Copilot for Education
Stop 10

The Safety & Privacy Office

Where student data stays protected

Copilot works inside the permissions your district already granted — it cannot show you a file you couldn't already open, and your prompts are not used to train public models. That is the floor, not the whole answer. Student records carry legal protections, so treat prompts like any other place you wouldn't paste a student's file, and follow your district's guidance first.

Example 01

Permissions you already trust

Copilot honors existing access. Your content stays inside your organization's tenant, and Microsoft doesn't use it to train the foundation models behind the service.

Try this — as a…

Task: explain in plain language what Copilot can and cannot see in my files. Persona: act as a privacy educator. Format: five short bullets plus two things I should never paste into a prompt. Audience: me and my colleagues. Tone: reassuring but honest. Context: Microsoft's published data and privacy documentation for Microsoft 365 Copilot.

Example 02

Good practice in a school setting

Keep student records out of prompts. Use roles and placeholders instead of names. Let Copilot draft and organize while the educator makes every decision about a student — and check your district's AI guidance before adopting anything new.

Try this — as a…

Task: rewrite this prompt so it contains no student-identifying information. Persona: act as a privacy reviewer. Format: the revised prompt plus a one-line note on what you removed and why. Audience: me. Tone: matter-of-fact. Context: the draft prompt below, which I want to reuse each week.