Do sensitivity labels control what Microsoft 365 Copilot can see?
Only in two specific situations. A sensitivity label changes what Microsoft 365 Copilot can read when the label locks the file with encryption that does not let the reader copy text out of it, or when a data loss prevention policy names that label and tells Copilot to skip it. A label on its own, applying no encryption and with no policy behind it, does not stop Copilot reading or summarising anything. Blue Arc IT Solutions sees that assumption cause more Copilot surprises than any other.
The words this answer depends on
Three pieces of jargon do the work on this page, so they are worth ten seconds each.
A sensitivity label is a marking you attach to a document or email, such as Internal or Confidential. Some labels only mark the file, adding a name in the app and perhaps a footer. Others also encrypt it.
Encryption here means the file is locked so that only named people can open it, and the lock travels with the file wherever it goes, including outside your organisation.
A usage right is one specific thing an encrypted file allows a given person to do: view it, print it, forward it, copy text out of it. The right that controls copying text is called EXTRACT, and Microsoft Purview displays it as "Copy and extract content". Remember that one, because it is the whole answer.
How Copilot decides what it can read
Two gates, in order, and the first one matters far more than the second.
The first gate is ordinary permissions. Copilot only uses content the person asking could already open. Microsoft's documentation puts it directly: Purview-supported AI apps use existing controls to ensure data in your tenant is "never returned to the user or used by a large language model (LLM) if the user doesn't have access to that data". If your staff can reach a file they should not, that is a permissions problem, and a label will not repair it. We cover that in why Copilot shows people files they should not see.
The second gate is the EXTRACT usage right, and it only exists when a label applies encryption. Microsoft is explicit about which right decides the outcome: "It's this usage right that determines whether Copilot or agents can display text to the user from encrypted content."
So if a reader can view an encrypted document but has not been granted EXTRACT, Copilot changes behaviour: "Copilot won't summarize this content but can reference it with a link so the user can then open and view the content outside Copilot." The file still appears, as a link. Its contents stay out of the answer.
Put plainly: an encrypted label that forbids copying is the closest thing Microsoft 365 has to a switch telling Copilot to keep out. Everything else is a marking.
Which labels actually withhold EXTRACT
This is where good intentions come unstuck, because the common permission choices include EXTRACT by default.
The Editor and Owner permission levels both include it. Full control includes it, because full control includes every usage right. The Encrypt-Only option for email includes it. Do Not Forward does not. A Read permission level does not include it either, unless whoever applied the label ticked the option allowing users with read access to copy content.
There is also a quirk worth knowing: the person who applied the encryption always has EXTRACT, because they are the rights owner. Their own protected content is always eligible to come back to them through Copilot, however restrictive the label looks.
If you want to check a specific document, Microsoft documents a manual test. Open the file in the Windows Office app, customise the status bar to show Permissions, select the icon next to the label name, and read the value shown for Copy. That value is the EXTRACT right, and it will say Yes or No.
Labelling a SharePoint site does not label the files inside it
This is the single most expensive misunderstanding in Microsoft 365 labelling, and it is worth stating without hedging.
Sensitivity labels can be applied to two very different things. They can be applied to a file or an email. They can also be applied to a container, meaning a SharePoint site, a Team, a Microsoft 365 group or a Loop workspace. Those are separate label types that behave differently, and the second does not flow into the first. From Microsoft's own considerations page: "Sensitivity labels that are applied to containers (groups and sites) aren't inherited by items in those containers."
The same page spells out the consequence for Copilot: those items will not display the container's label in Copilot, and cannot support label inheritance. A Teams channel conversation summarised out of a team marked Confidential does not carry that marking into the Copilot answer. Content from SharePoint site pages and lists does not carry the site's label either.
The everyday version: marking the filing cabinet does not mark the paper inside it. If you want Copilot to treat the documents as confidential, the documents need labels, not the site.
Getting labels onto the files themselves means one of three things. Staff apply them by hand. A label policy sets a default label for new content. Or the tenancy uses automatic labelling, or a default label on a specific document library, both of which need the Purview add-on discussed below.
How to actually stop Copilot using a labelled file
The control people are reaching for when they say labels should stop Copilot is a data loss prevention policy, usually shortened to DLP. DLP is a rule that watches for particular content and takes an action when it finds it. Microsoft Purview has a policy location specifically for Microsoft 365 Copilot and Copilot Chat.
Point a DLP rule at that location, tell it to look for a particular sensitivity label, and Copilot stops using those files. Not quite invisibly, though, and the nuance matters for how you explain it to staff: "Identified items still appear in the citations of the response, but the content of the item isn't used in the response or accessed by Copilot." The file's name can still surface as a citation. Its contents do not.
Four further limits from the same Microsoft page, all worth knowing before you promise anyone an outcome.
The policy location only exists in the Custom policy template, and selecting it disables every other location in that policy. A single rule cannot combine a sensitivity-label condition with a sensitive-information-type condition, though you can put each in its own rule in the same policy. Changes are not instant: "Updates to a DLP policy can take up to four hours to reflect in Microsoft 365 Copilot and Copilot Chat experience." And files a user attaches straight into a prompt are not inspected at all. Microsoft is explicit about it: "DLP can't scan the contents of files that you upload directly into prompts, so evaluation of the uploaded file for sensitive data doesn't occur."
Two smaller boundaries: for email the control covers messages sent on or after 1 January 2025, and calendar invites are not supported.
What this costs on Microsoft 365 Business Premium
Here is the part most published Copilot guidance skips, because it is written for enterprise tenancies.
Business Premium includes manual sensitivity labelling, and default and mandatory labelling through a label policy. What it does not include is automatic labelling. Microsoft's own troubleshooting guidance is blunt about the symptom: "Auto-labeling of files and emails isn't included at this SKU."
The DLP control described above is also not included with Business Premium. Microsoft's Purview service description lists the rule that restricts Copilot from processing labelled files and emails as unavailable on Microsoft 365 Business Basic, Standard and Premium, and available with the Microsoft Purview Suite. Default sensitivity labels on a SharePoint document library sit at the same tier.
The relevant add-on is the Microsoft Purview Suite for Business Premium, and Microsoft sizes it for exactly this market: "Add-ons require a Microsoft 365 Business Premium base license and are capped at 300 seats total." If you researched this before October 2025, note that Microsoft renamed the enterprise equivalent from Microsoft 365 E5 Compliance to the Microsoft Purview Suite, so older articles describe the same capabilities under the old name.
One honest caveat, because we would rather flag it than have you discover it at renewal. The service description names the Business Premium variant of the add-on explicitly in its audit table, but the label and DLP tables name the Microsoft Purview Suite without separately listing the Business Premium edition. Microsoft's licensing guidance describes the add-on as licensing all the advanced Purview capabilities for Business Premium users, which is consistent with that reading, but confirm the specific entitlement against your own tenancy before you budget for it. We check this for clients as part of a readiness review.
Not everything is gated, though. The same service description notes that Purview DLP for prompts is available to all users of Microsoft Copilot and Copilot Chat. Blocking chosen sensitive information types from being typed into a prompt, and stopping a prompt that contains them from reaching external web search, works on Business Premium without the add-on. We deliberately publish no dollar figures for any of these licences, because Microsoft's Australian pricing moves; ask us and we will quote current Australian dollar pricing against your seat count.
What Copilot inherits when it writes something new
Labels also travel forwards, which is the part of the system that works well and quietly.
When Copilot in Word, PowerPoint or Outlook creates content based on a labelled file, the new content inherits that label along with its protection settings. Where several files are referenced, "the sensitivity label with the highest priority is used for label inheritance". Copilot Chat also shows the highest-priority label of whatever it drew on, which Microsoft describes as displaying the most restrictive label to educate the user about the sensitivity of the data.
One rule here runs against the grain of every other labelling behaviour, so it is worth knowing before someone reports it as a bug: "Unlike other automatic labeling scenarios, an inherited label when you create new content will replace a lower priority label that was manually applied." Normally a hand-applied label wins. In this one case it does not.
Inheritance is not universal. It does not work from files encrypted with user-defined permissions, or where encryption was applied separately from the label. It also fails where the destination is read-only, or where the inherited label has not been published to that user.
What Copilot cannot see at all
A short list, useful when someone asks why a document never appears.
Content protected with Double Key Encryption, which is the highest-protection option and uses a second key you hold yourself, is out of reach entirely: "Copilot and agents can't access this data", and Copilot is unavailable in the app while such a file is open.
Files labelled with user-defined permissions, where the person applying the label picks who can open it, are not reachable in SharePoint or OneDrive unless the user directly references the file in a prompt or the library uses the label that extends SharePoint permissions to downloads, and in both cases the user still needs EXTRACT.
Sensitivity labels protecting Teams meetings and chats are not recognised by Copilot. Emails protected with S/MIME are not returned, and Copilot is unavailable in Outlook while one is open. Password-protected documents are unreachable unless already open. Labels and encryption applied by another organisation are not recognised, since Copilot can read your labels but not someone else's.
Why labels sometimes do nothing in SharePoint
This section is for whoever looks after your Microsoft 365 tenancy. If that is not you, skip to the next heading.
Sensitivity labels for files in SharePoint and OneDrive are an opt-in setting, and a surprising number of tenancies have labels published but this switch never thrown. Until it is enabled, the services cannot process encrypted files, which means "coauthoring, eDiscovery, data loss prevention, search, and other collaborative features won't work for these files". Check the current state by running (Get-SPOTenant).EnableAIPIntegration and confirming it returns True.
Files labelled before that switch was enabled stay broken, which catches people out during migrations: "The labels aren't recognized and if the labels applied encryption, the contents aren't processed." The fix is to download those files and upload them again to the same location.
PDF support is a second, separate opt-in, set with Set-SPOTenant -EnableSensitivityLabelforPDF $true. Microsoft warns that enabling it can increase how many files existing automatic labelling policies pick up, against a ceiling of 100,000 files a day.
Three more traps. Uploading a labelled and encrypted file when you hold less than view rights on it appears to succeed, but the service will not recognise the label. A labelled and encrypted Office file larger than 12 MB stops being processable once it is copied or moved to a different site. And a default label on a document library, if you license one, carries a limitation Microsoft states in a single line: "Doesn't apply to existing files at rest in SharePoint." It labels new files and files that get edited, so your historical content stays unlabelled until something touches it.
How Blue Arc IT Solutions helps
We audit permissions, sharing and labelling before Copilot is switched on, then publish a label set small enough that staff use it. Three or four labels applied consistently protect more than fifteen that everybody ignores. We also tell you plainly whether the Purview add-on earns its cost in your environment, or whether fixing permissions on Business Premium gets you where you need to be.
Blue Arc IT Solutions has supported Australian businesses since 2004, delivering nationally from Canberra, and is experienced supporting DISP member organisations where information handling is contractual rather than optional.
Next, read why Microsoft Copilot shows people files they should not see, or go back to getting a Business Premium tenancy ready for Copilot. For the wider obligations that come with adopting AI in Australia, see whether the Privacy Act applies when your business uses AI tools.
Last reviewed: 11 September 2026, against Microsoft Learn's Copilot information protection considerations page (updated 30 June 2026), the Purview DLP for Copilot page (updated 11 June 2026), the SharePoint and OneDrive sensitivity labels page (updated 15 April 2026) and the Purview service description licensing tables. The EXTRACT usage right, container label behaviour and Business Premium licensing position were each confirmed against those sources on that date.
Frequently asked questions
Does a Confidential label stop Microsoft 365 Copilot reading a document?
Only if that label applies encryption that withholds the EXTRACT usage right from the reader, or if a data loss prevention policy names the label. A Confidential label that applies no encryption and has no policy behind it does not stop Copilot reading or summarising the document.
If we label a SharePoint site as Confidential, are the files inside it protected from Copilot?
No. Microsoft states that sensitivity labels applied to containers such as SharePoint sites and Teams are not inherited by the items inside them. The site label does not reach the documents, so Copilot treats those documents as unlabelled unless each file carries its own label.
Can Microsoft 365 Business Premium block labelled files from Microsoft 365 Copilot?
Not on its own. Microsoft's Purview service description lists the data loss prevention control that stops Copilot processing labelled files and emails as unavailable on Microsoft 365 Business Basic, Standard and Premium, and available with the Microsoft Purview Suite. Blocking sensitive information types in prompts is available to all Copilot users regardless of plan.
Should you label everything before turning on Microsoft 365 Copilot?
No. Blue Arc IT Solutions fixes permissions and sharing settings first, because a label on a file the wrong people can still open changes very little. Labels are worth publishing once access is right, and a small set of three or four labels that staff will actually use beats an elaborate taxonomy they ignore.