the visibility, including the parts that are not automatic

Detects, does not block

Microsoft Purview Data Security Posture Management for AI gives you one place to see interactions across Copilot experiences, enterprise AI apps, and other AI apps. For the third category, which is where personal Copilot sits, Microsoft names two prerequisites explicitly: install the Microsoft Purview browser extension, and onboard devices to Microsoft Purview. Do both, then give it time, because reports take at least a day to populate.

This is also the step where most institutions find out what they did not know. We wrote about the wider version of that problem in how financial institutions fix Copilot data access before rollout.

3

Stop the paste itself with Endpoint DLP

Enforces

Microsoft Purview Endpoint DLP can detect when a user attempts to paste content to a restricted service domain. The detail that makes it useful here is that the evaluation runs on the content being pasted, independent of how the source item it came from was classified. That means it can reach text somebody typed out or copied off a screen, not only content lifted from a labeled document. Endpoint DLP can also block uploads to a restricted cloud service domain and redirect the user to Microsoft Edge.

It is not a blanket block on pasting, and it should not be sold internally as one. Three things all have to be true: the device has to be onboarded to Microsoft Purview, the destination has to sit in a restricted service domain group you have defined, and the pasted content still has to match the sensitive information types or classifiers your policy is looking for. Point it at the data you actually care about, such as account numbers and loan file identifiers, and it earns its place. Leave the conditions vague and it will quietly catch nothing.

If you are configuring Purview data loss prevention for AI more broadly, the three configurations to set before your first Copilot prompt covers the wider policy set.

4

Teach the tell, now that there is one

Informs only

This is the softest control and the cheapest, and it is the one the August 18 update finally makes possible. Until now there was no reliable visual answer to "which Copilot am I in?" From this rollout there is: a green shield and an account label mean the Microsoft Entra work account. That is a genuinely teachable thing, it fits on one slide, and it gives your staff a way to catch themselves.

Pair it with the plain-language version of why it matters. People follow a rule they understand far more reliably than one they were handed. The examiner-facing side of this is covered in the five Microsoft 365 controls examiners ask about before a Copilot rollout.

Four-step control stack infographic showing Microsoft Entra ID tenant restrictions, Microsoft Purview Data Security Posture Management for AI, Microsoft Purview Endpoint DLP, and staff training on the green shield work account indicator
Labels tell people. Controls stop them. Sources: Microsoft Learn documentation for Microsoft Entra ID and Microsoft Purview, verified August 2026.

A free security assessment that answers this specific question

No cost, no obligation

We look at your tenant and tell you what it can see, what it blocks, and what it misses.

  • Whether personal Microsoft accounts can currently be used from your managed devices, and by which route
  • Whether tenant restrictions are configured, and which of the three enforcement paths fits your device estate
  • Whether the Microsoft Purview prerequisites for third-party AI visibility are actually in place, or only assumed
  • What your existing data loss prevention policies do and do not cover on a paste into a browser
  • A written summary you can hand to an examiner, an auditor, or a board committee without translating it first

ABT manages your Microsoft 365 tenant as a Tier 1 Microsoft Cloud Solution Provider. The assessment is read-only and carries no cost or obligation. Note that not every control described on this page is available in every Microsoft 365 plan: tenant restrictions v2, the fuller Microsoft Purview data loss prevention capabilities, and Data Security Posture Management for AI depend on which plan or add-on you hold. Telling you which controls your current licensing actually gives you, before you buy anything, is part of what the assessment is for.

Why this lands differently in a regulated institution

ABT is a Tier 1 Microsoft Cloud Solution Provider serving more than 750 financial institutions. Credit unions, banks, and mortgage companies carry supervision and recordkeeping duties that assume you can produce what your people wrote and where they wrote it. An account outside your tenant is an account outside that story. We work on this problem inside regulated environments every week, which is why the caveats above are on the page instead of in a footnote after the project starts. More on what a Tier 1 CSP actually does.

Work and personal Copilot accounts, answered

Microsoft is updating the Copilot web, desktop, and mobile experiences so users can more easily tell their work account from their personal one. The update adds account labels, a green shield for Microsoft Entra work accounts, and distinct backgrounds for each account type, simplifies the app name and icon, and moves the web address from m365.cloud.microsoft to copilot.cloud.microsoft with automatic redirection. August 18 is the start rather than a single global switch: Microsoft describes the updated Windows and Mac desktop app as an early preview on that date, with broad deployment beginning in mid-September.
No. Microsoft states directly that security, compliance, and governance controls remain unchanged. The new indicators are a usability improvement that helps people notice which account they are in, which reduces honest mistakes. They are not a policy, they do not block anything, and they do not report anything to your administrators. Preventing personal account use requires separate controls, principally Microsoft Entra ID tenant restrictions v2.
From the August 2026 rollout onward, the visual tell inside the app is a green shield and an account label, which indicate a Microsoft Entra work account. The other reliable tell is the web address: copilot.cloud.microsoft is the work experience, and copilot.microsoft.com is the consumer one. Neither of those is an audit trail, though. If you need to know what is actually happening across your organization rather than what one person can see on their own screen, that comes from Microsoft Purview Data Security Posture Management for AI, and for third-party AI sites it requires the Microsoft Purview browser extension and onboarded devices.
Only if you have set it up for that, and it is not the default. Microsoft Purview publishes a list of more than 1,200 generative AI sites it supports for data security and compliance protections, and the consumer Copilot address appears on that list alongside other third-party AI destinations such as those used for ChatGPT and Gemini. Purview categorizes it as an "Other AI app" rather than as a Copilot experience. Microsoft's documentation names two prerequisites for third-party AI site coverage: install the Microsoft Purview browser extension, and onboard devices to Microsoft Purview. Without both, a tenant can have detailed visibility into its own Microsoft 365 Copilot usage and none into personal-account usage.
Microsoft Entra ID tenant restrictions v2 is the control designed for this. It governs Microsoft account authentication on both the identity and data planes, and unlike the legacy version it is configured as a server-side cross-tenant access policy in Microsoft Entra ID rather than as a header injected at a corporate proxy. If you are still running the version 1 mechanism, Microsoft's guidance is to remove its sec-Restrict-Tenant-Access-Policy header from the proxy once version 2 is in place. There are three enforcement options: universal tenant restrictions through Global Secure Access, which needs no corporate proxy and covers all browsers and platforms; corporate proxy header injection, which covers the authentication plane only; and Windows Group Policy on corporate-owned devices, which covers both planes without a proxy. Three limits are worth knowing before you plan around it: per-user tenant restrictions for Microsoft accounts is an unsupported scenario, so the policy applies to all Microsoft accounts rather than selected people, although application-level granularity is available; anonymous blocking to consumer OneDrive is unsupported and needs a proxy-level block instead; and blocking the Microsoft account tenant does not block business-to-business authentication of consumer accounts.
No, and the similarity of the names is part of why this is worth addressing. copilot.cloud.microsoft is the work experience, and it is where the Microsoft 365 Copilot web app is moving from m365.cloud.microsoft. copilot.microsoft.com is the consumer Copilot, signed in with a personal Microsoft account. They look broadly similar on screen, they carry the same brand, and only one of them sits inside your tenant with your data protection and your administrators.
Yes, this is what Microsoft Purview Endpoint DLP is for. Its "paste to supported browsers" capability detects when a user attempts to paste content to a restricted service domain, and Microsoft's documentation states that the evaluation is performed on the content being pasted, independent of how the source item it came from is classified. That independence is what makes it effective here, because it can reach text a person typed or copied off a screen rather than only content taken from a labeled document. It is not a blanket block on pasting, though: the device has to be onboarded to Microsoft Purview, the destination has to sit in a restricted service domain group you have defined, and the pasted content still has to match the sensitive information types or classifiers your policy looks for. Endpoint DLP can also block uploads to a restricted cloud service domain and redirect the user to Microsoft Edge.
Whether personal Microsoft accounts can currently be used from your managed devices and by which route, whether tenant restrictions are configured and which of the three enforcement paths suits your device estate, whether the Microsoft Purview prerequisites for third-party AI visibility are genuinely in place rather than assumed, and what your existing data loss prevention policies do and do not cover on a paste into a browser. You get a written summary suitable for an examiner, an auditor, or a board committee. It is read-only, free, and carries no obligation. Which of these controls your organization can use depends on your Microsoft 365 plan and add-ons, and telling you that before you buy anything is part of the assessment.
Talk to an Expert

Which Copilot
are your people in?

Tell us about your tenant and ABT's team will run a free security assessment: what your people can currently reach, what your tooling records when they do, and which of the four controls you already have in place.

SOC 1 Type 2 · Security Controls
SOC 2 Type 1
Tier-1 CSP
Zero Trust Baseline
25+
Years on Microsoft
750+
Institutions Served
$0
Assessment Cost
Get Your Free Security Assessment
Written summary within one business day. No obligation.
I am interested in... (optional)
First name is required
Last name is required
Valid email is required
Response within 1 business day. No obligation.
You are in.
An ABT security specialist will review your request and reach out within one business day.