To stop Microsoft 365 Copilot from using confidential files and emails, create a Microsoft Purview DLP policy that targets the Microsoft 365 Copilot and Copilot Chat location, add a rule with the Content contains > Sensitivity labels condition, and set the action to Prevent Copilot from processing content. Copilot then won't use the content of items carrying those labels in its responses, although they can still appear as citations. Add separate rules to block prompts and web searches that contain sensitive information types, and use encryption without the EXTRACT right and Restricted Content Discovery where you need stronger or broader controls.
Who this is for and what you will have at the end
This guide is for Microsoft 365, security and compliance administrators preparing for or already running Microsoft 365 Copilot, who need to make sure "Highly Confidential" and personal data doesn't end up in Copilot summaries.
At the end you will have:
- A clear picture of which control stops what.
- A DLP policy that excludes labelled files and emails from Copilot processing.
- Optional rules that block prompts, and web searches, containing card numbers or other sensitive information types.
- An encryption and site-level fallback for content that must never be summarised.
- A test and troubleshooting routine.
How Copilot sees your data
Every Copilot prompt runs in the security context of the user who sends it, so Copilot can only reach content that user can already open. DLP and labels don't fix overshared permissions; they add a second layer that decides whether Copilot may use content the user can access.
| Control | What it does | Status |
|---|---|---|
| DLP: Content contains > Sensitivity labels + Prevent Copilot from processing content | Copilot doesn't use the content of labelled files and emails; items can still be cited | Available |
| DLP: Sensitive information types + Processing prompts | Copilot doesn't respond when the typed prompt contains the chosen types | Preview, rolling out |
| DLP: Sensitive information types + Performing Web Searches | Prompts containing the chosen types aren't sent to external web search | Available |
| DLP: Email is received from > External users | External email is excluded from grounding, summaries and citations | Preview |
| Label encryption without EXTRACT | Copilot won't summarise the content and can't be used in an open file | Available |
| Double Key Encryption | Copilot can't access the content at all | Available |
| Restricted Content Discovery | Content from selected SharePoint sites doesn't appear in organisation-wide search or Copilot | Available with SharePoint Advanced Management |
Prerequisites
- Sensitivity labels published to users and applied to the content you want to protect, by users, defaults or auto-labelling.
- Roles. Any of: Microsoft Entra AI Admin, Purview Data Security AI Admin, Compliance Administrator, Compliance Data Administrator, Information Protection, Information Protection Admin, Security Administrator, or Global Administrator (avoid using Global Administrator where a lower role works).
- Licensing. Check the Microsoft 365 security and compliance licensing guidance for the DLP features you use. Restricted Content Discovery needs a Microsoft Copilot licence and SharePoint Advanced Management.
- Auditing turned on (it is by default) so that interactions and DLP matches are recorded.
Step 1: Decide which labels Copilot must not process
List the labels whose content Copilot should never summarise, for example Highly Confidential and Personal. Coverage to keep in mind:
- Files that are stored, and files that are actively open, in the file types supported by sensitivity labels.
- Emails sent on or after January 1, 2025.
- Calendar invites aren't supported.
- Labels applied to containers (teams, sites, groups) aren't inherited by the items inside, so items in a "Confidential" team aren't protected unless the items themselves carry the label.
Step 2: Create the label-based DLP policy
- Sign in to the Microsoft Purview portal and go to Data Loss Prevention > Policies > + Create policy.
- Choose the Custom template, then Custom policy. The Copilot location is only available from the custom template.
- Name the policy, for example "Copilot - exclude Highly Confidential".
- On the Locations page, turn on Microsoft 365 Copilot and Copilot Chat. Selecting it disables all other locations for this policy, and this location doesn't support admin units. Scope it to all users, or include and exclude specific accounts or distribution groups.
- Create a rule with Content contains > Sensitivity labels and select your labels.
- Add the action Prevent Copilot from processing content.
- Optionally turn on Policy Tips and select Provide a compliance URL for the end user to learn more about your organization's policies, entering a full
https://URL such ashttps://contoso.sharepoint.com/sites/compliance/data-handling. The Learn about access restrictions link in Copilot's block message then opens that page. - Start in simulation mode, which this location supports, then turn the policy on after testing.
The effect: Copilot, Copilot Chat and Copilot in Word, Excel and PowerPoint won't use the content of matching items. When a matching file is open in Word, Excel or PowerPoint, Copilot skills in that app are disabled.
Step 3: Block sensitive prompts and web searches
Create a second rule, because label and sensitive information type conditions can't share a rule:
- Condition: Content contains > Sensitive information types, for example card numbers or national ID types, including custom types.
- Action: Prevent Copilot from processing content > Processing prompts, so Copilot doesn't answer and doesn't use the prompt for internal or web searches. This is in preview; in Word, Excel and PowerPoint the user message may not clearly say an organisational policy blocked it.
- Alternative action: Performing Web Searches, which only stops the prompt being sent to external web search and still lets Copilot answer from internal Microsoft 365 data.
DLP evaluates only the typed prompt text. It doesn't scan files uploaded into the prompt.
Step 4: Create the policy with PowerShell (optional)
Microsoft documents a PowerShell route using the Copilot location ID 470f2276-e011-4e9d-a6ec-20768be3a4b0 and the CopilotExperiences enforcement plane. First find the label GUID, then create the policy and an advanced rule:
Connect-IPPSSession -UserPrincipalName admin@contoso.com
Get-Label | Format-List Priority,ContentType,Name,DisplayName,Identity,Guid
$guidVar = "<label GUID>"
$loc = '[{"Workload":"Applications","Location":"470f2276-e011-4e9d-a6ec-20768be3a4b0","Inclusions":[{"Type":"Tenant","Identity":"All"}]}]'
New-DlpCompliancePolicy -Name "Copilot Policy" -Locations $loc -EnforcementPlanes @("CopilotExperiences")
$advRule = @{
"Version" = "1.0"
"Condition" = @{
"Operator" = "And"
"SubConditions" = @(
@{
"ConditionName" = "ContentContainsSensitiveInformation"
"Value" = @(
@{
"groups" = @(
@{
"Operator" = "Or"
"labels" = @( @{ "name" = $guidVar; "type" = "Sensitivity" } )
"name" = "Default"
}
)
}
)
}
)
}
} | ConvertTo-Json -Depth 100
New-DlpComplianceRule -Name "Copilot Rule" -Policy "Copilot Policy" -AdvancedRule $advRule -RestrictAccess @(@{setting="ExcludeContentProcessing";value="Block"})To scope to a group instead of the whole tenant, replace the inclusion with {"Type":"Group","Identity":"<group ObjectId>"}, or use {"Type":"IndividualResource","Identity":"user@contoso.com"} for a user.
Step 5: Use encryption for content that must never be summarised
DLP is a policy layer. For the most sensitive content, encryption gives a second, independent control because Copilot honours the EXTRACT usage right (shown in the Purview portal as Copy and extract content (EXTRACT)):
- If a user has VIEW but not EXTRACT, Copilot won't summarise the content, can only link to it, and can't be used while that item is open in an app.
- The default Editor permission level, Full control (OWNER) and the Outlook Encrypt-Only option all include EXTRACT, so Copilot can use that content. Do Not Forward doesn't include EXTRACT.
- The person who applied the encryption is the Rights Management owner and always has EXTRACT, so Copilot can return their own encrypted content to them.
- Items protected with Double Key Encryption are never returned by Copilot.
Configure a separate label, for example "Highly Confidential - No Copilot", with custom permissions that exclude Copy and extract content (EXTRACT) for most users.
Step 6: Hide overshared sites while you fix permissions
When a site is overshared and you can't fix permissions quickly, turn on Restricted Content Discovery. In the SharePoint admin center go to Sites > Active sites, select the site, open the Settings tab, turn on Restrict content from Microsoft Copilot and select Save, or use SharePoint Online PowerShell:
Set-SPOSite -Identity https://contoso.sharepoint.com/sites/finance -RestrictContentOrgWideSearch $true
Get-SPOSite -Identity https://contoso.sharepoint.com/sites/finance | Select-Object RestrictContentOrgWideSearchIt doesn't change permissions (users who already have access can still open content directly), it doesn't remove content from the search index, and it can't be applied to OneDrive. Sites with more than 500,000 items can take more than a week to update. Treat it as a temporary control while owners review access.
Verify the policy works
- Allow up to four hours after creating or changing the policy.
- With a pilot account, ask Copilot Chat to summarise a document carrying the excluded label. The response shouldn't use its content, though the document may appear as a citation.
- Open the labelled file in Word and confirm Copilot isn't available in that file.
- Type a test prompt containing a sample card number and confirm the block message, or that no web results are used.
- In Activity explorer, look for DLP rule matched events for the Copilot interactions. If you use Data Security Posture Management for AI, its activity explorer also shows AI interaction events.
Troubleshooting
| Symptom | Cause and fix |
|---|---|
| Labelled file still listed in Copilot's answer | Expected. Citations can still appear; the content isn't used. Use encryption without EXTRACT or Restricted Content Discovery if even discovery is unacceptable. |
| Policy works in Copilot Chat but not in an open Word file | Policies are evaluated when the file opens. Close and reopen it after labelling. |
| Rule won't save with both labels and card numbers | The two conditions can't share a rule. Split them into two rules. |
| Old emails are still summarised | Label protection covers emails sent on or after January 1, 2025. |
| Teams meeting or channel chat content isn't protected | Labels that protect Teams meetings and chats aren't recognised by Copilot, and container labels aren't inherited. Label the files themselves. |
| Channel Agent in Teams summarises labelled files | DLP for Copilot doesn't apply to Channel Agent. Administrators can turn Channel Agent off. |
| Admin-unit-restricted admin can't select the location | The Copilot location doesn't support admin units. Use an unrestricted admin. |
| Changes not visible yet | Wait up to four hours before retesting. |
Closing checklist
- Excluded labels agreed and applied to real content, not only to containers.
- Label rule and sensitive information type rule in separate rules, tested in simulation first.
- Compliance URL configured so users understand blocks.
- Encryption without EXTRACT for content that must never be summarised.
- Restricted Content Discovery on the riskiest sites while permissions are reviewed.
- The same labels enforced in email, Teams and devices with Purview DLP for Exchange, SharePoint, Teams and endpoints. If you build your own retrieval-augmented apps, apply the same permission-trimming thinking described in production LLMOps and enterprise RAG architecture.
References
- https://learn.microsoft.com/en-us/purview/dlp-microsoft365-copilot-location-learn-about
- https://learn.microsoft.com/en-us/purview/ai-m365-copilot-considerations
- https://learn.microsoft.com/en-us/powershell/module/exchangepowershell/new-dlpcompliancepolicy
- https://learn.microsoft.com/en-us/powershell/module/exchangepowershell/new-dlpcompliancerule
- https://learn.microsoft.com/en-us/sharepoint/restricted-content-discovery
- https://learn.microsoft.com/en-us/purview/dspm-for-ai-considerations
- https://learn.microsoft.com/en-us/purview/dlp-learn-about-dlp
- https://learn.microsoft.com/en-us/powershell/exchange/connect-to-scc-powershell