[ ABORT TO HUD ]
SEQ. 1
SEQ. 2
SEQ. 3
Purview AI Hub & Cryptographic Sensitivity Labels
🛡️ Microsoft Purview AI Shield & Deep Governance⏱ 20 min⭐ 200 BASE XP⌨ HANDS-ON LAB
Microsoft Purview AI Shield
The greatest threat in enterprise generative AI adoption is oversharing—when an employee asks Copilot a question and receives sensitive executive compensation or trade secret data because document permissions were misconfigured. Microsoft Purview AI Shield prevents this through:
- Cryptographic Sensitivity Labels: Documents marked Confidential or Secret enforce encryption. If a user lacks the decryption certificate in Entra ID, Copilot's semantic search ignores the document.
- Inherited Labeling: When Copilot generates a Word document or email summarized from a Confidential source, the output artifact inherits the identical sensitivity label automatically.
- Adaptive Protection: Dynamically restricts Copilot grounding when an insider risk alert is triggered on a user account.
⌨ HANDS-ON LABAudit Sensitivity Labels on AI Knowledge Sources
⭐ +200 XPQuery Purview Sensitivity Labels applied to documents indexed by Copilot Studio to verify confidential documents are masked.
1Query sensitivity labels via Microsoft Graph Security API.
OBJECTIVE 1 / 1 — type "hint" if stuck
SYNAPSE VERIFICATION
QUERY 1 // 1
What happens when Microsoft 365 Copilot generates an email based on a Confidential SharePoint document?
The email is converted to public plaintext
The email automatically inherits the 'Confidential' sensitivity label from the source document
The email fails to send and crashes Outlook
The document is deleted from SharePoint