3.2.3 Ensure DLP policies are published for Copilot users

Information

Microsoft Purview Data Loss Prevention (DLP) policies can be scoped to Microsoft 365 Copilot and Copilot Chat interactions. When active, these policies can restrict Copilot from processing or surfacing content that matches configured sensitive information types. Organizations must define the sensitive data categories relevant to their environment and configure at least one DLP policy that covers Copilot interactions in enforcement mode.

The recommended state is to configure at least one DLP policy that includes Microsoft 365 Copilot and Copilot Chat - All accounts as a location with rules specific to the organization's needs.

Microsoft 365 Copilot can retrieve, summarize, and generate content based on data the authenticated user has access to across M365 workloads, including SharePoint, OneDrive, Teams, and Exchange. Without a DLP policy scoped to Copilot interactions, no technical control exists to prevent sensitive information such as PII, financial data, or health records from being incorporated into Copilot-generated responses and potentially exposed to users who would not otherwise have direct access to the source content. Enforcing DLP policies for Copilot ensures that sensitive data categories defined by the organization are intercepted before they are processed or surfaced by AI-generated responses.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

To remediate using the UI:

Note: Microsoft provides a guided wizard to create the Default DLP policy - Protect sensitive M365 Copilot interactions policy, which can be used when no Copilot DLP policy exists in the tenant. The steps below describe how to create a custom policy from scratch with Copilot included as a location.

- Navigate to Microsoft Purview compliance portal https://purview.microsoft.com/
- Under Solutions select Data loss prevention then Policies.
- Click Policies tab.
- Click + Create Policy.
- Click on Enterprise applications & devices.
- Under Categories select Custom and then Custom policy for the regulation.
- Name the policy, and if appropriate, select an Admin Unit.
- In Locations select Microsoft 365 Copilot and Copilot Chat.
- Click on Next to proceed to the Advanced DLP rules page.
- Click on + Create Rule

- Name the rule and give a brief description of the data that is being targeted.
- Click on + Add condition and select Content Contains
- Click on Add and select Sensitive info types
- Select the sensitive information types the organization wants to protect from being processed in Copilot interactions and click Add.
- Click on + Add an action and select Restrict Copilot from processing content
- Check the box for a relevant restriction.
- Click on Save.

- Repeat step 10 to create as many rules as the organization requires
- Click Next.
- On the Policy mode page, select the radial for Turn it on right away and click Next.
- Click Submit to create the policy once it has been reviewed.
- Finally, click Done.

Note: Compliance with this recommendation is not achieved until the policy is in enforcement mode.

Impact:

Users may find that Copilot declines to process or respond to prompts that involve content matching the organization's configured sensitive information types. In these cases, Copilot will notify the user that the request was blocked by policy. Users who rely on Copilot to summarize, draft, or retrieve content containing sensitive data such as documents with PII, financial records, or health information may need to rephrase their prompts or work with the content directly outside of Copilot. Administrators should communicate the scope of active DLP policies to affected users prior to enforcement.

See Also

https://workbench.cisecurity.org/benchmarks/24620

Item Details

Category: SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|CA-7, 800-53|SC-4, CSCv7|13, CSCv7|14.7

Plugin: microsoft_azure

Control ID: 4ff1c0819ab4bd6437ebed6ab5a05779331200cc044177230c49cef3b668013d