
Microsoft Copilot Studio provides governance controls based on the PPAC framework—Prevent, Protect, Audit, and Control—to help organizations manage AI copilots securely and compliantly.
PPAC is a governance model used across Microsoft's AI portfolio to align policies with security and compliance requirements.
The diagram below illustrates how PPAC pillars map to Copilot Studio capabilities.
Figure 1: PPAC framework and Copilot Studio governance capabilities.
Governance settings in Copilot Studio are found under Settings and the Power Platform admin center (PPAC).
PPAC provides tenant-wide controls for environments, policies, and DLP (Data Loss Prevention).
Screenshot of the PPAC policies page where governance and DLP policies are managed.
Figure 2: Power Platform Admin Center policies and data policy configuration.
Within Copilot Studio, each copilot has settings that align with PPAC:
Screenshot of Copilot Studio settings related to content filters, data, and analytics.
Figure 3: Copilot Studio governance and content moderation settings.
This article reflects Copilot Studio governance options as of Microsoft Copilot Studio availability. Check the Microsoft Learn documentation for the latest PPAC and governance updates.