Skip to content
Browse all topics

Can I block Copilot from specific users or content in Microsoft 365?

Yes on both counts. Copilot access is controlled per user by assigning or removing the Microsoft 365 Copilot licence. Content exclusion uses sensitivity labels that block Copilot processing, SharePoint Restricted Content Discovery, and specific Copilot-scoped exclusion controls in Purview.

User-level exclusion

  • Do not assign the Microsoft 365 Copilot licence — the app surfaces do not appear.
  • Use group-based licence assignment to include or exclude specific groups.
  • Conditional Access on the Microsoft 365 Copilot enterprise application can add further conditions (compliant device, trusted location) before Copilot loads.

Content-level exclusion

  • Sensitivity labels with the Do Not Train / Do Not Process by Copilot setting keep labelled content out of Copilot's retrieval.
  • SharePoint Restricted Content Discovery limits which sites Copilot searches — useful for HR, M&A, and other privileged workspaces.
  • Purview Data Loss Prevention rules can block Copilot from summarising content that would leak sensitive data downstream.
  • OneDrive and SharePoint permission trimming remains the primary control — Copilot only retrieves what the user already has access to.

What the exclusions do not cover

  • Copilot Chat with web grounding — the web results are grounded on public content the user could search anyway.
  • Content pasted into a Copilot prompt by the user — the user has already seen it; Copilot processes what the user provides.
  • M365 Copilot in third-party apps via connectors — governed by that connector's own permissions.

Read next

Other questions