A company's security team needs to review all interactions users have with Microsoft Copilot for Microsoft 365, including the prompts submitted and responses generated, to investigate a potential policy violation. Which Microsoft service provides access to this audit data?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — b is correct because Microsoft Purview Audit (Premium) captures Copilot interaction events in the unified audit log, including the user prompts sent to Copilot and the AI-generated responses, enabling compliance investigations. Copilot interaction records are surfaced through the CopilotInteraction audit schema.
Full explanation below image
Full Explanation
B is correct because Microsoft Purview Audit (Premium) captures Copilot interaction events in the unified audit log, including the user prompts sent to Copilot and the AI-generated responses, enabling compliance investigations. Copilot interaction records are surfaced through the CopilotInteraction audit schema. A is wrong because Defender XDR Advanced Hunting contains endpoint and identity security telemetry, not Copilot conversation logs. C is wrong because Entra ID Sign-in logs record authentication events, not the content of Copilot sessions. D is wrong because Defender for Cloud Apps Activity logs record app-level governance events, not the full content of individual Copilot prompts and responses.