Yes. Agent Builder knowledge sources have file-specific restrictions that can block a PDF even when the file is still usable elsewhere in Microsoft 365 Copilot.
The conditions documented for embedded files in Agent Builder are:
- Sensitivity label with Microsoft Purview Double Key Encryption (DKE) enabled
The file can be embedded but isn’t used as knowledge. - Sensitivity label with user-defined permissions enabled
The file uploads, but agent creation fails without an error message. - Sensitivity label where extract rights are disabled for the user
The file uploads, but agent creation fails without an error message. - Sensitivity label from another tenant with encryption enabled
The file can be embedded but isn’t used as knowledge. - Password-protected files
The builder sees an error message next to the uploaded file.
Based on the symptoms described:
- the PDF is not password protected,
- a newly created test PDF is accepted,
- the rejected files show a tooltip mentioning sensitivity labels,
The most likely cause is that those specific PDFs have a sensitivity-label or encryption condition that Agent Builder blocks for embedded knowledge, even though the files remain searchable or readable in Copilot Chat.
Also, Agent Builder has separate handling for embedded file knowledge. Uploaded files are stored in tenant-owned SharePoint Embedded containers, and Copilot uses only the text content of those files for grounding. That means Agent Builder ingestion is not just a general “Copilot Chat can read it” path.
For diagnostics, the documented behavior is limited:
- some blocked conditions fail without an error message,
- password-protected files show an error next to the file,
- the Share screen shows the sensitivity label if labels are set on embedded content.
No richer end-user diagnostic log is documented in the provided material beyond the UI behavior and support workflow.
A practical way to isolate the cause is:
- Compare a rejected PDF with the new test PDF that uploads successfully.
Focus on whether the rejected files have a sensitivity label, encryption, user-defined permissions, disabled extract rights, or came from another tenant. - If the rejected PDFs have any of those label/encryption conditions, remove or replace those files for Agent Builder knowledge use.
The documented guidance is to avoid uploading files with DKE, remove files with user-defined permissions, remove files with extract rights disabled, and avoid encrypted labeled files from another tenant. - If the issue must be escalated, use Send feedback inside Microsoft 365 Copilot and include:
- that the issue is related to Agent Builder in Microsoft 365 Copilot
- agent ID
- tenant ID
- environment ID
- session ID
- if relevant to the Agent preview pane or Describe tab, enter
/debugin the chat box and include that output
About a recent service change or incident: no service-change explanation is documented in the provided material. Only the known embedded-file restrictions and support path are documented.
One more important limitation: Microsoft Purview Information Barriers aren’t supported on embedded files. Any user who can access the agent can see responses grounded in that embedded content.
References: