01Copilot は閲覧権限のあるデータだけを表示する確認済

Copilot は、利用者が少なくとも閲覧権限を持つ組織データだけを表示する。Microsoft 365 のサービス境界の中で動くが、テナント全体が見えるわけではなく、アクセス範囲は常にサインインした利用者の権限に限られる。

手順
  1. 自分が見られる範囲は、Copilot が回答に使える範囲と同じだと理解する
  2. 本来見えるはずのない資料が回答に出たら、内容を広めず、サイトの所有者または IT 部門に報告する
  3. 自分が所有するサイトやフォルダーの権限を定期的に見直す
注意

権限の設定が広すぎるサイトがあると、その内容は Copilot でも見つかりやすくなる。Copilot は権限を広げないが、既存の広すぎる権限を目立たせる。

利用条件
Microsoft Copilot と Copilot Chat に共通。
出典
Microsoft Learn「Data, Privacy, and Security for Microsoft Copilot」
Microsoft Learn「How does Microsoft Copilot work?」
確認日
2026-09-12(第 1 版)
出典の該当箇所
Microsoft Copilot only surfaces organizational data to which individual users have at least view permissions.

02セマンティックインデックスの仕組みと除外方法確認済

Copilot は Microsoft Graph と、SharePoint Online のテキスト系ファイルから作る組織全体のセマンティックインデックスを使って根拠を探す。結果は、利用者がすでにアクセス権を持つ内容に限って表示される。インデックスは自動で有効になり、無効にはできない。

手順
  1. 対象は Word、PowerPoint、PDF、aspx、OneNote など(PDF、PPTX、DOCX は最大512 MB)
  2. 2人以上がアクセスできるサイトに追加された新しい文書は、1日1回インデックスされる
  3. 給与、人事、財務など特に機微な情報のサイトを除外する必要がある場合、サイト管理者は Site information > View all site settings > Search and offline availability で Allow this site to appear in search results を No にする
  4. DLP がある組織は、除外に DLP を使うことも検討する
注意

サイトを検索から除外すると、Microsoft Search とセマンティックインデックスの両方から外れる。片方だけを除外することはできない。除外は業務への影響が大きいため、IT 部門と相談して決める。

利用条件
Microsoft Copilot の有償ライセンスの利用者向けにセマンティックインデックスが作られる。管理者の作業なしで有効。
出典
Microsoft Learn「Semantic indexing for Microsoft Copilot」
Microsoft Learn「Data, Privacy, and Security for Microsoft Copilot」
確認日
2026-09-12(第 1 版)
出典の該当箇所
It's an organization-wide index generated from text-based SharePoint Online files. However, it only surfaces the results to a user if the user already has access to the content controlled by role-based access control. Additionally, the SharePoint Online site must remain searchable.

03秘密度ラベルの暗号化は EXTRACT 権限で判断される確認済

秘密度ラベルで暗号化された内容を Copilot が返すには、利用者に VIEW と EXTRACT の両方の使用権限が必要。VIEW だけの場合、Copilot はその内容を要約せず、リンクだけを示す。

手順
  1. Windows の Office アプリで文書を開き、ステータスバーに Permissions を表示する
  2. ラベル名の横のアイコンを選び、My Permission を表示する
  3. Copy(EXTRACT に対応)が Yes か No かを確認する
  4. Copilot に要約させたくない文書は、EXTRACT を含まない暗号化設定のラベルを使うよう管理者と相談する
注意

二重キー暗号化(DKE)の項目は Copilot から返されない。利用者が設定した権限で暗号化された未開封の文書は、条件付きでしか使えない。ラベル設定の変更は情報保護の管理者の判断で行う。

利用条件
Microsoft Copilot、Copilot Chat、エージェントに共通。
出典
Microsoft Learn「Use Microsoft Purview to manage data security & compliance for Microsoft 365 Copilot & Microsoft 365 Copilot Chat」
Microsoft Learn「Considerations for Microsoft Purview to manage Microsoft 365 Copilot and Channel Agent in Teams for security and compliance」
Microsoft Learn「Data, Privacy, and Security for Microsoft Copilot」
確認日
2026-09-12(第 1 版)
出典の該当箇所
When the sensitivity label applies encryption, users must have the EXTRACT usage right, as well as VIEW, for the AI apps to return the data.

04ラベル付き文書から作った内容はラベルを引き継ぐ確認済

Word、PowerPoint、Outlook の Copilot でラベル付きの文書を基に新しい内容を作ると、元のラベルと保護設定が自動で引き継がれる。複数の文書を使った場合は、優先度の最も高いラベルが使われる。Copilot Chat の回答にも、使ったデータの中で優先度が最も高いラベルが表示される。

手順
  1. Word で Draft with Copilot > Reference a file、PowerPoint で Create presentation from file を使う
  2. 新しい文書の上部の情報バーでラベルが変わったことを確認する
  3. Copilot Chat の回答と引用に表示されるラベルを確認する
  4. ラベルを変えるときは社内の規程に従う
注意

サイトやチームなどのコンテナーに付けたラベルは、中の項目に引き継がれない。Teams の会議とチャットを保護するラベルは現時点で Copilot に認識されない。

利用条件
Copilot in Word、PowerPoint、Outlook のラベル継承。Copilot Chat のラベル表示。
出典
Microsoft Learn「Use Microsoft Purview to manage data security & compliance for Microsoft 365 Copilot & Microsoft 365 Copilot Chat」
Microsoft Learn「Considerations for Microsoft Purview to manage Microsoft 365 Copilot and Channel Agent in Teams for security and compliance」
確認日
2026-09-12(第 1 版)
出典の該当箇所
If you use Copilot in Word, Copilot in PowerPoint, and Copilot in Outlook to create new content based on an item that has a sensitivity label applied, the sensitivity label from the source file is automatically inherited, with the label's protection settings.

05DLP で特定のラベルの文書を Copilot の処理から外す確認済

Microsoft Purview の DLP では、Microsoft 365 Copilot and Copilot Chat のポリシーの場所を使い、機密情報の種類を含むプロンプトの処理や、特定のラベルが付いたファイルとメールの処理を制限できる。

手順
  1. (管理者)Purview の DSPM for AI(classic)で Microsoft 365 Copilot のビューを開く
  2. Assess and prevent oversharing of sensitive data などの推奨事項を確認する
  3. Protect items with sensitivity labels from Microsoft 365 Copilot and agent processing の1クリックポリシーを検討する
  4. 少なくとも1日待ってから Reports でポリシーの結果を確認する
注意

DLP で除外された文書は、Copilot が要約しない代わりにリンクで示す。治験や安全性情報など、社内で扱いを限定しているラベルの文書を対象にするかは、情報保護と品質の担当部署で決める。Purview の各機能のライセンスはサービス記述書で確認する。

利用条件
管理者向け。ライセンス要件は Microsoft Purview のサービス記述書を参照。
出典
Microsoft Learn「Use Microsoft Purview to manage data security & compliance for Microsoft 365 Copilot & Microsoft 365 Copilot Chat」
Microsoft Learn「Considerations for Microsoft Purview to manage Microsoft 365 Copilot and Channel Agent in Teams for security and compliance」
確認日
2026-09-12(第 1 版)
出典の該当箇所
Use the Microsoft 365 Copilot and Copilot Chat policy location to restrict the processing of prompts that contain sensitive information types, or processing files and emails that have specific sensitivity labels applied.

06データアクセスガバナンスのレポートで過剰共有を探す確認済

SharePoint Advanced Management のデータアクセスガバナンスのレポートで、過剰に共有された可能性のあるサイトや機微な内容を含むサイトを特定できる。まずサイト権限のスナップショット、次に共有リンクと Everyone except external users の活動レポートを見る。

手順
  1. (管理者)SharePoint 管理センターで Reports > Data access governance を開く
  2. サイト権限のレポートで、アクセスできる人が多いサイトを確認する(四半期ごとが目安)
  3. 共有リンクと EEEU の活動レポートで、過去28日の広い共有を確認する(毎月が目安)
  4. Content Management Assessment を30日ごとに再実行し、進み具合を確認する
  5. 対応として Restricted Access Control やサイトアクセスレビューを使う
注意

治験、安全性情報、人事など機微なサイトから優先して確認する。Microsoft 365 E5 だけの場合、レポートは使えるがスナップショットレポートや是正の操作は提供されず、活動レポートは最大10,000サイトまでとされている。

利用条件
SharePoint Advanced Management の前提条件を満たす組織。E5 のみの場合は機能が限られる。
出典
Microsoft Learn「Get ready for Microsoft Copilot with SharePoint Advanced Management」
Microsoft Learn「Data access governance reports for SharePoint sites」
確認日
2026-09-12(第 1 版)
出典の該当箇所
Data access governance reports help you identify sites that contain potentially overshared or sensitive content.

07RCD で特定サイトを Copilot の検索対象から外す確認済

Restricted Content Discovery は、指定した SharePoint サイトの内容を組織全体の検索と Copilot の回答に出にくくする一時的な管理策。サイトの権限は変わらず、アクセス権のある人は引き続き直接開ける。サイト内の Copilot ボタンなど AI の入口も表示されなくなる。

手順
  1. (管理者)SharePoint 管理センターで Sites > Active sites を開く
  2. 対象のサイトを選び、Settings タブを開く
  3. Restrict content from Microsoft Copilot をオンにして Save を選ぶ
  4. PowerShell では Set-SPOSite -Identity <site-url> -RestrictContentOrgWideSearch $true
  5. 権限の見直しが終わったら解除する
注意

アクセス制御ではないため、権限そのものの是正は別に行う。最大20,000サイトまで、OneDrive には使えない。自分が所有する、または最近使った内容は引き続き見つかる。50万件を超えるサイトでは反映に1週間以上かかる場合がある。使いすぎると Copilot の回答の網羅性が下がる。画面の表記は Restrict content discovery と Restrict content from Microsoft Copilot の2通りがページにより記載されている。

利用条件
Microsoft Copilot のライセンスがあり、SharePoint Advanced Management が使える組織。Microsoft Learn(2026-09-11 更新)。
出典
Microsoft Learn「Restrict discovery of SharePoint sites and content」
Microsoft Learn「Get ready for Microsoft Copilot with SharePoint Advanced Management」
確認日
2026-09-12(第 1 版)
出典の該当箇所
Restricted Content Discovery doesn't change existing permissions. Users who already have access to content can continue to access that content directly.

08Restricted SharePoint Search は廃止へ確認済

Restricted SharePoint Search は廃止が決まり、2026年7月31日から新たに有効にできなくなった。Microsoft は代わりに Restricted Content Discovery などを使うよう案内している。

手順
  1. (管理者)現在 Restricted SharePoint Search を使っているか確認する
  2. 許可リスト(最大100サイト)に頼らず、SharePoint Advanced Management で過剰共有を是正する
  3. Purview の秘密度ラベル、DLP、監査を整える
  4. 検証が済んだら無効にし、Copilot の回答が変わることを利用者とエージェントの所有者に知らせる
注意

Restricted SharePoint Search はセキュリティの境界ではなく、権限も変えない。有効にしていても、最近アクセスしたサイトや直接共有されたファイルは回答に出る。

利用条件
2026年7月31日以降、新規の有効化は不可。
出典
Microsoft Learn「Restricted SharePoint Search」
確認日
2026-09-12(第 1 版)
出典の該当箇所
Restricted SharePoint Search is retiring. Starting July 31, 2026, new enablement is blocked. Use comprehensive data controls such as Restricted Content Discovery (RCD) for content discoverability.

09見せない必要がある場合は Restricted Access Control確認済

Restricted Access Control は、SharePoint サイトへのアクセスを指定したグループに限る。グループに属さない人は、以前に権限やリンクでアクセスできていても、サイトとその内容にアクセスできない。検索に出にくくするだけの Restricted Content Discovery とは目的が違う。

手順
  1. (管理者)Microsoft Entra のセキュリティグループか Microsoft 365 グループを用意する
  2. SharePoint 管理センターで Policies > Access control を開く
  3. Enable site access restriction を選ぶ(必要ならサイト管理者への委任も選ぶ)
  4. Save を選び、対象サイトにグループを設定する
注意

非盲検データや個人情報を扱うサイトなど、閲覧できる人を厳密に限る必要がある場合に検討する。設定前に業務で必要な人がグループに含まれているか確認する。

利用条件
SharePoint Advanced Management の機能。
出典
Microsoft Learn「Get ready for Microsoft Copilot with SharePoint Advanced Management」
確認日
2026-09-12(第 1 版)
出典の該当箇所
Users who aren't part of the specified group can't access the site or its contents, even if they had prior access through permissions or a link.

10Copilot connectors で社外システムの情報を根拠にする確認済

Microsoft 365 Copilot connectors は、社外や業務システムのデータを Copilot で検索・利用できるようにする。内容を Microsoft Graph に取り込む同期型と、MCP で都度取得する連携型がある。コネクタのデータは、利用者にアクセス権がある場合に回答に使われる。

手順
  1. (管理者)Copilot connectors gallery で、社内で使っているサービスのコネクタがあるか確認する(100以上)
  2. 取り込む内容と、各項目のアクセス権(ACL)の設定を決める
  3. Microsoft Entra 管理センターでアプリ登録と管理者の同意を行う
  4. 利用者は、回答の引用からコネクタ由来の項目を開いて確認する
注意

配置したコネクタは、項目のセキュリティを制限しない限りテナント全体に公開される。社外のデータに付いた秘密度ラベルや暗号化は Copilot Chat では認識されない(Purview の記載)。Microsoft のプライバシーのページでは Microsoft Graph connectors という旧来の表記も使われている。

利用条件
商用環境と GCC、GCCH、DoD で利用可。連携型の提供状況はコネクタごとに異なる。
出典
Microsoft Learn「Microsoft 365 Copilot connectors overview」
Microsoft Learn「Data, Privacy, and Security for Microsoft Copilot」
Microsoft Learn「Considerations for Microsoft Purview to manage Microsoft 365 Copilot and Channel Agent in Teams for security and compliance」
確認日
2026-09-12(第 1 版)
出典の該当箇所
Microsoft 365 Copilot connectors bring external, line-of-business data into Microsoft 365 Copilot so your users can search and reason over more of your enterprise content.