Microsoft to Extends DLP Support for Copilot to Prevent Sensitive File Processing
Microsoft has announced an expansion of its Purview Data Loss Prevention (DLP) controls to include Microsoft 365 Copilot, preventing the processing of sensitivity-labeled files across all storage locations, including local devices.
Microsoft has announced an expansion of its Purview Data Loss Prevention (DLP) controls to include Microsoft 365 Copilot, preventing the processing of sensitivity-labeled files across all storage locations, including local devices.
This update addresses a significant governance gap in enterprise AI deployments, where previously, DLP policy enforcement for Copilot was limited to files stored in SharePoint Online and OneDrive for Business. This limitation allowed files stored locally or on network drives to be accessed by Copilot, even with existing DLP policies in place.
The technical update involves changes in how Copilot's augmentation loop (AugLoop) retrieves sensitivity label information. Previously, AugLoop used Microsoft Graph for URL-based label detection, which excluded locally stored files. The new update allows Office clients to provide sensitivity label data directly to AugLoop, eliminating the need for cloud-based URL lookups.
This architectural change ensures consistent enforcement of DLP policies across all storage locations, including OneDrive, SharePoint, network drives, and local devices. If a file with a restricted sensitivity label is detected, Copilot is blocked from processing its content in Word, Excel, or PowerPoint.
Detail Information
Roadmap ID 557255
Message ID MC1234661
This limitation allowed files stored locally or on network drives to be accessed by Copilot, even with existing DLP policies in place.
Affected Apps Word, Excel, PowerPoint
Rollout Start Late Mar 2026
Rollout Complete Late Apr 2026
Required License Microsoft 365 Copilot + M365 E5
Policy Changes Needed None
Default State On (for tenants with DLP rules)
For tenants with existing DLP rules, no policy migration or reconfiguration is required. The existing policies will automatically gain broader enforcement coverage.
This update, identified by Roadmap ID 557255 and Message ID MC1234661, will be generally available for Worldwide and GCC environments starting in late March 2026, with completion expected by late April 2026.
Administrators managing Purview DLP policies should review sensitivity-label-based restrictions and update internal documentation as needed. It is also advisable to communicate this expansion to security and compliance teams for awareness.
Organizations using Microsoft 365 Copilot should ensure they have a Microsoft 365 Copilot license and a Microsoft 365 E5 license or equivalent to leverage the full capabilities of this DLP feature. This update does not change Copilot's core functionality but enhances the governance of content access and processing.
Based on reporting by Cyber Security News.
