Microsoft 365 Copilot can summarize a mailbox, reason over a conversation, and connect information across a user’s work. That reach is valuable, but an inbox also contains messages from people and domains the organization does not control.
Microsoft Security’s Oct. 8 guidance documents a new Microsoft Purview Data Loss Prevention (DLP) pattern: exclude email received from external users from Copilot grounding. It is a targeted defense against cross-prompt injection and misleading instructions in incoming mail, while leaving the user’s mailbox and normal mail flow intact.
What Microsoft changed
The policy uses the Microsoft 365 Copilot and Copilot Chat location in Purview DLP. Add a rule with the condition Email is received from → External users and the action Prevent Copilot from processing content.
- Copilot excludes matching external email from grounding, summarization, and citation.
- Internal email, files, and other permitted sources remain available unless another policy restricts them.
- The check compares the sender domain with the tenant’s accepted domains; Microsoft describes it as metadata-only.
- The capability is currently documented as a preview, so treat the rollout as a controlled change rather than a blanket default.
Why external email belongs in the threat model
External messages can carry prompt-injection attempts, manipulated instructions, unverified claims, or social-engineering language. A user may not notice the content, but Copilot can encounter it while answering a broad prompt such as “summarize my inbox” or “what should I do about this vendor request?”
With the DLP rule enabled, the message is not eligible as a grounding source. The policy does not need to classify every sentence or predict whether a message is malicious; it creates a simpler trust boundary around the sender domain.
What the policy does not do
- It does not delete or quarantine mail. Users can still read, reply to, forward, and manage external messages.
- It does not change mail flow or retention. The control operates at the Copilot grounding layer, not transport or storage.
- It does not inspect the body. The documented condition evaluates sender metadata against accepted domains.
- It does not make every response trustworthy. Internal content can still be overshared, stale, or wrong; permissions and data governance remain essential.
- It does not block web grounding. Use the separate Purview action for sensitive information types when the risk is a prompt being sent to external web search.
A safer rollout in five steps
1. Confirm accepted-domain hygiene
Review the tenant’s accepted domains before testing. Partner, subsidiary, and acquired-company domains that are treated as internal in practice must be represented correctly, or the rule will exclude mail users still expect Copilot to use.
2. Start in simulation
Create the custom DLP policy in the Purview portal, enable the Copilot location, add the external-user condition, and use simulation mode first. Define an owner for the policy and a time-boxed review window.
3. Test representative prompts
| Scenario | Expected result | Evidence to retain |
|---|---|---|
| Summarize a mailbox containing vendor mail | External messages are excluded; permitted internal mail can still ground the answer. | Simulation event, prompt, user, and source behavior |
| Ask Copilot to summarize an internal thread | Internal mail remains available when permissions and other policy conditions allow it. | Before/after response comparison |
| Open or reply to an external message | Normal Outlook access and mail flow continue. | User acceptance check and service-health note |
| Use a prompt with sensitive data and web grounding | Evaluate separately with the Purview SIT-to-web-search rule; this policy alone does not block web search. | DLP policy mapping and test result |
4. Review business exceptions
Some workflows intentionally rely on external mail, such as supplier operations, recruiting, or regulated client correspondence. Document those needs, decide whether the rule should be scoped, and give the exception an accountable owner and review date.
5. Enforce with a rollback plan
Move to enforcement only after simulation evidence shows the intended boundary. Tell users what a policy notification means, monitor DLP activity, and keep a tested rollback path. Revisit accepted domains and exceptions after mergers, new partners, and major mail-system changes.
Pair this with prompt and web-grounding controls
External-email DLP is one layer in a broader Copilot security design. Domain Exclusion can remove named public domains from web grounding, while a separate Purview DLP action can block external web search when a prompt contains selected sensitive information types. Together they cover different paths:
- External email DLP: controls which sender class may ground Copilot.
- Sensitive-prompt DLP: controls whether selected prompt content may trigger external web search.
- Domain Exclusion: controls which named public domains may ground a response.
- Permissions and labels: control which internal data Copilot can access and process.
Do not collapse these into one “Copilot security” switch. Each rule should have a business owner, a measurable risk statement, a test case, and evidence that a security or compliance reviewer can understand.
Frequently Asked Questions
Does this policy delete or quarantine external email? No. It only prevents matching email from being used by Copilot as a grounding, summarization, or citation source.
Does the policy inspect message content? No. The documented condition evaluates sender metadata and compares the domain with accepted domains.
Will internal email and files still work? Yes, where the user has permission and no other policy blocks the source.
Should we enforce it immediately? Usually not. Simulation, realistic prompt testing, and a documented exception review make the change safer.
Need a Copilot grounding baseline?
We can map external email, web search, permissions, Purview controls, and evidence ownership into a staged policy your team can test before enforcement.
Book a Free Consultation