Courseiva

Prevent Copilot from Accessing Sensitive Data

Your organization plans to use Microsoft 365 Copilot. To ensure compliance, you need to prevent Copilot from accessing sensitive content in SharePoint Online document libraries that are labeled as 'Highly Confidential'. What should you configure?

⚠ Common exam trap

It's easy for candidates to confuse DLP policies (which control data sharing) with sensitivity labels (which control access and usage), leading them to choose option C, but DLP does not block internal processing by Copilot.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure a sensitivity label with encryption and apply it to the documents.

Sensitivity labels with encryption can restrict access to documents based on their classification. When a document is labeled 'Highly Confidential' and encrypted, Microsoft 365 Copilot cannot process it because Copilot respects the encryption applied by the label, effectively preventing it from accessing the sensitive content. This is the only configuration that directly controls Copilot's ability to read the content at the file level.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure a retention policy to prevent Copilot from accessing older content.

    Why it's wrong here

    Retention policies are designed for data lifecycle management—applying deletion or preservation rules—not for restricting access or retrieval by AI workloads. Copilot's grounding can still surface older content that is within the retention period because the policy does not alter permissions or block the semantic index from crawling the item. Therefore, retention policies cannot be used to keep Copilot away from older documents.

  • ✗

    Create a conditional access policy to block Copilot from accessing SharePoint.

    Why it's wrong here

    Conditional Access policies evaluate the risk of a user sign-in or access request based on conditions, and they attach to user principals, not to the Microsoft 365 Copilot service itself. You cannot target Copilot as a workload or assign a policy that would apply to its processing engine, and blocking SharePoint via CA would also block all user access to SharePoint. Thus, a Conditional Access policy cannot selectively prevent Copilot from accessing SharePoint content.

  • ✗

    Create a DLP policy to block Copilot from processing 'Highly Confidential' content.

    Why it's wrong here

    DLP policies are built to monitor and restrict actions that exfiltrate sensitive data—such as sharing files or copying information outside the organization—not to prevent an AI service from reading or processing content internally. The Copilot semantic index operates under the same user identity and does not trigger DLP rule evaluations for mere processing. Therefore, a DLP policy would not stop Copilot from using 'Highly Confidential' content for responses.

  • ✓

    Configure a sensitivity label with encryption and apply it to the documents.

    Why this is correct

    Sensitivity labels that include encryption encrypt the file itself and protect it with cryptographic access controls that Copilot explicitly respects. Because Copilot requires decrypted content to index and generate grounded responses, encrypted files are excluded from its semantic index and are not returned in Copilot results, even for users who have permission. Applying such a label is the supported way to prevent Copilot from processing sensitive documents.

About these practice questions

Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.