A is correct: Microsoft 365 Copilot agents honor the permissions model within your tenant. The Semantic Index respects user identity-based access boundaries, and sensitivity labels with encryption restrict what content agents can process. Your existing data protection posture directly determines what the agent can access and return. Reference: https://learn.microsoft.com/en-us/copilot/microsoft-365/microsoft-365-copilot-privacy
B is incorrect: Sensitivity labels do not need to be removed. Agents work within existing data protection controls — some labeled content may be excluded from processing depending on the label configuration, but removing labels would undermine your compliance posture. Reference: https://learn.microsoft.com/en-us/copilot/microsoft-365/microsoft-365-copilot-architecture-data-protection-auditing
C is incorrect: Copilot agents do not bypass sensitivity labels at any stage of processing. Data protection controls are enforced throughout the entire process, including content retrieval and response generation, not just at the display stage. Reference: https://learn.microsoft.com/en-us/copilot/microsoft-365/microsoft-365-copilot-privacy
D is incorrect: Copilot agents do not create temporary unencrypted copies of labeled files. Files encrypted with user-defined sensitivity label permissions may be excluded from agent processing entirely. Data protection is maintained in place, not bypassed via temporary copies. Reference: https://learn.microsoft.com/en-us/copilot/microsoft-365/microsoft-365-copilot-architecture-data-protection-auditing