MC1486284Microsoft Purview | Data Loss Prevention: Administrative Units support for DLP policies for Microsoft Copilot
Summary
Microsoft Purview extends Microsoft Entra Administrative Units support to Copilot DLP policies, enabling delegated management within units while maintaining existing RBAC. Rollout starts late October 2026. No action required; organizations using AUs should review structure and assignments. Tenant-wide policies remain unchanged.
More information
What and why
We are extending existing Microsoft Entra Administrative Units (AUs) support in Microsoft Purview Data Loss Prevention (DLP) to DLP policies that apply to Microsoft Copilot and Copilot Chat. This enhancement allows organizations that use Administrative Units to delegate management of supported Copilot DLP policies while maintaining regional, departmental, or regulatory boundaries.
This update builds on existing Microsoft Purview role-based access control (RBAC) and Administrative Unit capabilities and does not introduce a new administrative model.
Rollout schedule
- Worldwide, GCC, GCC High, DoD: Beginning in late October 2026 and expected to complete by early November 2026
Impact on your organization
Who is affected
- Organizations using Microsoft Entra Administrative Units and Microsoft Purview Data Loss Prevention for Microsoft Copilot and Copilot Chat
- Administrators responsible for managing Microsoft Purview DLP policies for Microsoft Copilot and Copilot Chat
- Organizations that do not use Administrative Units do not need to change their existing Copilot DLP policies
Platforms and services
- Microsoft Purview Data Loss Prevention
- Microsoft Copilot
- Microsoft Copilot Chat
- Microsoft Entra ID Administrative Units
What will happen
- Administrators scoped to an Administrative Unit will be able to create, view, edit, and delete supported Copilot DLP policies within their assigned Administrative Unit.
- Administrative Unit scoped administrators will not be able to modify tenant-wide policies.
- Administrative Unit scoped administrators will not be able to manage policies assigned to other Administrative Units.
- Existing Microsoft Purview role-based access control permissions continue to apply.
- Tenant-wide Copilot DLP policies will continue to function as they do today.
- End users will not experience a new workflow.
- Copilot interactions will continue to be evaluated against applicable tenant-wide and Administrative Unit scoped DLP policies.
- Administrative Unit boundaries are determined by the user initiating the Copilot interaction, not by the owner or storage location of referenced content.
Action required and recommendations
No action is required.
If your organization plans to use Administrative Units for Copilot DLP policy management, we recommend the following:
- Review your Microsoft Entra Administrative Unit structure and membership assignments.
- Review Microsoft Purview role group assignments and ensure administrators are assigned only to the Administrative Units they manage.
- Review existing tenant-wide Copilot DLP policies before creating Administrative Unit scoped policies.
- When creating a new DLP policy, select the appropriate Administrative Unit and configure the Microsoft Copilot policy location for eligible users or groups within that Administrative Unit.
Licensing requirements for Microsoft Purview DLP and Microsoft Copilot continue to apply.
Learn more
- Administrative units in Microsoft Purview | Microsoft Learn
- Microsoft Purview DLP for Microsoft 365 Copilot and Copilot Chat | Microsoft Learn
Compliance considerations
| Question | Answer |
| Does the change modify DLP policies or enforcement? | Yes. Administrative Unit scoped administrators gain delegated management capabilities for supported Copilot DLP policies within their assigned Administrative Units. DLP enforcement functionality remains unchanged. |