Purview and Copilot tend to arrive in the same proposal. The logic is reasonable: Copilot can surface anything a user can reach, so buy the product that controls data, and the risk is handled.
Half of that is right. The half that is wrong is expensive, because it rests on a misunderstanding of what Purview does to Copilot. Microsoft’s own documentation states the principle directly: all Microsoft 365 Copilot prompts run in the security context of the user who initiates them. To see an item in a response, the user must already have permission to access it.
Purview does not change what a user can reach. It narrows what Copilot is allowed to process from the things they can already reach. If the problem is that a sales manager can open the board pack because a SharePoint site was shared with everyone, Purview can stop Copilot summarising the board pack. It does nothing about the sales manager opening it.
That distinction decides where the money should go.
Two different problems, sold as one
When Purview and Copilot are bought together, it helps to separate the two problems cleanly.
| Problem | What decides it | What fixes it |
| Exposure | Permissions on sites, libraries, files and mailboxes | Permissions remediation |
| Processing | What Copilot is allowed to use from what is already exposed | Purview controls |
Most Copilot risk conversations are really about the first row, and most Copilot risk budgets are spent on the second. The result is an estate where Copilot politely declines to summarise a sensitive document that half the company can still open directly.
If the oversharing assessment has not been done, what a Copilot readiness assessment checks covers the exposure stage, which comes before any of what follows.
What this looks like when it goes wrong
A professional services firm had done what most proposals recommend. Security had deployed a sensitivity label, Internal Confidential, applying encryption across its financial documents.
Separately, the executive compensation and partner distribution repository had been migrated from an on-premises file share into a team site. The site kept the default Everyone except external users permission group, and nobody had looked at it since the migration.
Every internal employee was entitled to decrypt Internal Confidential content, because that is what the label was configured to allow. Every internal employee could reach the site, because of the permission group. So when non-executive staff prompted Copilot, it summarised active partner draw schedules and bonus criteria back to them.
Purview did exactly what it was configured to do. The label encrypted the files, and the encryption admitted the people it was told to admit. The exposure came entirely from a site permission that no Purview control could see or change.
How common the underlying problem is
In the readiness assessments we run, roughly 75% to 80% of tenants have at least one business-critical SharePoint site or major library open to Everyone except external users, usually without IT being aware of it. Across a typical estate of 1,000 to 3,000 seats, the assessment uncovers 30 to 45 sensitive libraries, holding payroll, executive minutes or legal drafts, reachable through tenant-wide search.
That sits alongside the wider finding from the same work, that more than nine in ten tenants fail at least one readiness prerequisite before remediation starts. The Everyone except external users group is the most common route by which content becomes readable by the whole organisation without anyone intending it.
What Purview can actually stop
With that framing, Purview’s controls are genuinely useful. There are four in the DLP location for Microsoft 365 Copilot and Copilot Chat.
| Control | What it does | Status |
| Labelled files and emails | Excludes items with chosen sensitivity labels from Copilot processing | Available |
| Web search | Blocks external web grounding when a prompt contains sensitive information types | Available |
| Sensitive prompts | Refuses to respond when a prompt contains chosen sensitive information types | Preview |
| External email | Excludes email from outside accepted domains from grounding | Preview |
The label-based exclusion is the one most organisations mean when they say Purview protects Copilot. It is worth understanding exactly what it does: the excluded item can still appear in the citations of a response. Its content is not used and not accessed by Copilot, but its existence is visible. For most data that is fine. For a document whose title is itself sensitive, it is not.
Separately, sensitivity labels that apply encryption carry their own control. The EXTRACT usage right, shown in the portal as copy and extract content, decides whether Copilot can display text from encrypted content. Where a user has VIEW but not EXTRACT, Copilot will not summarise the content and cannot be used on it while it is open, though it can still offer a link. Content protected with Double Key Encryption is not accessible to Copilot at all.
What it cannot stop
This is the list that rarely appears in the proposal, and it is taken from Microsoft’s own documentation.
Files uploaded into a prompt. DLP cannot scan the contents of a file a user uploads directly into a Copilot prompt. It only checks the text they type.
Container labels. A sensitivity label on a Team, a SharePoint site or a Microsoft 365 group is not inherited by the items inside it. Copilot will not display that container label, so a chat summarised from a team labelled Confidential carries no label in the response.
Graph connectors and plugins. Sensitivity labels and encryption on data brought in from external sources through connectors are not recognised by Copilot Chat.
Channel Agent in Teams. This one deserves attention. DLP cannot prevent Channel Agent from summarising labelled files. It honours EXTRACT for the person asking, but it does not check permissions for every user in the channel, so it can summarise content that some members could not open themselves.
Calendar invites and older email. Label-based protection covers emails sent on or after 1 January 2025. Calendar invites are not covered.
Mid-session labelling. In Word, Excel and PowerPoint the policy is evaluated when a file is opened. A label applied during a session takes effect the next time the file is opened, not immediately.
Speed. Policy updates can take up to four hours to reach Copilot experiences.
None of these is a reason not to deploy the controls. Every one of them is a reason not to present the controls as the answer to exposure.
The containment controls, and why temporary matters
There are two further tools that organisations reach for when Copilot rollout is close and permissions are not ready.
Restricted Content Discovery removes selected SharePoint sites from organisation-wide search and Copilot discovery, and removes AI entry points from those sites. Microsoft describes it plainly as a temporary governance control that gives time to review and right-size access. It applies to up to 20,000 sites, does not change permissions, does not work for OneDrive, and on a site with more than 500,000 items can take more than a week to take effect. Its SharePoint Advanced Management prerequisite is met automatically as soon as one user in the tenant holds a Copilot licence.
Data Security Posture Management for AI runs an automatic weekly risk assessment on the top 100 SharePoint sites by usage, with the first results appearing after four days. Custom assessments take at least 48 hours and expire after 30 days. Item-level scanning is limited to ten SharePoint sites, and OneDrive is not supported for it. Note that Microsoft has replaced the classic DSPM for AI with a new Data Security Posture Management experience, so guidance written against the classic version is ageing.
Restricted Content Discovery hides a site. It does not fix it. An organisation that restricts its HR and Finance sites to unblock a Copilot launch, and then moves on, has bought a quieter version of the same exposure.
That is not a hypothetical. In the engagements we run where a tenant enabled Restricted Content Discovery or Restricted SharePoint Search to unblock an early pilot, over 80% never removed the restriction on their original timeline. A control Microsoft documents as short-term triage becomes a permanent, unmaintained crutch, and it quietly degrades Copilot’s answers as the estate grows around it.
Restricted SharePoint Search is retiring
That older control deserves a specific warning, because a lot of existing guidance still recommends it. Restricted SharePoint Search is retiring, and new enablement has been blocked since 31 July 2026. Microsoft now points to Restricted Content Discovery instead.
The two work in opposite directions. Restricted SharePoint Search was an allow list, capped at 100 sites, that limited organisation-wide search and Copilot to those sites plus content a user owned, visited frequently or had shared with them. Restricted Content Discovery is applied to the specific sites you want hidden. Any plan written earlier this year that says to switch on Restricted SharePoint Search before a pilot now describes a step that cannot be taken, and needs rewriting around Restricted Content Discovery.
Our position: fund remediation, and treat Purview as the second line
In our view the business case for Copilot security is mostly a permissions remediation case, and Purview is the second line of defence rather than the first.
The reasoning is commercial as much as technical. Purview controls operate on what Copilot processes, so their value is capped by the exposure underneath them. Every pound spent on processing controls over an unremediated estate protects less than the same pound spent reducing who can reach the data in the first place. Remediation also keeps paying after Copilot, because the same overshared sites are a risk to every search, every sharing link and every future AI tool.
We would not advise a Copilot rollout plan that relies on Restricted Content Discovery without a dated plan to remove it. Microsoft calls it temporary. A plan that treats it as permanent has not solved anything, it has moved the problem out of sight.
The cost of leaving it on arrives twice. Copilot’s answers get steadily worse, because it draws on less of the estate than users expect, and that erodes trust in a tool the organisation has just paid for. Meanwhile the content stays exactly as exposed as it was: anyone with permission can still open it directly or find it by searching within the site.
Purview cannot close that gap either. A DLP policy can stop Copilot processing a specific labelled file. It cannot repair broken permission inheritance, revoke a sharing link someone created two years ago, or shrink a security group that grew to include half the company. And a sensitive document that was never labelled is outside its reach entirely.
That does not make the Purview controls optional. Label-based exclusion for genuinely sensitive content, web search blocking for regulated data types, and the EXTRACT right on encrypted content are all worth having. They are just not a substitute for fixing access.
What the licences actually cover
The commercial question underneath all of this is what an organisation already owns. The answer is more specific than most proposals present, and two common assumptions are wrong.
| Capability | E3 tenant with Copilot | E5 tier |
| SharePoint oversharing controls: restricted access control, Restricted Content Discovery, Everyone except external users reports, site access reviews | Included once one user holds a Copilot licence | Included |
| Manual sensitivity labelling | Included | Included |
| DLP that checks Copilot prompts for sensitive information | Included for all Copilot users | Included |
| Automatic labelling of files and email | Not included | Included |
| DLP that stops Copilot processing labelled files and emails | Not included | Included |
| Trainable classifiers to auto-apply retention labels | Not included | Included |
The first assumption is that SharePoint Advanced Management has to be bought separately. For a Copilot customer it does not. As soon as a single user is assigned a Copilot licence, SharePoint administrators get the Advanced Management features that support a Copilot deployment, including restricted access control, Restricted Content Discovery and the oversharing reports. The standalone add-on is needed only for extras such as restricting which apps can create sites.
The second is that Purview for Copilot is an E5 conversation from end to end. DLP for Copilot prompts is available to every Copilot user. Microsoft’s listed prerequisites for monitoring Copilot interactions in Data Security Posture Management for AI are auditing and Copilot licences, with pay-as-you-go billing for AI apps beyond Copilot. What sits behind Microsoft 365 E5 or the E5-level Purview and Information Protection add-ons is automated classification and the label-based exclusion of files and emails from Copilot.
That is the commercial finding, and it is sharper than the general one. An E3 organisation buying Copilot seats at $30 per user per month gets the tools to find and restrict overshared sites. It does not get the control most Purview-for-Copilot proposals are actually selling, which is stopping Copilot processing labelled content, and it cannot automatically classify content in order to label it. Closing that gap means moving knowledge workers to an E5 tier or adding Information Protection licensing on top of E3.
Which is one more reason to fund remediation first. The remediation tooling already comes with Copilot. The processing controls are the part that costs extra.
Two operational details worth knowing
Audit is not a usage report. Auditing captures Copilot activity but not the prompt or the response. For those you need eDiscovery or DSPM for AI. Microsoft is also explicit that audit data is not intended as a basis for Copilot usage reporting, so a dashboard of prompts built from it will not match the official usage reports.
Policy design constraints. The Copilot DLP location is only available in the Custom policy template, selecting it disables every other location in that policy, and it does not support admin units. You also cannot combine a sensitive information type condition and a sensitivity label condition in the same rule. If you are designing these rules, how a Purview DLP policy is designed covers the wider mechanics, including simulation.
Where to start
Start with exposure, not with Purview. Run the oversharing assessment, identify the sites shared with everyone and the sensitive libraries with broad access, and put dates against remediating them.
Then decide which content genuinely warrants a Copilot processing control even after remediation, and label it. Apply the label-based exclusion to that set, and check whether any of it has a sensitive title that would still show in citations.
If Restricted Content Discovery is needed to unblock a launch, use it, and write down the date it comes off.
Veratas delivers Microsoft Purview and Copilot and AI programmes, including the permissions remediation work that the controls depend on.
If your Copilot security plan is mostly a Purview licence line, talk to our team. It is worth an hour before the budget is committed.
Frequently asked questions
Does Purview stop Copilot from seeing overshared content? No. Copilot prompts run in the security context of the user, so Copilot can only return what that user can already access. Purview narrows what Copilot processes from that set, for example by excluding labelled items, but it does not change the underlying permissions.
What Purview controls exist for Microsoft 365 Copilot? The DLP location for Copilot supports excluding files and emails with chosen sensitivity labels, blocking external web search when prompts contain sensitive information types, and, in preview, refusing sensitive prompts and excluding external email. Separately, the EXTRACT usage right on encrypted content decides whether Copilot can display its text.
What can Purview not stop Copilot from doing? DLP cannot scan files uploaded directly into a prompt. Container labels on Teams and sites are not inherited by their items. Labels on data from Graph connectors are not recognised. Channel Agent in Teams cannot be prevented from summarising labelled files and does not check permissions for every channel member.
Is Restricted Content Discovery a long-term fix? No. Microsoft describes it as a temporary governance control that gives time to review access. It hides sites from organisation-wide search and Copilot discovery but does not change permissions, and users with access can still open the content directly. Its older counterpart, Restricted SharePoint Search, is retiring and cannot be newly enabled after 31 July 2026.
Does an E3 tenant with Copilot have the Purview controls it needs? Partly. One Copilot licence unlocks the SharePoint Advanced Management oversharing controls, including restricted access control and Restricted Content Discovery, and DLP for Copilot prompts is available to all Copilot users. Automatic labelling and the DLP control that stops Copilot processing labelled files and emails require Microsoft 365 E5 or equivalent Purview and Information Protection licensing.
Do labelled files still show up in Copilot responses? They can appear in citations. When a DLP policy excludes a sensitivity label from Copilot processing, the item’s content is not used or accessed, but the item itself may still be listed as a citation.
Can the audit log be used to report Copilot usage? Microsoft advises against it. Audit captures Copilot activity but not prompts or responses, and metrics built on audit data may not match the official Copilot usage report or the Copilot Dashboard in Viva Insights.

Senior Business Intelligence Architect with 22 years of experience designing enterprise analytics and data platforms. Focus areas include Power BI, real-time analytics, and large-scale BI architecture across the Microsoft data stack.






