Microsoft 365How-To & HardeningRetrospectives

How to Reduce Copilot Prompt-Injection Exposure With Labels and DLP

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from June 2025, written in 2026 with the benefit of hindsight.

Prompt injection can manipulate AI assistants into exposing data they can access. You can't fully prevent it, but you can limit what Copilot can reach and leak. Here is how, using controls you likely already have.

Principle: reduce the blast radius

If Copilot can't access sensitive content, a manipulated Copilot can't leak it.

Step 1: Fix oversharing

Use SharePoint Advanced Management data access governance reports and site access reviews to remove broad access. Apply Restricted Content Discovery to sensitive sites.

Step 2: Label sensitive content

Publish sensitivity labels and use default and auto-labeling so confidential content is consistently labeled. Labels with encryption restrict which users (and therefore which Copilot sessions) can use the content.

Step 3: Use DLP for Microsoft 365 Copilot

In Microsoft Purview, create a DLP policy with the Microsoft 365 Copilot location:

  • Exclude content with Highly Confidential labels from Copilot processing.
  • Where available, block Copilot from responding to prompts containing specific sensitive information types.

Step 4: Reduce untrusted inputs where possible

  • Strengthen email filtering so malicious external messages are quarantined before they reach mailboxes.
  • Consider limiting which external content sources and web grounding Copilot can use for sensitive user groups.

Step 5: Govern agents and plugins

Review Copilot agents, connectors and plugins in the Microsoft 365 admin center. Each one adds data sources and actions.

Step 6: Monitor AI interactions

Use Purview DSPM for AI and audit logs to review Copilot interactions involving sensitive data.

Step 7: Track advisories

Subscribe to Microsoft Security Response Center updates and include AI CVEs in your vulnerability management process, even when fixes are server-side.

copilot dlp policyEchoLeak2025

More on this story