How to Reduce Copilot Prompt-Injection Exposure With Labels and DLP
Retrospective: this article looks back at events from June 2025, written in 2026 with the benefit of hindsight.
Prompt injection can manipulate AI assistants into exposing data they can access. You can't fully prevent it, but you can limit what Copilot can reach and leak. Here is how, using controls you likely already have.
Principle: reduce the blast radius
If Copilot can't access sensitive content, a manipulated Copilot can't leak it.
Step 1: Fix oversharing
Use SharePoint Advanced Management data access governance reports and site access reviews to remove broad access. Apply Restricted Content Discovery to sensitive sites.
Step 2: Label sensitive content
Publish sensitivity labels and use default and auto-labeling so confidential content is consistently labeled. Labels with encryption restrict which users (and therefore which Copilot sessions) can use the content.
Step 3: Use DLP for Microsoft 365 Copilot
In Microsoft Purview, create a DLP policy with the Microsoft 365 Copilot location:
- Exclude content with Highly Confidential labels from Copilot processing.
- Where available, block Copilot from responding to prompts containing specific sensitive information types.
Step 4: Reduce untrusted inputs where possible
- Strengthen email filtering so malicious external messages are quarantined before they reach mailboxes.
- Consider limiting which external content sources and web grounding Copilot can use for sensitive user groups.
Step 5: Govern agents and plugins
Review Copilot agents, connectors and plugins in the Microsoft 365 admin center. Each one adds data sources and actions.
Step 6: Monitor AI interactions
Use Purview DSPM for AI and audit logs to review Copilot interactions involving sensitive data.
Step 7: Track advisories
Subscribe to Microsoft Security Response Center updates and include AI CVEs in your vulnerability management process, even when fixes are server-side.
- EchoLeak (June 2025): The First Zero-Click Attack on Microsoft 365 Copilot Incident Teardowns
- Detecting Copilot Prompt Injection: Defender XDR and Sentinel Hunting Queries Detection & Response
- CIO Brief: Your AI Assistant Can Be Tricked Into Leaking Data CIO Briefings