← Back to Blog

AI and Microsoft 365 for Australian Defence Contractors

 ·  By Paul Harvey

Australian defence contractors adopting AI tools must ensure deployment meets the Defence Industry Security Program (DISP), ASD Essential Eight, and Information Security Manual (ISM) requirements — Mycelium 365 specialises in deploying Microsoft 365 Copilot and Azure AI within DISP-compliant Microsoft 365 environments for Australian defence contractors, primes, and subcontractors working on controlled or sensitive government projects.

What AI tools can Australian defence contractors use safely?

The set of AI tools acceptable inside a defence contractor's environment is deliberately narrow. In practice, three patterns work:

  • Microsoft 365 Copilot deployed inside a Microsoft 365 tenant configured to handle OFFICIAL and OFFICIAL: Sensitive information, with sensitivity labels, DLP, and conditional access enforced tenant-wide.
  • Azure OpenAI Service deployed in Azure Australia East or Australia Southeast, wrapping the firm's own indexed content and returning responses inside the same trust boundary.
  • Microsoft Azure Government / sovereign cloud for workloads at higher classification levels where commercial Azure regions are not accredited.

Consumer AI tools — the free web versions of ChatGPT, Claude, Gemini, Perplexity — must not be used with Controlled Unclassified Information (CUI), project data, ITAR-affected material, or anything that could aggregate to sensitive. These tools egress prompts to third-party model providers, may retain data for training, and provide no audit trail acceptable under DISP or the ISM.

The decision tree for defence contractors is: is the data classified or sensitive? If yes, only enterprise AI inside the firm's own accredited Microsoft 365 or Azure tenant is acceptable.

DISP compliance and AI — what defence contractors need to know

DISP membership carries specific obligations under the Governance, Personnel, Physical, and Information and Cyber Security categories. AI tools intersect directly with the information and cyber security category and, indirectly, with governance.

AI introduces four new risks that DISP-registered contractors must address:

  • Data egress — where does the prompt go, and where does the response come from?
  • Model training — is the firm's data used to train a third-party foundation model?
  • Audit trail — can the firm evidence who prompted what, when, and against which project data?
  • Aggregation — can AI responses aggregate multiple pieces of OFFICIAL information into an outcome that is more sensitive than any single input?

Microsoft 365 Copilot addresses the first two by keeping data inside the tenant boundary and excluding tenant data from Microsoft foundation model training. The last two require configuration: Microsoft Purview sensitivity labels, DLP policies, Entra ID conditional access, and audit log retention aligned to DISP evidentiary requirements. See our defence contractors industry page for the full compliance operating model.

Essential Eight requirements for defence contractors using AI

DISP requires contractors to align with the ASD Essential Eight, typically at Maturity Level 2 or above depending on the projects supported. AI tools do not sit outside the Essential Eight — they map into existing controls:

  • Application control — Copilot plugins, Microsoft 365 add-ins, browser extensions, and any AI-powered SaaS tool are applications and must be governed under ML2/ML3 application control.
  • Patch applications — AI connectors, Copilot Studio flows, and Azure OpenAI SDKs need the same patch cadence as any other software.
  • Multi-factor authentication — every Copilot licence assumes Entra ID with phishing-resistant MFA; sensitive projects should enforce FIDO2 or Windows Hello for Business.
  • Restrict administrative privileges — Copilot Studio, Power Platform environments, and Azure OpenAI resources are privileged surfaces and need PIM-gated access.
  • User application hardening — includes disabling consumer AI tools at the browser and endpoint level via Intune.

Our Huntress-powered SOC monitors AI tool usage for anomalous prompting patterns, off-hours access, and data exfiltration attempts across the tenant.

Microsoft 365 data residency for defence contractors

Microsoft's Australian data residency for Microsoft 365 covers customer data at rest in the Australia East and Australia Southeast regions. Microsoft 365 Copilot inherits this — prompts and responses are processed within the tenant boundary and Copilot does not use tenant data to train the underlying foundation models.

For most OFFICIAL and OFFICIAL: Sensitive work, Microsoft's Australian commercial cloud is the right foundation, provided the tenant is correctly configured (sensitivity labels, DLP, conditional access, audit retention).

For workloads at higher classification, contractors should evaluate Azure sovereign cloud offerings and the specific accreditation status of each service. Not every Microsoft service is accredited at every classification level, and the accreditation position changes — contractors should confirm current status against the ASD Cloud Assessment and Authorisation Framework and Defence's project-specific requirements before deploying.

The word "sovereign" is doing a lot of work here — for a defence contractor, it means data residency, operational sovereignty (who can access the underlying infrastructure), and legal sovereignty (which country's laws apply). Microsoft addresses each of these differently across its cloud offerings, and the right choice depends on the project.

How to build an AI governance framework for a defence contractor

An AI governance framework for a defence contractor is a written document, endorsed by the CISO or equivalent, that answers:

  • Which AI tools are approved? Named tools only — Microsoft 365 Copilot, Azure OpenAI Service, specific approved plugins.
  • Which data can be used with which tool? Mapped to sensitivity labels — OFFICIAL is fine in Copilot, project-specific CUI may require additional controls, anything above OFFICIAL: Sensitive is out of scope for standard Copilot.
  • Which projects are AI-eligible? Some prime contracts explicitly restrict AI use; the framework must respect contract-level constraints.
  • How is AI usage logged and audited? Microsoft Purview audit logs, retention aligned to DISP, and periodic review by the security function.
  • Staff training — every user of an approved AI tool completes AI-in-a-security-context training before their licence is provisioned.
  • Review cadence — the framework is reviewed at least every six months as the technology and threat landscape evolve.

Mycelium 365 builds and operates this framework for Australian defence contractors as part of our managed Microsoft 365 service and technology roadmap advisory.

Frequently asked questions

Can DISP-registered contractors use Microsoft 365 Copilot?

Yes, when deployed inside a properly configured Microsoft 365 tenant. Copilot processes prompts and responses within the tenant boundary, respects existing SharePoint permissions and Microsoft Purview sensitivity labels, and does not use tenant data to train Microsoft's foundation models. The prerequisites are Entra ID conditional access with phishing-resistant MFA, sensitivity labels on all OFFICIAL and OFFICIAL: Sensitive content, DLP policies covering Copilot prompts and responses, audit log retention aligned to DISP evidentiary requirements, and a written AI acceptable-use policy. Contract-specific restrictions from primes or Defence take precedence over Copilot capability.

Is Microsoft 365 approved for OFFICIAL: Sensitive defence contractor work?

Microsoft 365 is widely used across Australian government and defence-industry environments at OFFICIAL and OFFICIAL: Sensitive when correctly configured. Contractors should confirm current accreditation status against the ASD Cloud Assessment and Authorisation Framework and Defence project-specific requirements before deployment. Higher classifications typically require Azure sovereign cloud offerings rather than commercial Microsoft 365. The tenant configuration — sensitivity labels, DLP, conditional access, audit — is as important as the underlying platform accreditation.

How does Microsoft 365 Copilot handle data from sensitive defence projects?

Copilot operates within the customer's Microsoft 365 tenant boundary and inherits the tenant's data residency (Australia East and Australia Southeast for Australian tenants). Prompts and responses are not used to train Microsoft's foundation models. Copilot honours the SharePoint and OneDrive permissions the prompting user already has, and sensitivity labels applied to source content flow through to Copilot outputs. For sensitive project data, additional controls include tighter sensitivity labelling, project-scoped SharePoint sites with restricted membership, and conditional access requiring compliant devices.

What Essential Eight maturity level is required before deploying AI tools?

DISP membership typically requires Essential Eight Maturity Level 2 at a minimum, with Maturity Level 3 expected for contractors supporting more sensitive projects. AI tools do not create a new maturity requirement, but they do stress-test the existing controls — particularly application control, MFA, privileged access management, and user application hardening. In practice, contractors should reach and evidence ML2 baseline across the tenant before enabling Copilot broadly, and treat AI tools as an application class within their existing Essential Eight programme rather than a separate initiative.