msnugget
Purview DLP for Copilot Prompts – Stop Sensitive Data in Prompts
10 By Jannik Reinhard & Florian Salzmann · Published · Updated

Purview DLP for Copilot Prompts – Stop Sensitive Data in Prompts

Microsoft is extending Purview Data Loss Prevention to cover Microsoft 365 Copilot prompts. From now (Public Preview, GA expected Q1 2026), sensitive data typed directly into Copilot will be blocked in real-time. This is not optional. If a prompt contains sensitive data flagged in your DLP policy, Copilot will not respond. The data never reaches processing.

What it enables / Why this matters

This removes one of the last remaining gaps in Copilot security. Until now, DLP protected files and emails you referenced, but not the sensitive data you typed directly into a prompt. A user asking “What is the revenue for Project Wingtip?” with financial figures embedded in the question—that data was being processed.

The core issue is simple. Copilot processes everything in the prompt. It uses that data for grounding. If web search is enabled, it can send the prompt to external services. A single careless question containing customer PII, API keys, passport numbers, or financial data is enough to expose it.

Real-world example: A developer pastes an API key into a Copilot prompt asking for help. An analyst mentions a customer ID in a question about data. An HR manager types an employee’s salary in a question about payroll. These happen constantly because people work with what they know.

Purview DLP for Copilot Prompts stops this at the input layer. The sensitive data is detected before it enters the system. No processing. No grounding. No web search exposure. The user gets blocked and learns not to type sensitive data into Copilot.

This also closes a gap that Conditional Access rules did not always fully cover. Conditional Access logs your sign-in. This enforcement logs the attempt to use sensitive data in Copilot. You get visibility into risky behavior and can adjust policies accordingly.

When will it apply?

Always, if you have DLP policies configured. The feature works with existing DLP policies—you do not need to create new ones. If you have defined what constitutes sensitive data in your organization (credit card numbers, customer IDs, project codes, passport numbers, etc.), those same rules now apply to Copilot prompts.

It applies to:

  • Microsoft 365 Copilot (all chat modes)

  • Pre-built agents in Microsoft 365 Copilot

  • Microsoft 365 Copilot Chat

  • Web search queries through Copilot

This is especially relevant in regulated tenants (financial services, healthcare, government), but also matters in any environment handling customer data, proprietary information, or employee PII.

When NOT to use it

There is no real opt-out. But do not rely on this enforcement as your only data protection. It protects one entry point: the prompt. It does not prevent:

  • Users sharing sensitive data through Teams or email

  • Oversharing in SharePoint or OneDrive

  • Misconfigured sensitivity labels

  • Agents accessing data they should not access

Purview DLP for Copilot Prompts is a baseline control, not a security strategy.

Also: if an attacker already has a compromised user account and no Copilot blocking policy is configured, they could use Copilot to exfiltrate sensitive data before you detect it. This enforcement does not replace strong identity controls, Conditional Access, or proper monitoring.

The bigger picture

Purview DLP for Copilot Prompts fits into Microsoft’s broader Copilot Control System (CCS). This framework also includes:

  • Unified security dashboard in Microsoft 365 admin center

  • Data risk assessments for oversharing across SharePoint

  • Baseline Security Mode (applying Microsoft-recommended security settings)

  • Agent governance (controlling what agents can access)

Together, these controls create what we might call “AI security by design.” Protection embedded at the system level, not added on top.

References

🔗 Security and governance innovations for Microsoft 365 Copilot | Microsoft Community Hub 🔗 Purview Data Loss Prevention with Microsoft 365 Copilot | Microsoft Learn 🔗 Microsoft 365 Copilot Control System – aka.ms/CCS