01Copilot surfaces only data you can at least viewVerified
Copilot surfaces only organizational data that the user has at least view permission for. It runs inside the Microsoft 365 service boundary, but that does not give it tenant-wide visibility; access is always scoped to the signed-in user's permissions.
- Understand that what you can view is what Copilot can use in your answers
- If a document you should not see appears, do not spread it; report it to the site owner or IT
- Review permissions on sites and folders you own
Content on sites with overly broad permissions becomes easier to find through Copilot. Copilot does not widen permissions, but it makes existing overly broad permissions more visible.
Supporting passage from the source
Microsoft Copilot only surfaces organizational data to which individual users have at least view permissions.
02How the semantic index works and how to exclude a siteVerified
Copilot finds grounding data through Microsoft Graph and an organization-wide semantic index built from text-based SharePoint Online files. Results are shown only if the user already has access. Indexing is enabled automatically and cannot be disabled.
- Covered types include Word, PowerPoint, PDF, aspx, and OneNote (PDF, PPTX, and DOCX up to 512 MB)
- New documents on sites accessible by two or more users are indexed daily
- To exclude a highly sensitive site (payroll, HR, finance), a site admin sets Allow this site to appear in search results to No under Site information > View all site settings > Search and offline availability
- Organizations with DLP can consider DLP for exclusion
Excluding a site removes it from both Microsoft Search and the semantic index; you cannot exclude from only one. Decide with IT because it affects everyday search.
Supporting passage from the source
It's an organization-wide index generated from text-based SharePoint Online files. However, it only surfaces the results to a user if the user already has access to the content controlled by role-based access control. Additionally, the SharePoint Online site must remain searchable.
03Encrypted labels: Copilot needs VIEW and EXTRACTVerified
For Copilot to return content encrypted by a sensitivity label, the user needs both the VIEW and EXTRACT usage rights. With VIEW but not EXTRACT, Copilot will not summarize the content but can link to it.
- Open the document in a Windows Office app and add Permissions to the status bar
- Select the icon next to the label name to show My Permission
- Check whether Copy (which maps to EXTRACT) is Yes or No
- For documents Copilot should not summarize, work with your admin on labels that encrypt without EXTRACT
Items protected by Double Key Encryption are not returned by Copilot. Unopened documents encrypted with user-defined permissions are accessible only under specific conditions. Label changes are decided by your information protection admins.
Supporting passage from the source
When the sensitivity label applies encryption, users must have the EXTRACT usage right, as well as VIEW, for the AI apps to return the data.
04New content inherits the source sensitivity labelVerified
When Copilot in Word, PowerPoint, or Outlook creates content from a labeled item, the source label and its protection are inherited automatically. With multiple sources, the highest-priority label is used. Copilot Chat also shows the highest-priority label from the data it used.
- Use Draft with Copilot > Reference a file in Word, or Create presentation from file in PowerPoint
- Check the information bar in the new document for the applied label
- Check the labels shown in Copilot Chat responses and citations
- Follow company rules if you change a label
Labels applied to containers (sites, teams) are not inherited by items in them. Labels that protect Teams meetings and chats are not currently recognized by Copilot.
Supporting passage from the source
If you use Copilot in Word, Copilot in PowerPoint, and Copilot in Outlook to create new content based on an item that has a sensitivity label applied, the sensitivity label from the source file is automatically inherited, with the label's protection settings.
05Use DLP to keep labeled files out of Copilot processingVerified
Microsoft Purview DLP has a Microsoft 365 Copilot and Copilot Chat policy location that can restrict processing of prompts containing sensitive information types, and of files and emails with specific sensitivity labels.
- (Admin) In Purview DSPM for AI (classic), switch to the Microsoft 365 Copilot view
- Review recommendations such as Assess and prevent oversharing of sensitive data
- Consider the one-click policy Protect items with sensitivity labels from Microsoft 365 Copilot and agent processing
- Wait at least a day, then review results in Reports
Files excluded by DLP are not summarized but can be referenced with a link. Decide with your information protection and quality teams which labels (for example, clinical or safety data) to include. Check Purview licensing in the service description.
Supporting passage from the source
Use the Microsoft 365 Copilot and Copilot Chat policy location to restrict the processing of prompts that contain sensitive information types, or processing files and emails that have specific sensitivity labels applied.
06Find oversharing with data access governance reportsVerified
SharePoint Advanced Management data access governance reports identify sites with potentially overshared or sensitive content. Start with the site permissions snapshot, then the sharing links and Everyone except external users activity reports.
- (Admin) In the SharePoint admin center, open Reports > Data access governance
- Use the site permissions report to find sites with the broadest access (quarterly)
- Use the sharing links and EEEU activity reports for broad sharing in the past 28 days (monthly)
- Rerun the Content Management Assessment every 30 days to track progress
- Remediate with Restricted Access Control or site access reviews
Prioritize sensitive sites such as clinical, safety, and HR. With Microsoft 365 E5 only, reports are available but without snapshot reports or remedial actions, and activity reports return up to 10,000 sites.
Supporting passage from the source
Data access governance reports help you identify sites that contain potentially overshared or sensitive content.
07Hide sites from Copilot with Restricted Content DiscoveryVerified
Restricted Content Discovery is a temporary control that keeps content from specific SharePoint sites out of organization-wide search and Copilot responses. Permissions do not change, and people with access can still open content directly. AI entry points such as the Copilot button are removed from those sites.
- (Admin) In the SharePoint admin center, open Sites > Active sites
- Select the site and open the Settings tab
- Turn on Restrict content from Microsoft Copilot and select Save
- In PowerShell: Set-SPOSite -Identity <site-url> -RestrictContentOrgWideSearch $true
- Remove the restriction after the permission review is done
It is not an access control, so fix permissions separately. Up to 20,000 sites; not for OneDrive. Users can still find content they own or recently used. Sites with more than 500,000 items can take more than a week to update. Overuse reduces the completeness of Copilot answers. The setting appears as Restrict content discovery or Restrict content from Microsoft Copilot depending on the page.
Supporting passage from the source
Restricted Content Discovery doesn't change existing permissions. Users who already have access to content can continue to access that content directly.
08Restricted SharePoint Search is retiringVerified
Restricted SharePoint Search is retiring; new enablement is blocked starting July 31, 2026. Microsoft directs customers to controls such as Restricted Content Discovery.
- (Admin) Check whether you use Restricted SharePoint Search
- Instead of the allowed list (up to 100 sites), remediate oversharing with SharePoint Advanced Management
- Set up Purview sensitivity labels, DLP, and auditing
- After validation, disable it and tell users and agent owners that Copilot answers may change
Restricted SharePoint Search is not a security boundary and does not change permissions. Recently accessed sites and directly shared files still appear even when it is on.
Supporting passage from the source
Restricted SharePoint Search is retiring. Starting July 31, 2026, new enablement is blocked. Use comprehensive data controls such as Restricted Content Discovery (RCD) for content discoverability.
09Use Restricted Access Control to actually block accessVerified
Restricted Access Control limits access to a SharePoint site to a specified group. People outside the group cannot access the site or its content even if they had access through permissions or links. This differs from Restricted Content Discovery, which only limits discovery.
- (Admin) Set up a Microsoft Entra security group or Microsoft 365 group
- In the SharePoint admin center, open Policies > Access control
- Select Enable site access restriction (optionally delegate to site admins)
- Select Save and assign the group to the site
Consider it for sites that must be limited strictly, such as those holding unblinded data or personal information. Confirm that everyone who needs access is in the group before turning it on.
Supporting passage from the source
Users who aren't part of the specified group can't access the site or its contents, even if they had prior access through permissions or a link.
10Ground Copilot in other systems with Copilot connectorsVerified
Microsoft 365 Copilot connectors bring external and line-of-business data into Copilot. Synced connectors index content into Microsoft Graph; federated connectors fetch it in real time through MCP. Connector data is returned only if the user has permission to access it.
- (Admin) Check the Copilot connectors gallery (100+ connectors) for your services
- Decide what content to ingest and how item permissions (ACLs) are set
- Register the app and grant admin consent in the Microsoft Entra admin center
- Users open connector-based citations in responses to check the items
Deployed connectors are tenant-wide unless external item security is restricted. Sensitivity labels and encryption on external data are not recognized by Copilot Chat (per Purview documentation). The privacy page still uses the older term Microsoft Graph connectors.
Supporting passage from the source
Microsoft 365 Copilot connectors bring external, line-of-business data into Microsoft 365 Copilot so your users can search and reason over more of your enterprise content.