Secure Sensitive Files via DLP Integration
NOTE: Microsoft's sensitivity labels, formerly known as MIP and AIP, have been renamed to Microsoft Purview. While you may still see the previous names in some UIs, future updates will align all references with the new name.
In regulated industries (such as finance and legal), information barriers are essential to prevent communication across departments. An AI assistant like Microsoft 365 Copilot can unintentionally breach these barriers by combining information from restricted groups. Additionally, its data-processing capabilities could pose a significant risk. By applying AIP labels, you can prevent the sharing of sensitive files.
Azure Information Protection (AIP) labels are essential for preventing unauthorized access to sensitive data. AIP ensures that only authorized users can interact with specific information. This helps maintain compliance with data governance policies and enhances security against unauthorized sharing. Skyhigh DLP, working with information barrier policies, can prevent Copilot from generating responses that combine data from unauthorized groups.
Create an AIP Label to Protect the Indexing of Sensitive Files
Azure Information Protection (AIP) allows organizations to classify and optionally protect sensitive documents using default and custom labels. Create an AIP label in Microsoft Purview to prevent Copilot from indexing sensitive files.
Follow the steps below to create an AIP label to protect the indexing of sensitive files from Copilot:
- In the Azure portal, navigate to Azure Information Protection > Sensitivity Labels, and then click Create a label.

- In the Label details tab, enter the basic details of the label, such as name, description, and other relevant details.

- In the Scope tab, review the scope of the label, and then click Next.
Make sure Files and other data assets, Emails, and Meeting checkboxes are selected.

- In the Items tab, select the Control access checkbox, and then click Next.

- In the Access control tab, click Assign permissions to assign permission to specific users and groups.

- Select the required options to assign permissions. Here, the Add users or groups option is selected as an example.

- Select desired users or groups, and then click Add.

- Click Choose permissions.
- Select the View rights checkbox to apply view-only custom usage rights to the file.
NOTE: Setting the custom usage rights to view-only blocks Microsoft Copilot from extracting data from the file.

- Click Save, and then click Next.
- Review Auto-labeling for files and emails, and then click Next.

- Review protection settings, and then click Next.

- Review Auto-labeling for schematized data assets, and then click Next.

- Review the settings, and then click Create label.


You have successfully created a new label to protect the indexing of sensitive files from Copilot.
