A security engineer needs to configure a Microsoft Purview DLP policy to prevent employees from pasting content from documents labeled 'Confidential' into Microsoft 365 Copilot prompts. Which DLP policy scope achieves this?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — b is correct because Microsoft Purview DLP policies can be scoped specifically to Microsoft Copilot interactions and can use sensitivity label conditions (such as detecting content originating from 'Confidential' labeled documents) to block or alert when users attempt to include sensitive labeled content in Copilot prompts. A is incorrect because endpoint DLP can restrict paste operations on devices but it would broadly restrict paste rather than targeting specifically the Copilot prompt context for labeled content.
Full explanation below image
Full Explanation
B is correct because Microsoft Purview DLP policies can be scoped specifically to Microsoft Copilot interactions and can use sensitivity label conditions (such as detecting content originating from 'Confidential' labeled documents) to block or alert when users attempt to include sensitive labeled content in Copilot prompts. A is incorrect because endpoint DLP can restrict paste operations on devices but it would broadly restrict paste rather than targeting specifically the Copilot prompt context for labeled content. C is incorrect because a SharePoint/OneDrive DLP policy controls data actions within those services, not what users paste into Copilot prompts. D is incorrect because Defender for Cloud Apps session policies apply to browser sessions for cloud apps but do not specifically target content pasted from sensitivity-labeled documents into Copilot prompts.