Insight · AI Solutions

    How to Exclude Content From Copilot: Stop It Reading Stale or Sensitive Files

    Purview can now archive inactive SharePoint files out of Copilot's index, permanently clean up stale content, and block agents sending data to unsanctioned AI. Which control fits which problem.

    Nick de Vrye, CTOPublished 8 October 20266 min read
    Navy Solv Systems title card reading 'Keep Stale Content Out of Copilot' with a checklist with shield badge motif.

    In Short: How to Exclude Content From Copilot Without Breaking Anything

    Microsoft 365 Copilot answers from whatever the asking user can open. That includes the 2019 pricing deck, the draft policy nobody approved and the HR spreadsheet in the wrong library. Most Copilot answers that go wrong don't involve a security breach. They come from content that should have been archived years ago.

    In September 2026 Microsoft gave Purview administrators better tools to exclude content from Copilot without deleting it. Microsoft's September security update says administrators can now "archive inactive SharePoint content without archiving the entire site", and that the content stays under retention and legal hold "while dropping out of Microsoft 365 Copilot indexing (until reactivated)". The same update covers Priority Cleanup for content that should go entirely, and network DLP that now covers agent traffic.

    This post sorts the controls by problem: stale content, worthless content, sensitive content, sites under review and data leaving the building. It builds on our guide to Purview DSPM for AI, which covers finding oversharing in the first place.

    Stale Content: Archive It Out of Copilot's Index

    The new control is an archive action on Purview retention policies and retention labels for SharePoint. Microsoft Learn describes it plainly: the action "moves supported inactive files to Microsoft 365 Archive while the files remain subject to retention and legal holds", and archived files "remain available for Microsoft Purview eDiscovery and content search but are excluded from Microsoft 365 Copilot indexing".

    The details that matter for planning:

    • It is off by default. Existing retention policies and labels do not archive anything until an administrator adds the archive action.
    • You choose the trigger. The archive period can start when items were created or last modified, and you set how long files stay active first.
    • Licensing. File-level archive requires a Microsoft 365 E5 licence. To get the storage savings of Microsoft 365 Archive, you also set up its pay-as-you-go billing.
    • Users can bring files back. Anyone with read access can reactivate an archived file, and Learn says there is no fee to reactivate one. After reactivation, the file cannot be archived again for 120 days.
    • It is audited. Each archive is logged in the audit log as a FileArchived record.

    This is the right tool for most of the Copilot accuracy problem. The old content is not wrong to keep. It is wrong to search. Archiving keeps your records obligations intact while Copilot stops finding superseded versions. Our post on data quality for AI explains why stale sources produce such confident wrong answers.

    Worthless Content: Priority Cleanup

    Some content has no business value at all. Microsoft's own example is Teams meeting recordings and transcripts, which Learn says "are typically large and have little business value after 1-3 months" but may sit under a retention policy for years.

    Priority Cleanup in Purview Data Lifecycle Management deletes targeted SharePoint and OneDrive files after review and approval, even where retention settings or eDiscovery holds would normally keep them. The permanent deletion option bypasses the recycle bins. After deletion, Learn says the content is "no longer discoverable in SharePoint search, Microsoft 365 Copilot, or eDiscovery". Learn also notes that the public preview rollout of permanent deletion began on 24 August 2026, so check it has reached your tenant.

    The safeguards are strict, and they should be. The policy runs in simulation first, approvers review the items, and a second Priority Cleanup admin has to turn the policy on, because "the last person to edit the policy can't also turn it on". Agree the scope with legal before the first run. Items already copied to an eDiscovery review set are not deleted.

    Sensitive Content: Labels and DLP on the Copilot Location

    Archiving deals with old content. Current sensitive content needs a different control, because the people who can open it often have good reason to.

    Purview DLP has a policy location called Microsoft 365 Copilot and Copilot Chat. With a sensitivity label condition, Copilot and Cowork "don't process the content of the item or use it in the response summary", although the item can still appear in citations. The same location can:

    • Block prompts that contain sensitive information types such as card or passport numbers
    • Stop external web search for prompts containing sensitive data (preview)
    • Exclude email from external senders from grounding, which helps against prompt injection (preview)

    Two limits to note. DLP cannot scan files that users upload directly into a prompt; it checks only the text typed. And the location is only available in the Custom policy template.

    This only works if labels are applied. Microsoft's September update says auto-labeling simulations now support up to 20 million items and up to 50,000 sites through adaptive scopes, which makes labelling the high-risk areas first (finance, HR, legal) more practical. The same thinking applies to structured data: our guide to controlling what Microsoft 365 Copilot can see in Power BI covers the semantic model side.

    Sites Under Review: Restricted Content Discovery

    When you know a site has a permissions problem but have not fixed it yet, Restricted Content Discovery in SharePoint hides its content from organisation-wide search and Copilot responses. It also removes AI entry points from the site, such as the Copilot button and AI actions.

    Microsoft is clear that it is "a temporary governance control". It does not change permissions, it does not work on OneDrive, users can still find content they own or have recently used, and the change takes time to reach search and Copilot. Use it for a few sites while owners fix access, not as a permanent fence.

    Data Leaving the Building: Network DLP for Agents

    The last risk runs in the opposite direction: your data going out to AI tools you have not approved, sent by people or by agents acting for them.

    On 24 September 2026 Microsoft announced that Purview and Entra Global Secure Access network data security is "now generally available" for "human actions and on-behalf-of (OBO) agentic traffic". A Global Secure Access content policy can use Scan with Purview to inspect files and text against your DLP policies and block uploads to unsanctioned AI apps. A Session type condition lets a rule match traffic classified as agent traffic only. You need Entra Internet Access and Purview licensing, and Learn notes that some features in the scenario are still in preview.

    This pairs naturally with agent identity governance through Entra Agent ID: one controls what an agent is, the other what it can send.

    Which Control for Which Problem

    • Out of date but must be kept: archive action on a retention policy or label
    • No value and taking up space: Priority Cleanup, with legal sign-off
    • Current and sensitive: sensitivity labels plus DLP on the Copilot location
    • Permissions under review: Restricted Content Discovery, for weeks rather than years
    • Heading to shadow AI: Global Secure Access with Scan with Purview

    None of these replaces fixing permissions. They make the remaining risk smaller and the answers better. If you are rolling out Copilot Business with usage-based billing switched on, do this work before Cowork starts reading large content sets on your behalf.

    Where Solv Systems Comes In

    We help organisations prepare their Microsoft 365 and Fabric estates for Copilot: retention and archive policies agreed with legal, labelling for the high-risk areas, DLP on the Copilot location and a rollout plan based on evidence. Read more about our data governance services.

    Sources and Further Reading

    Frequently asked

    Add the archive action to a Purview retention policy or retention label for SharePoint. Supported inactive files move to Microsoft 365 Archive, stay under retention and legal hold, remain searchable in eDiscovery, and are excluded from Microsoft 365 Copilot indexing. The action is off by default and file-level archive requires a Microsoft 365 E5 licence.

    Yes. Any user with read access can reactivate an archived file, and Microsoft Learn says there is no fee for reactivating an archived file. After reactivation the file cannot be archived again, manually or by policy, for 120 days.

    A Purview Data Lifecycle Management feature that deletes targeted SharePoint and OneDrive files after review and approval, even where retention settings or eDiscovery holds apply. The permanent deletion option, which bypasses the recycle bins, began its public preview rollout on 24 August 2026. Deleted content is no longer discoverable in SharePoint search, Microsoft 365 Copilot or eDiscovery.

    Create a Purview DLP policy on the Microsoft 365 Copilot and Copilot Chat location with a sensitivity label condition. Copilot and Cowork then do not process the content of labelled items, although the item can still appear in citations. The same location can block prompts containing sensitive information types.

    No. Microsoft describes it as a temporary governance control. It hides a SharePoint site's content from organisation-wide search and Copilot while permissions are reviewed, but it does not change permissions, does not work on OneDrive, and users can still find content they own or recently used.

    Yes, at the network layer. Microsoft announced on 24 September 2026 that Purview and Entra Global Secure Access network data security is generally available for human and on-behalf-of agent traffic. A Global Secure Access content policy can scope rules to agent traffic and use Scan with Purview to block sensitive files and text. Learn notes that some features in the scenario are still in preview.