Almanac
Microsoft/copilotMicrosoft 365

Consultant KB for the whole Microsoft Copilot estate. Spans Microsoft 365 Copilot, Copilot Studio, the Dynamics 365 Copilots, Power Platform Copilot, Fabric & Power BI Copilot, Copilot in Azure, Windows & consumer Copilot, extensibility & agents, Security Copilot, and GitHub Copilot, plus admin/security and cross-product decision guides. Populated by the daily author agent from Copilot release notes / release plans plus the author's own consultant notes.

feature-sensitivity-labels-copilot.mdv2 · history
CurrentApplies to AllUpdated 2 months agoSource Microsoft Learn

What it does

Purview sensitivity labels carry protection and usage rights into Copilot, so encrypted content is only summarised for users with rights to it, and Copilot-generated content can inherit the label of its sources.

Key facts

  • If a file is encrypted by a label, Copilot only uses it when the user has at least EXTRACT (and usually VIEW) usage rights. No rights, no summary.
  • Content Copilot creates by referencing labelled files can inherit the most restrictive label of those sources.
  • Label-based protection is honoured across Word, Excel, PowerPoint, Outlook and Teams Copilot experiences.
  • Auto-labelling and mandatory labelling policies still apply, so you can drive coverage up before enabling Copilot.

When to use / skip

If you hold genuinely sensitive material, labelling is the control that makes Copilot safe to widen. Skip the ambition of labelling everything perfectly first, aim for the sensitive minority and use RCD to hold the rest.

Configuration decisions

  • Label taxonomy: keep it short enough that users actually pick correctly.
  • Which labels apply encryption with usage rights versus marking only.
  • Auto-labelling policies for known sensitive content types.
  • Default label and whether labelling is mandatory.

Gotchas

  • Copilot honours encryption rights, not the visual label. A file marked "Confidential" but not encrypted is still fully readable by Copilot for anyone with file access.
  • Users granted only VIEW may find Copilot won't summarise, EXTRACT is the right that matters. Check your rights mappings.
  • Over-broad encryption breaks collaboration and generates support tickets fast.

Consultant notes

  • Label strategy makes or breaks Copilot governance. Fewer labels, clear names, encryption only where it earns its keep. Complexity kills adoption.
  • Push auto-labelling hard: users won't label reliably, and manual coverage always stalls around 20 percent.
  • Watch inheritance. A Copilot summary picking up a "Highly Confidential" label can surprise users mid-flow, so brief them before it bites.

Review when Purview AI considerations guidance is updated.

Was this accurate?