Microsoft Purview
Make your tenant's sensitivity labels the data-protection rule on every workbench, ask Purview itself before a prompt leaves, and apply encrypting labels through SharePoint.
Your organisation already says what is Confidential and what is Highly Confidential: in Microsoft Purview, as sensitivity labels on files and mail. Connect AIOE to Purview and those labels become the rule every workbench follows. A labelled file decides where its contents may go, text that carries a label's marking is caught when someone pastes it into a prompt, Purview's own data loss prevention policies can judge a prompt before it goes to a hosted model, and every decision shows up in Purview's Activity explorer beside Copilot's.
Self-hosted only, after Agent 365
AIOE reads Purview as your Agent 365 blueprint, so connect Agent 365 first. Mojo Up AI Cloud organisations have no tenant of their own, so the panel is not offered there. Workbenches need AI Workbench 0.52.0 or later.
What you get
| In Purview | What AIOE does |
|---|---|
| Sensitivity labels | Read every hour with each label's markings (the header, footer and watermark text it stamps) and published to every workbench. A label on a file (Office, PDF, the Windows information-protection stream) decides whether its contents may reach a hosted model; marked text pasted into a prompt counts as that label. |
| Your order of labels | Each label's sensitivity (Public, Internal, Confidential, Restricted) starts from its place in your tenant's order. You change any one where your organisation sees it differently, add a partner tenant's label by hand, and write rules that allow, ask or block by label or sensitivity. |
| DLP policies for AI apps | With Ask Purview itself on, a workbench asks before a prompt goes to a hosted model whether the person is in scope and what Purview makes of the prompt. Block stops it, warn tells the person. AIOE never keeps the text. |
| Activity explorer and DSPM for AI | Every label and data-protection decision a machine reports is sent to Purview as content activity: the action, the label, the person, never the content. |
| Labels that encrypt | A label that encrypts cannot be applied on a machine. With the SharePoint route on, the workbench sends the file to AIOE, which puts it in a library you choose, applies the label, reads the protected file back and hands it over. Both copies are gone minutes later unless you keep the SharePoint one. |
Set it up
Grant the permissions
In the Entra admin centre, add Microsoft Graph application permissions and grant admin consent. The first four go on the Agent 365 blueprint's registration; the file permission goes on the AIOE API application's, because Entra refuses file permissions to a blueprint:
| Permission | On | For |
|---|---|---|
InformationProtectionPolicy.Read.All | the blueprint | reading the labels and their markings |
ProtectionScopes.Compute.User | the blueprint | whether a person's prompts are in scope of a DLP policy |
Content.Process.User | the blueprint | Purview's verdict on a prompt |
ContentActivity.Write | the blueprint | reporting activity |
Files.ReadWrite.All | the AIOE API application | the SharePoint route (Microsoft meters this call); Sites.Selected with write on the chosen site does instead |
The panel names the AIOE API application and its consent link grants permissions already on the blueprint's registration.
Connect
Open Settings, Microsoft Purview, and Connect. AIOE proves the connection by reading your labels. A refusal names the missing permission and keeps nothing.
Map the labels
Each label shows its markings, whether it encrypts, and a sensitivity marked "by order" until you choose one. Change the ones your organisation sees differently; the mapping survives re-reads. Say what an unknown label and another tenant's label count as (Confidential and Restricted by default).
Choose what more Purview does
Add rules (label:Highly Confidential or sensitivity:restricted, then allow, ask or block). Turn on Ask Purview itself for prompts, or for prompts and agent requests, once a DLP policy for AI apps names the blueprint as its location; tick Stop the prompt when Purview cannot answer if you want it closed by default. Turn on the SharePoint route and set a site; AIOE creates the folder in the site's default library.
What a person sees
On a workbench, a file under a label the policy keeps home is read by local models only, and a hosted request that would carry it is held, redacted or refused as the mapping says. Pasted text that carries a marking is treated as that label. When Purview blocks a prompt, the person sees Purview's own policy tip. For a label that encrypts, the workbench offers to apply it through SharePoint and shows the job's progress.
Disconnecting
Disconnect forgets the connection; the next policy refresh takes the labels off every workbench. Partner labels and mappings are forgotten with it.
Related
- Microsoft Agent 365: the blueprint AIOE reads Purview as.
- Policy: the data-protection section the labels land in.
- Audit: every connect, mapping, location and applied label is a
purview.*entry.