Almanac
Microsoft/copilotMicrosoft 365

Consultant KB for the whole Microsoft Copilot estate. Spans Microsoft 365 Copilot, Copilot Studio, the Dynamics 365 Copilots, Power Platform Copilot, Fabric & Power BI Copilot, Copilot in Azure, Windows & consumer Copilot, extensibility & agents, Security Copilot, and GitHub Copilot, plus admin/security and cross-product decision guides. Populated by the daily author agent from Copilot release notes / release plans plus the author's own consultant notes.

feature-purview-dlp-copilot.mdv1 · history
CurrentApplies to AllUpdated 2 months agoSource Microsoft Learn

What it does

Data Loss Prevention for Copilot uses a sensitivity-label condition to stop Copilot summarising or grounding on content that carries specified labels, even where the user has access.

Key facts

  • The Copilot DLP location works off sensitivity labels as the condition. It excludes labelled content from Copilot processing.
  • It's an exclusion control, not the full DLP action set. You don't get the same block-with-override, encrypt or notify actions you'd expect in the Exchange or endpoint locations.
  • Requires the relevant Purview and Copilot licensing, and labels must already be published and applied.
  • Complements sensitivity-label rights: DLP can exclude content the user could otherwise have Copilot read.

When to use / skip

Use it to fence off specific labelled categories from Copilot when access-based controls alone aren't enough, say a "Legal Privilege" label. Skip expecting it to behave like classic DLP, the action surface is deliberately narrow.

Configuration decisions

  • Which labels trigger exclusion from Copilot.
  • How this sits alongside label encryption, avoid double-controlling the same content by accident.
  • Scope: whole tenant versus specific users or groups.

Gotchas

  • People expect content-inspection DLP (credit cards, NINOs) to block Copilot. Today the Copilot policy keys off labels, not sensitive info types, so unlabelled sensitive content isn't caught this way. Set expectations accordingly.
  • If labels aren't applied, the policy does nothing. It's only as good as your labelling coverage, back to auto-labelling.
  • Test with a labelled document before you claim it works. The behaviour is quiet, no dramatic block message.

Consultant notes

  • The big limitation to flag upfront: Copilot DLP is label-driven, not SIT-driven. If a client expects pattern-based blocking of Copilot output, manage that expectation on day one.
  • Chain it to your label taxonomy rather than inventing new conditions. One clear label doing exclusion beats five overlapping policies.
  • Keep an eye on the roadmap here, the action set has been expanding, so recheck current capabilities per tenant.

Review when Purview DLP for Copilot capabilities change.

Was this accurate?