Security & identity

Stop Microsoft 365 Copilot using labelled files with Purview DLP

Use the Purview DLP location for Microsoft 365 Copilot, sensitivity labels without the EXTRACT right and Restricted Content Discovery to keep confidential files and prompts out of Copilot responses.

9 min read
On this page

To stop Microsoft 365 Copilot from using confidential files and emails, create a Microsoft Purview DLP policy that targets the Microsoft 365 Copilot and Copilot Chat location, add a rule with the Content contains > Sensitivity labels condition, and set the action to Prevent Copilot from processing content. Copilot then won't use the content of items carrying those labels in its responses, although they can still appear as citations. Add separate rules to block prompts and web searches that contain sensitive information types, and use encryption without the EXTRACT right and Restricted Content Discovery where you need stronger or broader controls.

Who this is for and what you will have at the end

This guide is for Microsoft 365, security and compliance administrators preparing for or already running Microsoft 365 Copilot, who need to make sure "Highly Confidential" and personal data doesn't end up in Copilot summaries.

At the end you will have:

  • A clear picture of which control stops what.
  • A DLP policy that excludes labelled files and emails from Copilot processing.
  • Optional rules that block prompts, and web searches, containing card numbers or other sensitive information types.
  • An encryption and site-level fallback for content that must never be summarised.
  • A test and troubleshooting routine.

How Copilot sees your data

Every Copilot prompt runs in the security context of the user who sends it, so Copilot can only reach content that user can already open. DLP and labels don't fix overshared permissions; they add a second layer that decides whether Copilot may use content the user can access.

ControlWhat it doesStatus
DLP: Content contains > Sensitivity labels + Prevent Copilot from processing contentCopilot doesn't use the content of labelled files and emails; items can still be citedAvailable
DLP: Sensitive information types + Processing promptsCopilot doesn't respond when the typed prompt contains the chosen typesPreview, rolling out
DLP: Sensitive information types + Performing Web SearchesPrompts containing the chosen types aren't sent to external web searchAvailable
DLP: Email is received from > External usersExternal email is excluded from grounding, summaries and citationsPreview
Label encryption without EXTRACTCopilot won't summarise the content and can't be used in an open fileAvailable
Double Key EncryptionCopilot can't access the content at allAvailable
Restricted Content DiscoveryContent from selected SharePoint sites doesn't appear in organisation-wide search or CopilotAvailable with SharePoint Advanced Management

Prerequisites

  • Sensitivity labels published to users and applied to the content you want to protect, by users, defaults or auto-labelling.
  • Roles. Any of: Microsoft Entra AI Admin, Purview Data Security AI Admin, Compliance Administrator, Compliance Data Administrator, Information Protection, Information Protection Admin, Security Administrator, or Global Administrator (avoid using Global Administrator where a lower role works).
  • Licensing. Check the Microsoft 365 security and compliance licensing guidance for the DLP features you use. Restricted Content Discovery needs a Microsoft Copilot licence and SharePoint Advanced Management.
  • Auditing turned on (it is by default) so that interactions and DLP matches are recorded.

Step 1: Decide which labels Copilot must not process

List the labels whose content Copilot should never summarise, for example Highly Confidential and Personal. Coverage to keep in mind:

  • Files that are stored, and files that are actively open, in the file types supported by sensitivity labels.
  • Emails sent on or after January 1, 2025.
  • Calendar invites aren't supported.
  • Labels applied to containers (teams, sites, groups) aren't inherited by the items inside, so items in a "Confidential" team aren't protected unless the items themselves carry the label.

Step 2: Create the label-based DLP policy

  1. Sign in to the Microsoft Purview portal and go to Data Loss Prevention > Policies > + Create policy.
  2. Choose the Custom template, then Custom policy. The Copilot location is only available from the custom template.
  3. Name the policy, for example "Copilot - exclude Highly Confidential".
  4. On the Locations page, turn on Microsoft 365 Copilot and Copilot Chat. Selecting it disables all other locations for this policy, and this location doesn't support admin units. Scope it to all users, or include and exclude specific accounts or distribution groups.
  5. Create a rule with Content contains > Sensitivity labels and select your labels.
  6. Add the action Prevent Copilot from processing content.
  7. Optionally turn on Policy Tips and select Provide a compliance URL for the end user to learn more about your organization's policies, entering a full https:// URL such as https://contoso.sharepoint.com/sites/compliance/data-handling. The Learn about access restrictions link in Copilot's block message then opens that page.
  8. Start in simulation mode, which this location supports, then turn the policy on after testing.

The effect: Copilot, Copilot Chat and Copilot in Word, Excel and PowerPoint won't use the content of matching items. When a matching file is open in Word, Excel or PowerPoint, Copilot skills in that app are disabled.

Step 3: Block sensitive prompts and web searches

Create a second rule, because label and sensitive information type conditions can't share a rule:

  • Condition: Content contains > Sensitive information types, for example card numbers or national ID types, including custom types.
  • Action: Prevent Copilot from processing content > Processing prompts, so Copilot doesn't answer and doesn't use the prompt for internal or web searches. This is in preview; in Word, Excel and PowerPoint the user message may not clearly say an organisational policy blocked it.
  • Alternative action: Performing Web Searches, which only stops the prompt being sent to external web search and still lets Copilot answer from internal Microsoft 365 data.

DLP evaluates only the typed prompt text. It doesn't scan files uploaded into the prompt.

Step 4: Create the policy with PowerShell (optional)

Microsoft documents a PowerShell route using the Copilot location ID 470f2276-e011-4e9d-a6ec-20768be3a4b0 and the CopilotExperiences enforcement plane. First find the label GUID, then create the policy and an advanced rule:

Connect-IPPSSession -UserPrincipalName admin@contoso.com
 
Get-Label | Format-List Priority,ContentType,Name,DisplayName,Identity,Guid
 
$guidVar = "<label GUID>"
$loc = '[{"Workload":"Applications","Location":"470f2276-e011-4e9d-a6ec-20768be3a4b0","Inclusions":[{"Type":"Tenant","Identity":"All"}]}]'
 
New-DlpCompliancePolicy -Name "Copilot Policy" -Locations $loc -EnforcementPlanes @("CopilotExperiences")
 
$advRule = @{
  "Version" = "1.0"
  "Condition" = @{
    "Operator" = "And"
    "SubConditions" = @(
      @{
        "ConditionName" = "ContentContainsSensitiveInformation"
        "Value" = @(
          @{
            "groups" = @(
              @{
                "Operator" = "Or"
                "labels" = @( @{ "name" = $guidVar; "type" = "Sensitivity" } )
                "name" = "Default"
              }
            )
          }
        )
      }
    )
  }
} | ConvertTo-Json -Depth 100
 
New-DlpComplianceRule -Name "Copilot Rule" -Policy "Copilot Policy" -AdvancedRule $advRule -RestrictAccess @(@{setting="ExcludeContentProcessing";value="Block"})

To scope to a group instead of the whole tenant, replace the inclusion with {"Type":"Group","Identity":"<group ObjectId>"}, or use {"Type":"IndividualResource","Identity":"user@contoso.com"} for a user.

Step 5: Use encryption for content that must never be summarised

DLP is a policy layer. For the most sensitive content, encryption gives a second, independent control because Copilot honours the EXTRACT usage right (shown in the Purview portal as Copy and extract content (EXTRACT)):

  • If a user has VIEW but not EXTRACT, Copilot won't summarise the content, can only link to it, and can't be used while that item is open in an app.
  • The default Editor permission level, Full control (OWNER) and the Outlook Encrypt-Only option all include EXTRACT, so Copilot can use that content. Do Not Forward doesn't include EXTRACT.
  • The person who applied the encryption is the Rights Management owner and always has EXTRACT, so Copilot can return their own encrypted content to them.
  • Items protected with Double Key Encryption are never returned by Copilot.

Configure a separate label, for example "Highly Confidential - No Copilot", with custom permissions that exclude Copy and extract content (EXTRACT) for most users.

Step 6: Hide overshared sites while you fix permissions

When a site is overshared and you can't fix permissions quickly, turn on Restricted Content Discovery. In the SharePoint admin center go to Sites > Active sites, select the site, open the Settings tab, turn on Restrict content from Microsoft Copilot and select Save, or use SharePoint Online PowerShell:

Set-SPOSite -Identity https://contoso.sharepoint.com/sites/finance -RestrictContentOrgWideSearch $true
 
Get-SPOSite -Identity https://contoso.sharepoint.com/sites/finance | Select-Object RestrictContentOrgWideSearch

It doesn't change permissions (users who already have access can still open content directly), it doesn't remove content from the search index, and it can't be applied to OneDrive. Sites with more than 500,000 items can take more than a week to update. Treat it as a temporary control while owners review access.

Verify the policy works

  1. Allow up to four hours after creating or changing the policy.
  2. With a pilot account, ask Copilot Chat to summarise a document carrying the excluded label. The response shouldn't use its content, though the document may appear as a citation.
  3. Open the labelled file in Word and confirm Copilot isn't available in that file.
  4. Type a test prompt containing a sample card number and confirm the block message, or that no web results are used.
  5. In Activity explorer, look for DLP rule matched events for the Copilot interactions. If you use Data Security Posture Management for AI, its activity explorer also shows AI interaction events.

Troubleshooting

SymptomCause and fix
Labelled file still listed in Copilot's answerExpected. Citations can still appear; the content isn't used. Use encryption without EXTRACT or Restricted Content Discovery if even discovery is unacceptable.
Policy works in Copilot Chat but not in an open Word filePolicies are evaluated when the file opens. Close and reopen it after labelling.
Rule won't save with both labels and card numbersThe two conditions can't share a rule. Split them into two rules.
Old emails are still summarisedLabel protection covers emails sent on or after January 1, 2025.
Teams meeting or channel chat content isn't protectedLabels that protect Teams meetings and chats aren't recognised by Copilot, and container labels aren't inherited. Label the files themselves.
Channel Agent in Teams summarises labelled filesDLP for Copilot doesn't apply to Channel Agent. Administrators can turn Channel Agent off.
Admin-unit-restricted admin can't select the locationThe Copilot location doesn't support admin units. Use an unrestricted admin.
Changes not visible yetWait up to four hours before retesting.

Closing checklist

  • Excluded labels agreed and applied to real content, not only to containers.
  • Label rule and sensitive information type rule in separate rules, tested in simulation first.
  • Compliance URL configured so users understand blocks.
  • Encryption without EXTRACT for content that must never be summarised.
  • Restricted Content Discovery on the riskiest sites while permissions are reviewed.
  • The same labels enforced in email, Teams and devices with Purview DLP for Exchange, SharePoint, Teams and endpoints. If you build your own retrieval-augmented apps, apply the same permission-trimming thinking described in production LLMOps and enterprise RAG architecture.

References

Questions people ask

Does a DLP policy stop Copilot from showing a labelled file at all?

Not entirely. With the sensitivity label condition, Copilot doesn't read or use the content of the item in its response, but the item can still appear in the response citations. Users who already have access can still open the file directly.

How long does a Copilot DLP policy take to apply?

Microsoft states that updates to a DLP policy can take up to four hours to show in Microsoft 365 Copilot and Copilot Chat. In Word, Excel and PowerPoint the policy is evaluated when the file is opened, so a label applied mid-session takes effect the next time the file is opened.

Can one DLP rule check both sensitivity labels and sensitive information types for Copilot?

No. For the Microsoft 365 Copilot and Copilot Chat location you can't use the sensitivity label and sensitive information type conditions in the same rule. Create a separate rule for each condition, in the same policy if you like.

Does Copilot DLP scan files that users upload into a prompt?

No. DLP can't scan the contents of files uploaded directly into a Copilot prompt. It only checks the text the user types into the prompt.

Microsoft 365 CopilotMicrosoft PurviewDLPSensitivity labels
  1. Build Purview DLP policies for Exchange, SharePoint, Teams and devices

    Step-by-step Microsoft Purview DLP setup that stops card numbers and PII leaking through email, SharePoint, OneDrive, Teams chat and Windows or macOS devices, with a safe simulation rollout.

  2. Deploy Purview sensitivity labels: encryption, defaults and auto-labeling

    Plan, create and publish Microsoft Purview sensitivity labels, add encryption safely, set default and mandatory labeling, and roll out auto-labeling with simulation.

  3. Migrate Defender for Cloud Apps file policies to Purview DLP before 2027

    Defender for Cloud Apps file policies retire on 6 January 2027. Inventory them, run the DLP to Purview migration tool, rebuild what it can't move and cut over without a protection gap.