Microsoft made a Purview Data Loss Prevention control available in preview that can stop Microsoft 365 Copilot and Copilot Chat from using email received from external domains. The policy checks sender-domain metadata and excludes matching email from grounding, summarization, and citation; it does not inspect the message body. Microsoft lists the general-availability rollout for January 2027.
Microsoft has made a Microsoft Purview Data Loss Prevention (DLP) control available in preview that can prevent Microsoft 365 Copilot and Copilot Chat from using email received from external domains. Microsoft says the control excludes matching email from grounding, summarization, and citation while allowing Copilot to continue using permitted internal Microsoft 365 data.
The feature is Microsoft 365 roadmap item 561552. The roadmap lists preview availability in June 2026 and the general-availability rollout starting in January 2027. A Message Center notice republished by Hands on Tek says the control also extends to agents built in Copilot Studio when they are published to Microsoft 365 Copilot.
The rule checks origin, not message content
Administrators configure a DLP policy for the Microsoft 365 Copilot and Copilot Chat location with the condition Email is received from > External users and the action Prevent Copilot from processing content. Microsoft determines whether a message is external by comparing the sender domain with the tenant's accepted domains.
That boundary is important: Microsoft says the policy evaluates email metadata only. It does not inspect the email body, and it does not remove the user's access to the message. Instead, the control prevents qualifying external email from being used as Copilot grounding material.
Microsoft presents the feature as a way to reduce prompt-injection and untrusted-data influence. Office 365 IT Pros also notes that external email is a practical path by which misleading content or malicious instructions can enter an organization's information environment.
What security teams should test
The control narrows one retrieval path; it is not a complete prompt-injection defense. Teams evaluating the preview should verify how accepted domains are configured, confirm that external messages are excluded from summaries and citations, and account for Microsoft's note that DLP policy updates can take up to four hours to appear in Copilot experiences.
Security reviews should also cover other repositories and agent permissions. The external-email rule reduces exposure to one class of untrusted input, while files, connected data sources, user permissions, and agent actions still require separate controls and testing.
Key Points #
- 1A preview Microsoft Purview DLP rule can exclude externally received email from Microsoft 365 Copilot and Copilot Chat grounding, summarization, and citation.
- 2The rule evaluates sender-domain metadata against the tenant's accepted domains; it does not inspect the email body or remove the user's access to the message.
- 3Microsoft lists preview availability in June 2026 and the general-availability rollout starting in January 2027.
Scoring Rationale #
This is a targeted governance control for organizations deploying Microsoft 365 Copilot against enterprise email. It reduces one untrusted-grounding path but does not replace broader permission, repository, and prompt-injection testing.
Sources #
Primary source and supporting public references used for this report.
Practice interview problems based on real data
1,625 SQL & Python problems across 15 industry datasets — the exact type of data you work with.