“I Archived That in 2018″—So Why Is Copilot Quoting It Back to Me?

Archive mailboxes aren't cold storage—Microsoft Search indexes them just like primary mailboxes, which means Copilot has full access to every email your users filed away and forgot. Here's what that means for compliance and…

A user asked Copilot to summarise everything it knew about a former supplier. It returned a tidy brief, including a price negotiation from 2018 the user swore they’d deleted. They hadn’t deleted it. They’d archived it—moved it to the online archive mailbox and forgotten it existed. Copilot did not forget.

This surprised the user. It should not surprise you, and I want to walk through why, because a colleague cornered me about it last week and made some fair points.

“Hang on—archives are cold storage. How is an AI reading cold storage?”

They’re not cold. That’s the whole misconception. The Exchange Online archive isn’t tape in a vault; it’s a second mailbox stitched onto the first. And Microsoft Search indexes it exactly the same way it indexes the primary mailbox. Same tenant, same user identity, same search index. Copilot for Microsoft 365 doesn’t crawl mailboxes directly—it asks the Microsoft Search index “what does this user have access to?” and the index answers with primary and archive content.

Think of it like a house with a basement. You stopped going down there years ago, so in your head it’s sealed. But the lights still work and the door was never locked. Copilot just walked down the stairs.

“Fine, but surely content under a compliance hold is protected from this?”

This is the one that catches compliance teams. A litigation or in-place hold preserves content so it can’t be purged. It does not make that content invisible to the user who owns the mailbox. If a held email still sits in a folder the user can open, the user can read it—and so can Copilot acting on that user’s behalf. Hold is about retention, not concealment. Copilot surfacing held content isn’t a leak; it’s Copilot showing the user what the user could already see. The problem is that “could already see” and “would ever think to look for” are very different things, and AI collapses the distance.

“OK, but our sensitivity labels will stop it exposing the sensitive stuff.”

Partly. This draws on general Microsoft 365 labelling behavior rather than archive-specific detail: a sensitivity label with encryption travels with the message into the archive, and the usage rights in that encryption govern access. A user who can’t open the content normally shouldn’t get it through an AI, either. Treat that as design intent, verify against current Microsoft documentation for your scenario, and don’t assume it’s a blanket guarantee.

The bigger gap is the unlabelled mail. Autolabelling policies, as a rule, apply to new and newly-touched content going forward—retroactive classification of a decade of forgotten correspondence isn’t something you should assume happened unless you explicitly ran it. So the 2018 supplier email? Almost certainly unlabelled, fully readable, fully indexed.

There is no documented per-mailbox “hide the archive from Copilot” switch, and I wouldn’t go hunting for one. The control you actually have is knowing what’s in there.

So audit it

Start with Microsoft Graph to find who even has an archive enabled, with pagination and error handling so it survives a real tenant:

audit.ps1PowerShell
Connect-MgGraph -Scopes "User.Read.All" -NoWelcome
​
try {
    $users = Get-MgUser -All -Property Id,UserPrincipalName,Mail -ErrorAction Stop
}
catch {
    Write-Error "Graph query failed: $($_.Exception.Message)"
    return
}
​
Write-Host ("Retrieved {0} users for review." -f $users.Count)
# Export for review BEFORE acting on anything.
$users | Select-Object UserPrincipalName, Id |
    Export-Csv .\users-to-review.csv -NoTypeInformation

Graph will enumerate identities, but it won’t give you archive size or folder counts—that genuinely lives in Exchange Online. Feed the reviewed CSV in, never a live query:

audit.ps1PowerShell
$reviewed = Import-Csv .\users-to-review.csv
​
foreach ($u in $reviewed) {
    try {
        $stats = Get-MailboxStatistics -Identity $u.UserPrincipalName -Archive -ErrorAction Stop
        [pscustomobject]@{
            User        = $u.UserPrincipalName
            ArchiveSize = $stats.TotalItemSize
            ItemCount   = $stats.ItemCount
            Holds       = (Get-Mailbox $u.UserPrincipalName).InPlaceHolds -join ';'
        }
    }
    catch {
        Write-Warning "No archive or lookup failed for $($u.UserPrincipalName): $($_.Exception.Message)"
    }
}

Cross-reference the Holds column with archive size. A multi-gigabyte archive sitting under a legal hold, full of unlabelled mail, is your highest-risk combination: preserved, readable, unclassified, and now conversationally searchable.

Find it in the Purview portal under Data lifecycle management and Information protection; the archive toggle itself is in the Exchange admin center under each recipient.

Archiving was always a filing decision, never a security boundary. Copilot didn’t change the rules. It just turned your users into very fast, very literal archivists who never forget where anything is.