Microsoft 365 Copilot DLP – Inconsistent Enforcement Between PII, Financial and Technical SITs

Kiersten Robinson 0 Reputation points
2026-10-09T12:16:00.28+00:00

Hi everyone,

I'm looking to understand whether anyone else has experienced inconsistent DLP enforcement when using Sensitive Information Types (SITs) to prevent Microsoft 365 Copilot from processing sensitive information entered directly into Copilot Chat prompts.

We've configured a Microsoft Purview DLP policy targeting the Microsoft 365 Copilot location, with the action Prevent Copilot from processing content – Processing prompts.

The policy is configured to detect built-in Microsoft Sensitive Information Types and prevent Copilot from processing prompts containing matching information.

However, during testing, we're observing inconsistent behaviour depending on the category of SIT being tested.

All test data has been independently validated against the corresponding Microsoft Purview Sensitive Information Types, confirming successful detection at the configured confidence levels.

Observed Behaviour:

  • PII SITs: Copilot appears to process the information before responding that it cannot assist with the request.

Financial SITs: Similar behaviour is observed, with Copilot appearing to recognise the sensitive information before declining to respond.

Technical SITs: Copilot processes the information and provides a response without any apparent restriction, despite the information matching the technical SITs configured within the DLP policy.

This raises concerns about whether the responses we're seeing for PII and financial information are actually the result of DLP enforcement or Copilot's own built-in safeguards.

More importantly, technical SITs appear to be handled differently, with no apparent enforcement taking place.

Questions:

Has anyone successfully validated SIT-based prompt blocking in Microsoft 365 Copilot Chat, particularly using technical SITs?

Are there any known differences in enforcement behaviour between PII, financial and technical SITs?

Does Copilot apply additional built-in safeguards to PII and financial information independently of Microsoft Purview DLP policies?

Are there any known limitations affecting technical SIT detection or enforcement within Copilot Chat?

According to Microsoft 365 Roadmap ID 515945, the functionality for safeguarding Copilot prompts using SIT-based DLP policies is marked as launched and generally available.

However, Microsoft's documentation continues to reference preview availability and rollout considerations.

Any insight into whether this is expected behaviour, a known limitation or if I am just being silly at this point would be appreciated.

Thanks in advance.Title: Microsoft 365 Copilot DLP – Inconsistent Enforcement Between PII, Financial and Technical SITs

Hi everyone,

I'm looking to understand whether anyone else has experienced inconsistent DLP enforcement when using Sensitive Information Types (SITs) to prevent Microsoft 365 Copilot from processing sensitive information entered directly into Copilot Chat prompts.

We've configured a Microsoft Purview DLP policy targeting the Microsoft 365 Copilot location, with the action Restrict Copilot from processing content – Processing prompts.

The policy is configured to detect built-in Microsoft Sensitive Information Types and prevent Copilot from processing prompts containing matching information.

However, during testing, we're observing inconsistent behaviour depending on the category of SIT being tested.

All test data has been independently validated against the corresponding Microsoft Purview Sensitive Information Types, confirming successful detection at the configured confidence levels.

Observed Behaviour:

PII SITs: Copilot appears to process the information before responding that it cannot assist with the request.

Financial SITs: Similar behaviour is observed, with Copilot appearing to recognise the sensitive information before declining to respond.

Technical SITs: Copilot processes the information and provides a response without any apparent restriction, despite the information matching the technical SITs configured within the DLP policy.

This raises concerns about whether the responses we're seeing for PII and financial information are actually the result of DLP enforcement or Copilot's own built-in safeguards.

More importantly, technical SITs appear to be handled differently, with no apparent enforcement taking place.

Questions:

Has anyone successfully validated SIT-based prompt blocking in Microsoft 365 Copilot Chat, particularly using technical SITs?

Are there any known differences in enforcement behaviour between PII, financial and technical SITs?

Does Copilot apply additional built-in safeguards to PII and financial information independently of Microsoft Purview DLP policies?

Are there any known limitations affecting technical SIT detection or enforcement within Copilot Chat?

According to Microsoft 365 Roadmap ID 515945, the functionality for safeguarding Copilot prompts using SIT-based DLP policies is marked as launched and generally available.

However, Microsoft's documentation continues to reference preview availability and rollout considerations.

Any insight into whether this is expected behaviour, a known limitation or if I am just being silly at this point would be appreciated.

Thanks in advance.

Microsoft Copilot | Other
0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.