A user deletes a Microsoft 365 Copilot conversation and legal asks whether it disappeared from eDiscovery. Security wants to know which document grounded the answer, while privacy asks how long the prompt remains. These questions look similar but belong to three layers: visible history, the compliance copy and audit metadata. Microsoft Purview treats them separately. Governance cannot begin with “we retain Copilot chats for 30 days” until the organization defines chat, viewer and whether the statement concerns content or an event log.
One interaction creates several distinct traces
The prompt and response are interaction content. For retention they are stored in a hidden area of the user’s Exchange Online mailbox that ordinary Outlook does not expose. An audit record instead captures the event: user, time, workload and references to files, sites or resources used by Copilot. A file uploaded to Copilot Chat can live in the user’s OneDrive; Copilot Pages can live in a user-owned SharePoint Embedded container. A single question can therefore have different lifecycles for conversation text, audit metadata, upload and output artifact.
Deletion in the interface does not define compliance state
When a user deletes a message before its retention period ends, a copy moves into the hidden SubstrateHolds folder where eDiscovery can still find it. Timer jobs are not immediate. Microsoft documents typical processing windows of one to seven days, at least one day in the hold folder and then another job before permanent deletion. If another retention policy or eDiscovery hold applies, retention principles take precedence. The visible chat is therefore weak evidence that the compliance copy exists or has been destroyed.
New retention locations separate classes of AI applications
New Purview retention policies no longer treat Copilot only as an extension of Teams chats. Documentation distinguishes Microsoft Copilot experiences, Enterprise AI apps and Other AI apps. The first includes Microsoft 365 Copilot, Security Copilot, Copilot in Fabric and Copilot Studio. Enterprise AI apps include Entra-registered AI apps and ChatGPT Enterprise; Other AI apps include consumer services such as ChatGPT, Gemini or DeepSeek when captured by a collection policy. Each location therefore needs explicit scope and ownership.
| Trace | Question | Control |
|---|---|---|
| Prompt and response | What did the user ask and receive? | Purview retention and eDiscovery |
| Audit event | Who, when, where and which resources? | Purview Audit |
| Referenced content | Which document version grounded the answer? | SharePoint/OneDrive, labels and eDiscovery |
| Uploaded file | What was supplied directly to chat? | OneDrive retention and DLP |
| Output artifact | What was created or shared next? | Policies of the destination workload |
Audit Standard already includes Microsoft Copilot
Microsoft applications including Microsoft 365 Copilot are logged automatically in Audit Standard when auditing is enabled; that baseline does not require pay-as-you-go. Records identify user, time, workload and references to sources. Audit Standard provides 180-day searchable retention for common plans. Audit Premium adds longer defaults for selected records, custom retention policies, intelligent insights and higher API bandwidth. An interaction event is not a substitute for conversation content: a complete investigation combines Audit and eDiscovery.
Non-Microsoft AI applications follow a different billing path
Auditing interactions with non-Microsoft AI applications uses pay-as-you-go, and Microsoft specifies 180-day retention for those audit records. Microsoft apps remain included in Audit Standard. Capturing prompts and responses from other AI services additionally requires the relevant collection policy. An organization allowing ChatGPT Enterprise or another service cannot copy its Microsoft 365 Copilot conclusion. It must design collection, billing, retention location and lawful purpose separately.
eDiscovery Standard and Premium are different workflows
eDiscovery Standard can create a case, search, hold and export relevant Copilot interactions when licensing is appropriate. Premium adds an end-to-end process with custodians, collections, review sets, analysis and legal communications. The service description also distinguishes premium search for Copilot interactions. Purview roles for investigators and licenses for users whose data benefits from the service are separate concerns. Test the actual query and export before an incident rather than confirming only that a menu is visible.
The referenced file can change after the answer
Audit can indicate that Copilot used a file or site. An investigator may need the version that was available at that moment. Purview can apply retention labels to cloud attachments and links to preserve the exact shared version; Microsoft extends this capability to content referenced in Copilot interactions. Without it, today’s document may differ from the one that grounded the answer. Connect audit references with SharePoint and OneDrive version and retention design.
Source permissions are enforced at query time
Copilot can use only content the user is authorized to access. Encrypted material additionally requires VIEW and EXTRACT rights; sensitivity labels and Azure Rights Management are enforced during grounding and generation. Current permission, however, does not prove the historic state. The user might have had access when asking and lost it later. Investigations should correlate audit, sign-in, sharing changes, file version and interaction content. A screenshot of an answer is not sufficient evidence.
Prompts can themselves be sensitive records
Users put names, contract context, customer information and incident details into prompts. Governance must define lawful purpose, retention duration, investigator access and data-subject processes. Minimization does not always mean the shortest deletion policy; deleting too quickly can destroy evidence required for an incident or dispute. Indefinite retention increases the stock of sensitive text. The decision should follow a records schedule and risk assessment rather than a technical default.
| Scenario | Priority | Typical design |
|---|---|---|
| Routine productivity | Minimization and operational need | Defined period from the records schedule |
| Regulated activity | Evidence of decisions | Longer retention and explicit scope |
| Litigation or investigation | Prevent relevant deletion | eDiscovery hold for affected custodians |
| Security incident | Correlate source and event | Audit plus preserved content and versions |
| External AI service | Collection and lawful purpose | Separate policy, billing and privacy assessment |
Access to prompts should be narrower than ordinary log access
Audit and eDiscovery can expose highly sensitive material, so do not give every administrator a global compliance role. Separate Audit Reader, case-based eDiscovery access, export approval and oversight of investigators. Record the reason for a search and scope cases to necessary custodians and dates. Teams should also understand that audit schemas evolve: fields such as Messages, jailbreak detection and DLP evaluation flags are metadata whose availability depends on workload and scenario.
A test protocol for one prompt
- 01
Create a controlled interaction
Use a unique phrase and versioned document without real sensitive data
- 02
Record the visible state
Capture time, app, account, source and expected answer
- 03
Find the audit event
Verify user, workload, operation and references
- 04
Find content in eDiscovery
Search the phrase and verify prompt and response
- 05
Delete the visible chat
Confirm compliance results still follow the retention policy
- 06
Change the source document
Check whether the relevant historic version remains discoverable
- 07
Document timing and licensing
Put timer jobs and roles in the runbook; do not call delay data loss
Governance minimum before broad rollout
The Copilot approval pack should contain a trace map, retention decision record, roles and separation of duties, an eDiscovery test, legal-hold procedure, DLP and sensitivity-label baseline, oversharing remediation and user guidance. Add an incident contact for prompt-related events and a regular review of new AI locations in Purview. The product changes faster than many records schedules, so an owner should verify locations, supported workloads and licensing at least quarterly.
The management conclusion
The choice is not simply to retain or not retain “AI history.” The organization manages several traces with different purposes, costs and risks. A short visible history does not eliminate the compliance copy, Audit Premium alone does not preserve prompt text, and eDiscovery hold does not repair access to source content. A defensible model joins records management, legal process, security monitoring and SharePoint governance. Only then can the company say who can retrieve what, for how long and with which evidence.
Frequently asked questions
Does a prompt disappear from eDiscovery when the user deletes the chat?
Not necessarily. Retention or hold can preserve the copy in hidden storage for eDiscovery according to policy and processing time.
Is Microsoft 365 Copilot included in Audit Standard?
Yes. Microsoft AI applications are included when organizational auditing is enabled.
Does the audit log contain the complete prompt and response text?
Audit captures interaction metadata. Use retention and eDiscovery for content, holds and export.
Is 30 days the correct retention period?
There is no universal number. Derive it from records schedules, legal obligations, incident response and data minimization.








