A Setting Most Admins Never Saw Auto-Enabled Itself
On 24 July 2026, Microsoft auto-enabled a setting inside every eligible Microsoft 365 tenant that most organisations never reviewed. OpenAI had been added to the Microsoft Online Services Subprocessors list on 23 June, the setting itself appeared in the admin centre on 9 July, disabled by default, with a two-week window before it switched itself on. Unless an admin actively selected "No users" before that date, OpenAI-operated models, starting with GPT-5.6, are now running as part of Microsoft 365 Copilot in your tenant.
If this is the first you're hearing of it, you're not alone. It landed as a Message Center announcement (MC1422074), a channel most business stakeholders never see, and the two-week window closed before many organisations' IT and compliance teams connected the two.
What Actually Changed
Microsoft has onboarded OpenAI as a subprocessor to run certain OpenAI-operated models directly, rather than exclusively through Microsoft's own Azure OpenAI infrastructure. This is a meaningful distinction. Models operated by Microsoft through Azure OpenAI Service run entirely within Microsoft's own infrastructure and are unaffected by this setting. Models operated by OpenAI as a subprocessor are a separate category, still governed by the Microsoft Product Terms and Data Protection Addendum, but processed by a different party under a subprocessor relationship, not run inside Microsoft's infrastructure directly.
The setting affects Microsoft 365 Copilot, Copilot within the core Microsoft 365 apps, and Copilot Studio agents. It doesn't touch Azure OpenAI-hosted usage, which remains governed separately.
Microsoft's documentation states these models carry the same enterprise-grade protections already in place, "except as otherwise disclosed in Microsoft Learn documentation." For tenants under the EU Data Boundary or regional data residency requirements, that qualifier is exactly the kind of detail that needs a deliberate compliance review, not a default opt-in.
What to Check in Your Tenant Right Now
Even though the auto-enable date has passed, the setting remains reviewable and adjustable at any time.
- Open the Microsoft 365 admin centre
- Go to Copilot, then Settings
- Select View all
- Find AI providers operating as Microsoft subprocessors
- Review the current status and restrict to specific users and groups, or set to "No users" if OpenAI-operated models shouldn't be enabled
This is also worth flagging to whoever manages Power Platform and Copilot Studio agents specifically, since the same setting affects external model configuration there too, not just Copilot Chat and the core Microsoft 365 apps.
Why This Belongs in a Broader Copilot Governance Review
This is the second time in recent months that a meaningful Copilot-related change has rolled out as a default-on setting inside the admin centre rather than a decision organisations were prompted to make. The pattern is becoming familiar: Microsoft ships capability quickly, defaults do the deciding, and the organisations that stay ahead of it are the ones actively reviewing tenant settings rather than waiting for a Message Center digest to surface something after the fact.
This is exactly the kind of configuration drift Copilot Safe Scan is built to catch, not just data exposure and permissions, but the compliance-relevant settings that shift underneath a tenant between one admin review and the next. A subprocessor toggle is a small setting with a genuinely large downstream question attached: where is your data actually going, and who decided that.




