Microsoft Purview

Sensitivity labels and Copilot: which ones actually keep content out

A user opens a protected document, reads it without any trouble, and then asks Copilot to summarise it. Copilot refuses. It just hands back a link to the very file they already have open. So they raise a ticket saying Copilot is broken. It is not broken. It is doing one thing right that almost nobody knows about.

How Microsoft 365 Copilot behaves around sensitivity labels comes down to a single usage right you have probably never looked at, called EXTRACT. Once that one idea lands, the rest of it stops being confusing.

VIEW lets you read. EXTRACT lets Copilot summarise.

When a sensitivity label applies encryption, it grants each person a set of usage rights. Two of them matter here. VIEW is the right to open the file and read it. EXTRACT, which shows up in the Purview portal as “Copy and extract content” and carries the friendly name Copy, is the right to copy text out of it.

Copilot needs EXTRACT. Not VIEW, EXTRACT. In Microsoft’s own words, if the content grants a user VIEW but not EXTRACT, Copilot will not summarise it and can only point to it with a link.

So the user in that ticket had VIEW and not EXTRACT. They could read the file with their own eyes all day. Copilot, which works by pulling the text out, was never allowed to. Same file, same person, two different answers, and both are correct.

One exception is worth knowing: whoever applied the encryption always has EXTRACT, because they own it. So a file you protected yourself will always come back to you in Copilot. The restriction is for everybody else.

So here is the switch

Turn that around and you have the cleanest control you will find. If you want a class of content genuinely out of Copilot’s reach, use a sensitivity label that applies encryption without the Copy (EXTRACT) right. People who need to can still open and read. Copilot cannot summarise it, quote it, or carry the text into anything it generates. You have not taken access away from anyone, you have taken it away from the machine.

The stronger settings go further. Content labelled with user-defined permissions is off-limits to Copilot and agents entirely while it sits unopened in SharePoint or OneDrive. And Double Key Encryption, the one meant for your most sensitive material, Copilot cannot touch at all.

Now the trap

Here is where people get a false sense of safety. You put a Confidential label on the site, assume everything inside it is now hidden from Copilot, and move on. It is not. A label applied to a container, a SharePoint site or a Microsoft 365 group, is not inherited by the files inside it. Copilot does not see the site’s Confidential label on the document, and the document carries no protection of its own. As far as Copilot is concerned, the label on the site does nothing at all for the files.

If you want the files protected, the label has to be on the files. The site label is for the site.

What Copilot writes carries the label forward

There is a nice half to this. When Copilot builds new content out of labelled sources, it inherits the highest-priority label among them. Summarise three documents where the most sensitive is Confidential, and the summary itself comes out Confidential. The protection follows the content into whatever Copilot produces, which is exactly the behaviour you would want.

How to check one file in ten seconds

If you are ever not sure whether a document you can open is also readable by Copilot, open it in the Windows Office app and add Permissions to the status bar. Click the icon next to the label name, look at My Permission, and read the value for Copy. Yes means EXTRACT, which means Copilot can use it. No means it cannot.

The one thing labels do not do

Labels decide what Copilot is allowed to do with a file. They do not decide who can open it. A document shared with Everyone is still shared with Everyone; the label only stops Copilot from summarising it for them. So a label is a good lever, and it is not a substitute for fixing who has access in the first place. If you also want to block Copilot from summarising specific labelled files without touching their encryption, a Purview DLP policy for the Copilot location can do that, but the EXTRACT right is the idea that explains everything else.

The access question is still yours to sort out. If that is where you are stuck, I wrote a free tool for it: User Access Explorer.