Message Center
No tracked metadata fields changed between these versions.
Introduction
We’re expanding Microsoft Purview Data Loss Prevention (DLP) controls for Microsoft 365 Copilot and Copilot Chat to help organizations reduce the risk of untrusted or externally sourced content influencing AI‑generated responses. This new capability allows admins to exclude emails from external senders from being used as grounding data during Copilot prompt processing. When enabled, Copilot continues to generate responses using trusted internal Microsoft 365 data sources, subject to existing licensing and policy controls.
This message is associated with Microsoft 365 Roadmap ID 561552548671.
When this will happen
How this affects your organization
Who is affected
What will happen
This change does not:
Default state:
Screenshot 1. Select Microsoft 365 Copilot and Copilot Chat as the DLP policy location:

Screenshot 2. New DLP setting to restrict processing of external email content:

What you can do to prepare
No action is required if you do not plan to use this capability.
If you want to enable the feature:
Learn more:
Compliance considerations
| Question | Answer |
| Does the change alter how existing customer data is processed? | Yes. External email content is excluded from Copilot grounding when the policy is enabled; underlying email storage, access, and retention are unchanged. |
| Does the change introduce or modify AI/ML capabilities interacting with customer data? | Yes. Copilot grounding logic is updated to respect a new DLP exclusion for external email content. |
| Does the change modify Purview DLP enforcement? | Yes. Adds a new DLP control scoped specifically to Copilot and Copilot Chat grounding behavior. |
| Does the change include an admin control? | Yes. The feature is controlled via Microsoft Purview DLP policies and is admin-configurable. |