Restrict processing of external emails in Microsoft 365 Copilot and Copilot Chat (Preview)

Microsoft Purview Data Loss Prevention (DLP) now lets compliance administrators control whether emails from external or untrusted domains can be used as grounding data by Microsoft 365 Copilot and Copilot Chat. This affects organizations using Microsoft 365 Copilot or Copilot Chat and is not configured by default.

Timeline
  • Public Preview is available.
  • General availability is scheduled for February 2027.


How does this affect your organization?

Purview compliance administrators can create a DLP policy that detects emails received from senders outside the organization’s accepted domains and prevents Copilot from processing them. The configuration is off by default. The Copilot behavior changes only when an administrator explicitly creates and enables a policy with this condition.

Here is a sample in the default configuration: Copilot returns emails from external senders.

Sample from a default configuration (in Outlook Web)
Sample from a default configuration (in Outlook Web)


When the policy is enabled and triggered, Copilot excludes the affected emails from being referenced, summarized, or used as grounding data. Copilot continues to generate responses from trusted internal Microsoft 365 sources, such as SharePoint, OneDrive, and internal Exchange content.

A Purview administrator can configure the new option in the Purview admin portal > Data Loss Prevention by selecting the Microsoft 365 Copilot and Copilot Chat DLP policy location. Define which internal users should be included in the policy. Copilot excludes the information for these users.

Select the Microsoft 365 Copilot and Copilot Chat DLP policy location
Select the Microsoft 365 Copilot and Copilot Chat DLP policy location

Configure the control using the Email is received from People outside the organization condition.
The policy evaluates the sender domain against the tenant’s accepted domains only. Email content is not inspected.

Configure the condition for email is received from people outside the organization
Configure the condition for email is received from people outside the organization

After the policy is active, if users try to find such information with Copilot, they are informed that the information has been restricted.

Information has been restricted
Information has been restricted
Avatar photo

Tobias Asböck

Tobias is a Senior System Engineer with more than 10 years of professional experience with Microsoft 365 products such as SharePoint Online, SharePoint Premium, OneDrive for Business, Teams Collaboration, Entra ID, Information Protection, Universal Print, and Microsoft 365 Licensing. He also has 15+ years of experience planning, administering, and operating SharePoint Server environments. Tobias is a PowerShell Scripter with certifications for Microsoft 365 products. In his spare time, Tobias is busy with updates in the Microsoft 365 world or on the road with his road bike and other sports activities. If you have additional questions, please contact me via LinkedIn or [email protected].

Leave a Comment