AccuroAI
Products
What We Do
Solutions
Company
Resources
Book demo
← Blog·Enterprise AI9 read

Running Microsoft 365 Copilot and ChatGPT Enterprise Together: The 2026 Control Matrix

Most enterprises run both. Nobody published the control matrix. Built from Microsoft's and OpenAI's current documentation: what Purview reaches into ChatGPT Enterprise (and the 24-hour lag), what it cannot, the five seams that cause incidents, and what to configure on each side.

J
James Okafor
Field CISO
2026-08-16

Most large organisations did not choose between Microsoft 365 Copilot and ChatGPT Enterprise. They ended up with both — Copilot because it came with the tenant, ChatGPT Enterprise because a business unit bought it, or because the engineers insisted. Running the two together is now the normal enterprise shape, and nobody has published a control matrix for it: Microsoft's documentation describes what Purview can do with ChatGPT Enterprise, OpenAI's describes its own admin plane, and neither describes the seams. This is the matrix, built from both vendors' current documentation, with the seams marked.

Three naming facts first, because they trip up every procurement conversation. Microsoft renamed the product "Microsoft Copilot" in July 2026; licences are still sold as Microsoft 365 Copilot. OpenAI renamed ChatGPT Team to ChatGPT Business in August 2025. And "ChatGPT Work" is not a plan — it is the cloud-agent capability launched on 9 July 2026 inside Business and Enterprise.

The control matrix

ControlMicrosoft CopilotChatGPT EnterpriseDoes one side see the other?
Identity (SSO)Entra ID, Conditional Access honouredSAML/OIDC SSO after DNS domain verification; can be fronted by Entra IDSame IdP, separate sessions. Conditional Access enforcement on ChatGPT sessions is not documented — do not assume it.
ProvisioningNativeSCIM for users and groups (Enterprise only; Business lacks SCIM group sync and custom RBAC)Entra can be the SCIM source for both.
Sensitivity labels and encryptionInherited; Copilot needs the EXTRACT usage right to read protected contentNo label awarenessPurview's ChatGPT Enterprise connector does not support sensitivity labels or encryption.
DLP at the promptPurview DLP policy location for Copilot: block web search on sensitive prompts, block sensitive prompts (preview), exclude labelled files and emails, block external email (preview). Cannot scan files uploaded into prompts; changes take up to four hours.None native; connectors and apps disabled by default in Enterprise and enabled per action by adminsPurview DLP does not reach ChatGPT Enterprise. Browser/endpoint DLP applies only to the "Other AI apps" category — consumer ChatGPT — not to the Enterprise connector.
AuditPurview audit, record type CopilotInteraction; provider logged, model version notCompliance API and Compliance Logs Platform (30-day retention, export for longer); append-only eventsPurview ingests ChatGPT Enterprise prompts and responses as ConnectedAIAppInteraction24 hours after they occur, text only, pay-as-you-go, preview.
eDiscoverySupported; query builder "Copilot activity"Via Compliance API exportsPurview eDiscovery supports the ingested ChatGPT Enterprise interactions.
RetentionPurview retention policies; "Microsoft Copilot experiences" location; data held in a hidden mailbox folderAdmin-set workspace retention; project files and third-party records follow separate rulesPurview has an "Enterprise AI apps" retention location that names ChatGPT Enterprise — but it governs the ingested copy, not OpenAI's primary store. Two retention clocks.
Insider risk and communication complianceSupportedPurview supports both for ingested ChatGPT Enterprise content.
Connectors and agent actionsGraph connectors inherit user permissions; Restricted Content Discovery; Agent 365 registry (GA 1 May 2026, $15/user/month)Apps and connectors disabled by default; custom MCP connectors; admins approve specific actions; source systems enforce their own permissionsNo shared registry. An agent built in each platform is visible only to that platform's admin plane.
Web groundingAdmin policy per mode; DPA, HIPAA and EU Data Boundary do not apply to generated web queriesWorkspace settingNeither sees the other's web traffic.
Model provider and subprocessorsAzure OpenAI, plus OpenAI-operated GPT-5.6 and Anthropic as Microsoft subprocessors (default-on for commercial tenants)OpenAIOpenAI now sits in both chains — as your vendor in one, as Microsoft's subprocessor in the other, under different terms.
Data residencyEU Data Boundary with documented exceptions; flex routing for newer EU tenantsMultiple regions including US, EU, UK and JapanSeparate commitments; nothing reconciles them for you.
Training on your dataNot used to train foundation modelsNot by defaultBoth documented.

The five seams that cause incidents

1. Your labels stop at the Copilot boundary

Microsoft's capability table for ChatGPT Enterprise is explicit: DSPM, audit, classification, insider risk, communication compliance, eDiscovery, lifecycle management and Compliance Manager are supported; sensitivity labels, encryption without labels and data loss prevention are not. A "Highly Confidential" document that Copilot will refuse to extract from can be pasted into ChatGPT Enterprise with nothing in the Microsoft stack intervening — you will find out a day later, in the audit log, if you configured the connector and turned on pay-as-you-go billing.

2. The 24-hour window

"Due to OpenAI's current API limitations, conversations are ingested 24 hours after they occur." Purview's controls for ChatGPT Enterprise are therefore detective, not preventive. For an organisation whose policy is "no client data into external assistants", the Microsoft stack will tell you on Tuesday what left on Monday. That is useful for investigations and useless for prevention.

3. Two admin planes, zero shared policy

OpenAI's controls are real — SSO, SCIM, RBAC, IP allowlisting, per-action connector approval, a compliance log — but they decide who can use ChatGPT and which apps it can reach. They do not evaluate what data is in the prompt against a classification. Microsoft's controls evaluate content but only inside Copilot. A rule such as "redact payment card numbers before they reach any model" has to be written twice, in two vocabularies, and still will not exist for the assistant your designers use next year.

4. Agents in both houses

Agent 365 gives you a registry, risk columns and quarantine for agents built on Microsoft platforms. ChatGPT Work's cloud agents and custom MCP connectors live under OpenAI's admin plane. Neither inventory knows the other exists. An employee can build an agent in each that reaches the same SharePoint site through different credentials, and no single screen shows both.

5. OpenAI on both sides of the table

Since 24 July 2026, OpenAI-operated GPT-5.6 is enabled by default in commercial Copilot tenants, with OpenAI as a Microsoft subprocessor. You now have OpenAI processing your data under two contracts with different assurance sets — Microsoft's DPA with documented exclusions (no FedRAMP High, PCI AOC, HITRUST or SOC 1 Type 2 for the OpenAI-operated models) on one side, your direct ChatGPT Enterprise agreement on the other. Your subprocessor register should say so.

What to configure on each side this quarter

Microsoft side: enable the Purview ChatGPT Enterprise connector (it needs an Azure subscription, Key Vault credential, a collection policy and a manually scoped OpenAI Compliance API key requested by email); create the DLP policy for the Copilot location and the "Enterprise AI apps" retention location; decide the subprocessor switches for OpenAI-operated and Anthropic models, scoped by group; register Copilot Studio agents in Agent 365.

OpenAI side: SSO with domain verification and SCIM from the same IdP; RBAC with a small admin set; connectors and apps left disabled by default and approved per action; IP allowlisting for web access; the Compliance API wired to your SIEM or to Purview, with an export job that outruns the 30-day platform retention; workspace retention aligned to your records schedule.

Between them: one inline inspection layer that sees the prompt before it reaches either model, applies the same classification-based redact, warn or block rule to both, and records provider, data class and decision in one audit trail. That is the only place the policy can be written once — and it is where the 24-hour gap closes.

Pricing, for the business case

Microsoft 365 Copilot lists at $30 per user per month paid annually ($31.50 with monthly billing); Copilot Business at $21, with an $18 promotion running to 30 September 2026; Agent 365 at $15. ChatGPT Enterprise has no published price and is quoted per deal — industry write-ups report ranges from roughly $45 to $75 per seat with seat minimums, and ChatGPT Business is reported at $20 per seat annually since April 2026. Treat the OpenAI figures as reported, not list.

FAQ

Can Microsoft Purview govern ChatGPT Enterprise?

Partly. Purview supports audit, DSPM, classification, insider risk, communication compliance, eDiscovery, lifecycle management and Compliance Manager for ChatGPT Enterprise through a preview connector that ingests text prompts and responses 24 hours after they occur. It does not support sensitivity labels, encryption or DLP for ChatGPT Enterprise.

Does ChatGPT Enterprise's compliance tooling reach Copilot?

No. OpenAI's Compliance API covers ChatGPT workspaces only. Copilot interactions are governed by Microsoft's audit, retention and eDiscovery.

Can I apply one DLP policy to both?

Not with either vendor's native tooling. Purview DLP applies to Copilot; ChatGPT Enterprise has no prompt-level DLP. A single policy requires an inspection layer in front of both.

Is it safe to let one IdP front both?

Yes, and it is the right design — one joiner-mover-leaver process, one MFA posture. Just do not assume Conditional Access policies are enforced on ChatGPT sessions; that is not documented.

Should we standardise on one instead?

Usually not. The two products win different workloads, and consolidation attempts tend to produce shadow use of the other. Govern both with one inspection layer and one inventory, and let the business choose per use case.

Sources: Microsoft Learn, Purview capabilities for ChatGPT Enterprise (1 May 2026, updated 29 Jul 2026) · Microsoft Learn, ChatGPT Enterprise connector (19 Jun 2026) · Microsoft Learn, Purview for AI apps (27 May 2026) · Microsoft Learn, DLP for Copilot (10 Jun 2026) · Microsoft Learn, audit for Copilot (17 Jul 2026) · Microsoft Learn, retention for Copilot and AI apps (updated 25 Jun 2026) · Microsoft Learn, Enterprise Data Protection (29 May 2026) · Microsoft Learn, OpenAI as a subprocessor (5 Aug 2026) · Microsoft, Agent 365 GA (1 May 2026) · OpenAI, ChatGPT for work admin FAQ · OpenAI, Compliance API · Microsoft 365 Copilot pricing · Microsoft 365 Copilot Business pricing.

Related: Copilot vs ChatGPT Enterprise: Security Comparison · GPT-5.6 Is in Your Copilot Tenant (Unless You Opted Out) · Is Purview Enough for AI Security? · Data Security for AI.

See AccuroAI in action.
30-minute demo tailored to your top AI risk.
Book a demo
More from the blog
See AccuroAI in action.

Book a 30-minute demo and see how security teams use AccuroAI to discover, govern, and protect every AI asset across their organization.

Book a demoTalk to security