The mystery of personal SharePoint skills

Screenshot 2026-09-25 075006

You can ask Copilot in SharePoint to create a personal skill as you see above. When you do so it is store in your OneDrive for Business.

Screenshot 2026-09-25 075244

Specifically in:

My files > Documents > Copilot > Agent Assets > Skills > <Skill name>

Interestingly, I can’t find this documented anywhere officially. All I can find is information about SharePoint site skills here (i.e. saved into a SharePoint site):

Extend Copilot in SharePoint with skills

and mentions nothing about personal SharePoint skills, just site skills per:

Skills are stored as Markdown (.md) files in the Agent Assets library on the site, under /Agent Assets/Skills/<skill-name>/SKILL.md

Such as the follow site skill in my SharePoint site:

Screenshot 2026-09-25 080629

Note – “on the SITE” and there no mention in the article of ‘personal SharePoint skills’. However, as you see in my screen shots, you can definitely ask SharePoint to create a personal skill and it ends up in your OneDrive for Business.

So, the best advice is that personal skills in SharePoint are currently an ‘undocumented’ feature and should be used with caution because they may not be supported going forward. Hopefully, we’ll see official documentation on SharePoint personal skills shortly.

Need to Know podcast–Episode 370

In this episode I ask the question about whether privacy is becoming and optional and take a deep dive into creating better data structures in places like SharePoint and Teams that help users and AI generate better results. There is also the usual look at recent cloud news from Microsoft and thoughts on how even all this is become about AI. Love your feedback.

Brought to you by www.ciaopspatron.com

you can listen directly to this episode at:

https://ciaops.podbean.com/e/episode-370-structure/

Subscribe via iTunes at:

https://itunes.apple.com/au/podcast/ciaops-need-to-know-podcasts/id406891445?mt=2

or Spotify:

https://open.spotify.com/show/7ejj00cOuw8977GnnE2lPb

Don’t forget to give the show a rating as well as send me any feedback or suggestions you may have for the show

Resources

CIAOPS Need to Know podcast – CIAOPS – Need to Know podcasts | CIAOPS

X – https://www.twitter.com/directorcia

director@ciaops.com

CIAOPS Blog

Join my Teams Shared Channel – CIAOPS

CIAOPS Merch store – CIAOPS

Become a CIAOPS Patron

CIAOPS AI Dojo

CIAOPS weekly news update – CIA Brief – CIAOPS

CIAOPS Labs – The Special Activities Division of the CIAOPS

Support CIAOPS

Get your M365 questions answered via email

Join my email list

A special thanks to the CIAOPS Patron community for making this podcast possible. You can find the benefits of a subscription to the community and become a member at https://www.ciaopspatron.com

Updates

Take control of your EWSAllowedAppIDs list before EWS access changes

Microsoft is changing how Exchange Web Services (EWS) access is managed. Organizations should review and manage their EWSAllowedAppIDs list now to ensure approved applications retain access and to avoid disruptions when the new controls take effect.

Link: https://techcommunity.microsoft.com/blog/exchange/take-control-of-your-ewsallowedappids-list-before-ews-access-changes/4553534

Understanding the new 100 GB mailbox entitlement for Microsoft 365 Business suites

Microsoft explains the introduction of 100 GB mailbox storage for eligible Microsoft 365 Business plans, outlining entitlement requirements and how organizations can benefit from increased mailbox capacity.

Link: https://techcommunity.microsoft.com/blog/exchange/understanding-the-new-100-gb-mailbox-entitlement-for-microsoft-365-business-suit/4548243

AI

Available today: OpenAI GPT-6 Astra in Microsoft Copilot

Microsoft has added OpenAI’s GPT-6 Astra model to Copilot, giving users access to an advanced foundation model designed to improve reasoning, content generation, and productivity experiences across Microsoft 365.

Link: https://techcommunity.microsoft.com/blog/microsoft-copilot-blog/available-today-openai-gpt-6-astra-in-microsoft-copilot/4552808

Available today: Anthropic Claude Fable 5.1 in Microsoft Copilot

Anthropic’s Claude Fable 5.1 model is now available in Microsoft Copilot, expanding the range of AI models users can leverage for research, analysis, content creation, and complex business tasks.

Link: https://techcommunity.microsoft.com/blog/microsoft-copilot-blog/available-today-anthropic-claude-fable-5-1-in-microsoft-copilot/4551974

Expanding model choice in Copilot with Grok

Access to Grok models is rolling out through the Microsoft Frontier Program in Microsoft Word, Excel, and PowerPoint. We are starting with a focused release to gather customer feedback and learn how customers use the model across common productivity scenarios.

https://techcommunity.microsoft.com/blog/microsoft-copilot-blog/expanding-model-choice-in-copilot-with-grok/4555749

What’s New in Microsoft Copilot | August 2026

A monthly roundup of new Copilot capabilities, including model updates, workflow enhancements, productivity improvements, and new AI-powered features designed to help users work more effectively.

Link: https://techcommunity.microsoft.com/blog/microsoft-copilot-blog/what%25E2%2580%2599s-new-in-microsoft-copilot–august-2026/4551960

Security

What’s new in Microsoft Security: August 2026

Microsoft’s monthly security update covering new capabilities across Defender, Sentinel, Entra, Security Copilot, and other security products, along with recent security announcements and enhancements.

Link: https://www.microsoft.com/en-us/security/blog/2026/08/27/whats-new-in-microsoft-security-august-2026/

Passkey-themed social engineering leads to identity and cloud compromise

Microsoft details a campaign where attackers used passkey-related social engineering techniques to trick users into compromising credentials and cloud identities, while also providing mitigation guidance.

Link: https://www.microsoft.com/en-us/security/blog/2026/09/09/passkey-themed-social-engineering-leads-identity-cloud-compromise/

Protecting organizations from AI-assisted executive impersonation and invoice fraud

This security guidance examines how attackers are using AI to impersonate executives and conduct invoice fraud, alongside recommendations to help organizations detect and prevent these attacks.

Link: https://www.microsoft.com/en-us/security/blog/2026/09/10/protecting-organizations-ai-assisted-executive-impersonation-invoice-fraud/

Impersonating IT support: how threat actors turn a remote session into enterprise-wide access

Microsoft analyzes how attackers impersonate IT support staff to gain remote access and expand their foothold within organizations, highlighting attack techniques and defensive measures.

Link: https://www.microsoft.com/en-us/security/blog/2026/09/02/impersonating-it-support-threat-actors-turn-remote-session-into-enterprise-wide-access/

From CIAOPS

Image Model Comparison

A practical comparison of image generation models, reviewing differences in output quality, style, and effectiveness to help users evaluate which AI image generation model best suits their needs.

Link: https://directorcia.github.io/Office365/image-comparison.html

September webinar – local AI

https://blog.ciaops.com/2026/09/10/ciaops-need-to-know-microsoft-365-webinar-september-5/

Better Is a Direction, Not a Starting Point

image

I have made plenty of decisions that looked sensible at the time and less impressive a year later. Usually, I was working with the experience, evidence and tools I had then. The real test is not whether I got everything right on day one. The test is what I changed after new information arrived.

That distinction matters because hindsight can become a very comfortable hiding place. I can criticise an old process without doing anything differently today. Reflection only becomes useful when it alters the next action.

Progress needs some humility

In technology, yesterday’s good practice can become today’s unnecessary friction. A workflow built around emailed spreadsheets may once have been the most practical answer. Later, a shared file in SharePoint may remove version confusion. Then a well-designed process using Teams, Planner or Power Automate may make the work clearer again.

I do not think that means every earlier choice was a failure. It means the environment changed, the team learned and better options became available.

This is where humility matters. I need enough confidence to make a decision with incomplete information, but not so much confidence that I defend it forever. Experience should sharpen my judgement, not harden my position.

Copilot makes the learning visible

Microsoft 365 Copilot gives me a practical way to shorten this learning loop.

Imagine I have been preparing a weekly client update by opening several emails, reviewing Teams messages and rebuilding the same summary in Word. I may have done that for months because it worked. It was familiar and reliable.

Then I try a different approach. I ask Copilot in Outlook to summarise the relevant thread. I use Copilot in Teams to identify decisions and unresolved actions from a meeting. I bring the material into Word and ask for a first draft organised around progress, risks and next steps. I still review every line, because responsibility remains with me, but I have changed the process based on what I now know.

The first prompt may be average. The summary may miss context. My instructions may be too vague. That is not evidence that the whole idea is useless. It is feedback. I can refine the prompt, provide a better reference file, correct the structure and save the improved version for next week.

Getting value from Copilot is rarely one brilliant prompt. It is repeated adjustment inside real work.

Improvement is a behaviour

I often see businesses delay change because they are waiting for certainty. They want the perfect governance model, the perfect use case and the perfect training plan before anyone begins. I understand the caution, especially where client data, security and accuracy are involved. Some boundaries must be established first.

But perfection can also become an excuse. A small, governed trial with a real workflow can teach more than another month of abstract discussion. Use a low-risk task. Check the output. Note what failed. Update the instructions. Share the lesson in Teams. Repeat.

It is about creating a culture where changing your method after learning something new is considered sound judgement, not an admission of weakness.

I cannot demand flawless foresight from my earlier self, my team or my clients. I can demand honesty about what the evidence now shows. I can keep what still works, replace what does not and document why the change was made.

That is how useful progress happens. Not through shame about the past, and not through blind loyalty to it. I act responsibly with what I understand today, then make tomorrow’s work better when experience gives me a clearer view.

How SharePoint environments can be improved for Copilot results

image

The short answer is this:

Copilot results are only as good as the SharePoint environment underneath them. If your SharePoint is messy, overshared, full of duplicate files, stale content, and inconsistent naming, Copilot will surface messy, duplicate, stale content. If SharePoint is well-structured, governed, and maintained, Copilot becomes dramatically more useful.

From everything I’ve seen in SMB environments, improving SharePoint for Copilot usually delivers a bigger productivity gain than buying additional AI licences.

1. Fix permissions and oversharing first

This is the most important step.

Copilot doesn’t magically know what information is important. It relies on Microsoft Graph and existing permissions. If users can access content they shouldn’t, Copilot can discover and surface that content.

Common problems

  • Everyone has access to everything

  • Legacy project sites never cleaned up

  • Anonymous sharing links still active

  • “Everyone except external users” permissions

  • Former employees still own sites

What to do

  • Review site permissions

  • Remove unnecessary access

  • Review sharing links

  • Remove broad access groups

  • Identify inactive sites

  • Implement site lifecycle management

SharePoint Advanced Management and Data Access Governance reports were specifically highlighted as ways to identify oversharing risks before Copilot rollout.


2. Create a proper information architecture

Many organisations have:

Documents
├── New Folder
├── Old Stuff
├── Final
├── Final V2
├── Copy of Final
└── Misc

Copilot struggles because the business itself has no structure.

Instead build:

Finance Hub
├── Budget Planning
├── Forecasting
├── Reporting
└── Policies

Sales Hub
├── Proposals
├── Customers
├── Pricing
└── Marketing

The clearer the structure, the easier it is for:

  • SharePoint Search

  • Microsoft Search

  • Copilot Chat

  • SharePoint Agents

  • Copilot Agents

to locate relevant content.


3. Improve file naming standards

Copilot does read document content, but filenames still matter.

Bad:

Proposal.docx
Proposal New.docx
Proposal Final.docx
Proposal Final Final.docx

Good:

CustomerName-Proposal-2026-07.docx
CustomerName-SOW-v1.docx
CustomerName-SOW-Approved.docx

In one of your SharePoint discussions, naming conventions were specifically called out as something that should be standardised across the site.


4. Use metadata instead of folders where possible

Metadata is one of the biggest Copilot improvements available.

Rather than:

Projects
 ├── Sydney
 ├── Melbourne
 ├── Brisbane

Use columns such as:

Column
Value

Client
ABC

Region
Sydney

Project Type
Migration

Status
Active

This gives Copilot richer context when searching and grounding answers.

Instead of finding a file based only on its location, Copilot can reason over:

  • client

  • project type

  • status

  • department

  • business owner


5. Remove stale content

One major challenge is outdated content appearing in search results.

Microsoft now provides features that recommend:

  • demoting inactive pages

  • identifying content gaps

  • fixing broken links

to improve discoverability and Copilot relevance.

Ask yourself:

  • Is this document still current?

  • Is there a newer version?

  • Does anyone own it?

  • Should it be archived?

A common issue is Copilot finding a policy from 2019 while a better one exists from 2026.


6. Identify authoritative sources

One of the newest improvements is the ability to mark SharePoint sites as authoritative.

Examples:

  • HR

  • Finance

  • Legal

  • Corporate Communications

Content from these sites can be prioritised in Copilot Search and Copilot Chat results.

For example:

Site
Why make it authoritative?

HR
Official policies

Finance
Budgets and governance

Legal
Contracts

Company Communications
Executive announcements

This helps reduce contradictory responses.


7. Apply sensitivity labels

Copilot respects sensitivity labels and information protection controls.

Typical labels:

  • Public

  • Internal

  • Confidential

  • Highly Confidential

Benefits include:

  • Better governance

  • Controlled sharing

  • AI visibility controls

  • Better compliance outcomes


8. Improve search quality

Copilot depends heavily on Microsoft Search.

Poor search equals poor Copilot.

Things that help:

Create quality pages

Instead of storing everything in Word documents:

  • Create SharePoint pages

  • Add summaries

  • Add FAQs

  • Add ownership information
Add page owners

Every key page should have:

  • business owner

  • review date

  • contact person
Use meaningful titles

Bad:

Welcome
General Information
Policies

Good:

Employee Leave Policy
Expense Claim Procedure
Remote Work Guidelines


9. Build hub sites

Hub sites create logical business groupings.

Example:

Corporate Hub
 ├── HR
 ├── Finance
 ├── Operations
 └── IT

Customer Hub
 ├── Sales
 ├── Marketing
 └── Service

Hub sites improve navigation, search context and content relevance for Copilot.


10. Create SharePoint agents for specialised knowledge

Where a user only needs answers from a particular area, create a SharePoint Agent.

Examples:

  • HR Agent

  • Policy Agent

  • Finance Agent

  • Project Agent

These agents ground themselves on specific SharePoint locations and often produce more accurate answers than tenant-wide searches.


11. Add more organisational context

Copilot works best when content explains:

  • who owns it

  • what it is for

  • where it applies

  • when it was reviewed

Bad document:

Procedure.docx

Good document:

Financial Approval Process
Owner: Finance
Review Date: July 2026
Applies To: Australia Operations

The extra context significantly improves grounding quality.


12. Measure and improve continuously

The best Copilot environments are not set-and-forget.

Establish a quarterly process:

Review
  • Oversharing

  • Inactive sites

  • Broken links

  • Orphaned content
Clean up
  • Duplicate files

  • Old projects

  • Stale policies
Improve
  • Metadata

  • Authority sites

  • Labels

  • Search experience

Data Access Governance reports and Content Management assessments are specifically designed for this ongoing process.

My practical SMB recommendation

If I were preparing a tenant for Copilot today, I’d prioritise:

  1. Permission cleanup

  2. Oversharing remediation

  3. Sensitivity labels

  4. Review inactive sites

  5. Standard naming conventions

  6. Create hub sites

  7. Add metadata

  8. Designate authoritative sites

  9. Build targeted SharePoint agents

  10. Quarterly governance review

In most SMB tenants, doing just those ten things improves Copilot results more than any prompt engineering or user training because you’re improving the quality of the information Copilot can see and trust.

The Business Doubled When I Started Cutting, Not Adding

MAI_04847cec600d83e4

For years I ran my business trying to make it look impressive. Impressive to peers, to prospects, to whoever happened to be watching at a networking event. Every new tool, every new process, every clever workaround was another thing I could point to and say, look how sophisticated this is. The problem is that nobody scales a business off how it looks from the outside. They scale it off how it actually runs on a Tuesday afternoon when three clients call at once.

Somewhere along the way I stopped building for the audience and started building for me. For how the work felt to do. That single shift is the closest thing I have to a real explanation for how we went from eight million a year to twenty.

The mess was self-inflicted

Here’s the uncomfortable part. The complexity that was strangling the business wasn’t forced on me by clients or by Microsoft or by the market. I built it. Every duct-taped process was a decision I made at some point to patch a problem rather than fix it. A spreadsheet here to track what a proper system should have tracked. A manual checklist there because nobody trusted the automation. A Teams channel for this, a separate one for that, a third one nobody remembered the purpose of.

None of it was wrong on the day I added it. It was all reasonable in isolation. But reasonable decisions stacked on top of each other for five years become a structure that no one person can hold in their head. And when no one can hold it in their head, everything slows down. People stop deciding and start asking. The business gets heavier with every fix.

Why adding more is the instinct, and the trap

When things feel chaotic, the instinct is to reach for another tool. New ticketing platform. New project board. Another layer of approval to stop the mistakes. It feels like progress because you’re doing something. But you’re usually just adding another joint to a structure that already has too many.

I had to break that habit in myself first. The question I started asking wasn’t “what can I add to fix this” but “what can I remove so this stops happening at all.” Removal is harder. It means admitting that something you built no longer earns its keep. It means killing the spreadsheet you were quietly proud of.

This is where I leaned on the Microsoft 365 stack properly rather than around it. We were running four overlapping trackers, so I had Copilot in Excel pull them apart and show me where the same data lived in three places. Then we cut it to one source of truth in SharePoint and let Copilot answer the questions people used to dig through the others to find. The chat channels got the same treatment. Half of them went. The ones that stayed got a clear job, and when someone asked “where does this go,” the answer was finally obvious.

Simplicity is a discipline, not a milestone

The thing nobody warns you about is that simplicity doesn’t stay. It’s not a state you reach and then relax. Complexity creeps back the moment you stop watching, because every small patch feels harmless in the moment. So now I run a regular review where the only acceptable change is a subtraction. What process can we retire. What approval step is just fear wearing a hat. What report does nobody actually read. I use Copilot to summarise where time is going across the team’s Outlook and Teams activity, and more often than not it points straight at something we could stop doing entirely.

That review is the most valuable hour in my month. Not because it adds capability, but because it protects the lightness that let us grow in the first place.

The takeaway

If your business feels stuck and heavy, resist the urge to bolt on one more thing. You almost certainly don’t have a tooling gap. You have an accumulation problem, and you built the accumulation yourself, one sensible patch at a time. Growth didn’t come to me from being more elaborate. It came from being willing to cut, to trust the simpler version, and to stop caring whether it looked clever to anyone else.

The hard part isn’t knowing what to remove. It’s having the nerve to actually pick up the scissors.

Certificate-Based Authentication for SharePoint Online: The Bit Everyone Avoids


image

There’s a point every SharePoint admin eventually hits.

The script works.
The logic is solid.
But it still needs a username.

And that’s where it falls apart.

Because anything that relies on a human login isn’t automation. It’s just a task waiting to break the moment MFA tightens, conditional access changes, or the account gets locked.

Certificate-based authentication fixes that. It has for years.

The problem hasn’t been what to do.
It’s been how much effort it takes to do it properly.


The Problem Isn’t Authentication. It’s Assembly.

If you’ve ever set this up manually, you’ll know the sequence:

  • Create or import a certificate

  • Register an app in Entra ID

  • Assign API permissions like Sites.FullControl.All
  • Upload the certificate

  • Grant admin consent

  • Capture the thumbprint

  • Wire it all into your PowerShell scripts

None of it is particularly hard.

But it’s fragmented, fiddly, and very easy to get wrong.

Which is why most environments quietly fall back to interactive sign-ins… right up until they stop working.


What This Approach Actually Does

I’ve been written a new script —

https://github.com/directorcia/Office365/blob/master/o365-connect-spo-cert.ps1

with full documentation here – https://github.com/directorcia/Office365/wiki/Certificate-based-authentication-for-SharePoint-Online

The script behind this approach is designed to remove that friction.

Instead of documenting the steps, it executes them.

At a high level, it runs in one of two modes:

1. Generate Everything Locally

-GenerateLocalCertificate

This builds the foundation:

  • Creates a local certificate (optionally exports a PFX)

  • Can provision an Entra app automatically

  • Assigns required permissions (including SharePoint and Graph)

  • Prepares everything needed for ongoing use

It effectively handles the “setup once” phase.

2. Use Certificate Authentication

-UseCertificateAuth

This is the day-to-day mode:

  • Connects to SharePoint Online using the app and certificate

  • No username

  • No password

  • No MFA prompt

  • No interaction required

Just a clean, repeatable connection into the SharePoint admin endpoint. [github.com]


Why This Matters More Than It Looks

At face value, this is just authentication.

In reality, it’s capability.

Once your connection is non-interactive, a whole class of work becomes possible:

  • Scheduled SharePoint reporting

  • Overnight clean-up jobs

  • Site lifecycle management

  • External sharing audits

  • Compliance checks

All the tasks that were “nice ideas” suddenly become operational.

Because they no longer depend on someone being present.

That’s the real shift.


The Security Side (That People Miss)

There’s also a security upside that often gets overlooked.

Certificate-based authentication:

  • Removes passwords from scripts entirely

  • Reduces exposure to phishing and credential theft

  • Uses a service principal instead of a human identity

  • Allows tighter, scoped permissions (like Sites.Selected)

In short, it’s both more secure and more predictable than traditional login methods.


The Gotcha Everyone Hits Once

If you build this from scratch, you’ll probably hit the same issue most people do:

It doesn’t work immediately.

Not because it’s broken — but because permissions need time to propagate across Entra ID and SharePoint.

That delay is normal.

It’s also the main reason people abandon setups halfway through and revert to “just use an account”.


Where This Fits for MSPs

If you’re managing multiple tenants, this becomes even more valuable.

The pattern is simple:

  • One script

  • One certificate per tenant

  • One app registration per workload (or per tenant, depending on your model)

  • Store the mapping once

  • Reuse it everywhere

From there, your tooling becomes predictable.

No credential prompts.
No dependence on admin accounts.
No surprises when security policies tighten.


The Bottom Line

Certificate-based authentication isn’t new.

It’s just been inconvenient.

What this approach does is remove the inconvenience.

And once you do that, you start using it everywhere.

Because the real benefit isn’t the connection.

It’s everything that becomes possible after it.


Source material


Where Do Your Uploaded Documents Actually Go in Copilot Notebooks?

image

One of the questions I get asked most often about Microsoft 365 Copilot Notebooks is deceptively simple: when I upload a document into a notebook, where does it actually live? It’s a fair question. If you’re an MSP, an administrator, or anyone responsible for governance, “it’s in the cloud somewhere” isn’t a good enough answer. You need to know exactly where that data sits, who can reach it, and what compliance controls apply. The answer turns out to be more interesting than most people expect, and it hinges on a relatively new piece of the Microsoft 365 storage platform called SharePoint Embedded.

The short answer: SharePoint Embedded

When you upload a document into a Copilot Notebook, it does not land in your OneDrive, and it doesn’t go into a regular SharePoint site or document library that you can browse to. Instead, it’s stored in SharePoint Embedded — specifically inside a user-owned container.

Here’s the part that surprises people. Copilot Notebooks, Copilot Pages, and Loop’s “My workspace” all share the same single user-owned container per user. You don’t get a separate container for each. The first time you need any one of those experiences, Microsoft provisions one container and reuses it for all three. Even the container’s name depends on which app you opened first: it’s called “Pages” if you visited the Microsoft 365 Copilot app first, or “My workspace” (localised to your Loop language) if you opened Loop first.

There’s a governance wrinkle worth committing to memory: in the SharePoint admin center, in PowerShell, and in Purview audit data, this container’s application name always shows as “Loop” — even when it only holds Copilot Notebooks. There is no separate “Copilot Notebooks” application filter. So if you go hunting for Copilot content in your audit logs and only search for “Copilot”, you’ll come up empty. Look for Loop.

So what is SharePoint Embedded?

SharePoint Embedded is an API-only file and document management system built on the same proven Microsoft 365 storage platform that powers SharePoint and OneDrive. The key word is API-only. Unlike a normal SharePoint site, there’s no friendly web UI you can navigate to. When an application uses SharePoint Embedded, it creates a separate storage partition inside your Microsoft 365 tenant, and the documents in that partition are only accessible through Microsoft Graph APIs — and only to the owning application.

Within that partition, the application stores content in entities called File Storage Containers. Think of a container as an API-only document library: it can hold any file type, supports folders, versioning, search, and co-authoring, but it’s dedicated to and reachable by just the one app that owns it. That isolation is the whole point. The files your Copilot Notebook depends on are walled off from other applications, yet they still benefit from the full richness of the Office stack — you can open an uploaded Word or Excel file in Office for the web straight from the experience.

This is the same architecture Microsoft uses under the hood for Loop and Designer. Copilot Notebooks is simply another first-party consumer of the platform.

The detail that matters most: your data stays in your tenant

This is the line I always emphasise with clients. The storage partition that SharePoint Embedded creates lives inside your own Microsoft 365 tenant. Your uploaded documents do not leave your tenant boundary. That means everything your existing Microsoft Purview controls already do, they continue to do here:

  • eDiscovery — content is discoverable

  • Auditing — actions are logged (remember: under the “Loop” application name)

  • Data Loss Prevention (DLP)
  • Retention policies and sensitivity labels
  • Conditional access

So while the storage mechanism is new, the compliance posture is reassuringly familiar. The data is yours, it’s in your tenant, and your governance tooling applies.

Quotas, limits, and a billing nuance

Here’s a distinction that trips people up. The general, developer-facing SharePoint Embedded model bills storage separately through an Azure pay-as-you-go subscription, and that storage does not count against your SharePoint quota. But Microsoft’s first-party use of it for Copilot Pages and Copilot Notebooks works differently. Copilot Pages and Copilot Notebooks content counts against your organisation’s existing SharePoint storage quota — there’s no separate Azure bill for it. The user-owned container has a hard ceiling of 25 TB, which can’t be raised or lowered.

Lifecycle: tied to the user, with sharp edges

The container’s lifecycle is bound to its owner. Content is private by default, much like OneDrive — there’s no forced sharing. When the owning user’s account is deleted, the container is scheduled for deletion and follows the same lifecycle as OneDrive, including a manual handoff step at departure and the option to permanently reassign the container to a new owner.

One critical warning for anyone planning their data protection strategy: there is no end-user recycle bin for Copilot Notebooks. If a notebook is deleted, neither the user nor an administrator can recover it. That’s a meaningful gap compared to the recycle-bin safety net we take for granted in SharePoint and OneDrive, and it’s worth flagging to end users before they start relying on Notebooks for anything important.

Why this matters

Copilot Notebooks feel lightweight and personal, but underneath sits real enterprise-grade storage that you already know how to govern — just wearing a new name. Knowing it’s SharePoint Embedded, that it surfaces as “Loop” in your admin tools, that it counts against SharePoint quota, and that it has no recycle bin turns “somewhere in the cloud” into something you can actually manage.

Copilot Notebooks storage & governance

SharePoint Embedded platform