The situation tends to arrive in the same shape. The office works in Microsoft 365, so mail and calendar live there. The customer data sits in a CRM from a different vendor. Someone asks whether the staff could just have an AI assistant that "can look into our own data".
The question that follows is almost always which model is best. That is the wrong question, because the models sit closer together than the setup around them does. Five things decide whether this works here, and all five can be looked up before you start a trial.
1. Is your CRM on the list, and in which way
Microsoft has two kinds of connector and the difference is bigger than the naming suggests. A synced connector does what Microsoft itself describes as "Index data into Microsoft Graph for Copilot and search". That means a copy of your CRM data inside Microsoft 365, alongside the original. A federated connector works differently: "Use a Model Context Protocol (MCP) model to fetch data in real time, without indexing content into Microsoft 365" (Copilot connectors overview, page updated 14-05-2026, read 09-10-2026).
For anyone holding personal data, that difference is the whole point. A second copy is a second place with a retention period, a permissions model and a deletion process.
So check first whether your CRM is on the federated list. That list is shorter than you would hope: in the CRM category, the version of 30-09-2026 held three names, Clarify, HubSpot and Intercom (connectors gallery, read 09-10-2026). If your package is not there, the route Microsoft points to is "you can build a custom connector by using the Microsoft 365 Agents Toolkit or the Microsoft Graph connectors API", and that is the indexing variant. You are back at the copy, or at building it yourself.
This is where a conversation about "which assistant" turns into a conversation about construction work. That is no reason not to do it. It is a reason not to schedule it for a couple of weeks.
2. Rights per user, or one account for everybody
Here sits the dividing line that shows up most in practice. A connection that signs in with a single service account gives every member of staff the rights of that account. If your CRM works with roles, you have just switched those roles off in one step.
The federated variant gets this right: "Synced connectors are supported at an organization level; federated connectors are federated at the user level. User credentials, rather than admin credentials, are required to connect to any data source" (federated connectors overview, updated 30-09-2026, read 09-10-2026). Every member of staff signs in once themselves and then sees what they would be allowed to see in the CRM without an assistant anyway.
Put this on paper as a requirement before anyone starts building. A service account is always the easiest path during the build, and hard to undo afterwards.
3. Read-only is rarely enforceable
This is the surprise when you go looking, and it runs against intuition. You would expect an administrator to be able to set a connection to read-only. With the federated connectors you cannot: "Write, update, and delete tools are part of the connector and aren't enabled separately". What does exist is a question to the user. "Read tools are always allowed and don't require approval. Write, update, and delete tools default to Needs approval", and a user who once picks Always allow has clicked that question away for the whole group of write actions (same page, read 09-10-2026).
A confirmation prompt the user can switch off themselves is not a technical boundary. It is a habit.
With ChatGPT it works differently, and only on the more expensive tier. There the administrator can "Enable MCP server connections and assign access by workspace role" and "For connections that support Action control, allow read-only actions or an approved custom set" (Apps and connectors, read 09-10-2026). That is a real read-only setting at the administrator.
If you want read-only to be solid, there is one more lock that depends on nobody's licence: have the connection itself offer no write actions at all. Two locks in different places is the difference between an agreement and a measure.
4. EU processing, and what falls just outside it
For Copilot the answer is short: "For EU customers, Microsoft Copilot is an EU Data Boundary service". With one exception you need to know when picking a model: "Models provided by Anthropic as a subprocessor are currently excluded from the EU Data Boundary" (Copilot privacy, page 18-08-2026, read 09-10-2026).
With ChatGPT it is possible too, on Enterprise and Edu, with storage in Europe (EEA + Switzerland) and on top of that the model running in that region. "Data residency is included at no additional cost for ChatGPT Enterprise and Education plans" (data residency, read 09-10-2026). The same page carries the caveat that belongs in a DPIA: "Activities such as authentication, routing, and analytics may still occur outside the selected region."
A regional guarantee covers the step where your data gets processed. Not the signing in, the routing and the measuring around it.
5. Logging and the data processing agreement
Ask every candidate for two things in writing. What trail does the administrator see afterwards, and do read actions appear in it. That second part gets skipped a lot, and when a data subject asks, who viewed what is exactly the question you need to be able to answer. How honest such an answer can be is shown by ChatGPT's own administrator guide: "MCP hooks do not provide a complete Compliance API audit trail."
You should be able to read the data processing agreement before you switch anything on, not after. Sometimes that simply works: OpenAI's DPA is public, applies from 1 January 2026, and provides that a customer based in the EEA or Switzerland contracts with OpenAI Ireland Ltd. (data processing addendum, read 09-10-2026). Microsoft operates under the DPA that already covers your existing tenant, an advantage that rarely gets counted.
What to do this week
Look up one thing before talking any further: whether your CRM is on the federated list of your assistant, or can only be connected through an indexing copy. That single answer decides whether this is a week of configuration or a project, and it takes ten minutes.
What that looks like in your situation is something we map out at AI automation. On where data sits during a project like this, read keeping data under your own control.