Published May 5, 2026
Message Center
Updated June 24,July 17, 2026: We have updated the timeline. Thank you for your patience.
Introduction
We’re We are expanding Microsoft Purview Data Loss Prevention (DLP) controlsDLP for Microsoft 365 Copilot and Copilot Chat to help organizations reduce the risk of untrusted or externally sourced content influencing AI‑generated responses. This new capability allows admins to exclude emailssafeguard risks from external senders from being used as groundingemails. This real-time control helps organizations mitigate data during Copilot prompt processing. When enabled, Copilot continues to generate responses using trusted internalrisks by preventing Microsoft 365 data sources, subjectCopilot and Chat from processing emails from senders external to existing licensing and policy controls.your organization.
This message is associated with Microsoft 365 Roadmap ID 561552.
When this will happen
How this affects your organization
Who is affected
What will happen
This change does not:
Default state:
Screenshot 1. Select Microsoft 365 Copilot and Copilot Chat as the DLP policy location:

Screenshot 2. New DLP setting to restrict processing of external email content:

What you can do to prepare
No action is required if you do not plan to use this capability.
If you want to enable the feature:
Learn more:
Compliance considerations
| Question | Answer |
| Does the change alter how existing customer data is processed? | Yes. External email content is excluded from Copilot grounding when the policy is enabled; underlying email storage, access, and retention are unchanged. |
| Does the change introduce or modify AI/ML capabilities interacting with customer data? | Yes. Copilot grounding logic is updated to respect a new DLP exclusion for external email content. |
| Does the change modify Purview DLP enforcement? | Yes. Adds a new DLP control scoped specifically to Copilot and Copilot Chat grounding behavior. |
| Does the change include an admin control? | Yes. The feature is controlled via Microsoft Purview DLP policies and is admin-configurable. |
Updated June 24, 2026: We have updated the timeline. Thank you for your patience.
Introduction
We’re expanding Microsoft Purview Data Loss Prevention (DLP) controls for Microsoft 365 Copilot and Copilot Chat to help organizations reduce the risk of untrusted or externally sourced content influencing AI‑generated responses. This new capability allows admins to exclude emails from external senders from being used as grounding data during Copilot prompt processing. When enabled, Copilot continues to generate responses using trusted internal Microsoft 365 data sources, subject to existing licensing and policy controls.
This message is associated with Microsoft 365 Roadmap ID 561552.
When this will happen
How this affects your organization
Who is affected
What will happen
This change does not:
Default state:
Screenshot 1. Select Microsoft 365 Copilot and Copilot Chat as the DLP policy location:

Screenshot 2. New DLP setting to restrict processing of external email content:

What you can do to prepare
No action is required if you do not plan to use this capability.
If you want to enable the feature:
Learn more:
Compliance considerations
| Question | Answer |
| Does the change alter how existing customer data is processed? | Yes. External email content is excluded from Copilot grounding when the policy is enabled; underlying email storage, access, and retention are unchanged. |
| Does the change introduce or modify AI/ML capabilities interacting with customer data? | Yes. Copilot grounding logic is updated to respect a new DLP exclusion for external email content. |
| Does the change modify Purview DLP enforcement? | Yes. Adds a new DLP control scoped specifically to Copilot and Copilot Chat grounding behavior. |
| Does the change include an admin control? | Yes. The feature is controlled via Microsoft Purview DLP policies and is admin-configurable. |