Defender for Cloud Apps session policies cannot control what Microsoft 365 Copilot can access when users pick files directly from SharePoint or OneDrive. Session policies inspect and control file upload/download traffic in real time between the user and the cloud app, but they do not govern how Copilot later uses files already stored in SharePoint/OneDrive and accessed via Microsoft 365’s internal APIs.
To meet the requirement “only files with a specific sensitivity label can be processed by Copilot,” and keep all other SharePoint content out of Copilot processing, use Microsoft Purview DLP for Microsoft 365 Copilot instead of (or in addition to) Defender for Cloud Apps session policies.
Below are the supported implementation options based on the provided information.
- Restrict Copilot processing to files with a specific sensitivity label
Use Microsoft Purview DLP with the Microsoft 365 Copilot and Copilot Chat policy location:
- In the Purview portal, create a custom DLP policy.
- Set the location to Microsoft 365 Copilot and Copilot Chat or Microsoft 365 Copilot (for agents), as described in:
- “Create a custom DLP policy with Microsoft 365 Copilot as the location.”
- Add a condition:
- Content contains → Sensitivity labels
- Select the sensitivity label that is allowed (for example, the label used to encrypt and classify files permitted for Copilot).
- Configure the action:
- For all labels other than the allowed one, create a rule with action Prevent Copilot from processing content.
- This ensures that when Copilot encounters a file or email with a disallowed label, “the content of the item isn't processed by Copilot or used in the response summary, but the item could be available in the citations of the response.”
- Run the policy in simulation mode first to validate impact, then enforce.
This approach aligns with:
- “Create DLP policies that use the Microsoft 365 Copilot and Copilot Chat policy location with the Content contains > Sensitivity labels condition to exclude items from being processed.”
- “Set conditions to detect content labeled with specific sensitivity labels (for example, Highly Confidential). Set the action to restrict Copilot from processing the file.”
Important behaviors:
- Coverage includes “file items, which are stored and items that are actively open” in SharePoint Online and OneDrive for Business.
- In Word, Excel, and PowerPoint, the policy is evaluated at file open; if a label is applied mid‑session, enforcement starts next time the file is opened.
- Ensure unlabeled or differently labeled files are not processed by Copilot
To ensure that only the special “Copilot‑allowed” label is processed and everything else is excluded:
- Use Purview Information Protection to:
- Configure default and/or auto‑labeling policies so that sensitive files get appropriate labels.
- In the Copilot DLP policy, create rules such as:
- Rule A: If Content contains → Sensitivity labels = [Copilot‑allowed label] → Allow (no Copilot restriction).
- Rule B: If Content contains → Sensitivity labels = [any other label] → Prevent Copilot from processing content.
- Optionally, a catch‑all rule for unlabeled content to also Prevent Copilot from processing content.
This matches the guidance: “Are there files or emails that shouldn't be used by Copilot for grounding? If yes, setup Microsoft Purview DLP for Copilot policies to restrict Copilot processing of files and emails with specific sensitivity label.”
- Limiting Copilot by SharePoint site (grounding data scope)
The provided context does not describe a way to restrict Copilot processing by SharePoint site using Defender for Cloud Apps or Purview DLP. The documented control surface for Copilot processing is:
- Sensitivity labels
- Sensitive information types in prompts
- DLP policies for Copilot
What can be done instead is:
- Use site sensitivity labels and access controls (for example, Restricted Access Control) to limit who can access specific sites.
- Since “All Microsoft 365 Copilot prompts run in the security context of the user,” users can only see items they already have permission to access. DLP for Copilot then adds an extra layer to exclude certain labeled items from processing.
- Disabling or controlling file uploads from SharePoint/OneDrive into Copilot
Defender for Cloud Apps session policies can:
- “Block upload of unclassified documents in real time” by inspecting file uploads and enforcing that only files with certain sensitivity labels are uploaded to cloud apps.
However, this applies to traffic where Defender for Cloud Apps can act as a proxy (for example, browser‑based uploads to SaaS apps). It does not control internal Microsoft 365 flows where Copilot accesses files already stored in SharePoint/OneDrive.
To control Copilot’s use of SharePoint/OneDrive content, use Purview DLP for Copilot as described above; there is no documented option in the provided material to “completely disable file uploads from SharePoint and OneDrive into Copilot” via Defender for Cloud Apps.
- Recommended combined approach
- Use Defender for Cloud Apps session policies to:
- Block uploads of unclassified or unlabeled documents to external cloud apps.
- Example: “Select the file filter Sensitivity label does not equal and then select the labels your company uses to tag classified files. Under Actions, select Block.”
- Use Purview sensitivity labels and auto‑labeling to classify and protect content in SharePoint/OneDrive.
- Use Purview DLP for Microsoft 365 Copilot and Copilot Chat to:
- Allow Copilot processing only for the specific “Copilot‑allowed” label.
- Prevent Copilot from processing all other labeled or unlabeled content.
This combination enforces:
- Only properly labeled content can be uploaded to external services.
- Within Microsoft 365, only files with the designated label are processed by Copilot, regardless of whether users select them from local storage or directly from SharePoint/OneDrive.
References: