Data Loss Prevention now covers the external web searches Copilot and Copilot Chat make on your behalf, not just files and messages.
Source: Microsoft Purview: Data Loss Prevention - Data Loss Prevention to safeguard sensitive information from external web search in Microsoft 356 Copilot and Copilot Chat —
Microsoft 365 Roadmap, item 565870
Before you act on this: these entries are drafted with AI assistance from Microsoft's
own roadmap feed, in the interest of keeping this readable and current. AI can make mistakes — names,
dates and what a feature actually does can be summarised wrong. Treat everything below as a starting
point, not advice. Always check back to the source roadmap entry linked below, and do your own
human-in-the-loop validation before you tell anyone else what to do about it.
What it is
An extension of Microsoft Purview Data Loss Prevention, now covering external web searches made from inside Microsoft 365 Copilot and Copilot Chat.
What it does
When Copilot would otherwise send sensitive data out to the open web as part of answering a question, this control can block that search in real time, based on your organisation's existing DLP policies.
Why I should care
Copilot Chat with web grounding is genuinely useful, but it also means data can leave your tenant in a way older DLP rules weren't built to catch. This is a direct answer to a reasonable worry: does asking Copilot a question ever leak information you didn't mean to share externally.
What action I need to take
This is a policy-and-configuration change, not something you switch on yourself. If your organisation handles regulated or commercially sensitive data, ask your Microsoft 365 or Purview administrator whether this DLP rule is in scope for your Copilot rollout, and whether it's actually enabled rather than merely available.
Your notes
Saved only in this browser — it never leaves your device.