Governing Microsoft 365 Copilot with Microsoft Purview
TL;DR: Microsoft Purview documents controls for Microsoft 365 Copilot: DSPM for AI, sensitivity labels, DLP, audit, retention, eDiscovery, communication compliance and insider risk. Learn also lists exceptions. Run the read-only skills below to gather evidence of what is configured. They do not certify compliance.
This is a guide, not a skill. It maps each Microsoft Purview capability to what Microsoft Learn says about Microsoft 365 Copilot, then to the skill in this library that checks it. Every claim below comes from the Learn pages listed in Sources. Where Learn is silent, this guide says so rather than guessing.
What does Microsoft Purview cover for Microsoft 365 Copilot?
Microsoft Learn lists eleven Purview capabilities as supported for interactions with Microsoft 365 Copilot and Microsoft 365 Copilot Chat: DSPM and DSPM for AI (classic), auditing, data classification, sensitivity labels, encryption without labels, data loss prevention, Insider Risk Management, communication compliance, eDiscovery, Data Lifecycle Management and Compliance Manager.
Learn says supported AI apps use existing Microsoft Purview controls. That means the quality of your Copilot governance depends on the quality of your existing labelling, retention and audit configuration. It also means existing permissions still decide what Copilot can retrieve, because Learn says data a user cannot access is never returned to them.
What are the prerequisites before you start?
Answering this first saves rework. Learn’s getting-started steps assume the following.
- Access to the Microsoft Purview portal with an account that has appropriate permissions, for example membership of the Microsoft Entra Compliance Administrator group role.
- Auditing turned on for the tenant. DSPM for AI (classic) shows this under Get Started, with an Activate Microsoft Purview Audit option if it is off.
- Sensitivity labels in use. Learn recommends enabling sensitivity labels for SharePoint and OneDrive too, because otherwise the encrypted files Copilot and agents can reach are limited to data in use from Office apps on Windows.
- The Microsoft Purview Content Explorer Content Viewer role group, only if an analyst must see prompts and responses in activity explorer.
- Patience: Learn says to wait at least a day for report data to appear.
Which Purview capability answers which Copilot governance question?
Each row below pairs a capability with what Learn documents and the skill here that inspects your configuration. All skills are read-only.
| Capability | What Learn says | Skill that checks it |
|---|---|---|
| DSPM for AI | Front door for discovering and securing AI use; default weekly data risk assessment for oversharing; one-click policies | DSPM for AI remediation |
| Sensitivity labels | Copilot honours label protection; highest-priority label shown; inheritance in Word, PowerPoint and Outlook | Purview label coverage |
| DLP for the Copilot location | Blocks sensitive prompts, web search on sensitive prompts, and labelled files and emails | Copilot DLP impact simulation |
| Unified audit | Prompts and responses are captured in the unified audit log; search events show accessed resources | Audit log retention validator |
| Retention | Retention policies can retain or delete prompts and responses (Microsoft Copilot Experiences option) | Retention and records audit |
| eDiscovery | Interactions sit in the user mailbox and are searchable as Copilot activity | eDiscovery legal hold readiness |
| Communication compliance | Policies can detect on user prompts and responses for AI apps | Communication compliance coverage |
| Insider Risk Management | Risky AI usage policy template covers prompt injection and protected material access | Insider risk coverage review |
How does DSPM for AI fit in?
Data Security Posture Management for AI is the recommended starting point. Learn describes it as the front door to discover, secure and apply compliance controls for AI usage, with personalised recommendations and one-click policies. Its Microsoft 365 Copilot view has sections for assessing oversharing, securing data and discovering Copilot activity.
Learn names these one-click policies for Copilot: sensitivity labels and policies, Detect risky AI usage, Unethical behavior in AI apps, and Protect sensitive data from Copilot processing. Reports then show sensitive interactions, top sensitivity labels referenced and insider risk severity. Activity explorer offers drill-down to individual interactions.
Do sensitivity labels actually stop Copilot from returning data?
Sensitivity labels add a layer on top of existing permissions. Learn says Copilot never returns data a user cannot access. When a label applies encryption, the user needs the EXTRACT usage right as well as VIEW for Copilot to return the content. Without EXTRACT, Copilot can reference the item by link but not summarise it.
Learn also documents limits worth testing:
- Labels applied to containers (Teams, SharePoint sites, Microsoft 365 Groups, Loop workspaces, Viva Engage) are not inherited by items inside them.
- Items protected with Double Key Encryption are not accessible to Copilot and agents.
- Labels that protect Teams meetings and chat are not currently recognised by Copilot and agents.
- Encrypted files labelled with user-defined permissions are not accessible unopened, with stated exceptions.
What can DLP for the Copilot location block, and what can’t it?
The Microsoft 365 Copilot and Copilot Chat DLP location can stop Copilot processing prompts that contain sensitive information types, stop web search for those prompts, and stop it using files and emails with chosen sensitivity labels. Learn also describes a preview control that excludes external email from grounding.
| Documented behaviour | Detail from Learn |
|---|---|
| Policy template | The location is only available in the Custom template, and other locations are disabled when it is selected |
| Rule conditions | Sensitive information types and sensitivity labels cannot be combined in the same rule |
| Email coverage | Labelled emails sent on or after 1 January 2025; calendar invites are not supported |
| Uploaded files | DLP cannot scan files uploaded directly into prompts; only typed prompt text is checked |
| Propagation | Policy updates can take up to four hours to reflect |
| Admin units | Not supported for this location |
| Channel Agent in Teams | Learn says you cannot prevent it summarising labelled files identified by DLP |
What does the unified audit log record for Copilot?
Learn says Copilot prompts and responses are captured in the unified audit log, and that Copilot activity is logged as part of Audit (Standard) with no extra configuration once auditing is on. Records include the accessed resources, their sensitivity label IDs, any policy details where access was blocked, and whether cross prompt injection was detected. Search them from Audit in the Microsoft Purview portal.
Learn’s considerations page adds caveats. Auditing captures the search activity but not the actual prompt or response text, which comes from eDiscovery or DSPM for AI activity explorer. Admin-related changes for Copilot auditing are not yet supported there. Audit data is also not intended as the basis for usage reporting.
Where does Learn document gaps?
Gaps matter most for evidence, so this table collects exceptions Learn states for Microsoft 365 Copilot and related agents.
| Area | Documented gap or exception |
|---|---|
| Teams transcripts | If transcripts are off, auditing, eDiscovery and retention are not supported for Copilot in Teams |
| Retention notices | Retention policies for Copilot interactions do not inform users when messages are deleted |
| Copilot Chat retention | Copilot cannot currently retain files it returns as cloud attachments; files users reference can be retained |
| Device identity | Device identity information is not currently in audit details |
| Plugins and connectors | Labels and encryption on data from Graph connectors and plugins are not recognised by Copilot Chat |
| Channel Agent in Teams | Permissions are not checked for all channel users; information barriers are not supported |
| Non-Microsoft AI apps | Audit logs for these use pay-as-you-go billing and 180-day retention |
Learn does not document a per-model breakdown of Purview controls, so Multi-model Purview controls records what is and is not stated.
What should you run, and in what order?
Work outwards from the data, then the controls, then the evidence. Each skill is read-only.
- Copilot readiness assessment to establish a baseline before Microsoft 365 Copilot reaches more users.
- SharePoint oversharing audit because Learn says Copilot never returns data a user cannot access, so review what users can access.
- Data Access Governance report review for reviewing who can access SharePoint data.
- Restricted SharePoint Search readiness as a further oversharing control; this guide does not cite Learn for how it works.
- Data classification and SIT coverage to check the sensitive information types your DLP will rely on.
- Purview label coverage, then Teams meeting label inheritance check for the documented meeting-label limit.
- Tenant DLP coverage audit, then Copilot DLP impact simulation for the Copilot location.
- Audit log retention validator and Copilot interaction compliance audit to confirm interactions are captured and reviewable.
- Purview AI activity explorer and DSPM for AI remediation to act on findings.
- Retention and records audit and eDiscovery legal hold readiness for preservation and collection.
- Communication compliance coverage and Insider risk coverage review for conduct and risk monitoring.
- Compliance Manager control mapper to map configuration to frameworks.
- Shadow AI app discovery for AI apps outside Copilot.
- Copilot Control System governance validator, Copilot Notebooks governance, Copilot Studio DLP gap check and Agent audit trail forensics for agents and notebooks.
What do these skills prove, and what don’t they?
Skills in this library are read-only by default. They inspect configuration and produce evidence, a scored report or a remediation plan. They do not certify compliance, and they do not change a label, policy or setting. A clean report shows your tenant matched a documented control on the day it ran, nothing more.
For the wider picture, read these sibling guides:
- What is an AI skill? explains how the skills work.
- Copilot readiness guide covers the SharePoint and Microsoft 365 architecture side.
- Australian Copilot compliance maps this evidence to Australian frameworks.
- Agent governance guide covers agents built on Microsoft 365 Copilot.
Sources
- Use Microsoft Purview to manage data security and compliance for Microsoft 365 Copilot and Microsoft 365 Copilot Chat
- Considerations to manage Microsoft 365 Copilot and Channel Agent in Teams for security and compliance
- Use Microsoft Purview DLP to protect interactions with Microsoft 365 Copilot and Copilot Chat
- Audit logs for Copilot and AI applications
Licensed under CC BY 4.0 by EDUC4TE .
Last reviewed 2026-09-30