Microsoft 365 Copilot Gets New Safeguard Against Email-Based Prompt Injection
AI-summarised brief · reviewed before publication
Microsoft has introduced a new Data Loss Prevention (DLP) policy in Microsoft Purview that allows administrators to block external emails from being used as grounding data for Microsoft 365 Copilot. The policy checks sender metadata against accepted domains, preventing Copilot from referencing external messages when generating responses or summaries. Internal documents, spreadsheets, presentations, and web results remain accessible. The safeguard does not alter email delivery or retention, and can be configured via the Purview portal by users with Compliance or DLP administrator roles. The feature aims to reduce prompt‑injection risks while preserving normal email functionality.
💡 Why It Matters
- · By isolating external emails from Copilot’s data set, organizations can curb a subtle attack vector that could otherwise manipulate AI outputs without disrupting everyday communication workflows.