A security engineer is reviewing Microsoft Copilot for Microsoft 365 usage logs and notices that users are submitting prompts containing customer PII. The engineer needs to prevent sensitive data from being included in Copilot prompts without blocking Copilot entirely. Which feature should the engineer configure?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — a is correct because Microsoft Purview Communication Compliance policies can be scoped to Microsoft Copilot for Microsoft 365 interactions, enabling detection and remediation when users include sensitive content like PII in prompts. B is incorrect because Defender for Cloud Apps session policies apply to browser-based sessions and do not natively inspect Copilot prompt content.
Full explanation below image
Full Explanation
A is correct because Microsoft Purview Communication Compliance policies can be scoped to Microsoft Copilot for Microsoft 365 interactions, enabling detection and remediation when users include sensitive content like PII in prompts. B is incorrect because Defender for Cloud Apps session policies apply to browser-based sessions and do not natively inspect Copilot prompt content. C is incorrect because Insider Risk Management identifies risky behavior patterns but does not block or prevent specific prompt content. D is incorrect because Conditional Access can restrict access to Copilot entirely but cannot selectively filter prompt content.