Courseiva

How to Restrict Microsoft 365 Copilot from Using Sensitive Data

Your company is deploying Microsoft 365 Copilot for all users. You need to ensure that Copilot responses are grounded only in organizational data that users already have permission to access. Additionally, you must comply with data residency requirements in the European Union. Which THREE actions should you take?

⚠ Common exam trap

A common mix-up: candidates confuse conditional access policies (which control access) with data residency controls (which control data storage and processing location), and may incorrectly think caching in Purview is a real feature for data residency, when in fact Microsoft 365 Copilot does not use Purview caching for this purpose.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Apply sensitivity labels to restrict Copilot from accessing specific files.

Sensitivity labels can be configured to block Copilot from accessing files with specific labels, ensuring that Copilot responses are grounded only in organizational data that users already have permission to access. This is done by using Microsoft Purview Information Protection to define label-based restrictions that Copilot respects, preventing it from surfacing content from labeled files even if the user has direct access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Apply sensitivity labels to restrict Copilot from accessing specific files.

    Why this is correct

    Sensitivity labels in Microsoft Purview can be configured with encryption or permissions settings that explicitly exclude the Copilot service principal, preventing Copilot from retrieving labeled content. For example, applying a label with 'Do Not Forward' or custom conditional access grants ensures Copilot only returns data when the user has the corresponding decryption rights. This provides granular control at the file level, allowing specific documents or emails to be hidden from Copilot-generated responses while other content remains accessible.

  • ✓

    Set the data residency preference for Microsoft 365 Copilot to the European Union in the admin center.

    Why this is correct

    In the Microsoft 365 admin center, administrators can define a data residency preference for Microsoft 365 Copilot that pins processing of prompts and responses to specific regional datacenters, such as those in the European Union. This setting ensures that all prompt text, retrieved content, and generated output are handled within the chosen geographic boundary, satisfying compliance requirements like GDPR. It is a tenant-level control distinct from user access or conditional access policies, and it is essential for organizations subject to data sovereignty regulations.

  • ✓

    Configure Microsoft 365 Copilot to respect existing user permissions via Microsoft Entra ID.

    Why this is correct

    Configuring Microsoft 365 Copilot to honor existing user permissions via Microsoft Entra ID is the foundational security model: Copilot uses the signed-in user's access token and Microsoft Graph scopes to retrieve information, and it never receives additional authorization beyond what that user already holds. An administrator should verify that the tenant has no overly broad service principal grants or stale user permissions and should use Entra ID access reviews to enforce least privilege. This ensures that if a user lacks access to a specific mailbox, site, or file, Copilot will not surface that content in a summary or answer.

  • ✗

    Block Copilot for all users outside the EU using conditional access policies.

    Why it's wrong here

    Blocking users outside the EU through conditional access policies controls user sign-in and authentication, not the geographic location where Microsoft 365 Copilot processes AI workloads. Copilot data processing is determined by the tenant's data residency setting; even if every user is located in the EU, the service can still process data in non-EU datacenters unless the residency preference is explicitly configured. Moreover, conditional access is an identity security tool, not a data storage control, so it would not achieve compliance with data residency requirements.

  • ✗

    Enable Copilot caching in Microsoft Purview to control data storage locations.

    Why it's wrong here

    The phrase 'Copilot caching' misrepresents the architecture: Microsoft 365 Copilot does not maintain a persistent or temporary cache of your content; instead, it performs live queries via Microsoft Graph whenever a user submits a prompt. Microsoft Purview offers data lifecycle management tools like retention policies and eDiscovery, but none of them expose a setting to 'cache' Copilot data or control where that data resides. To govern data storage locations, you must adjust the Copilot data residency preference in the admin center, not look for a caching toggle in Purview.

About these practice questions

Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.