Microsoft 365 Copilot Gets New Safeguard Against Email-Based Prompt Injection


Microsoft is giving organizations more control over what Microsoft 365 Copilot can use when generating responses. A new Microsoft Purview Data Loss Prevention (DLP) policy lets administrators exclude external emails from Copilot’s grounding data. The idea is to reduce prompt injection risks without disrupting everyday email access.

Microsoft wants Copilot to stop trusting every email it receives

If you use Microsoft 365 Copilot at work, you must be aware of how deeply the AI assistant connects with your organizational data. Speaking of which, emails can become a potential security risk when they contain hidden instructions designed to manipulate AI responses.

For instance, an attacker could send an email containing instructions that attempt to make Copilot ignore previous guidance. If an employee later asks Copilot to summarize their inbox, that message could influence the generated response.

Microsoft’s new DLP policy aims to address this problem. When enabled, it excludes emails from external senders from Copilot’s grounding sources. This means Copilot cannot use those messages as sources when answering questions or summarizing communications.

Notably, the policy checks sender metadata against the organization’s accepted domains. It does not inspect the email body or analyze its contents. Internal emails, documents, spreadsheets, presentations, and web results remain available as permitted grounding sources.

External emails remain accessible, but Copilot cannot use them

One important detail is that this protection operates at the Copilot grounding layer. It does not block incoming messages, change mail delivery, or affect email retention.

Users can still read, reply to, forward, and manage external emails normally. The restriction only prevents Copilot from processing those messages as grounding sources. Microsoft says administrators can configure the policy through the Microsoft Purview portal. They need the Compliance Administrator or Data Loss Prevention administrator role, or equivalent permissions.

To set it up, open Microsoft Purview, navigate to Data Loss Prevention > Policies, and create a custom policy. Enable the Microsoft 365 Copilot and Copilot Chat location, then add the condition Email is received from > External users. Set the action to Prevent Copilot from processing content.

Microsoft also recommends testing the policy in simulation mode before enforcing it. This helps administrators check its impact, especially when external emails support important business workflows. As of now, the policy’s effectiveness depends on correctly configured accepted domains and carefully scoped rules. Organizations must balance reducing prompt injection risks with preserving the external information their employees need.

Cybersecurity threats continue to evolve across popular platforms and services. Recently, FakeGit flooded GitHub with more than 17,000 malware repositories, while Anthropic launched an OSS scanner designed to help Claude spot vulnerabilities before attackers do.

In another concerning incident, hackers hijacked Google domains and obtained valid HTTPS certificates, showing how even trusted infrastructure can be abused.

More about the topics: AI, Copilot, microsoft

Readers help support Windows Report. We may get a commission if you buy through our links. Tooltip Icon

Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more

User forum

0 messages