Bellows College has deployed multiple AI agents that assist faculty with administrative tasks. The data protection officer has raised concerns that agents may be processing or transmitting student PII (Personally Identifiable Information) in ways that violate FERPA requirements. The administrator needs to configure protections to prevent agents from processing labeled sensitive data without authorization. Which Agent 365 capability should the administrator use?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Agent 365's sensitive data protection is like a bouncer that reads every file's sensitivity label before letting an agent touch it. Set the policy, and agents that try to process PII or confidential content get stopped cold.
Full explanation below image
Full Explanation
Agent 365 includes sensitive data protection controls that allow administrators to configure policies governing how AI agents interact with content classified by Microsoft Purview sensitivity labels. Administrators can define policies that prevent agents from reading, processing, or transmitting content bearing specific sensitivity labels (such as 'Confidential - Student PII' or 'FERPA Protected'). When an agent attempts to process labeled content, the protection controls enforce the policy and block or log the interaction, providing both preventive control and an audit trail for compliance reporting.
Option A, Microsoft Purview retention policies scoped to agent interactions, manage how long data is kept and when it is deleted. Retention policies address data lifecycle but do not prevent agents from actively processing sensitive data in real time — they are a data lifecycle control, not an access or processing control.
Option C, Microsoft Intune app protection policies, control how organizational data is used within managed mobile apps. They operate at the endpoint and app level for human users, not at the agent-to-data interaction level within Microsoft 365 services.
Option D, Microsoft Entra Privileged Identity Management (PIM), enables just-in-time privileged access for human users and administrators. While PIM can be extended to some non-human identity scenarios, it is not the purpose-built control for preventing agents from processing sensitivity-labeled content during normal operations.
Exam tip: When a question asks about protecting sensitive data specifically from agent processing — particularly in relation to sensitivity labels — Agent 365's sensitive data protection controls are the answer. This is a key differentiator from general Purview policies, which protect data from human access patterns.