Microsoft Copilot on Windows 11 can now read your local files, search through them, and even act on them. That is either the most useful feature since the Start menu or a privacy nightmare, depending on your settings. I spent an afternoon going through every toggle and permission, and here is what I found.

If you have been following the recent Windows updates — like WSL Containers finally reaching general availability — you probably noticed Copilot getting more ambitious. It is no longer just a chatbot that answers questions from the web. It can surface your recent files, summarize documents, and in preview builds, perform actions on your behalf. All of that requires access to your data. The question is: how much access did you actually grant, and how do you take it back?
What Changed: Copilot’s New File Access
Copilot on Windows 11 now operates with two distinct file permissions that work independently:
- File search — lets Copilot index and discover files on your local drive and OneDrive. Without this, Copilot cannot even see that your files exist.
- File read — lets Copilot open and analyze the contents of those files. This is what powers features like “summarize this document” or “find the report I worked on last week.”
Both are off by default. You have to explicitly turn them on in Copilot’s settings. But here is the catch: once enabled, Copilot can search through most file types including .docx, .xlsx, .pptx, .txt, .pdf, and .json files stored locally or synced from OneDrive.
Microsoft’s privacy FAQ states plainly: “Copilot does not scan your PC or upload any files automatically.” Files are only accessed when you ask Copilot to search for them or when you manually upload a file in the Composer. That is a meaningful distinction, but it also means the risk is concentrated in the moments you actively use the feature.
How to Check and Manage Copilot’s File Permissions
Here is the step-by-step walkthrough. It takes about two minutes.
Step 1: Open Copilot Settings
Launch the Copilot app from the taskbar or press Win + C. Click your profile icon (account menu) in the top-left corner, then select Settings from the dropdown.
Step 2: Review Permission Settings
Under the “Permission settings” section, you will see two toggles:
- File search — controls whether Copilot can discover and index your local files and OneDrive content.
- File read — controls whether Copilot can open and analyze file contents for summarization and Q&A.
Turn both on if you want the full experience. Turn both off if you want Copilot to behave like a standard web chatbot with no local file access. You can also enable search without read, which lets Copilot find files but not open them — useful if you just want it as a smarter Windows Search.
Step 3: Manage Recent Files
There is also a “Show recent files on home” toggle. Turn this off if you do not want Copilot displaying files you have recently opened on its main page. This references Windows Recent Items, not a separate scan, but it is still a privacy surface worth closing if you share your screen often.
Privacy Settings: Stop Microsoft From Using Your Data
File access is only half the conversation. The other half is what Microsoft does with your conversations and diagnostic data. In the same Settings menu, click the Privacy page. You will find four toggles that matter:
- Diagnostic Data Sharing — controls whether diagnostic data is sent to Microsoft.
- Model training on text — controls whether your text conversations are used to train AI models.
- Model training on voice — same, for voice interactions.
- Personalization and memory — controls whether Copilot stores persistent memory about you across sessions.
Turn all four off if you want the strictest privacy posture. You can also click Delete Memory to clear everything Copilot has stored about you. Microsoft says conversation activity is stored for 18 months by default, and you can delete individual conversations or your entire history at any time.
I turned off model training and personalization immediately. Diagnostic data I left on — it helps catch bugs, and I am comfortable with that trade-off. Your mileage may vary. If you want a broader framework for thinking about AI security, I put together a practical security checklist for AI deployments that covers similar ground.
Known Folders and Agent Permissions
This is where things get more serious. In preview builds (26100.7344+), Windows 11 introduced agentic features that give Copilot the ability to read and write files in your “known folders”: Desktop, Documents, Downloads, Music, Pictures, and Videos.
By default, when an agent requests access to these folders, Windows asks for your consent. You get three options:
- Allow Always — the agent can access all six known folders whenever it needs to.
- Ask every time — Windows prompts you each time the agent requests access.
- Never allow — the agent is denied access to known folders.
Manage this at Settings > System > AI Components > Agents. Select the agent from the list, go to the “Files” section, and choose your preferred permission level.
One important limitation: the permission is all-or-nothing across the six known folders. You cannot grant access to Documents while denying Desktop. If you want any agent access, you are granting it to all six folders as a set.
I set mine to “Ask every time.” The convenience of “Allow Always” is not worth the risk of an agent acting on a file I did not explicitly approve.
The Cross-Prompt Injection Problem
Microsoft openly acknowledges a threat called cross-prompt injection (XPIA). The concept is simple: an attacker embeds malicious instructions in a document, email, or web page. When an AI agent ingests that content, the hidden instructions can override the agent’s plan and trigger unintended actions — data exfiltration, file moves, even malware installation.
This is not theoretical. Microsoft’s own security blog documents AI recommendation poisoning attacks where companies embed hidden “Summarize with AI” buttons that inject persistence commands into AI memory via URL parameters. The broader challenge of tracking AI-generated content is something I explored in my piece on OpenAI’s textGrain watermarking. Microsoft has implemented mitigations in Copilot, including prompt filtering, content separation, and memory controls, but the threat model is real.
The practical takeaway: if you enable agentic file access, treat every document and email as a potential attack vector. Do not let agents process files from untrusted sources without reviewing the content first.
Enterprise Considerations
If you are managing devices in an organization, Microsoft 365 Copilot adds governance layers. It respects Microsoft 365 permissions — Copilot only surfaces data the signed-in user can already access. Administrators can enforce DLP and Purview policies to prevent accidental exposure of sensitive data.
Microsoft also allows administrators to uninstall the Copilot app entirely on Pro, Enterprise, and Education versions, though only if users have not launched it recently and specific policy conditions are met. For managed environments, the AllowWindowsCopilot MDM policy in Microsoft Intune provides granular control.
But here is the thing: access models reduce exposure, they do not eliminate it. If a user has broad permissions, Copilot can surface broad data. The principle of least privilege applies to AI agents just as it applies to human users. The market is noticing — HiddenLayer just raised $100M on the bet that AI security is the most honest signal in tech right now.
My Recommended Settings
After going through everything, here is the configuration I landed on for my own machine:
- File search: ON — I want Copilot to find files when I ask.
- File read: ON — I want document summarization and Q&A.
- Show recent files on home: OFF — I do not need that on the main page.
- Diagnostic Data Sharing: ON — acceptable trade-off for bug fixes.
- Model training on text and voice: OFF — I do not want my conversations training models.
- Personalization and memory: OFF — I do not want persistent memory across sessions.
- Known folder agent access: Ask every time — I want to approve each access request.
This gives me the productivity benefits of Copilot’s file features while keeping tight control over what Microsoft does with my data and when agents can touch my files. It is not the most convenient setup, but it is the one I can defend.
Bottom Line
Copilot’s file access is opt-in, granular, and manageable — but only if you actually go through the settings. The defaults are reasonably safe (file search and read are off, agent access requires consent), but the privacy toggles for model training and personalization deserve a conscious decision rather than an acceptance of defaults.
Take five minutes to review your Copilot settings. It is a lot easier to configure privacy upfront than to explain a data exposure after the fact. And if you are worried about AI-generated content slipping into your workflow, here is how to use AI text detectors without getting burned by false positives.