MC1486284 - Microsoft Purview | Data Loss Prevention: Administrative Units support for DLP policies for Microsoft Copilot

Microsoft 365 Message Center announcement MC1486284.

MS Message Center's Summary

Microsoft Purview is introducing Microsoft Entra Administrative Units support for Data Loss Prevention policies applied to Microsoft Copilot and Copilot Chat. Rolling out globally from late October 2026 to early November 2026, this change allows delegated policy management within specific units while preserving existing role based access controls and tenant wide policies. Administrators should review their current directory structure and role assignments to prepare for scoped management capabilities.

Administrator impact
No direct administrator action is required.
End user impact
No direct end user impact is expected.
Importance
3/10: This update introduces new administrative capabilities for Copilot data loss prevention policies without altering existing enforcement or requiring immediate intervention.

Administrative units in Microsoft Purview

Microsoft Purview DLP for Microsoft 365 Copilot and Copilot Chat

Microsoft Summary

Microsoft Purview extends Microsoft Entra Administrative Units support to Copilot DLP policies, enabling delegated management within units while maintaining existing RBAC. Rollout starts late October 2026. No action required; organizations using AUs should review structure and assignments. Tenant-wide policies remain unchanged.

Message Center ID
MC1486284
Category
stay Informed
Severity
normal
Services
Microsoft Purview
Tags
User impact, Admin impact
Published
2026-10-02
Last updated
2026-10-02
Expires
2026-12-05

[What and why] We are extending existing Microsoft Entra Administrative Units (AUs) support in Microsoft Purview Data Loss Prevention (DLP) to DLP policies that apply to Microsoft Copilot and Copilot Chat. This enhancement allows organizations that use Administrative Units to delegate management of supported Copilot DLP policies while maintaining regional, departmental, or regulatory boundaries. This update builds on existing Microsoft Purview role-based access control (RBAC) and Administrative Unit capabilities and does not introduce a new administrative model. [Rollout schedule] Worldwide, GCC, GCC High, DoD: Beginning in late October 2026 and expected to complete by early November 2026 [Impact on your organization] Who is affected Organizations using Microsoft Entra Administrative Units and Microsoft Purview Data Loss Prevention for Microsoft Copilot and Copilot Chat Administrators responsible for managing Microsoft Purview DLP policies for Microsoft Copilot and Copilot Chat Organizations that do not use Administrative Units do not need to change their existing Copilot DLP policies Platforms and services Microsoft Purview Data Loss Prevention Microsoft Copilot Microsoft Copilot Chat Microsoft Entra ID Administrative Units What will happen Administrators scoped to an Administrative Unit will be able to create, view, edit, and delete supported Copilot DLP policies within their assigned Administrative Unit. Administrative Unit scoped administrators will not be able to modify tenant-wide policies. Administrative Unit scoped administrators will not be able to manage policies assigned to other Administrative Units. Existing Microsoft Purview role-based access control permissions continue to apply. Tenant-wide Copilot DLP policies will continue to function as they do today. End users will not experience a new workflow. Copilot interactions will continue to be evaluated against applicable tenant-wide and Administrative Unit scoped DLP policies. Administrative Unit boundaries are determined by the user initiating the Copilot interaction, not by the owner or storage location of referenced content. [Action required and recommendations] No action is required. If your organization plans to use Administrative Units for Copilot DLP policy management, we recommend the following: Review your Microsoft Entra Administrative Unit structure and membership assignments. Review Microsoft Purview role group assignments and ensure administrators are assigned only to the Administrative Units they manage. Review existing tenant-wide Copilot DLP policies before creating Administrative Unit scoped policies. When creating a new DLP policy, select the appropriate Administrative Unit and configure the Microsoft Copilot policy location for eligible users or groups within that Administrative Unit. Licensing requirements for Microsoft Purview DLP and Microsoft Copilot continue to apply. Learn more Administrative units in Microsoft Purview | Microsoft Learn Microsoft Purview DLP for Microsoft 365 Copilot and Copilot Chat | Microsoft Learn [Compliance considerations] Question Answer Does the change modify DLP policies or enforcement? Yes. Administrative Unit scoped administrators gain delegated management capabilities for supported Copilot DLP policies within their assigned Administrative Units. DLP enforcement functionality remains unchanged.