Microsoft 365 Copilot Gets Clearer DLP Notifications

Have you ever wondered why Copilot couldn’t access, process, or return certain content?
Microsoft is making that experience much easier to understand. Previously, users could see different messages depending on how a Microsoft Purview Data Loss Prevention (DLP) policy was triggered, which sometimes made it unclear why content wasn’t available.

With this update, Microsoft 365 Copilot will now display a consistent notification whenever organisational DLP policies prevent access to content. The goal is simple: improve transparency, reduce confusion, and help users understand that Copilot is respecting their organisation’s data protection policies.

What’s Covered?

The new standardized message applies to Microsoft Purview DLP protections across Microsoft 365 Copilot and Copilot Chat, including:

  • Grounding DLP
  • Prompt DLP
  • External Email DLP

Where Will Users See It?

The unified notification can appear across Microsoft 365 Copilot experiences powered by Microsoft 365 Chat orchestration, including:

  • Microsoft 365 Copilot
  • Microsoft 365 Copilot Chat
  • Microsoft Teams Copilot experiences
  • Outlook on the web Copilot experiences
  • Microsoft Edge Copilot experiences
  • Other Microsoft 365 Copilot chat experiences that rely on Microsoft 365 Chat orchestration

Whenever a DLP policy restricts Copilot from using specific content, users will see the same clear message indicating that access to some content has been restricted by an organisational policy.

Rollout Timeline

The feature is now rolling out across all environments:

  • Worldwide: Available from July 15, 2026
  • GCC: Available from July 20, 2026
  • GCC High and DoD: Available from July 23, 2026

What This Means for Your Organisation

Organizations already using Microsoft Purview DLP with Microsoft 365 Copilot or Copilot Chat don’t need to take any action. The update does not change how DLP policies work. Instead, it improves the user experience by providing a clearer and more consistent explanation when content is blocked.

For IT administrators, this is a good opportunity to review existing training materials, user documentation, and support resources to ensure they reflect the new messaging experience.

Bottom line: the protection remains the same, but the explanation gets better. Users gain more clarity on why content is unavailable, while organisations continue to benefit from the same trusted data protection controls.

🚀Microsoft 365 Copilot Adds Custom Guidance Links for Users Blocked from Copilot Chat

Starting in July 2026, Microsoft 365 Copilot will introduce a new optional feature that allows administrators to add a custom policy or guidance link for users who are blocked from accessing Copilot Chat. When restricted users attempt to open Copilot Chat, they’ll be directed to organisation-specific information that can explain access requirements and provide next steps. The feature can be configured through the Microsoft 365 admin centre and does not affect existing access controls or policies. No administrative action is required unless organisations choose to enable and customise this experience.

What’s changing?

Organisations will now have the option to add a custom policy or support link for users who are blocked from Copilot Chat through administrative policies. Instead of only seeing a standard Microsoft message, affected users can be directed to organization-specific guidance that explains why access is restricted and outlines the appropriate next steps.

This enhancement is designed to reduce confusion, improve communication, and make it easier for users to find the information they need when access is unavailable.

Rollout timeline

  • General Availability (Worldwide): Starting in July 2026
  • Expected completion: August 2026

Who is affected?

This update may be relevant for:

  • Organizations using the Microsoft 365 Copilot app
  • Administrators managing Copilot access through Integrated Apps policies
  • Users whose access to Copilot Chat has been restricted by policy

What admins should know

This feature is optional and disabled by default. Organisations that want to provide customised guidance can configure a support URL in the Microsoft 365 admin centre under Copilot settings.

Potential uses include:

  • Explaining why access is restricted
  • Sharing internal Copilot adoption policies
  • Providing licensing information
  • Directing users to support resources or help-desk contacts
  • Outlining the process for requesting access

Recommended actions

No action is required.

However, organizations that want to take advantage of this feature should consider:

  • Reviewing their current Copilot access policies
  • Identifying relevant internal guidance or support resources
  • Configuring a custom URL in the Microsoft 365 admin center
  • Preparing helpdesk teams for the updated experience
  • Monitoring Microsoft Learn documentation for additional setup guidance

Microsoft Purview DLP: Instances Policy Location Retiring in January 2027

Microsoft has announced the retirement of the Instances policy location in Microsoft Purview Data Loss Prevention (DLP), with the change taking effect on January 6, 2027.

Today, organizations using the Instances location rely on the Microsoft Defender for Cloud Apps file policy infrastructure to enforce DLP and auto-labeling policies across supported third-party applications. To simplify policy management and provide a more consistent compliance experience, Microsoft is moving away from this approach and introducing dedicated application-specific policy locations directly within Microsoft Purview.

Supported applications include:

  • Google Workspace
  • Box
  • Dropbox
  • Salesforce
  • ServiceNow
  • AWS
  • Cisco Webex
What’s Changing?

Instead of creating policies under a generic Instances location, administrators will use dedicated locations for each supported application.

For example:

Current LocationNew Location
Instances (Google Workspace)Google Workspace
Instances (Box)Box
Instances (Dropbox)Dropbox
Instances (Salesforce)Salesforce
Instances (ServiceNow)ServiceNow
Instances (AWS)AWS
Instances (Cisco Webex)Cisco Webex

This change aligns non-Microsoft application protection more closely with the broader Microsoft Purview compliance framework.

Microsoft is introducing these new application locations ahead of the retirement date to allow organizations time to migrate.

Key dates:

  • Dedicated application locations will be rolled out before retirement.
  • January 6, 2027: Instances policy location officially retires.
  • Retirement rollout begins in early January 2027 and is expected to complete by mid-January 2027.
What Happens After January 6, 2027?

Once the retirement takes place:

  • New policies can no longer be created using the Instances location.
  • Existing policies configured with the Instances location will no longer be supported.
  • Organizations should use the new dedicated application locations for all future DLP and auto-labeling policies.
  • Policies that continue to rely on the retired Instances location may no longer be enforced as expected.

If your organization currently uses the Instances location, Microsoft strongly recommends recreating those policies in the new application-specific locations before the retirement deadline.

Recommended Next Steps

To avoid any disruption to DLP enforcement, organizations should begin preparing well before the 2027 deadline.

1. Review Existing Policies

Identify any DLP or auto-labeling policies currently configured through the Instances location.

2. Identify Affected Applications

Determine which non-Microsoft platforms are involved and map them to their new dedicated policy locations.

3. Recreate Policies

Build equivalent policies using the new application-specific locations within Microsoft Purview.

4. Test and Validate

Before retiring legacy policies, verify that policy enforcement, labeling, and user experiences behave as expected.

5. Update Documentation

Review operational procedures, internal documentation, and administrator guidance to reflect the new management model.

6. Notify Stakeholders

Make sure compliance, security, and support teams are aware of the upcoming change and migration timeline.

While the retirement is still several months away, organizations using third-party cloud platforms for collaboration and data storage should start planning their migration strategy now. Moving to dedicated application locations will ensure continued DLP and auto-labeling protection while providing a more streamlined and unified compliance experience within Microsoft Purview.

The bottom line: If you’re using the Instances location today, plan your migration before January 6, 2027. If you’re not, you can safely continue using Microsoft Purview as normal and take advantage of the new dedicated application locations as they become available.

💜🏆Honored to Be Renewed as a Microsoft MVP for a Second Year

Some milestones feel just as special the second time around.

I’m incredibly grateful and honored to share that I have been renewed as a Microsoft Most Valuable Professional (MVP) for another year in M365 Copilot and Microsoft Purview.

When I first received the MVP award, I saw it as both a recognition and a responsibility. A responsibility to continue learning, sharing knowledge, supporting the community, and helping others get the most value from Microsoft technologies.

Over the past year, the pace of innovation has been extraordinary. The rapid evolution of AI, the growing adoption of Microsoft 365 Copilot, and the increasing importance of data security, governance, and compliance through Microsoft Purview have made this an exciting time to contribute to the community.

As I reflect on the past year, I’m grateful for every opportunity to engage with fellow professionals, exchange ideas, share experiences, create content, and learn from some of the brightest minds in the Microsoft ecosystem. The MVP community is filled with individuals who are passionate about helping others succeed, and it is a privilege to be part of it.

This renewal is not just about individual achievements. It represents the value of collaboration, community, and continuous growth. Every conversation, challenge, lesson learned, and connection made along the way has contributed to this journey.

Thank you to Microsoft for this continued recognition and trust. Thank you to the MVP Program team, my colleagues, friends, mentors, customers, and the incredible community members who inspire me every day.

Most importantly, thank you to everyone who shares their knowledge, asks thoughtful questions, provides feedback, and helps make our community stronger. Your contributions are what make this ecosystem thrive.

As I begin my second year as an MVP, I’m excited to continue exploring what’s possible with AI, M365 Copilot, and Microsoft Purview, while giving back to the community that has given me so much.

Here’s to another year of learning, sharing, growing, and making an impact together.

Thank you for being part of the journey. 💜

Joanna Vathis
Microsoft MVP | M365 Copilot | Microsoft Purview

🎙️ New Broadcast Episode: Microsoft Purview Time-Limited Role Assignments

In this episode, we dive into the new Microsoft Purview Time-Limited Role Assignments feature, which allows administrators to grant temporary access to Purview role groups with automatic expiration.

Learn how this enhancement helps organizations implement least-privilege access, reduce privilege creep, strengthen governance, and improve compliance.

✅ Feature overview
✅ Security and compliance benefits
✅ Common use cases
✅ What admins need to know

🔔 Don’t forget to 👍 Like, ✅ Subscribe, and 🔔 Turn On Notifications for more Microsoft 365 ☁️, Security 🛡️, and Microsoft Purview 📋 updates! 🚀✨

🎙️ New Broadcast Episode: Microsoft Purview Time-Limited Role Assignments

Watch on YouTube ➡️

Microsoft Purview Tightens Rules for Custom Sensitive Information Types

Organizations using Microsoft Purview custom Sensitive Information Types (SITs) should be aware of an upcoming change that may require updates to existing regex patterns.

Microsoft is moving forward with enforcing a long-documented rule that allows only one capturing group per regular expression in custom SIT definitions. The goal is to improve the consistency, reliability, and predictability of how sensitive data is identified and classified across Microsoft Purview and Data Loss Prevention (DLP) workloads.

When is this happening?

The rollout is expected to be completed by early July 2026 across all Microsoft cloud environments, including:

  • Worldwide
  • GCC
  • GCC High
  • DoD
Who is affected?

This change primarily impacts:

  • Microsoft Purview administrators
  • Compliance teams managing custom Sensitive Information Types
  • Organizations using custom SITs in DLP, data classification, and compliance solutions

The enforcement applies whether SITs are managed through:

  • The Microsoft Purview portal
  • PowerShell, including:
    • New-DlpSensitiveInformationTypeRulePackage
    • Set-DlpSensitiveInformationTypeRulePackage
What changes?

Once enforcement is in place:

✅ New custom SITs must contain only one capturing group in each regular expression.

❌ Creating a new SIT with multiple capturing groups will be blocked.

❌ Updating an existing SIT that contains multiple capturing groups will fail validation.

❌ Administrators will not be able to save changes to existing SITs until non-compliant regex patterns are updated.

What about existing SITs?

Existing custom SITs that contain multiple capturing groups will continue to work in their current state. However, they become a potential issue the moment you need to modify, update, or re-save them.

In other words, if an existing SIT contains a regex pattern with multiple capturing groups, you’ll need to redesign that pattern to comply with the one-capturing-group rule before any future changes can be saved.

Many organizations rely on custom SITs to identify sensitive business information and power key compliance capabilities such as:

Why does this matter?
  • Data Loss Prevention (DLP)
  • Data classification
  • Compliance monitoring
  • Information protection policies

If a custom SIT cannot be updated because it fails validation, it could delay policy changes, compliance updates, or new data protection initiatives.

What should you do now?

To avoid surprises, Microsoft Purview administrators should proactively:

  1. Audit existing custom SITs
  2. Identify regex patterns that use multiple capturing groups
  3. Redesign patterns to use a single capturing group
  4. Test and validate updated SITs before future modifications are required

🛡️ Jo SNAI Reimagined: Same Mission. New Look. Bigger Impact.

Some characters evolve not because their purpose changes, but because the world around them does.

Since the beginning, Jo SNAI has represented the vision behind Security Nebula AI (SNAI), a place where cybersecurity, artificial intelligence, and innovation converge to create a safer and smarter digital future. As a digital superhero, Jo SNAI has always stood for protection, knowledge, resilience, and the responsible use of emerging technologies.

Today, Jo SNAI unveils a bold new look.

The transition from the original blue design to the new purple powered appearance, is more than a visual refresh. It reflects the growth of Security Nebula AI and the expanding role of AI in cybersecurity, automation, and digital transformation. The new design symbolizes innovation, creativity, intelligence, and the limitless possibilities that emerge when security and AI work together.

While the appearance has evolved, the mission remains unchanged.

Jo SNAI continues to champion the values that define Security Nebula AI: protecting what matters most, empowering people through technology, embracing innovation responsibly, and helping organizations navigate the future with confidence.

In a digital universe where threats grow more sophisticated and opportunities become more exciting, Jo SNAI stands as a reminder that security should never slow innovation, it should enable it.

Welcome to the next chapter of Jo SNAI.

Same hero. New look. Stronger vision.

Security Nebula AI

Cyber Strong. AI Smart. Human First. 💜🛡️✨🚀

Microsoft Purview Adds Time-Limited Role Assignments to Strengthen Security

Microsoft is enhancing Microsoft Purview with a new capability that allows administrators to assign expiration dates to role group memberships. This update makes it easier to grant temporary administrative access while supporting the principle of least privilege, helping organizations reduce the risk associated with long-term privileged accounts.

With this new feature, administrators can specify how long a user or security group should remain in a Purview role group, choosing a duration anywhere from one day up to two years. Once the assigned period expires, access is automatically removed, helping security and compliance teams maintain tighter control over administrative permissions.

When Will It Be Available?

Microsoft plans to roll out the feature according to the following schedule:

  • Worldwide General Availability: Starting in late July 2026 and expected to complete by late August 2026.
  • GCC, GCC High, and DoD: Starting in late August 2026 and expected to complete by late September 2026.
What Does This Mean for Organizations?

This enhancement primarily benefits:

  • Microsoft Purview administrators
  • Security administrators
  • Compliance teams
  • Organizations managing role-based access through Microsoft Purview

The feature will be available through:

  • Microsoft Purview Compliance Portal
  • Microsoft Purview Role-Based Access Control (RBAC)
Key Benefits

Once the rollout is complete, administrators will be able to:

✅ Assign users or security groups to role groups with a predefined expiration date.

✅ Set assignment durations ranging from 1 day to 2 years.

✅ Apply the capability to both new and existing role assignments.

✅ Reduce the likelihood of forgotten or unnecessary privileged access.

✅ Improve governance, compliance, and security posture with minimal administrative effort.

Importantly, existing role assignments will not be automatically modified, and end-user workflows will remain unchanged.

What Do You Need to Do?

The good news is that no action is required to enable this feature. It will be available by default once deployed, with no additional configuration or policy changes needed.

However, organizations may want to take advantage of the new functionality by:

  • Reviewing privileged access management processes.
  • Using expiration-based assignments for temporary projects, audits, or administrative tasks.
  • Updating internal documentation and operational procedures.
  • Informing Purview administrators about the new capability.

From a compliance perspective, time-limited role assignments help organizations demonstrate stronger control over privileged access.

Many regulatory frameworks and security standards—including ISO 27001, NIST, SOC 2, GDPR accountability requirements, and Zero Trust security principles—expect organizations to follow the principle of least privilege, ensuring users only have access to the resources they need and only for as long as they need it.