Microsoft Adds DLP Controls for Copilot External Email
Agencies deploying Microsoft 365 Copilot gain a configurable control to reduce external-email prompt-injection risk - a known grounding vulnerability.
Key points
- Microsoft Purview now offers a preview DLP control blocking external email from grounding Microsoft 365 Copilot responses.
- APS agencies using Microsoft 365 Copilot should note this as a concrete prompt-injection risk mitigation option.
- General availability is January 2027; the control addresses one untrusted-input path, not a complete prompt-injection defence.
Implications for Australian agencies
- Consider Agencies already deploying or piloting Microsoft 365 Copilot could assess whether enabling this DLP control aligns with their AI risk and data-handling requirements.
- Monitor Security and AI governance teams may want to monitor the general-availability rollout in January 2027 and review Microsoft's updated guidance on Copilot DLP at that time.
Implications are AI-generated. Starting points, not advice — see methodology for how they're framed.
View original source
Copied.
Appeared in:
Weekly digest, 27 July 2026
"Microsoft Adds DLP Controls for Copilot External Email"
Source: Let's Data Science – AI Governance
Published: 29 July 2026
URL: https://letsdatascience.com/news/microsoft-adds-dlp-controls-for-copilot-external-email-ef44c313
Microsoft has released a preview Purview Data Loss Prevention control that prevents Microsoft 365 Copilot and Copilot Chat from using externally received email as grounding, summarisation, or citation material. The rule operates on sender-domain metadata rather than message content, and does not remove user access to the email itself. It also extends to agents built in Copilot Studio when published to Microsoft 365 Copilot. General availability is scheduled for January 2027. The control narrows one retrieval path for untrusted content but does not replace broader permission, repository, and prompt-injection testing.
Implications for Australian agencies:
- [Consider] Agencies already deploying or piloting Microsoft 365 Copilot could assess whether enabling this DLP control aligns with their AI risk and data-handling requirements.
- [Monitor] Security and AI governance teams may want to monitor the general-availability rollout in January 2027 and review Microsoft's updated guidance on Copilot DLP at that time.
Retrieved from SIMS, 16 September 2026.