AI engineering

Exclude Labeled Files from Microsoft 365 Copilot with Sensitivity Labels

Use sensitivity label encryption without the EXTRACT right, Double Key Encryption, the BlockContentAnalysisServices setting and a label-based DLP rule to keep labeled files and emails out of Copilot answers.

12 min read
On this page

To exclude labeled files and emails from Microsoft 365 Copilot, configure the sensitivity label so that its encryption grants users VIEW but not the Copy and extract content (EXTRACT) usage right, or use Double Key Encryption for the most sensitive content. Copilot then won't summarize that content and can only link to it. For labels that must stay unencrypted, add a Purview DLP rule for the Microsoft 365 Copilot and Copilot Chat location that uses the Sensitivity labels condition and the Prevent Copilot from processing content action.

Who this is for and what you will have at the end

This guide is for Microsoft Purview and Microsoft 365 administrators who already have a sensitivity label taxonomy and need certain labels, such as "Highly Confidential" or "Board", to be off limits to Copilot summaries.

At the end you will have:

  • A clear map of which label configuration stops Copilot, and which doesn't.
  • A "no Copilot" label that uses encryption without EXTRACT.
  • A DLP rule for labels you don't want to encrypt.
  • An optional PowerShell setting that blocks Office connected experiences for one label.
  • A test routine and a troubleshooting table based on documented behavior.

How Copilot treats labeled content

Copilot always runs as the signed-in user, so it can only reach content that user can already open. Sensitivity labels add a second layer on top of permissions. The important point is that classification alone doesn't block anything: the effect comes from encryption usage rights or from a policy that targets the label.

Label configurationWhat Copilot doesScope
Label with no encryptionUses the content normally and displays the label name in responsesAll Copilot experiences
Encryption that grants VIEW and EXTRACT (for example Editor or Owner)Uses the content for that userAll Copilot experiences
Encryption that grants VIEW but not EXTRACTWon't summarize; can reference the item with a link; Copilot is unavailable while the item is open in an appAll Copilot experiences
Double Key EncryptionNever returns the item; Copilot is unavailable while a DKE item is openAll Copilot experiences
DLP rule on the label with Prevent Copilot from processing contentDoesn't use the content; the item can still appear as a citationCopilot, Copilot Chat and Copilot in Word, Excel and PowerPoint
Advanced setting BlockContentAnalysisServicesContent isn't sent to connected experiences, including CopilotOnly Word, Excel, PowerPoint and Outlook; Copilot Chat and Teams can still use the content

Two more behaviors matter when you design labels:

  • Copilot honors EXTRACT however it was applied. If someone applied Information Rights Management restrictions independently of a label, the content's usage rights can differ from what the label says.
  • Labels that protect Teams meetings and chats aren't currently recognized by Copilot, and labels on containers (teams, sites, groups, Loop workspaces) aren't inherited by the items inside.

Prerequisites

  • Sensitivity labels already created and published in the Microsoft Purview portal, with a role that can manage them (for example Information Protection Admin or Compliance Administrator).
  • Sensitivity labels enabled for Office files in SharePoint and OneDrive. Without this, the encrypted files that Copilot and agents can access are limited to data in use from Office apps on Windows.
  • For the DLP option, a role that can edit DLP policies for the Copilot location (for example Purview Data Security AI Admin, Compliance Administrator or Information Protection Admin), and licensing that covers it; the DLP for Copilot documentation points to the Microsoft 365 security and compliance licensing guidance.
  • Security & Compliance PowerShell (Connect-IPPSSession) for the optional advanced setting.
  • For Outlook: Copilot works with encrypted items from Outlook (classic) for Windows version 2408 in Current Channel and Monthly Enterprise Channel, Outlook for Mac 16.86.609 or later, Outlook for iOS and Android 4.2420.0 or later, Outlook on the web and new Outlook for Windows.
  • A small pilot group with Microsoft 365 Copilot licenses to test with.

Step 1: Decide which control fits each label

Not every sensitive label should use the same mechanism. Encryption changes how people work with the file, while a DLP rule only changes what Copilot does.

RequirementRecommended control
Copilot must never summarize the content, and users can live with restricted copy and pasteEncryption without EXTRACT
Content is subject to the strictest protection requirements and you already run DKEDouble Key Encryption label
Users need to copy and edit freely, but Copilot shouldn't use the contentDLP rule on the label
Only Office desktop and mobile apps must stop sending content to Microsoft cloud analysisBlockContentAnalysisServices

Be aware of the side effects of removing EXTRACT. The Copy usage right also governs copying data and screen captures, and in Teams a presenter needs it to share an encrypted document; without it, attendees see the document blacked out.

Step 2: Create a label that encrypts without EXTRACT

  1. Sign in to the Microsoft Purview portal and go to Solutions > Information Protection > Sensitivity labels.
  2. Select + Create a label (classic label scheme) or + Create > Label (modern label scheme). Name it clearly, for example "Highly Confidential - No Copilot".
  3. On Define the scope for this label, select Files & other data assets and Emails.
  4. On Choose protection settings for the types of items you selected, select Control access.
  5. On the Access control page, select Configure access control settings, then Assign permissions now.
  6. Set User access to content expires to Never unless you have a time-bound requirement, and choose an Allow offline access value. Microsoft's guidance is 7 days for sensitive business data and Never for the most sensitive data.
  7. Select Assign permissions, add the users or groups (groups are easier to maintain), and select Choose permissions.
  8. Choose a permission level that doesn't include Copy:
    • Viewer gives View, Open, Read and View Rights, without Copy.
    • Restricted Editor (previously Reviewer) lets people edit and save but doesn't include Copy.
    • Or choose Custom and select the rights you need, leaving Copy and extract content (EXTRACT) cleared.
  9. If a smaller group, such as the document owners, needs full rights, add them separately with Editor or Owner. One label can grant different permissions to different users.
  10. Save, then complete the wizard.

Avoid these configurations for a "no Copilot" label, because they include EXTRACT: the Editor and Owner levels, Full control (OWNER) in custom permissions, and the Outlook Encrypt-Only option. Do Not Forward doesn't include EXTRACT.

Also avoid Let users assign permissions for this purpose. Copilot can't access unopened SharePoint and OneDrive documents encrypted with user-defined permissions in most cases, but label inheritance isn't supported for them either, so users can't send that content into new Copilot-created items. Admin-defined permissions are more predictable.

Double Key Encryption labels

If your organization has deployed the Double Key Encryption service, create a separate label and select the Double Key Encryption option. After the label is saved you can't edit it. Copilot and agents can't access DKE-protected items at all, so this is the strongest exclusion, at the cost of DKE's operational overhead.

Step 3: Use a DLP rule for labels that stay unencrypted

When encryption isn't acceptable, target the label with Purview DLP instead:

  1. In the Purview portal, go to Data Loss Prevention > Policies > + Create policy.
  2. Choose the Custom template, then Custom policy. The Copilot location is only available here.
  3. On Locations, turn on Microsoft 365 Copilot and Copilot Chat. All other locations are disabled for this policy, and admin units aren't supported.
  4. Add a rule with Content contains > Sensitivity labels and pick the labels.
  5. Add the action Prevent Copilot from processing content.
  6. Run it in simulation mode first, then turn it on.

The rule covers stored files, files that are open, and emails sent on or after January 1, 2025. Calendar invites aren't supported. You can't combine the sensitivity label condition and the sensitive information type condition in one rule. Policy updates can take up to four hours to reach Copilot. In Word, Excel and PowerPoint the policy is evaluated when the file opens, so a label applied mid-session takes effect the next time the file is opened.

If you use Data Security Posture Management for AI, the one-click policy DSPM for AI - Protect sensitive data from Copilot processing creates the same kind of policy for the labels you select. The DSPM for AI setup guide walks through it.

Step 4: Optionally block connected experiences in Office apps

The advanced label setting BlockContentAnalysisServices prevents Word, Excel, PowerPoint and Outlook from sending content with that label to Microsoft for content analysis. It isn't available in the portal. Find the label GUID first, then set it:

Connect-IPPSSession -UserPrincipalName admin@contoso.com
 
Get-Label | Format-Table -Property DisplayName, Name, Guid, ContentType
 
Set-Label -Identity "8faca7b8-8d20-48a3-8ea2-0f96310a848e" -AdvancedSettings @{BlockContentAnalysisServices="True"}
 
(Get-Label -Identity "8faca7b8-8d20-48a3-8ea2-0f96310a848e").settings

Use this carefully. It also stops other services from working as designed, such as automatic and recommended labeling, DLP policy tips in Outlook, Designer and Translator on older Windows builds, and every connected experience that analyzes content on newer clients. And it only excludes the content from Copilot in those Office apps: the same content remains available to Copilot in Teams and Copilot Chat. To revert, remove the setting or set it to False.

Step 5: Publish the label and apply it to existing content

  • Add the new label to an existing label policy. If you edit a label that's already published, no extra step is needed, but allow up to 24 hours for changes to replicate to all apps and services.
  • If you add encryption to a label that's already in use, files in SharePoint and OneDrive (with labeling enabled) pick up the new encryption the next time they're opened in Office for the web or downloaded. Other items keep their previous encryption status until the label is removed and reapplied.
  • Relabeling existing encrypted content requires the Export or Full Control usage right, or the Rights Management issuer or owner role. Otherwise users see: You don't have permission to make this change to the sensitivity label. Please contact the content owner.
  • Consider an auto-labeling policy to apply the label to existing sensitive content at scale.

What labels do to Copilot-created content

Labels don't only block. They also travel with Copilot output:

  • Copilot Chat displays the sensitivity label of items in responses and citations, and shows the highest-priority label from the data used in the latest response.
  • Copilot in Word, PowerPoint and Outlook applies label inheritance: content drafted from a labeled file gets that label and its protection. With several sources, the highest-priority label wins.
  • Unlike other automatic labeling, an inherited label replaces a lower-priority label that was applied manually, automatically, by default policy or by a library default. It doesn't replace a higher-priority label.
  • If the inherited label can't be applied (the destination is read-only, already encrypted without EXPORT or Full Control, or the label isn't published to the user), the text isn't added to the destination.

This makes label priority order important. Keep your most restrictive labels at the highest priority.

Verify the configuration

  1. Allow up to 24 hours after label changes, and up to four hours after DLP changes.
  2. Open a test document with the new label in the Windows Office app as a pilot user who isn't the author. Customize the status bar to show Permissions, select the icon next to the label name, open My Permission, and confirm Copy shows No.
  3. In Copilot Chat, ask the pilot user to summarize that document. Copilot should offer a link rather than a summary.
  4. Repeat as the document author. The author is the Rights Management owner and will still get a summary; that's expected.
  5. In Outlook, check an email with the label: select the label banner and then View Permission.
  6. In Purview Audit, search for Copilot interactions. The AccessedResources property records resources Copilot accessed, including their SensitivityLabelId, and PolicyDetails when a policy restricted access.

Troubleshooting

SymptomCause and fix
Copilot still summarizes the labeled fileThe permissions include EXTRACT (Editor, Owner, Full control, Encrypt-Only), or the tester is the Rights Management owner. Test with another user and check My Permission.
Copilot is greyed out when the file is openExpected when the user lacks EXTRACT, when the file uses DKE, or when a DLP rule targets the label.
An older labeled file isn't encrypted after you edited the labelItems outside SharePoint and OneDrive keep their old encryption state until the label is removed and reapplied.
A file labeled "General" behaves as encryptedEncryption was applied independently of the label, for example with IRM restrictions. Copilot honors the actual usage rights.
Content from a labeled team still appears in answersContainer labels aren't inherited by items. Label the items, or use Restricted Content Discovery for the site.
Meeting chat content isn't protectedLabels for Teams meetings and chat aren't currently recognized by Copilot.
Copilot in Edge summarizes an encrypted pageCopilot in Edge and Windows can reference encrypted content in the active tab unless DLP is used in Edge.
Text from Copilot isn't inserted into a documentThe inherited label couldn't be applied, for example because the target is read-only or the label isn't published to the user.

Closing checklist

  • Each sensitive label mapped to one control: no EXTRACT, DKE, DLP rule, or connected-experience block.
  • "No Copilot" label uses Assign permissions now with Viewer, Restricted Editor or custom rights without EXTRACT.
  • Label priority order reviewed so inheritance lands on the right label.
  • Sensitivity labels enabled for SharePoint and OneDrive.
  • DLP rule for unencrypted labels tested in simulation, with separate rules for label and sensitive information type conditions.
  • Pilot tests done with a non-author account, then audit records reviewed.
  • Interaction monitoring set up with DSPM for AI. If you also bring external data into Copilot, plan its permissions with Copilot connectors, because labels on connector data aren't recognized.

References

Questions people ask

Does a sensitivity label on its own stop Copilot from reading a file?

Not by default. A label without encryption only classifies and marks the content, so Copilot can still use it for anyone who can open it. The label stops Copilot when its encryption doesn't grant the user the EXTRACT (Copy) usage right, when it uses Double Key Encryption, or when a Purview DLP policy for Copilot targets that label.

Why can the author of an encrypted document still use Copilot on it?

The person who applies the encryption becomes the Rights Management issuer and owner, which always includes Full Control and therefore EXTRACT. Copilot honors that, so the author's own encrypted content is always eligible to be returned to them. The restrictions apply to everyone else the label grants access to.

Does Copilot respect a label on a Teams team or SharePoint site?

No. Labels applied to containers such as teams, sites and Microsoft 365 groups aren't inherited by the items inside them, so Copilot doesn't see the container label on those items. Label the files and emails themselves, or use Restricted Content Discovery for a whole site.

What label does Copilot apply when it creates a document from labeled files?

Copilot in Word, PowerPoint and Outlook inherits the sensitivity label of the source item, with its protection settings. When several sources are used, the label with the highest priority wins, and it replaces a lower-priority label already on the destination item.

Microsoft Purview Information ProtectionSensitivity LabelsMicrosoft 365 CopilotData Loss Prevention
  1. Audit, Retain and Search Microsoft 365 Copilot Prompts with Purview

    Find Copilot interactions in the Purview audit log, keep or delete prompts and responses with a retention policy, and search or purge them with eDiscovery when something goes wrong.

    AI engineering11 min read
  2. Control Web Search in Microsoft 365 Copilot and Copilot Chat: Admin Guide

    Allow, restrict or disable Bing web grounding for Copilot and Copilot Chat with the Cloud Policy setting, and understand exactly what leaves the tenant.

    AI engineering11 min read
  3. Govern Copilot Studio Agents with Data Policies and an Environment Strategy

    Use Power Platform environments, environment routing and data policies to control which knowledge sources, connectors, HTTP calls and channels Copilot Studio agents can use and publish to.

    AI engineering11 min read