Microsoft Purview DLP will add real-time evaluation to block sensitive data in Microsoft 365 Copilot and Copilot Chat from external web searches. When blocked, Copilot uses internal Microsoft Graph data. Rollout begins late March 2026; admins must opt in by updating DLP policies in the Purview portal.
Introduction
We’re expanding Microsoft Purview Data Loss Prevention (DLP) for Microsoft 365 Copilot and Copilot Chat to help organizations prevent sensitive data from being sent to external web search. This enhancement introduces real‑time DLP evaluation for prompts containing sensitive information types (SITs), ensuring Copilot and Microsoft 365‑published agents avoid using sensitive content for external web queries. When blocked, Copilot will still respond based on internal Microsoft Graph grounding if licensed.
This message is associated with Microsoft 365 Roadmap ID 548671.
When this will happen
How this affects your organization
Who is affected
What will happen
New DLP control for Copilot web search
New investigation and monitoring experiences
Policy management updates
Default state
Screenshot 1 - Choose M365 Copilot and Copilot Chat as the policy location:

Screenshot 2 - New DLP protection to restrict Copilot from performing web searches:

What you can do to prepare
No action is required for enablement. To begin using the feature, admins can:
Learn more:
Compliance considerations
| Question | Answer |
| Does the change alter how existing customer data is processed, stored, or accessed? | Yes. Sensitive data included in Copilot prompts will now be assessed by DLP before being sent to external web search. When blocked, data remains internal and is not transmitted externally. |
| Does the change introduce or modify AI/ML or agent capabilities that interact with customer data? | Yes. Copilot agents adapt behavior by restricting web search when sensitive data is detected, using Microsoft Graph grounding only. |
| Does the change modify, interrupt, or disable Purview capabilities? | Yes. Adds new enforcement behavior for DLP policies in Copilot scenarios. |
| Does the change alter how admins can monitor or report compliance activities? | Yes. New Copilot‑specific activities appear in Activity Explorer and DLP alerting. |
| Does the change include an admin control? | Yes. Admins must explicitly configure or update a DLP policy to enable this protection. |