Copilot Studio – Upcoming updates to Data Loss Prevention policy enforcement [MC973179]

Copilot Studio – Upcoming updates to Data Loss Prevention policy enforcement [MC973179]

Message ID: MC973179

We are updating how we enforce Data Loss Prevention (DLP) policies in Copilot Studio. Currently, enforcing DLP policies is a two-step process. A DLP policy must first be created in the Power Platform admin center (PPAC) for your tenant and then you must opt-in to enforce the DLP policy to copilots in your tenant using PowerShell commands, which allows three different enforcement levels:

  • Disabled. This is the default mode and no DLP checks are enforced for published bots or when updates are made to existing bots.
  • Soft-Enabled. This mode allows published bots to continue to run without enforcing any DLP policies but prevents any further updates to bots that are affected by DLP blocks.
  • Enabled. This mode enforces DLP policy checks for running bots and for updates made to existing bots.

How does this affect me?
We will be transitioning the default enforcement level from Disabled to Enabled in a two-stage process.

Beginning in January 2025, the default mode for all tenants will be changed to Soft-Enabled. Following this change, published bots will continue to run and DLP checks will be enforced when publishing updates to bots. We will also be removing the option to change the enforcement mode back to Disabled in PowerShell.

Finally, in February 2025, the default mode for all tenants will be changed to Enabled. Following this change, all published bots and any updates made to existing bots will be subject to DLP policies as defined within your tenant. We will also be removing the PowerShell commands to change the enforcement level.

What do I need to do to prepare?
We recommend updating your DLP policy enforcement level to Enabled prior to the planned updates outlined above. If you need additional time to make these updates beyond the planned enforcement change in February 2025, please contact Microsoft Support to apply for a temporary exception to these changes.

Source: Microsoft

Show 1 Comment

1 Comment

  1. Mike Rosoft

    The upcoming updates to Data Loss Prevention (DLP) policy enforcement in Copilot Studio are set to create significant ripples for both admins and users alike. With the transition from a two-step enforcement process to a more streamlined approach, we can expect a smoother operation, albeit with a few adjustments along the way.

    For admins, the shift to a default enforcement level of Soft-Enabled in January 2025, followed by the full transition to Enabled in February, means a little less wiggle room. Gone will be the days of toggling the enforcement mode back to Disabled via PowerShell commands. This change will require admins to be proactive in updating their DLP policies, ensuring that all bots are compliant before the hard deadline. It’s a bit like preparing for a surprise inspection—best to tidy up your DLP policies now rather than later!

    On the user side, the impact is equally significant. With DLP checks being enforced for published bots and updates, users can expect a more secure environment. This means fewer surprises when attempting to deploy updates, as DLP policies will now be actively enforced. While this may seem restrictive at first, it ultimately fosters a safer digital workspace, where data integrity is prioritized. It’s like having a strict but well-meaning guardian watching over your digital playground!

    Overall, the changes are poised to enhance security while requiring a bit of adjustment from both sides. The impact will likely be profound, as organizations will need to adapt to these new norms. So, let’s embrace this opportunity to tighten up our data protection efforts—after all, a little diligence now can save us from a lot of headaches later!

    What are your thoughts on these updates? Do you think they’ll make a positive difference, or are there concerns you’d like to share? Let’s keep the conversation going! And for more insights, don’t forget to check out additional posts on mwpro.co.uk!

Leave a Reply

Your email address will not be published. Required fields are marked *