MC1182689 Low
(Updated) Microsoft Purview | New Copilot Security Controls in Microsoft Admin Center
Summary AI-generated
Microsoft Purview adds new DLP and security features in Admin Center to help admins monitor and control Copilot data sharing, with public preview starting mid-November 2025.
Suggested actions AI-generated
- Review Copilot security settings
- Plan DLP policy configuration
- Coordinate with data security admins
Written by Azure OpenAI (gpt-4.1) from the text of the post below. It can be incomplete or wrong; the original post is authoritative.
Similar posts
Search for more like this- MC1191257 (Updated) New Microsoft Purview data security posture management experience
- MC1187780 New experiences for Copilot management in Microsoft 365 admin center
- MC1413308 (Updated) Microsoft Purview | Data Lifecycle Management: Insights for Copilot and AI app interactions
- MC1400827 Microsoft Purview | Data Lifecycle Management: Retention support expanded to all supported Microsoft Copilot apps
- MC1192665 (Updated) Microsoft 365 admin center: Copilot settings – readiness
- MC1183292 Microsoft Purview | Data Lifecycle Management - Introducing secure priority cleanup workflows for OneDrive/SharePoint
Original post from Microsoft
Updated November 12, 2025: We have updated the content. Thank you for your patience.
[Introduction]
To help organizations adopt Microsoft 365 Copilot securely, Microsoft Purview is introducing new capabilities in Microsoft Admin Center. These enhancements allow AI and IT admins to gain visibility into oversharing risks, remediate issues, and apply a new Data Loss Prevention (DLP) policy directly within Microsoft Admin Center. This update supports secure usage of Copilot by enabling protection of sensitive interactions.
This message is associated with Microsoft 365 Roadmap ID 523212.
[When this will happen:]
- Public Preview: We will begin rolling out mid-November 2025 and expect to complete by late November 2025.
- General Availability (Worldwide): We will begin rolling out mid-January 2026 and expect to complete by late January 2026.
[How this affects your organization:]
- Who is affected: Admins managing Microsoft 365 Copilot and data security policies via Microsoft Admin Center or Purview portal.
- What will happen:
- A new Security pivot will be added to the Microsoft Admin Center.
- By default, a Purview data loss prevention policy for Copilot will be available in simulation mode. Admins can configure this policy and enable it to block specific sensitive information types from being used in Copilot. You can learn more in Message Center Post 1181998.
- Visibility into oversharing risks and sensitive Copilot interactions will be available.
[What you can do to prepare:]
- Review how Copilot is secure by default and assess if additional protections are needed.
- Once the feature is released:
- Use an Entra AI Admin or Entra Global Admin role to create a policy to block sensitive information types in Microsoft Admin Center.
- Collaborate with your data security admin to apply additional protections and ensure compliance with AI regulations.
- These actions can also be performed in the Purview portal. Learn more: Use Microsoft Purview to manage data security & compliance for Microsoft 365 Copilot & Microsoft 365 Copilot Chat.
[Compliance considerations:]
| Compliance Area | Explanation |
|---|---|
| Alters how existing customer data is processed | Sensitive information types can be blocked from Copilot interactions, modifying how data is accessed and used. |
| Modifies Purview capabilities | Adds ability to create DLP policy for Copilot from the Microsoft Admin Center. |
| Alters admin monitoring/reporting | Admins gain visibility into oversharing risks and Copilot data usage. |
| Includes admin control via Entra ID | Requires Entra AI Admin or Global Admin role to configure policies. |
Additional details from Microsoft
- RoadmapIds
- 523212
- Summary
- Microsoft Purview introduces new Copilot security controls in Microsoft Admin Center, including a default DLP policy in simulation mode, visibility into oversharing risks, and admin-configurable protections. Rollout begins mid-November 2025 (preview) and mid-January 2026 (general availability). Entra admin roles are required for policy management.
- Platforms
- Web