Microsoft Merged the Copilot Apps. A Green Shield Is Now Your Boundary.
From August 18, work and personal Copilot live in one app with an account switcher. Microsoft kept every technical control. The human boundary is what changed.
Starting August 18, Microsoft began rolling out an update that brings the consumer Copilot app and the Microsoft 365 Copilot app together into a single application across web, desktop and mobile. Microsoft's announcement describes clearer account indicators, a simplified name and icon, and a move of the web address from m365.cloud.microsoft to copilot.cloud.microsoft, with users redirected automatically unless the new address is blocked inside their organization.
If you run a business on Microsoft 365, two things happened here. One is an administrative task with a deadline that has already passed. The other is a governance change that does not look like one.
Start with the administrative task
The redirect is automatic, and the qualifier attached to it is the part to catch. Users are sent to the new address unless access to it is blocked within their organization.
Microsoft's own guidance for administrators is to verify that copilot.cloud.microsoft is not blocked by existing network, proxy, firewall or access policies. Plenty of organizations allowlisted m365.cloud.microsoft at some point and never revisited it. Those environments will see Copilot stop working for reasons that look like an outage and are actually a stale rule.
Separately, three features retired on the same date: Group Chat, Podcasts and Deep Research. For Group Chat the retirement is not a pause. Threads, messages and content created there, including images, are not carried forward. If anyone in your organization was using Group Chat threads as a working record of a project, that record is gone, and the time to have known that was before August 18.
Now the part that matters longer
Microsoft's technical assurances here are specific, and we have no reason to doubt them. Work and personal accounts remain separate. Data does not flow between them. Your organization's security, privacy, compliance and administrative controls continue to apply to the work account. Commercial data boundaries, tenant controls and compliance protections are unchanged. Microsoft states directly that security, compliance and governance controls remain as they were.
Every one of those statements is about the software. None of them is about the person using it.
What changed is the distance between two contexts that used to be separated by friction. Before, the work assistant and the personal assistant were different apps. Different icons, different names, often different devices. That separation was not a security control in any formal sense, and no administrator ever configured it. It worked anyway, because it took a deliberate act to cross.
Now there is one app, one name, one icon, and an account switcher inside it. Microsoft has done thoughtful work to keep the contexts legible: account labels, distinct backgrounds, and a green shield marking a Microsoft Entra work account. Those are good design decisions and we would have made the same ones.
They are also visual cues, and the security question for your business is what happens on the day somebody does not look.
The failure this actually creates
The risk is not a data leak between the two accounts. Microsoft has addressed that, and the architecture holds.
The risk is an employee with a client contract open, a deadline, and a Copilot window in front of them that is signed into a personal account, pasting the contract in to get a summary. That content has now left your tenant. It did not cross a boundary inside the app. It went around the boundary, carried by a person who did not register which side of the switcher they were on.
Nothing in your tenant configuration sees this. Your data loss prevention rules govern your tenant. A personal Microsoft account is not your tenant. The compliance controls Microsoft correctly says are unchanged are unchanged, and entirely beside the point, because the content never entered the system they govern.
We wrote about shadow AI a while back, in the sense of staff using tools the business never approved. This is a narrower and more awkward version. The tool is approved. The vendor is approved. The app is the one you pay for. The account is the wrong one, and it lives one click away inside the same window.
For a law firm, an accounting practice or a tribal health program, the class of content most likely to be pasted into an assistant is exactly the class you are obligated to protect.
What we would actually do
Confirm the address is reachable. Check copilot.cloud.microsoft against your proxy, firewall and conditional access policies before someone opens a ticket about Copilot being down.
Decide your position on personal account sign-in. The single app supports signing in with a personal account, a work account, or both. Whether you permit both on a company device is a policy question you now have to answer, and the honest options are to allow it, to discourage it in writing, or to restrict it. What is not available anymore is not having a position, because the default is that both work.
Teach the shield, not the policy. A written policy about approved AI tools does not help here, because the tool is approved. What helps is that every person who touches client material can answer one question without thinking: how do I know which account I am in right now? Green shield, account label, background. Ninety seconds in a staff meeting.
Check where Group Chat content lived. If any team used it for project threads, that content did not survive the transition. Better to find out now than during a matter where someone needs it.
Ask what the workaround is. People reach for a personal account when the work account will not do something. If Copilot is restricted in your tenant in a way that makes it less useful than the free version, staff will use the free version, and they will use it on the material they are trying to get through. That is a configuration finding, not a discipline problem.
Microsoft built a cleaner product here, and the account indicators show real care about the exact problem we are describing. The part that moved onto your side of the line is that a boundary which used to be enforced by two separate apps is now enforced by a person noticing a color. That is worth ninety seconds of training before it is worth an incident report.
If you want a second read on how AI tools are actually being used inside your business, that is a conversation we are glad to have.
Join the conversation
Straight talk welcome. Comments are moderated, no pitches, no spam.
Comments load once the Hyvor Talk Website ID is set in
article.html.