Prevent Data Loss to AI Apps and Agents
Turn classification and labels into enforcement boundaries for Copilot, agents, prompts, grounding data, and the browser-based AI apps users reach on their own.
Core capabilities
-
Exclude sensitivity-labeled files and emails from Microsoft 365 Copilot and agent processing, and apply SIT-based rules to prompts and external web search
-
Warn or block users on managed devices from pasting, uploading, or copying sensitive data into third-party AI sites in a browser
-
Inspect and block sensitive text typed or pasted into AI prompts inline in Microsoft Edge for Business, without onboarding the device
-
Detect and block sensitive data shared with unmanaged AI apps through non-Microsoft browsers, apps, APIs, and add-ins via a SASE or secure web gateway integration
Supporting capabilities 4
-
Temporarily exclude sensitive SharePoint sites from Copilot and agent discovery while access is remediated
-
Reduce the discoverable data surface by enforcing access boundaries on high-risk SharePoint sites
-
Apply stronger controls to users whose risk signals justify tighter data-loss prevention
-
Carry the source sensitivity label onto Copilot responses and generated files so protection follows the AI output rather than stopping at the grounding data