Microsoft Purview compliance portal: Data Loss Prevention - Data Loss Prevention to restrict Microsoft 365 Copilot processing on content with sensitivity labels

🚨 The Signal: Microsoft Purview Data Loss Prevention (DLP) now extends to Microsoft 365 Copilot. This prevents Copilot from processing sensitive content identified by sensitivity labels, enhancing data protection and reducing exposure risks within AI interactions.

The Impact

Security teams and data owners are affected by enhanced data protection, reducing the risk of sensitive information exposure via Copilot.

  • Security teams: Reduced risk of sensitive data exposure through Copilot.
  • Data owners: Improved control over how classified data is used by AI.
  • Compliance officers: Stronger attestation for data handling policies.
  • End-users: Copilot may be restricted from accessing sensitive documents.

The Action

  1. Review existing Microsoft Purview DLP policies for sensitivity label conditions.
  2. Verify sensitivity labels are correctly applied to sensitive enterprise data.
  3. Test DLP policy enforcement with Copilot using sample sensitive content.
  4. Communicate Copilot's new data restrictions to end-users and data owners.
  5. Monitor Purview DLP alerts for Copilot-related policy violations.

Domain: Purview · Impact: high · Workload: Microsoft Purview