|

Sensitivity labels and Copilot: which ones actually keep content out

The user opens the document protected with a sensitivity label and reads the content smoothly and then asks Copilot to provide a summary of the document. Copilot denies the request by providing a link to the exact same document which was open all along. Therefore, they create a support ticket stating that Copilot does not work. Copilot works perfectly but there is one thing which it does correctly which most people are unaware of.

The way MS365 Copilot works in the presence of sensitivity labels depends on one right usage of which you are probably unaware of and it goes by EXTRACT.

VIEW lets you read. EXTRACT lets Copilot summarise.

When the sensitivity label encrypts the data, it gives an individual a set of usage rights. There are two of those, and they are relevant in this case. VIEW means the right to view the file and its content, while EXTRACT (“Copy and extract content,” “Copy”) is the right to extract the text from it.

Copilot requires EXTRACT. Not VIEW, but EXTRACT. As per the Microsoft’s description, when the content provides the user with the VIEW and not EXTRACT, Copilot does not create the summary and can only provide it through the link.

That was the case in that particular ticket. The user had VIEW and not EXTRACT for that file. He was perfectly able to read the file himself as much as he wanted. Copilot, as an extraction-based tool, was simply not allowed to do that. One file, one user, different results, but both are correct.

There is one special case that should be mentioned. When someone creates the encryption, the user automatically has EXTRACT rights to the file, as they own it. That is why any self-protected file will always be available to Copilot.

So here is the switch

Reverse that and you get the tightest control possible. To create a set of documents truly out of Copilot’s reach, apply a sensitivity label that uses encryption and does not include the Copy (EXTRACT) permission. It is still readable by those who require it. Copilot cannot summarize, quote, or move that text into any of its outputs. You are not denying anyone access, but rather you are denying access to the system.

The higher levels take it a step further. Documents with custom permissions applied to them are completely inaccessible to Copilot and other agents when locked down in SharePoint or OneDrive. Even the Double Key Encryption, which was designed for top-secret data, cannot be accessed by Copilot.

Now the trap

This is where the illusion of security starts. You give the Confidential designation to the site, think that the content inside becomes invisible to Copilot, and go your way. It doesn’t. The label assigned to a container, to a SharePoint site or to a Microsoft 365 group, is not passed down to files in that container. Copilot does not care about the Confidential designation of the site that the document is on, nor does the document itself have any protection. For Copilot, it’s like there is no such label.

If you need to protect the files, assign the label to the files. The site label is for the site only.

What Copilot writes carries the label forward

But there is a happy side to it as well. In case Copilot generates new content using tagged source material, the content will carry the most important tag from the set of those that have been used for tagging the source material. So if Confidential is the most sensitive tag out of three, the resulting summary will be Confidential as well.

How to check one file in ten seconds

When there is any confusion about the readability of the file, which is openable, open it in the Windows Office application, and put Permissions on the status bar. Then click on the icon beside the label name and see your permission under My Permission. When the value of Copy is YES, it means that Copilot can use the file. Otherwise, it cannot use the file.

The one thing labels do not do

The labels will determine what Copilot will be permitted to do with the files. However, labels cannot determine who can open the files. A document with Everyone label remains a document with Everyone label, but the label prevents Copilot from summarizing the document for Everyone. Therefore, a label can be used as a lever, and it is not a replacement for securing access first. In case there is a need to prevent Copilot from summarizing some labeled files while maintaining their encryption, a Purview DLP policy for Copilot location is a solution, but the EXTRACT right is a concept that covers all other concepts.

It is your problem with the access, and if that is what you are facing, I have developed a free utility for this problem User Access Explorer.

Related posts

Similar Posts

One Comment

Comments are closed.