MC1478467Microsoft Purview | Data Loss Prevention: Admin-configurable compliance URL in M365 Copilot data access messages
Summary
Microsoft Purview DLP now lets admins configure the destination URL for the "Learn about access restrictions" link in Microsoft 365 Copilot data access messages. This directs users to organization-specific compliance guidance instead of Microsoft's public documentation. The feature rolls out worldwide in late September 2026 and requires admin configuration.
More information
What and Why:
We are introducing a new Microsoft Purview Data Loss Prevention (DLP) capability that allows administrators to configure the destination URL for the Learn about access restrictions link displayed in Microsoft 365 Copilot data access messages. This enhancement enables organizations to direct users to internal compliance guidance, data governance resources, or support content that is specific to their organization, while maintaining a consistent and localized user experience. This supports enterprise-ready AI by helping organizations provide policy-specific guidance when DLP policies restrict Copilot access to content.
Today, when a Microsoft Purview DLP policy prevents Microsoft 365 Copilot from grounding on, processing, or returning content, users receive a message explaining that the content was restricted by an organizational policy, together with a Learn about access restrictions link to Microsoft's public DLP documentation. With this update, organizations can direct that link to a compliance URL of their own, such as an internal data-handling policy page, data governance portal, or help desk request form, so users are connected to guidance that is specific to their organization.
The message wording and the link label remain standardized, Microsoft-controlled, and localized. Only the destination of the link changes. Administrator-authored message text is not part of this release.
Rollout Schedule:
- General Availability (Worldwide): Beginning in late September 2026 and expected to complete by late September 2026
- General Availability (GCC, GCC High, DoD): Beginning in late September 2026 and expected to complete by mid-October 2026
Impact on Your Organization:
Who is affected
- Organizations using Microsoft Purview DLP policies that apply to Microsoft 365 Copilot
- Microsoft Purview administrators who manage DLP policies
- Users who encounter DLP-enforced access restrictions in supported Microsoft 365 Copilot experiences
Platforms/Services
Microsoft 365 Copilot
- copilot.microsoft.com
- Microsoft365.com
- Teams (Copilot app)
- Copilot mobile app
- Copilot Search
- Copilot Pages
Microsoft Teams
- Copilot in Chat (1:1 and group)
- Copilot in Meetings (live)
- Meeting Recap (post-meeting)
- Copilot in Channels
- Copilot in Calls
Outlook on the web
- Web Copilot pane (chat)
Microsoft Edge
- Copilot sidebar (any webpage)
- Edge web-mode chat
What will happen
- Administrators can configure a compliance URL on supported Microsoft Purview DLP rules.
- If a DLP rule with a configured compliance URL blocks a Copilot interaction, the Learn about access restrictions link opens the configured organizational URL.
- If no compliance URL is configured, the link continues to open Microsoft's existing public DLP documentation.
- Organizations that do not configure a compliance URL will experience no change in behavior.
- When multiple DLP rules or policies match the same Copilot interaction, Microsoft Purview selects a single winning policy tip using policy priority and the most restrictive action.
- Only the compliance URL from the winning rule is displayed to the user. URLs from non-winning rules are not shown.
- This setting applies only to Microsoft Purview DLP restrictions.
- Organization-specific link resolution for other access control technologies is not included in this release.
- Message wording and link labels remain Microsoft-controlled and localized.
- Administrator-authored message text is not included in this release.
- Existing DLP enforcement behavior is unchanged.
- The feature is not enabled automatically. Administrators must configure a compliance URL on a DLP rule for users to see an organization-specific destination.
Image 1 - User experience showing a Microsoft 365 Copilot data access message with the Learn about access restrictions link:

Image 2 - Microsoft Purview DLP rule configuration showing the compliance URL setting under User notifications:

Action Required / Recommendations:
No action is required if you want users to continue using the default Microsoft documentation link.
To direct users to organization-specific guidance:
- Identify Microsoft Purview DLP policies that apply to the Microsoft 365 Copilot location.
- In the Microsoft Purview portal, edit the appropriate DLP rule.
- Expand User notifications.
- Turn on Policy tips.
- Select Provide a compliance URL for the end user to learn more about your organization's policies.
- Enter the URL you want users to open.
We also recommend that you:
- Verify that the configured URL is accessible to all users targeted by the DLP policy. Microsoft Purview validates the format of the URL, but it does not test whether the destination is reachable.
- Test the destination URL before deployment.
- Review DLP policy priority settings because only the winning rule's compliance URL is displayed when multiple rules match.
- Update internal help desk documentation, FAQs, and governance resources if users will be redirected to internal guidance.
- Communicate the change to compliance, governance, and support teams.
Learn more
Compliance Considerations
| Question | Answer |
| Does the change include an admin control, and can it be controlled through Entra ID group membership? | The feature includes an administrator-configurable compliance URL setting on individual Microsoft Purview DLP rules. |