Home / Guides / secure-microsoft-copilot-pii
Securing Microsoft Copilot and M365 Copilot from PII leaks
Copilot sits inside Word, Outlook, and Teams — another LLM egress surface. Compare Purview controls with on-device Browser Shield for unsanctioned web LLMs.
Published 2026-08-28 · NoeticGuard engineering notes
Microsoft Copilot processes content inside your M365 tenant boundary when deployed with Purview policies. Security reviews often stop there — while employees still paste customer data into chatgpt.com in another tab.
- Sanctioned Copilot — align with Microsoft Purview DLP, sensitivity labels, and tenant admin settings.
- Unsanctioned web LLMs — deploy Browser Shield + optional Brand Guard for codenames and competitor mentions.
- File uploads — Media Guard blocks image/file uploads on supported AI chat hosts (Startup+).