From 6afb36c3579186a2779b739871a85fedda12e6e1 Mon Sep 17 00:00:00 2001 From: soyalejolopez <88358406+soyalejolopez@users.noreply.github.com> Date: Wed, 30 Sep 2026 16:30:11 -0500 Subject: [PATCH] Agent 365 guide 1.2.1: clarify DLP scoping for agent instances Purview has no separate Agent 365 instance picker. Scope DLP through a security group containing the agents' Entra agent user accounts under each Exchange, Teams, and OneDrive location's Edit scope; scope SharePoint by site. Detailed task 4.21 now sets scope in the Locations step. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> --- .../CHANGELOG.md | 4 ++++ .../README.md | 4 ++-- .../index.html | 12 +++++++----- 3 files changed, 13 insertions(+), 7 deletions(-) diff --git a/copilot-agent-strategy/agent-365-customer-implementation-guide/CHANGELOG.md b/copilot-agent-strategy/agent-365-customer-implementation-guide/CHANGELOG.md index 6c8936c7..40e91582 100644 --- a/copilot-agent-strategy/agent-365-customer-implementation-guide/CHANGELOG.md +++ b/copilot-agent-strategy/agent-365-customer-implementation-guide/CHANGELOG.md @@ -2,6 +2,10 @@ All notable changes to the Microsoft Agent 365 Customer Implementation Guide are documented here. +## 1.2.1 - 2026-09-30 + +- Clarified how to scope Purview DLP to Agent 365 agents. Purview has no separate "Agent 365 instances" picker: each instance is an Entra agent user account, so the Simple checklist control **Scope DLP to Agent 365 instances and supported interactions** now starts by adding the approved agents to a reviewed security group, then includes that group under **Edit** for each Exchange, Teams, and OneDrive location. It also notes that Exchange scoping accepts only groups and that SharePoint is scoped by site. Detailed task **4.21** now sets this scope in the **Locations** step instead of after the rule actions. + ## 1.2.0 - 2026-09-25 - Removed the "Value plays" section, its navigation link, the related hero metric, CSS, and scripts. Its Microsoft Defender advanced hunting queries now live where you use them: the Simple checklist row **Hunt for agent inventory and activity with advanced hunting** and Detailed task **2a**, each with a schema check, eight sample queries, and copy buttons. The queries were rechecked against current Microsoft Learn schemas; the activity query now filters on the documented Agent 365 `ActionType` values, and the behavior query summarizes the values your tenant emits. diff --git a/copilot-agent-strategy/agent-365-customer-implementation-guide/README.md b/copilot-agent-strategy/agent-365-customer-implementation-guide/README.md index 72e01ab4..c304d34e 100644 --- a/copilot-agent-strategy/agent-365-customer-implementation-guide/README.md +++ b/copilot-agent-strategy/agent-365-customer-implementation-guide/README.md @@ -7,9 +7,9 @@ author: - "Pratik Bhusal" - "Manas Biswas" - "Alejandro Lopez" -version: 1.2.0 +version: 1.2.1 published: 2026-09-09 -updated: 2026-09-25 +updated: 2026-09-30 tags: - agent-365 - implementation diff --git a/copilot-agent-strategy/agent-365-customer-implementation-guide/index.html b/copilot-agent-strategy/agent-365-customer-implementation-guide/index.html index 37d8fc34..b519bddf 100644 --- a/copilot-agent-strategy/agent-365-customer-implementation-guide/index.html +++ b/copilot-agent-strategy/agent-365-customer-implementation-guide/index.html @@ -4122,8 +4122,8 @@

Threat protection (Microsoft Defender)

{ id: "purview-dlp", portal: "purview", action: "Configure", setting: "Scope DLP to Agent 365 instances and supported interactions", path: "Microsoft Purview \u2192 Data Loss Prevention \u2192 Policies", - role: "Compliance Administrator", applicability: "Agent 365 instances or groups whose Teams, OneDrive/SharePoint, or email interactions require DLP", - recommended: "Select the intended agent instances or groups; choose supported conditions, audit or block actions, and test/enforcement mode for agent-to-human and human-to-agent interactions. Treat a separate Microsoft 365 Copilot prompt sensitive-information-type block (Preview) as adjacent validation, not proof that an Agent 365 instance policy works.", + role: "Compliance Administrator", applicability: "Agent 365 instances (Entra agent user accounts) whose Teams, OneDrive/SharePoint, or email interactions require DLP", + recommended: "Purview has no separate Agent 365 instance picker: add the intended agents' Entra agent user accounts to a reviewed security group and include that group in each Exchange, Teams, and OneDrive location; scope SharePoint by site. Choose supported conditions, audit or block actions, and test/enforcement mode for agent-to-human and human-to-agent interactions. Treat a separate Microsoft 365 Copilot prompt sensitive-information-type block (Preview) as adjacent validation, not proof that an Agent 365 instance policy works.", proof: "A representative interaction with a targeted Agent 365 instance is audited or blocked exactly as the scoped policy specifies.", source: S.PURVIEW_DLP, simpleAnchor: "cfg-purview" }, { id: "purview-labels", portal: "purview", action: "Review", @@ -4541,12 +4541,14 @@

Threat protection (Microsoft Defender)

"Open the completed result and verify the expected activity, actor, workload, and timestamp." ] }, "purview-dlp": { steps: [ + "In Microsoft Entra, add the approved agents to a reviewed security group. Each Agent 365 instance is an Entra agent user account, so Purview has no separate Agent 365 instance picker.", "Open Microsoft Purview > Data Loss Prevention > Policies and create or edit the approved DLP policy.", "Select only supported Teams, Exchange, OneDrive, or SharePoint locations that store the intended agent-to-human or human-to-agent interactions.", - "Include the approved Agent 365 instances or a reviewed security group, then configure the required sensitive-information conditions and supported audit or block actions.", + "For each Exchange, Teams, or OneDrive location, select Edit and include that security group. Exchange accepts only groups; add an agent user account directly only where the picker offers accounts. Scope SharePoint by the sites the agents use.", + "Configure the required sensitive-information conditions and supported audit or block actions.", "Start in simulation mode, save the policy, and review Activity explorer results for a representative targeted-agent interaction.", "Tune false positives and obtain approval before turning on enforcement; repeat the targeted interaction to confirm the specified result." - ], caution: "DLP blocks can interrupt downstream agent workflows because the agent is unaware of the block.", recovery: "Return the policy to simulation or off, narrow the instance and location scope, and retest before enforcement." }, + ], caution: "DLP blocks can interrupt downstream agent workflows because the agent is unaware of the block.", recovery: "Return the policy to simulation or off, narrow the security group membership and location scope, and retest before enforcement." }, "purview-labels": { steps: [ "Open Microsoft Purview > Information Protection > Sensitivity labels and identify the approved label for agent-created output.", "Review the label's protection and content-marking settings and the policy that publishes it to the responsible users or workflow.", @@ -6636,7 +6638,7 @@
Rollback
  • Use intuitive names; avoid mixing Confidential, Restricted and Internal, which users struggle to tell apart.
  • Use labels to set SharePoint site and Teams privacy to Private by default and rely on company-shareable links — private sites with company-shareable links preserve collaboration while reducing unintended discovery in search and Copilot.
  • Note that encryption on labels can be implemented later — it does not have to be part of the first rollout. -
  • Ordering guidanceThe strategy progresses in this order: manual labelling → client-side auto-labeling with sensitive information types → service-side auto-labeling at rest. Do not start with auto-labeling.
    Validate
    Rollback

    Official Microsoft references

    4.18 · Grant agents VIEW and EXTRACT rights on encrypted labels

    Without both rights granted explicitly to the agent, encrypted content is never returned to it.

    Part A
    E5 + Agent 365Microsoft Purview portal

    Applies to: Copilot Studio agents · Microsoft Foundry agents · Microsoft 365 Copilot &amp; agents

    ✓ Completed
    Portal path

    Microsoft Purview portal → Information Protection → Labels → select an encrypting label → encryption settings.

    Role required

    Information Protection Admins

    Watch outThis is the step most often missed. A label configured for all users or any authenticated users does not grant an agent access.
    Steps
    1. Identify every sensitivity label with encryption that agents legitimately need to read.
    2. Open the label's encryption settings and review the assigned permissions.
    3. Add the agent instance, or a security group containing agent instances, granting both VIEW and EXTRACT usage rights.
    4. Do not rely on adding all users and groups in your organization, or any authenticated users — neither is sufficient for an agent instance.
    5. Republish the label policy and allow time for the change to propagate.
    6. Remember that files must also be explicitly shared with the agent for it to access them.
    Validate
    Rollback

    4.19 · Plan labelling for content agents create

    Agent-created content does not inherit labels from its source, so it is not automatically protected.

    Part A
    E5 + Agent 365Microsoft Purview portal

    Applies to: Copilot Studio agents · Microsoft Foundry agents · Microsoft 365 Copilot &amp; agents

    ✓ Completed
    Portal path

    Microsoft Purview portal → Information Protection → Auto-labeling policies.

    Role required

    Information Protection Admins

    Watch outAuto-labelling data held outside Microsoft 365 uses the data-at-rest consumption meter, which is billed separately.
    Steps
    1. Identify where content generated by your agents is stored.
    2. Assess the risk of that content sitting unlabelled and therefore unprotected.
    3. Where appropriate, configure auto-labelling for those locations so new content is classified on creation.
    4. Consider a default label on the library or container holding agent output.
    5. Record any residual gap on your risk register where auto-labelling cannot cover it.
    Validate
    Rollback

    4.20 · Restrict Microsoft 365 Copilot processing of labelled knowledge content

    Uses the Microsoft 365 Copilot and Copilot Chat DLP location to exclude supported labelled knowledge content; it is not blanket protection for Copilot Studio, Foundry, or every agent interaction.

    Part A
    E5 + Agent 365Microsoft Purview portal

    Applies to: Microsoft 365 Copilot and Copilot Chat

    ✓ Completed
    Portal path

    Microsoft Purview portal → Solutions → Data Loss Prevention → Policies → + Create policy.

    Role required

    DLP Compliance Management

    Coverage limitsTest in simulation before enforcing and allow up to four hours for policy changes. The rule does not inspect the contents of files uploaded directly into a prompt, and citations can remain visible even when labelled source content is excluded. Prompt blocking by sensitive information type is a separate Preview capability.
    Steps
    1. Go to Data Loss Prevention, select Policies, then + Create policy.
    2. Choose Enterprise applications and devices. Under Categories select Custom, and under Regulations select Custom, then Next.
    3. Give the policy a name — the description is optional.
    4. Under Locations, deselect everything except Microsoft 365 Copilot and Copilot Chat.
    5. Under Policy settings, choose Create or customize advanced DLP rules, then + Create rule.
    6. Name the rule. Under Conditions select + Add condition → Content contains → Sensitivity labels, then choose the label you want to protect — for example your Confidential label.
    7. Under Actions select + Add an action → Restrict Copilot from processing content, and tick the Accessing knowledge sources checkbox.
    8. Save the rule in simulation or test mode first, review results, and obtain approval before enforcement.
    9. Review and submit, then allow up to four hours for the change to take effect.
    Validate
    Rollback

    4.21 · Create a DLP policy to stop agents emailing sensitive data

    Blocks sensitive information leaving the organization through agent-sent email.

    Part A
    E5 + Agent 365Microsoft Purview portal

    Applies to: Copilot Studio agents · Microsoft Foundry agents · Microsoft 365 Copilot &amp; agents · Custom agents you build · Non-Microsoft cloud agents · Third-party AI apps

    ✓ Completed
    Portal path

    Microsoft Purview portal → Solutions → Data Loss Prevention → Policies → + Create policy.

    Role required

    DLP Compliance Management

    Watch outAn agent is not aware that it has been blocked in the way a person is. The policy owner must monitor matches and understand the impact on downstream workflows.
    Steps
    1. Create another policy and choose Enterprise applications and devices. Set Categories to Custom and Regulations to Custom, then Next.
    2. Name the policy. Leave Admin units as they are unless you scope by administrative unit.
    3. Under Locations, deselect everything and keep only Exchange email.
    4. Under Policy settings select + Create rule.
    5. Under Conditions select Add condition → Content contains → Sensitive info types, then add the types that matter to you — for example Credit Card Number and ABA Routing Number.
    6. Under Actions select + Add an action → Restrict access or encrypt the content in Microsoft 365 locations.
    7. Choose Block users from receiving email or accessing shared files, and set the scope — Block everyone, or block only people outside your organization.
    8. Explicitly add the agent instances, or a security group containing them, so the policy covers agents as well as people.
    9. Review the rule, then turn the policy on immediately or start in test mode.
    10. Assign a named owner responsible for monitoring the policy.
    Validate
    Rollback

    4.22 · Apply endpoint DLP for public AI websites

    Warns or blocks staff pasting or uploading sensitive information into public AI sites.

    Part A
    E5 + Agent 365Microsoft Purview portal

    Applies to: Public AI websites

    ✓ Completed
    Portal path

    Microsoft Purview portal → Data Loss Prevention → Policies → Create policy → Devices location.

    Role required

    DLP Compliance Management

    Steps
    1. Confirm devices are onboarded and the browser extension is deployed.
    2. Create a DLP policy with the Devices location selected.
    3. Configure the rule to detect sensitive information being pasted or uploaded to generative AI sites.
    4. Choose the action — warn with override is the usual starting point, moving to block once the impact is understood.
    5. Run in audit or test mode first and review the match volume.
    6. Move to enforcement once the false-positive rate is acceptable.
    Validate
    Rollback

    Detect and govern behavior

    The policies you must actively create to monitor and control how agents behave.

    4.23 · Create an Insider Risk policy using the Risky AI usage template

    Different from Risky Agents — this one covers how your people use AI tools and websites.

    Part A
    E5 + Agent 365Microsoft Purview portal

    Applies to: Public AI websites · Third-party AI apps

    ✓ Completed
    Portal path

    Microsoft Purview portal → Insider Risk Management → Policies → User policies → Create policy → Risky AI usage.

    Role required

    Insider Risk Management

    Watch outDo not confuse this with Risky Agents (preview). Risky AI usage scores how your people use AI tools; Risky Agents scores what your agents themselves do.
    Steps
    1. Deploy the required browser extension on user devices first — the Microsoft Insider risk extension on Microsoft Edge, or the Microsoft Purview extension on Chrome. The template does not function without it.
    2. Go to Policies and stay on the User policies tab — Risky AI usage is a user policy, not an agent policy. Create a new policy and select the Risky AI usage template.
    3. Scope the policy to the relevant users.
    4. Review what it detects: user browsing to generative AI websites, and user prompts and AI responses containing sensitive information in Microsoft 365 Copilot, Microsoft Copilot and agents.
    5. Optionally configure a Microsoft HR connector to detect departing users, and a Communication Compliance policy for wider detection coverage.
    6. Alternatively create it as a one-click policy from DSPM by acting on the recommendation Detect risky interactions in AI apps — the resulting policy is named DSPM for AI - Detect risky AI usage.
    Validate
    • The policy is active and scoped to the intended users.
    • The browser extension reports as deployed on pilot devices.
    • Detected activity contributes to user risk scoring in Adaptive Protection.
    Rollback
    • Stop the policy generating new alerts, or delete it.
    • Existing alerts and cases remain and should be closed normally.
    • Removing the browser extension stops the browsing signal but also affects other browser-based detections.

    4.24 · Create a Communication Compliance policy for AI agents

    Detects unethical or risky prompts and responses in agent interactions.

    Part A
    E5 + Agent 365 · PAYG for non-M365 AI dataMicrosoft Purview portal

    Applies to: Copilot Studio agents · Microsoft Foundry agents · Microsoft 365 Copilot &amp; agents · Custom agents you build · Non-Microsoft cloud agents · Third-party AI apps

    ✓ Completed
    Portal path

    Microsoft Purview portal → Solutions → Communication Compliance → Policies → + Create policy.

    Role required

    Communication Compliance

    Watch outPay-as-you-go billing is required to detect interactions in non-Microsoft 365 AI data — this explicitly includes Microsoft Copilot Studio, Copilot in Microsoft Fabric, Microsoft Security Copilot, and any connected or cloud AI application. Only Microsoft 365 Copilot data is exempt.
    Steps
    1. Confirm you hold one of the required roles — Communication Compliance, Communication Compliance Analysts, or Communication Compliance Investigators. To view and act on alerts you must also be named as a Reviewer in the policy associated with the alert.
    2. Go to Communication Compliance. If the solution card is not displayed, select View all solutions and choose Communication Compliance from the Core section.
    3. Select Policies, then + Create policy. To review an existing policy instead, select Detect unethical interactions for AI agents and choose View policy settings, then Edit.
    4. From the dropdown, select Detect unethical interactions for AI agents. This is the agent-specific template — do not pick Detect Microsoft Copilot interactions, which targets Copilot rather than agents.
    5. On the Agents and Reviewers step, select which agents you want to supervise — for example Copilot Studio and Azure Foundry — and who in the organization reviews the communications the policy returns.
    6. On the Conditions and percentage step, configure your conditions, choose whether to enable OCR to inspect text inside images, set the percentage of communications to monitor, and choose whether to filter out messages from email blasting services.
    7. Add the reviewers who will triage matches. You must be named in the Reviewers field to investigate items yourself.
    8. Select Create policy.
    9. Confirm matches arrive on the Policies page under the Pending tab, with separate entries for prompts and responses.
    Validate
    • The policy appears in the policy list as active.
    • Test content produces a match on the Pending tab — the Subject column shows [Copilot] for Microsoft Copilot interactions or [AI app] for other generative AI interactions.
    • Reviewers can open, tag, escalate and resolve a match end to end.
    • In-scope AI interactions appear in Communication Compliance reports and audit data.
    Rollback
    • Pause or delete the policy to stop new items being captured.
    • Items already in the review queue remain and should be resolved normally.
    • If the policy is too noisy, narrow the conditions or reduce the review percentage rather than deleting it.

    4.25 · Create a retention policy for AI prompts and responses

    Retains or deletes agent interaction data to meet legal and regulatory obligations.

    Part A
    E5 + Agent 365Microsoft Purview portal

    Applies to: Copilot Studio agents · Microsoft Foundry agents · Microsoft 365 Copilot &amp; agents · Custom agents you build · Non-Microsoft cloud agents · Third-party AI apps

    ✓ Completed
    Foundry retention needs a collection policy tooSelecting Enterprise AI apps retains Foundry interactions only once a collection policy is capturing the prompts and responses. Confirm capture is working before you rely on retention for a regulatory commitment.
    Portal path

    Microsoft Purview portal → Data Lifecycle Management → Retention policies → New retention policy.

    Role required

    Records Management / Retention Management

    Watch outRetention is the one control where an incorrect rollback can destroy evidence. Agree changes with your legal or compliance owner first.
    Steps
    1. Agree the retention period with your legal or compliance stakeholder before configuring anything.
    2. Create a retention policy covering AI prompts and responses.
    3. Select the location that matches the agent type: Microsoft Copilot Experiences for Copilot and Copilot Studio agent interactions; Enterprise AI apps for Microsoft Foundry and connected enterprise AI app interactions. Agent interactions in Microsoft 365 are also covered by the Teams, OneDrive and SharePoint, and Exchange email locations.
    4. Set whether content is retained, deleted, or retained then deleted after the agreed period.
    5. Review existing retention policies touching the same locations and confirm the combined outcome is what you expect.
    6. Save and confirm the policy reaches an active state.
    7. If you have older retention policies using the legacy Teams chats and Copilot interactions location, note they are not shown on the DSPM Policies page — create separate policies for Microsoft Copilot Experiences so coverage is visible and complete.
    Validate
    • The policy is active and shows the intended locations.
    • Retention behavior matches the agreed period on a test item.
    • Where policies overlap, the outcome follows the principles of retention — the longest retention wins.
    Rollback
    • Disable or delete the policy to stop it applying to new content.
    • Content already retained stays retained until the policy is fully removed and the period is reconciled — deletion is not instant.
    • Coordinate any rollback with legal, as reducing retention can have compliance consequences.

    Prove and operate

    Evidence, assurance, and keeping the configuration healthy over time.

    4.26 · Validate eDiscovery can retrieve agent interactions

    Proves you can meet a legal or regulatory request covering agent activity.

    Part A
    E5 + Agent 365Microsoft Purview portal

    Applies to: Copilot Studio agents · Microsoft Foundry agents · Microsoft 365 Copilot &amp; agents · Custom agents you build · Non-Microsoft cloud agents · Third-party AI apps

    ✓ Completed
    Foundry and third-party interactions must be collected firstFor Microsoft Foundry agents, enterprise AI apps and non-Microsoft cloud agents, prompts and responses only reach the mailbox once a collection policy is capturing them — for example DSPM for AI - Detect sensitive info shared with AI via network from the recommendation Extend insights into sensitive data in AI app interactions. Without that policy the eDiscovery search returns nothing for those agents, however correct the query is. Microsoft 365 Copilot and agents in Microsoft 365 need no collection policy.
    Portal path

    Microsoft Purview portal → eDiscovery → Cases.

    Role required

    eDiscovery Manager

    Steps
    1. Open the eDiscovery solution. If the card is not displayed, select View all solutions and choose eDiscovery from the Core section.
    2. Go to Cases → Create case, enter the case name and search name, then select Create.
    3. Add the relevant mailbox as a data source — prompts and responses for AI apps are stored in a user’s mailbox. Identify an agent instance as you would a user.
    4. Use the query that matches the agent type — this is not one size fits all:
      • Agent 365 / Microsoft 365 Copilot &amp; agents — query builder Add condition → Type → Contains any of → Edit → Copilot activity, which includes all Copilot and other AI application activity.
      • Copilot Studio agents — search the ItemClass property for IPM.SkypeTeams.Message.Copilot.Studio.*.
      • Microsoft Foundry agents — search the ItemClass property for IPM.SkypeTeams.Message.ConnectedAIApp.AzureAI.&lt;AzureResourceName&gt;.
    5. Run the search and review the hit count.
    6. Once the search is refined, export the results or add them to a review set — you can review and export information directly from the review set.
    7. Confirm your team knows how to place a hold when a real matter arises.
    Validate
    • The search returns agent interaction items.
    • Items open correctly inside the review set.
    • An export completes successfully.
    • Remember eDiscovery for agents supports agent-to-human and human-to-agent interactions — it does not capture agent-to-agent or agent-to-tools activity, which is visible in Audit only.
    Rollback
    • Close and delete the test case once validation is complete.
    • Never delete a case associated with a live legal matter.
    • Release any test hold so content is not retained unnecessarily.
    Interaction scopeeDiscovery for agents covers agent-to-human and human-to-agent interactions only. Agent-to-agent and agent-to-tools activity is visible in Audit, not eDiscovery.

    4.27 · Review the AI regulations assessment in Compliance Manager

    Turns the configuration you have built into reportable compliance evidence.

    Part A
    On by default — verifyMicrosoft Purview portal

    Applies to: Copilot Studio agents · Microsoft Foundry agents · Microsoft 365 Copilot &amp; agents

    ✓ Completed
    Portal path

    Microsoft Purview portal → Compliance Manager → Assessments.

    Role required

    Compliance Manager Administrators

    Steps
    1. Open Compliance Manager and find the assessments for AI regulations that agents are automatically included in.
    2. Review the improvement actions relevant to the controls in this checklist.
    3. Map completed steps to their corresponding improvement actions.
    4. Note any actions still open and agree an owner and target date.
    5. Export or record the assessment as a baseline.
    Validate
    • The AI regulation assessment is visible and scored.
    • Improvement actions reflect the controls you configured.
    • You have a dated baseline to re-measure against.
    Rollback
    • No rollback — this is assessment and reporting only.

    4.28 · Assign policy owners and agree a review cadence

    Without named owners and a routine, these policies quietly decay.

    Part A
    E5 + Agent 365Microsoft Purview portal

    Applies to: Copilot Studio agents · Microsoft Foundry agents · Microsoft 365 Copilot &amp; agents · Custom agents you build · Non-Microsoft cloud agents · Third-party AI apps · Public AI websites

    ✓ Completed
    Portal path

    An agreed operating model, documented and owned internally.

    Role required

    Compliance Administrator

    Steps
    1. List every policy created during this work.
    2. Assign a named owner to each, especially DLP policies where the agent cannot report a block.
    3. Agree how often alerts and matches are reviewed, and by whom.
    4. Agree who reviews DSPM AI observability and how often, so new agents are noticed as they appear.
    5. Document the escalation path for a suspected agent data incident.
    6. Record which policies remain in audit or test mode and when they will be reassessed for enforcement.
    Validate
    • Every policy has a named owner recorded.
    • A review cadence is agreed and documented.
    • Your team can say who acts on an agent-related alert.
    Rollback
    • No technical rollback — this is an operating agreement.
    • If ownership changes, update the record so no policy is left unowned.

    Official Microsoft references

    Role: Compliance AdministratorMicrosoft Purview portalMicrosoft 365 E5 + Agent 365Some tasks need pay-as-you-go
    Quick wins · PurviewConfirm auditing and DSPM AI observability are already flowing before you build any policy on top of them, then run a data risk assessment so you fix oversharing before an agent surfaces it.

    05. SharePoint — controlling agent-caused oversharing

    The #1 SharePoint risk with agents is oversharing. SharePoint provides visibility, discoverability controls, and Restricted site access control (RAC) as an additional authorization gate. RCD/RSS limit discovery; RAC limits access. The durable fix remains right-sizing permissions.

    5a · Agent access insights — see what agents ground on

    5 configuration steps with portal paths, required roles and official references.

    Part A
    ✓ Completed

    5a · Agent access insights — see who’s grounding on what

    WhereSharePoint admin center → Reports → Agent insights → Agent access
    1. Review which agents (SharePoint agents, declarative/Copilot agents, custom agents) are accessing which SharePoint and OneDrive sites — your starting map for oversharing exposure. +
    Ordering guidanceThe strategy progresses in this order: manual labelling → client-side auto-labeling with sensitive information types → service-side auto-labeling at rest. Do not start with auto-labeling.
    Validate
    • A labelled Office file in SharePoint displays its label correctly.
    • Encrypted labelled files are processed by the service rather than skipped.
    Rollback
    • Disabling label support reverts processing to data-in-use only in Office apps on Windows, reducing protection coverage — avoid unless necessary.

    4.18 · Grant agents VIEW and EXTRACT rights on encrypted labels

    Without both rights granted explicitly to the agent, encrypted content is never returned to it.

    Part A
    E5 + Agent 365Microsoft Purview portal

    Applies to: Copilot Studio agents · Microsoft Foundry agents · Microsoft 365 Copilot &amp; agents

    ✓ Completed
    Portal path

    Microsoft Purview portal → Information Protection → Labels → select an encrypting label → encryption settings.

    Role required

    Information Protection Admins

    Watch outThis is the step most often missed. A label configured for all users or any authenticated users does not grant an agent access.
    Steps
    1. Identify every sensitivity label with encryption that agents legitimately need to read.
    2. Open the label's encryption settings and review the assigned permissions.
    3. Add the agent instance, or a security group containing agent instances, granting both VIEW and EXTRACT usage rights.
    4. Do not rely on adding all users and groups in your organization, or any authenticated users — neither is sufficient for an agent instance.
    5. Republish the label policy and allow time for the change to propagate.
    6. Remember that files must also be explicitly shared with the agent for it to access them.
    Validate
    • Ask the agent for content protected by that label and confirm it can now return or summarise it.
    • An agent without those rights still cannot access the content, confirming least privilege holds.
    • No label has been opened more broadly than intended.
    Rollback
    • Remove the agent instance from the label's encryption permissions and republish.
    • The agent loses access to newly opened content protected by that label.
    • Keep a record of which labels were changed so the original permissions can be restored exactly.

    4.19 · Plan labelling for content agents create

    Agent-created content does not inherit labels from its source, so it is not automatically protected.

    Part A
    E5 + Agent 365Microsoft Purview portal

    Applies to: Copilot Studio agents · Microsoft Foundry agents · Microsoft 365 Copilot &amp; agents

    ✓ Completed
    Portal path

    Microsoft Purview portal → Information Protection → Auto-labeling policies.

    Role required

    Information Protection Admins

    Watch outAuto-labelling data held outside Microsoft 365 uses the data-at-rest consumption meter, which is billed separately.
    Steps
    1. Identify where content generated by your agents is stored.
    2. Assess the risk of that content sitting unlabelled and therefore unprotected.
    3. Where appropriate, configure auto-labelling for those locations so new content is classified on creation.
    4. Consider a default label on the library or container holding agent output.
    5. Record any residual gap on your risk register where auto-labelling cannot cover it.
    Validate
    • Content created through an agent receives the intended label from your auto-labelling rule.
    • No sensitive agent output is left unlabelled in the target location.
    Rollback
    • Return the auto-labelling policy to simulation mode, or delete it.
    • Labels already applied remain and must be removed separately if that is intended.

    4.20 · Restrict Microsoft 365 Copilot processing of labelled knowledge content

    Uses the Microsoft 365 Copilot and Copilot Chat DLP location to exclude supported labelled knowledge content; it is not blanket protection for Copilot Studio, Foundry, or every agent interaction.

    Part A
    E5 + Agent 365Microsoft Purview portal

    Applies to: Microsoft 365 Copilot and Copilot Chat

    ✓ Completed
    Portal path

    Microsoft Purview portal → Solutions → Data Loss Prevention → Policies → + Create policy.

    Role required

    DLP Compliance Management

    Coverage limitsTest in simulation before enforcing and allow up to four hours for policy changes. The rule does not inspect the contents of files uploaded directly into a prompt, and citations can remain visible even when labelled source content is excluded. Prompt blocking by sensitive information type is a separate Preview capability.
    Steps
    1. Go to Data Loss Prevention, select Policies, then + Create policy.
    2. Choose Enterprise applications and devices. Under Categories select Custom, and under Regulations select Custom, then Next.
    3. Give the policy a name — the description is optional.
    4. Under Locations, deselect everything except Microsoft 365 Copilot and Copilot Chat.
    5. Under Policy settings, choose Create or customize advanced DLP rules, then + Create rule.
    6. Name the rule. Under Conditions select + Add condition → Content contains → Sensitivity labels, then choose the label you want to protect — for example your Confidential label.
    7. Under Actions select + Add an action → Restrict Copilot from processing content, and tick the Accessing knowledge sources checkbox.
    8. Save the rule in simulation or test mode first, review results, and obtain approval before enforcement.
    9. Review and submit, then allow up to four hours for the change to take effect.
    Validate
    • The policy appears in the policy list with the intended simulation or enforcement state.
    • Ask Microsoft 365 Copilot or Copilot Chat for supported knowledge content carrying that label and confirm the protected content is excluded; a citation can still remain visible.
    • Content without the label is still returned normally, confirming the rule is correctly scoped.
    • Record that direct prompt file uploads are outside this rule's content-inspection coverage.
    Rollback
    • Set the policy to test mode or turn it off, then allow for documented propagation time.
    • If Copilot lost access to material it legitimately needs, disable the rule first, confirm the workflow recovers, then narrow the label condition.
    • Keep the policy in test mode while re-tuning rather than deleting it.

    4.21 · Create a DLP policy to stop agents emailing sensitive data

    Blocks sensitive information leaving the organization through agent-sent email.

    Part A
    E5 + Agent 365Microsoft Purview portal

    Applies to: Copilot Studio agents · Microsoft Foundry agents · Microsoft 365 Copilot &amp; agents · Custom agents you build · Non-Microsoft cloud agents · Third-party AI apps

    ✓ Completed
    Portal path

    Microsoft Purview portal → Solutions → Data Loss Prevention → Policies → + Create policy.

    Role required

    DLP Compliance Management

    Watch outAn agent is not aware that it has been blocked in the way a person is. The policy owner must monitor matches and understand the impact on downstream workflows.
    Steps
    1. Create another policy and choose Enterprise applications and devices. Set Categories to Custom and Regulations to Custom, then Next.
    2. Name the policy. Leave Admin units as they are unless you scope by administrative unit.
    3. Under Locations, deselect everything and keep only Exchange email. Select Edit next to it and include a security group that contains the agents' Entra agent user accounts, plus any groups of people the policy should also cover. Exchange scoping accepts groups, not individual accounts, and Purview has no separate Agent 365 instance picker.
    4. Under Policy settings select + Create rule.
    5. Under Conditions select Add condition → Content contains → Sensitive info types, then add the types that matter to you — for example Credit Card Number and ABA Routing Number.
    6. Under Actions select + Add an action → Restrict access or encrypt the content in Microsoft 365 locations.
    7. Choose Block users from receiving email or accessing shared files, and set the scope — Block everyone, or block only people outside your organization.
    8. Review the rule, then turn the policy on immediately or start in test mode.
    9. Assign a named owner responsible for monitoring the policy.
    Validate
    • The policy is active with Exchange email as the only location.
    • A test message containing non-production sensitive data is blocked as expected.
    • DLP rule match events appear in activity explorer for agent activity.
    • The agent receives an email-not-delivered response when blocked, and the owner can see the reason in the policy match.
    Rollback
    • Set the policy back to test mode, or turn it off.
    • If a block disrupted a legitimate agent workflow, disable the rule first, confirm recovery, then redesign the condition.
    • Consider blocking only external recipients rather than everyone if internal workflows are affected.

    4.22 · Apply endpoint DLP for public AI websites

    Warns or blocks staff pasting or uploading sensitive information into public AI sites.

    Part A
    E5 + Agent 365Microsoft Purview portal

    Applies to: Public AI websites

    ✓ Completed
    Portal path

    Microsoft Purview portal → Data Loss Prevention → Policies → Create policy → Devices location.

    Role required

    DLP Compliance Management

    Steps
    1. Confirm devices are onboarded and the browser extension is deployed.
    2. Create a DLP policy with the Devices location selected.
    3. Configure the rule to detect sensitive information being pasted or uploaded to generative AI sites.
    4. Choose the action — warn with override is the usual starting point, moving to block once the impact is understood.
    5. Run in audit or test mode first and review the match volume.
    6. Move to enforcement once the false-positive rate is acceptable.
    Validate
    • A test paste of non-production sensitive data produces the expected warning or block.
    • Events appear in activity explorer showing the site and the sensitive information type.
    • Users receive the intended notification text.
    Rollback
    • Switch the policy to audit mode to remove user impact immediately while keeping visibility.
    • Turn the policy off if it disrupts legitimate work, then re-tune the conditions.
    • Because this affects staff directly, communicate any enforcement change in advance.

    Detect and govern behavior

    The policies you must actively create to monitor and control how agents behave.

    4.23 · Create an Insider Risk policy using the Risky AI usage template

    Different from Risky Agents — this one covers how your people use AI tools and websites.

    Part A
    E5 + Agent 365Microsoft Purview portal

    Applies to: Public AI websites · Third-party AI apps

    ✓ Completed
    Portal path

    Microsoft Purview portal → Insider Risk Management → Policies → User policies → Create policy → Risky AI usage.

    Role required

    Insider Risk Management

    Watch outDo not confuse this with Risky Agents (preview). Risky AI usage scores how your people use AI tools; Risky Agents scores what your agents themselves do.
    Steps
    1. Deploy the required browser extension on user devices first — the Microsoft Insider risk extension on Microsoft Edge, or the Microsoft Purview extension on Chrome. The template does not function without it.
    2. Go to Policies and stay on the User policies tab — Risky AI usage is a user policy, not an agent policy. Create a new policy and select the Risky AI usage template.
    3. Scope the policy to the relevant users.
    4. Review what it detects: user browsing to generative AI websites, and user prompts and AI responses containing sensitive information in Microsoft 365 Copilot, Microsoft Copilot and agents.
    5. Optionally configure a Microsoft HR connector to detect departing users, and a Communication Compliance policy for wider detection coverage.
    6. Alternatively create it as a one-click policy from DSPM by acting on the recommendation Detect risky interactions in AI apps — the resulting policy is named DSPM for AI - Detect risky AI usage.
    Validate
    • The policy is active and scoped to the intended users.
    • The browser extension reports as deployed on pilot devices.
    • Detected activity contributes to user risk scoring in Adaptive Protection.
    Rollback
    • Stop the policy generating new alerts, or delete it.
    • Existing alerts and cases remain and should be closed normally.
    • Removing the browser extension stops the browsing signal but also affects other browser-based detections.

    4.24 · Create a Communication Compliance policy for AI agents

    Detects unethical or risky prompts and responses in agent interactions.

    Part A
    E5 + Agent 365 · PAYG for non-M365 AI dataMicrosoft Purview portal

    Applies to: Copilot Studio agents · Microsoft Foundry agents · Microsoft 365 Copilot &amp; agents · Custom agents you build · Non-Microsoft cloud agents · Third-party AI apps

    ✓ Completed
    Portal path

    Microsoft Purview portal → Solutions → Communication Compliance → Policies → + Create policy.

    Role required

    Communication Compliance

    Watch outPay-as-you-go billing is required to detect interactions in non-Microsoft 365 AI data — this explicitly includes Microsoft Copilot Studio, Copilot in Microsoft Fabric, Microsoft Security Copilot, and any connected or cloud AI application. Only Microsoft 365 Copilot data is exempt.
    Steps
    1. Confirm you hold one of the required roles — Communication Compliance, Communication Compliance Analysts, or Communication Compliance Investigators. To view and act on alerts you must also be named as a Reviewer in the policy associated with the alert.
    2. Go to Communication Compliance. If the solution card is not displayed, select View all solutions and choose Communication Compliance from the Core section.
    3. Select Policies, then + Create policy. To review an existing policy instead, select Detect unethical interactions for AI agents and choose View policy settings, then Edit.
    4. From the dropdown, select Detect unethical interactions for AI agents. This is the agent-specific template — do not pick Detect Microsoft Copilot interactions, which targets Copilot rather than agents.
    5. On the Agents and Reviewers step, select which agents you want to supervise — for example Copilot Studio and Azure Foundry — and who in the organization reviews the communications the policy returns.
    6. On the Conditions and percentage step, configure your conditions, choose whether to enable OCR to inspect text inside images, set the percentage of communications to monitor, and choose whether to filter out messages from email blasting services.
    7. Add the reviewers who will triage matches. You must be named in the Reviewers field to investigate items yourself.
    8. Select Create policy.
    9. Confirm matches arrive on the Policies page under the Pending tab, with separate entries for prompts and responses.
    Validate
    • The policy appears in the policy list as active.
    • Test content produces a match on the Pending tab — the Subject column shows [Copilot] for Microsoft Copilot interactions or [AI app] for other generative AI interactions.
    • Reviewers can open, tag, escalate and resolve a match end to end.
    • In-scope AI interactions appear in Communication Compliance reports and audit data.
    Rollback
    • Pause or delete the policy to stop new items being captured.
    • Items already in the review queue remain and should be resolved normally.
    • If the policy is too noisy, narrow the conditions or reduce the review percentage rather than deleting it.

    4.25 · Create a retention policy for AI prompts and responses

    Retains or deletes agent interaction data to meet legal and regulatory obligations.

    Part A
    E5 + Agent 365Microsoft Purview portal

    Applies to: Copilot Studio agents · Microsoft Foundry agents · Microsoft 365 Copilot &amp; agents · Custom agents you build · Non-Microsoft cloud agents · Third-party AI apps

    ✓ Completed
    Foundry retention needs a collection policy tooSelecting Enterprise AI apps retains Foundry interactions only once a collection policy is capturing the prompts and responses. Confirm capture is working before you rely on retention for a regulatory commitment.
    Portal path

    Microsoft Purview portal → Data Lifecycle Management → Retention policies → New retention policy.

    Role required

    Records Management / Retention Management

    Watch outRetention is the one control where an incorrect rollback can destroy evidence. Agree changes with your legal or compliance owner first.
    Steps
    1. Agree the retention period with your legal or compliance stakeholder before configuring anything.
    2. Create a retention policy covering AI prompts and responses.
    3. Select the location that matches the agent type: Microsoft Copilot Experiences for Copilot and Copilot Studio agent interactions; Enterprise AI apps for Microsoft Foundry and connected enterprise AI app interactions. Agent interactions in Microsoft 365 are also covered by the Teams, OneDrive and SharePoint, and Exchange email locations.
    4. Set whether content is retained, deleted, or retained then deleted after the agreed period.
    5. Review existing retention policies touching the same locations and confirm the combined outcome is what you expect.
    6. Save and confirm the policy reaches an active state.
    7. If you have older retention policies using the legacy Teams chats and Copilot interactions location, note they are not shown on the DSPM Policies page — create separate policies for Microsoft Copilot Experiences so coverage is visible and complete.
    Validate
    • The policy is active and shows the intended locations.
    • Retention behavior matches the agreed period on a test item.
    • Where policies overlap, the outcome follows the principles of retention — the longest retention wins.
    Rollback
    • Disable or delete the policy to stop it applying to new content.
    • Content already retained stays retained until the policy is fully removed and the period is reconciled — deletion is not instant.
    • Coordinate any rollback with legal, as reducing retention can have compliance consequences.

    Prove and operate

    Evidence, assurance, and keeping the configuration healthy over time.

    4.26 · Validate eDiscovery can retrieve agent interactions

    Proves you can meet a legal or regulatory request covering agent activity.

    Part A
    E5 + Agent 365Microsoft Purview portal

    Applies to: Copilot Studio agents · Microsoft Foundry agents · Microsoft 365 Copilot &amp; agents · Custom agents you build · Non-Microsoft cloud agents · Third-party AI apps

    ✓ Completed
    Foundry and third-party interactions must be collected firstFor Microsoft Foundry agents, enterprise AI apps and non-Microsoft cloud agents, prompts and responses only reach the mailbox once a collection policy is capturing them — for example DSPM for AI - Detect sensitive info shared with AI via network from the recommendation Extend insights into sensitive data in AI app interactions. Without that policy the eDiscovery search returns nothing for those agents, however correct the query is. Microsoft 365 Copilot and agents in Microsoft 365 need no collection policy.
    Portal path

    Microsoft Purview portal → eDiscovery → Cases.

    Role required

    eDiscovery Manager

    Steps
    1. Open the eDiscovery solution. If the card is not displayed, select View all solutions and choose eDiscovery from the Core section.
    2. Go to Cases → Create case, enter the case name and search name, then select Create.
    3. Add the relevant mailbox as a data source — prompts and responses for AI apps are stored in a user’s mailbox. Identify an agent instance as you would a user.
    4. Use the query that matches the agent type — this is not one size fits all:
      • Agent 365 / Microsoft 365 Copilot &amp; agents — query builder Add condition → Type → Contains any of → Edit → Copilot activity, which includes all Copilot and other AI application activity.
      • Copilot Studio agents — search the ItemClass property for IPM.SkypeTeams.Message.Copilot.Studio.*.
      • Microsoft Foundry agents — search the ItemClass property for IPM.SkypeTeams.Message.ConnectedAIApp.AzureAI.&lt;AzureResourceName&gt;.
    5. Run the search and review the hit count.
    6. Once the search is refined, export the results or add them to a review set — you can review and export information directly from the review set.
    7. Confirm your team knows how to place a hold when a real matter arises.
    Validate
    • The search returns agent interaction items.
    • Items open correctly inside the review set.
    • An export completes successfully.
    • Remember eDiscovery for agents supports agent-to-human and human-to-agent interactions — it does not capture agent-to-agent or agent-to-tools activity, which is visible in Audit only.
    Rollback
    • Close and delete the test case once validation is complete.
    • Never delete a case associated with a live legal matter.
    • Release any test hold so content is not retained unnecessarily.
    Interaction scopeeDiscovery for agents covers agent-to-human and human-to-agent interactions only. Agent-to-agent and agent-to-tools activity is visible in Audit, not eDiscovery.

    4.27 · Review the AI regulations assessment in Compliance Manager

    Turns the configuration you have built into reportable compliance evidence.

    Part A
    On by default — verifyMicrosoft Purview portal

    Applies to: Copilot Studio agents · Microsoft Foundry agents · Microsoft 365 Copilot &amp; agents

    ✓ Completed
    Portal path

    Microsoft Purview portal → Compliance Manager → Assessments.

    Role required

    Compliance Manager Administrators

    Steps
    1. Open Compliance Manager and find the assessments for AI regulations that agents are automatically included in.
    2. Review the improvement actions relevant to the controls in this checklist.
    3. Map completed steps to their corresponding improvement actions.
    4. Note any actions still open and agree an owner and target date.
    5. Export or record the assessment as a baseline.
    Validate
    • The AI regulation assessment is visible and scored.
    • Improvement actions reflect the controls you configured.
    • You have a dated baseline to re-measure against.
    Rollback
    • No rollback — this is assessment and reporting only.

    4.28 · Assign policy owners and agree a review cadence

    Without named owners and a routine, these policies quietly decay.

    Part A
    E5 + Agent 365Microsoft Purview portal

    Applies to: Copilot Studio agents · Microsoft Foundry agents · Microsoft 365 Copilot &amp; agents · Custom agents you build · Non-Microsoft cloud agents · Third-party AI apps · Public AI websites

    ✓ Completed
    Portal path

    An agreed operating model, documented and owned internally.

    Role required

    Compliance Administrator

    Steps
    1. List every policy created during this work.
    2. Assign a named owner to each, especially DLP policies where the agent cannot report a block.
    3. Agree how often alerts and matches are reviewed, and by whom.
    4. Agree who reviews DSPM AI observability and how often, so new agents are noticed as they appear.
    5. Document the escalation path for a suspected agent data incident.
    6. Record which policies remain in audit or test mode and when they will be reassessed for enforcement.
    Validate
    • Every policy has a named owner recorded.
    • A review cadence is agreed and documented.
    • Your team can say who acts on an agent-related alert.
    Rollback
    • No technical rollback — this is an operating agreement.
    • If ownership changes, update the record so no policy is left unowned.

    Official Microsoft references

    Role: Compliance AdministratorMicrosoft Purview portalMicrosoft 365 E5 + Agent 365Some tasks need pay-as-you-go
    Quick wins · PurviewConfirm auditing and DSPM AI observability are already flowing before you build any policy on top of them, then run a data risk assessment so you fix oversharing before an agent surfaces it.

    05. SharePoint — controlling agent-caused oversharing

    The #1 SharePoint risk with agents is oversharing. SharePoint provides visibility, discoverability controls, and Restricted site access control (RAC) as an additional authorization gate. RCD/RSS limit discovery; RAC limits access. The durable fix remains right-sizing permissions.

    5a · Agent access insights — see what agents ground on

    5 configuration steps with portal paths, required roles and official references.

    Part A
    ✓ Completed

    5a · Agent access insights — see who’s grounding on what

    WhereSharePoint admin center → Reports → Agent insights → Agent access
    1. Review which agents (SharePoint agents, declarative/Copilot agents, custom agents) are accessing which SharePoint and OneDrive sites — your starting map for oversharing exposure.
    2. Backed by the unified audit log; requires the SharePoint Administrator role + SharePoint Advanced Management or Microsoft 365 Copilot entitlement; data retained ~28 days.
    3. Operational timing: reports cover 1, 7, 14, or 28 days; large tenants can take up to 48 hours for data to become available; you can run a report only after 24 hours pass since the last report for that range; if no reports are generated for roughly three months, data collection can pause.
    4. Portal display is limited to the top 100 sites and top 20 agents for a selected site; downloaded reports can contain up to one million sites. Unified-audit data might not contain every event.