Securing Microsoft 365 Copilot with Sensitivity Labels and DLP

Microsoft 365 Copilot is a genuinely useful tool for business productivity. It summarises documents, drafts communications, analyses data and pulls together information from across your Microsoft 365 environment to answer questions faster. That last part is also where the concern sits: Copilot answers questions by reaching into your data, and if your data isn’t properly classified and governed, the answers it gives can include information that was never intended for the person asking.
The good news is that Microsoft has built a governance layer specifically for this problem. Microsoft Purview, the compliance and information protection platform built into Microsoft 365, provides the controls to make Copilot safer without switching it off. Two of those controls, sensitivity labels and Data Loss Prevention (DLP) policies, work together to put guardrails around what Copilot can read, surface and share.
Why Copilot changes your data governance picture
When a staff member searches SharePoint manually, they can only find files they have permission to access. Copilot works the same way in principle: Copilot can only summarise or reference content that the user is authorised to access. The issue isn’t that Copilot bypasses permissions. The issue is that permissions in most organisations are broader than they should be.
A document shared with an entire department might contain routine materials alongside sensitive pricing data or client information. Without a classification layer on top of permissions, Copilot treats both documents the same way. It will include the sensitive content in a response to anyone who holds access, even if that access was granted incidentally rather than deliberately. This is the oversharing problem that Copilot deployment tends to surface and accelerate, because the AI can find and synthesise content much faster than a manual search could.
Sensitivity labels are the bridge between who can access content and how sensitive that content actually is. DLP policies then enforce what Copilot is allowed to do with labelled content. Together, they give your organisation meaningful control over the AI rather than leaving everything up to permission inheritance.
How sensitivity labels work with Copilot
Sensitivity labels in Microsoft Purview are metadata tags applied to files, emails and other content. They persist with the content wherever it goes. Copilot and agents recognise and integrate sensitivity labels into user interactions to help keep labelled data protected. When a file carries a label, Copilot checks that label before deciding what to do with it.
The label hierarchy matters here. In a Copilot Chat conversation that references content from multiple files, Copilot surfaces the label with the highest priority. If any of the referenced files carry a Confidential or Highly Confidential label, that label becomes visible to the user and influences what Copilot will include in its response. Where encryption is applied to a label, the access check goes further: Copilot only returns content from an encrypted item if the user holds the EXTRACT and VIEW usage rights for that specific item.
A practical label taxonomy for most Australian SMEs looks something like this:
- Public – no restrictions, no encryption, Copilot can use freely.
- Internal – for general business content, Copilot can reference with standard access controls in place.
- Confidential – for content with business sensitivity; restrict Copilot responses to authorised groups and apply encryption.
- Highly Confidential – for the most sensitive data; DLP policy blocks Copilot from retrieving or including this content in any response.
Labels can be applied manually by users or automatically by Purview auto-labelling policies based on the content of files. Auto-labelling is important for existing content, because most organisations have years of documents on SharePoint and OneDrive that have never been classified. Unlabelled content is the gap: without a label, DLP policies that match on sensitivity labels cannot protect it. Getting auto-labelling working across your existing SharePoint libraries is one of the first practical steps in any Copilot governance project.
What DLP policies do for Copilot
Data Loss Prevention (DLP) in Microsoft Purview enforces what Copilot can do when it encounters labelled content or sensitive information in a prompt. There are two distinct DLP controls available for Copilot, and they operate at different points in the interaction.
The first control works at the file level. You can create a DLP policy using the Microsoft 365 Copilot and Copilot Chat policy location to restrict the processing of files and emails that carry specific sensitivity labels. When a DLP rule is configured to block Copilot from processing a labelled file, Copilot will not include that file’s content in any response, and if the file is open in Word, Excel or PowerPoint, the Copilot features in those apps are disabled for that document. This is now generally available, meaning it is production-ready for deployment.
The second control works at the prompt level. Announced at Microsoft Ignite 2025 and now generally available, this capability scans the text a user types into Copilot before Copilot processes it. If the prompt contains a recognised Sensitive Information Type (SIT), such as a credit card number, passport number, or a custom pattern your organisation defines, Copilot blocks the response entirely. No data is sent for internal or external grounding. The user receives a notification that their request cannot be completed under company policy. This real-time protection means sensitive data cannot be leaked through the prompt itself, even if the underlying documents were never labelled.
The three protections working together
Microsoft Purview now provides three overlapping layers of Copilot protection. Understanding the scope of each one helps you plan which to configure first.
- Sensitivity label-based file blocking – DLP policy prevents Copilot from reading files and emails carrying specific sensitivity labels. Generally available. Best suited to protecting your most sensitive stored documents.
- Prompt-level SIT blocking – DLP policy scans what the user types into Copilot in real time. If it detects a sensitive information type, the prompt is blocked before any AI processing occurs. Generally available. Best suited to preventing data being typed directly into AI prompts.
- External web search blocking – A separate DLP control in public preview prevents Copilot from using a user’s prompt to query external web services when that prompt contains sensitive information. Copilot continues to respond using internal Microsoft 365 data only.
These three controls can coexist in the same tenant. Note one important configuration constraint: you cannot combine a “Content contains sensitive information types” condition and a “Content contains sensitivity labels” condition within the same DLP rule. You can place both as separate rules inside the same policy, but not merged into one rule.
Addressing oversharing before you turn Copilot on
Sensitivity labels and DLP policies work best when your content is already classified. If a large proportion of your SharePoint and OneDrive documents carry no label, the label-based DLP control cannot protect them. This is the oversharing gap that catches many organisations off-guard when they deploy Copilot: the AI surfaces files that were technically accessible to a user but were never intended to be surfaced in an AI response.
Microsoft’s Data Security Posture Management (DSPM) for AI in Purview addresses this directly. DSPM runs weekly data risk assessments across your top SharePoint sites, identifying content that is accessible to broader audiences than intended. From the assessment results, you can create DLP policies, apply default sensitivity labels to new content, and run bulk remediation to disable overshared sharing links across SharePoint at scale. This is a practical starting point for organisations that want to understand their exposure before or during a Copilot rollout.
Setting a default label for all new content is one of the simplest and most effective controls available. Without it, every document created after your initial labelling project adds to the unlabelled gap. Applying “Internal” as the default label for new files in SharePoint and OneDrive ensures the baseline is covered even when users don’t manually classify their work.
A short readiness check
Before relying on Purview controls to secure your Copilot deployment, it is worth working through a few practical questions:
- What percentage of your SharePoint and OneDrive files currently carry a sensitivity label? (The Purview Data Classification dashboard gives you this.)
- Do you have auto-labelling policies active for your most common sensitive content types, such as financial records, health information or contracts?
- Have you set a default label for new content created in SharePoint and OneDrive?
- Have you configured a DLP policy using the Microsoft 365 Copilot policy location to block processing of Confidential and Highly Confidential labelled files?
- Have you run a DSPM data risk assessment to identify overshared content before expanding Copilot access?
If the answer to most of these is no or not yet, that is where to start. The controls exist and they are included in your Microsoft 365 Copilot licence, but they need to be configured before they do anything.
What this means for licences and existing Microsoft 365 plans
The DLP capability for Copilot prompt protection is included for all users with access to Microsoft 365 Copilot and Copilot Chat, including across E1, E3 and E5 licence tiers. Sensitivity labels and basic DLP policies are available in Microsoft 365 Business Premium and above. Advanced Purview features, such as auto-labelling at scale and insider risk management, sit in Microsoft 365 E5 Compliance add-ons. If you are unsure which Purview features your current licences include, that is worth clarifying before you plan your governance rollout. Our Microsoft 365 service covers licence planning alongside deployment.
Where to from here?
Getting Copilot working safely is less about restricting the AI and more about knowing what your data looks like and applying consistent classification. Sensitivity labels and DLP policies give you that classification layer. They are already built into your Microsoft 365 environment; they just need to be configured correctly.
If you are planning a Copilot deployment or want to review the governance controls already in place, we can help you work through label taxonomy, auto-labelling configuration, DLP policy design and oversharing remediation. Our IT consulting team has worked through this process with organisations across a range of industries, and we can scope what is needed for yours. Get in touch to start the conversation.



