Blog/OpenAI Is Now a Default Subprocessor in Microsoft 365 Copilot: What IT Admins Need to Check
Microsoft 365CopilotData PrivacyIT GovernanceCompliance

OpenAI Is Now a Default Subprocessor in Microsoft 365 Copilot: What IT Admins Need to Check

August 31, 20266 min readBy Brad McCorkle, Founder & CEO, Lesos AI

OpenAI as a subprocessor means Microsoft 365 Copilot can now send some prompts to models that run on OpenAI's own infrastructure instead of exclusively through the Azure OpenAI Service inside Microsoft's compliance boundary. As of July 24, 2026, that routing switched on by default for every eligible commercial tenant that had not already set the control to "No users," and most IT admins never saw the notice that made it happen.

Nobody in your organization approved this default.

Microsoft added OpenAI to its Online Services Subprocessors list on June 23, 2026, then rolled the control into the Microsoft 365 admin center on July 9 with the setting initially off. Fifteen days later, on July 24, it auto-enabled for eligible commercial customers, the same pattern Microsoft used earlier this year when it turned on Copilot's federated connectors by default: ship the capability, publish a message center notice, and let admins find the toggle after the fact.

What Changed in Microsoft 365 Copilot on July 24, 2026?

Before July 24, every Copilot prompt in a standard tenant stayed inside infrastructure Microsoft operates directly, processed by models under Microsoft's existing Data Protection Addendum. After July 24, tenants that had not explicitly restricted the new setting began routing eligible prompts, including ones that use GPT-5.6, to models OpenAI operates itself. The message center notice covering this change, MC1422074, framed it as giving customers access to OpenAI's newest models faster than Microsoft could rebuild them inside Azure. That part is true. It is also a data flow decision that took effect without anyone in most IT departments approving it.

What Does OpenAI as a Subprocessor Actually Mean for Your Data?

A subprocessor is any third party that processes your data on Microsoft's behalf under Microsoft's own contractual terms. In practice, OpenAI-operated models in Copilot still fall under Microsoft's Data Protection Addendum and its enterprise security commitments, so this is not the same as an employee pasting company data into a personal ChatGPT account. But it is a real change to where processing happens: prompts and the content Copilot grounds them on can now leave the boundary Microsoft operates directly and land on infrastructure a second company controls.

Microsoft's own subprocessor documentation states that OpenAI-operated models in Copilot are currently excluded from in-country data processing commitments when those commitments apply to your tenant. If your organization operates under EU data residency requirements, a healthcare data handling agreement, or a client contract that specifies where processing occurs, this setting is the one place that promise can quietly stop being true.

Where Do You Find and Change the Setting?

  • Sign in to the Microsoft 365 admin center and open Settings, then Copilot.
  • Select View all, then find "AI providers operating as Microsoft subprocessors."
  • Choose one of three options: all users, specific users or groups, or no users.
  • Confirm which Copilot experiences your organization actually depends on before restricting the setting; some GPT-5.6-only features, including parts of Copilot Cowork, are unavailable when OpenAI-operated models are turned off.
  • Document the decision wherever you already track your Purview and DLP configuration, since an auditor will ask about it the same way they ask about DLP coverage.
SettingWhat It DoesBest Fit
All users (default since July 24, 2026)Every user can be routed to OpenAI-operated models when Copilot needs themOrganizations with no data residency or contractual restriction on subprocessors
Specific users or groupsOnly a scoped group, for example a pilot team testing new features, can use OpenAI-operated modelsTeams that want to test GPT-5.6 features without exposing regulated data
No usersBlocks OpenAI-operated models entirely; Copilot falls back to models Microsoft operates directlyHealthcare, finance, government, and any tenant under EU or in-country data residency commitments

Should a Mid-Market IT Team Turn This Off?

Not automatically, and not without checking what breaks first. If your company has no client contract or regulatory requirement that specifies where AI processing happens, leaving the default on is a defensible choice, and turning it off costs you access to new OpenAI models the day they ship instead of whenever Microsoft finishes rebuilding them inside Azure. We covered a similar tradeoff in the HIPAA-compliant AI helpdesk automation post: the right setting depends on what your data actually is, not on a generic best practice.

For a healthcare, financial services, or public-sector tenant, the answer is closer to obvious.

How This Fits Your Broader AI Governance Program

Treat this setting the same way we told clients to treat Purview DLP for Copilot: not a one-time toggle, but a line item in whatever review process already covers SSO, MFA, and data loss prevention. The pattern is consistent enough now that it should change how you evaluate every future Copilot announcement. Microsoft ships the capability enabled, publishes a notice most admins never see, and leaves the compliance review to whoever eventually reads the Purview DLP configuration guide or its equivalent for the feature in question.

That is not a criticism of the OpenAI partnership itself. It is a scheduling problem: review new Copilot subprocessor and connector settings on a fixed cadence, quarterly at minimum, instead of waiting for a client contract or an audit to force the question.

Frequently Asked Questions

What is OpenAI's subprocessor setting in Microsoft 365 Copilot?

It is an admin control in the Microsoft 365 admin center, under Copilot Settings, that determines whether Copilot can route prompts to AI models OpenAI operates directly rather than models Microsoft operates through the Azure OpenAI Service. It has three states: all users, specific users or groups, and no users.

Is OpenAI processing my Microsoft 365 Copilot data by default?

Yes, if your tenant did not explicitly set the control to "No users" before July 24, 2026. Microsoft auto-enabled the setting for all eligible commercial customers on that date, so most organizations are sending at least some Copilot prompts to OpenAI-operated infrastructure right now without having made an active decision to do so.

How do I turn off OpenAI as a subprocessor in Copilot?

Go to the Microsoft 365 admin center, open Settings, then Copilot, then View all, and find "AI providers operating as Microsoft subprocessors." Select "No users" to block it entirely, or restrict it to a specific group if you want to keep testing new models with a smaller, lower-risk audience.

Does disabling the OpenAI subprocessor break Copilot features?

Some of them. Features built on GPT-5.6 and other OpenAI-operated models, including parts of Copilot Cowork, become unavailable once the setting is turned off, so check which capabilities your users actually rely on before you restrict it tenant-wide.

Get an Honest Read on Your Copilot Governance Gaps

Support Team reviews your live Copilot, Purview, and subprocessor settings against what your compliance obligations actually require, then shows you exactly what to change before an auditor or a client finds it first.

See How It Works

How AI-ready is your organization?

Free 2-minute assessment. Get an industry-specific score and action plan — no call required.

Get My Readiness Score