A healthcare organization needs to prevent Microsoft 365 Copilot from generating responses that include patient health information (PHI) when users ask Copilot to summarize documents. Which Microsoft Purview feature should be configured?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — b is correct because Microsoft Purview Data Loss Prevention policies can be scoped to Microsoft 365 Copilot as a location. A DLP rule can detect sensitive information types (such as U.S.
Full explanation below image
Full Explanation
B is correct because Microsoft Purview Data Loss Prevention policies can be scoped to Microsoft 365 Copilot as a location. A DLP rule can detect sensitive information types (such as U.S. Health Insurance Act PHI types) in Copilot responses and block or restrict the output, preventing Copilot from surfacing PHI in its generated responses. A is wrong because sensitivity label auto-classification labels documents but does not directly block Copilot from generating text containing PHI. C is wrong because communication compliance detects policy violations after the fact for investigation and does not block Copilot responses in real time. D is wrong because insider risk management identifies risky user behaviors for investigation, not for real-time blocking of Copilot outputs.