Allow only selected files to be uploaded to the AI ​​service

Mountain Pond 1,716 Reputation points
2026-05-27T23:23:21.62+00:00

Hello, community.

I have a question about blocking file uploads to AI services. I need to allow uploads only for those files that are considered allowed.

I thought I could implement this using labels:

  1. The files will be hosted in SharePoint.
  2. The Auto-labeling policy will assign a label to the file.
  3. Create an Enterprise application & devices policy or Inline web traffic. Specify the conditions in the rules to block file uploads to AI services if the required label is missing.

However, it's possible to create a rule that only blocks file uploads without a label, or vice versa, if a specific label is set, but only with a blocking condition (and I need to allow the opposite).

So, I don't know how to label files that can be allowed to be transferred to AI. I can't yet figure out how to label files and delegate the ability to transfer them to AI and only them.

Trying question. As far as I know, to use Inline Web Traffic, the AI ​​service needs to use SSO with M365. Only then will the app be considered "Managed."

Thank you in advance if you can share a solution. I don't know how to solve this problem yet.

Thank you.

Microsoft Security | Microsoft Purview
0 comments No comments

Answer accepted by question author
Vasil Michev 128.1K Reputation points MVP Volunteer Moderator
2026-05-28T05:30:53.2733333+00:00

Purview DLP supports a "block" condition for labeled files, so it's easy to configure a block for items with specific label. In a nutshell: choose the label(s) you want the policy to apply to, create a new DLP policy scoped only to Copilot, create a rule with the "Content contains > Sensitivity labels" condition, choose the Restrict Copilot from processing content action, configure the rest as needed.

NOT conditions are not supported for Copilot rules, so you cannot use the "opposite" approach.

Here's the relevant documentation: https://learn.microsoft.com/en-us/purview/dlp-microsoft365-copilot-location-learn-about#block-files-and-emails-with-sensitivity-labels-from-being-processed

Was this answer helpful?

1 person found this answer helpful.

1 additional answer

Sort by: Most helpful
  1. AI answer

    2026-05-27T23:23:52.2166667+00:00

    Use a “default deny” approach and then explicitly allow only the labeled content, combining Purview DLP and Defender for Cloud Apps / Network Data Security rather than trying to express both directions in a single rule.

    Key points from the available capabilities:

    1. Label the files that are allowed to go to AI
      • Use Microsoft Purview Information Protection sensitivity labels and auto-labeling on SharePoint so that only files that meet your criteria get a specific label (for example, an “AI-Allowed” label).
      • Everything without that label is implicitly “not allowed”.
    2. Block uploads of unlabeled or disallowed content
      There are two main enforcement paths in the provided material: a. Defender for Cloud Apps session policies (for managed / onboarded apps)
      • In the Microsoft Defender portal, under Cloud Apps → Policies → Policy management, create a Session policy.
      • Under Session control type, select Control file upload (with inspection).
      • Use the file filter Sensitivity label does not equal and select the labels that represent classified or allowed content.
      • Under Actions, select Block. Optionally customize the block message.
        This effectively means: only files with the selected labels are allowed to upload; everything else is blocked.
        (This is the pattern described in “Block upload of unclassified documents in real time.”)
      b. Network Data Security / Inline web traffic (for unmanaged AI apps and non-Microsoft browsers)
      • In the Microsoft Purview portal, create a DLP policy using Inline web traffic or Network Data Security.
      • In the rule conditions, use Content contains → Sensitivity labels and select the labels that represent sensitive or disallowed content, then set the action Restrict browser and network activities → File uploaded to or shared with cloud or AI apps → Block.
      • Alternatively, for a “block unless allowed” model, invert the logic by blocking uploads where Sensitivity label does not equal your “AI-Allowed” label (if available in the rule designer for that scenario).
        The examples in the context show blocking based on sensitive info types and labels, with actions set to Block for file uploads to cloud or AI apps.
    3. Endpoint DLP for copy/paste and uploads from devices
      • Use Endpoint DLP with Devices as the location to block paste and upload operations to AI application websites.
      • Set conditions to detect content containing specific sensitivity labels or sensitive info types and set actions to block paste/upload.
        This ensures that even if users bypass browser controls, uploads of non-allowed content are blocked at the device level.
    4. On “managed” vs “unmanaged” AI apps and Inline web traffic
      • The context shows two patterns:
        • Edge for Business / Browser Data Security: policies apply to text and file uploads to unmanaged AI apps from managed devices.
        • Network Data Security: requires integration with a SASE or secure browser provider and can protect traffic to cloud or AI apps over the network.
      • For apps that are SAML-based and use Microsoft Entra ID SSO, or are onboarded to Defender for Cloud Apps, session controls can be used to block or allow uploads in real time.
      • For truly unmanaged AI apps without SSO, use Browser Data Security (Edge for Business) and/or Network Data Security to enforce the same label-based rules.
    5. Practical design pattern
      • Define a dedicated “AI-Allowed” sensitivity label.
      • Auto-label or manually label only those SharePoint files that are safe to send to AI with this label.
      • In DLP / session / network policies, block uploads to AI apps when Sensitivity label does not equal AI-Allowed (or equivalently, block when content contains any other label or sensitive info types).
      • Run policies in simulation mode first where available, review activity (for example, via DLP activity explorer), then turn them on immediately once tuned.

    This approach gives a clear delegation model: only files explicitly labeled as “AI-Allowed” can be uploaded; everything else is blocked by default, enforced consistently across SharePoint-hosted content, browsers, devices, and network paths.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.