Manage Copilot in Edge & Microsoft 365 Apps on Mobile devices using Intune

 
I have finally jumped on the Copilot bandwagon and started familiarizing myself with the feature. For those who are unware or getting to know it like me, then it is Microsoft's latest AI-powered productivity tool that uses large language models (LLMs) and integrates data with the Microsoft Graph and Microsoft 365 apps and services. I don't intend to do a deep dive into what Copilot is as there is plenty of material available online for that, but I will like touch base on commercial data protection and what organizations can do to manage Copilot on mobile devices using Intune.

According to Microsoft,

To provide chat responses, Copilot uses global data centers for processing and may process data in the United States. Optional, Bing-backed connected experiences don't fall under Microsoft's EU Data Boundary (EUDB) commitment. They also don't fall under the terms of the Data Protection Addendum (DPA) which requires company data to remain inside geographic or tenant boundaries.

What about Organizations with strict data restriction policies?

In an enterprise setting, Microsoft has enabled commercial data protection to help business and educational organizations protect corporate data. This means that through Commercial data protection,  organizations can protect data whenever users access corporate resources with eligible work or school accounts against the use of Copilot. For this, organizations can now use the 'Commercial data protection for Microsoft Copilot' service plan under their Office 365 license to manage Copilot for their users. However, in absence of the required licenses or in case where organizations are not ready to fully rollout Copilot, they can chose to disable Copilot feature altogether. I have explored the configuration and will be covering the details for managing Copilot for Edge and Microsoft 365 Apps on mobile devices.

How to manage Copilot for Edge on Mobile devices?

Copilot for Edge can be managed using an app configuration profile against both managed devices and managed apps. During my testing, I found managed apps configuration to give more consistent results. Also, the same can work for both managed and un-enrolled devices. Therefore, I will be covering the configuration through a managed apps enrollment type.

2. Go under Apps->App configuration policies->Add->Managed Apps.
3. Provide a name.
4. Under Selected apps, add Microsoft Edge for both Android and iOS.
5. Add the necessary configuration settings as shown below -


6. Under General configuration settings, configure the following:

com.microsoft.intune.mam.managedbrowser.Chat value false (Default is true)
com.microsoft.intune.mam.managedbrowser.ChatPageContext value false (Default is true)


7. Deploy to all users or a user based group.

How to manage Copilot for Microsoft 365 Apps on Mobile devices?

Copilot for Microsoft 365 Apps can be managed using an app configuration profile against both managed devices and managed apps. Just like for Edge, I have used a managed apps enrollment type here as well.

2. Go under Apps->App configuration policies->Add->Managed Apps.
3. Provide a name.
4. Under Selected apps, add Microsoft Edge for both Android and iOS.
5. Add the necessary configuration settings as shown below -


Note: I have added other Office apps as well, but you don't need to if you are not using them in your organization.

6. Under General configuration settings, configure the following:

com.microsoft.office.officemobile.BingChatEnterprise.IsAllowed value false (Default is true)


7. Deploy to all users or a user based group.

End User Experience

On Android -

When both Microsoft Edge: AI Browser & Microsoft 365 (Office) are installed on the device and the management policy for Copilot has not yet applied from Intune, then the feature will be enabled as shown below -


After the policy is applied, Copilot button will disable and the settings will no longer be accessible either.


On iOS -

Just like in Android, when both Microsoft Edge: AI Browser &  Microsoft 365 (Office) are installed on the device and the management policy for Copilot has not yet applied from Intune, then the feature will be enabled as shown below -



After the policy is applied, Copilot button will disable and the settings will no longer be accessible.


From a compliance point of view, it can verified in Intune under App Configuration Status Reports -

Caveats:

1. App Configuration status report can take a while to update.
2. Managed Devices app configuration policy type for managing Copilot can give inconsistent results, just like it did during my testing. See below -

On Android, the policy didn't apply and threw an unknown error against Edge policy.


On iOS, the policy applied, but also threw the same Unknown error as above.

Final thoughts..

Copilot is accessible from copilot.microsoft.com, Bing.com/chat, Edge, and Windows. It’s also available through the Copilot, Bing, Edge, Microsoft Start, and Microsoft 365 mobile apps. Eligible users who sign in to Copilot services with Entra ID get commercial data protection. The important bit is that all chat data is processed by Microsoft and with commercial data protection, the data isn't retained nor used to train the underlying large language models. In my opinion, this is very important as data in all forms is like gold dust in today's fast moving day and age of Internet.

Comments

Popular posts from this blog

How to force escrowing of BitLocker recovery keys using Intune

Intune: Configure Printers for Non-Administrative Users

Intune: UAC Elevation Prompt Behavior for Standard Users