Exercise - Create a DLP policy for Microsoft 365 Copilot
You must demonstrate to Woodgrove Bank that Relecloud's Copilot deployment actively prevents sensitive data loss, not just theoretically covered by policy. Build the DLP policy that proves it.
Important
Prerequisites for this exercise:
- A Microsoft 365 E5 tenant (or Microsoft Purview Suite / Information Protection and Governance add-on), or Microsoft 365 E7 (Frontier Suite).
- A Microsoft 365 Copilot license assigned to your exercise test user.
- Microsoft Purview portal access with sufficient permissions to create DLP policies.
If your lab tenant doesn't have a Copilot license to spare, complete Task 1 and read through Task 2 to see the simulation-to-enforce transition.
Task 1: Create a DLP policy scoped to Copilot and Copilot Chat
- Sign in to the Microsoft Purview portal at purview.microsoft.com with your DLP-creation permissions.
- Go to Data loss prevention > Policies, then select Create policy.
- Choose a custom policy template (or start from a template close to your need), and name it
Copilot – block sensitive prompt processing. - On the Locations step, turn on only Microsoft 365 Copilot and Copilot Chat, and turn off the other locations for this exercise.
- On the Policy settings step, add a rule that detects a sensitive information type relevant to Woodgrove's data (for example, a financial account number or the custom transaction-pattern SIT from an earlier module, if available in your tenant).
- Set the rule's action to Block for prompts and responses that contain the detected sensitive information.
Task 2: Run in simulation mode, then switch to enforce
- On the policy's mode step, select Run the policy in simulation mode. Complete the wizard and create the policy.
- Have your test user (with the Copilot license) submit a prompt to Copilot Chat containing the sensitive data pattern your rule detects. Confirm the policy would have matched by reviewing the simulation results in DLP alerts (the interaction still succeeds in simulation mode—this step doesn't yet block anything).
- Return to the policy, select Edit policy, and change the mode from Simulation to On.
- Have the test user submit the same prompt again. Confirm Copilot now blocks the interaction and shows a policy tip indicating sensitive content was detected.
- Reflect: simulation mode let you validate the rule catches the right content before it started blocking real interactions—exactly the confidence Woodgrove needs to see documented, not just asserted.
You've now built and enforced a DLP policy that actively blocks sensitive prompt processing in Microsoft 365 Copilot—proof, not just policy, for Woodgrove's review.