Copilot was already running. A selection of employees used it every day. Then the organization hit the brakes: no broader rollout until sensitivity labels were in place for everyone. That’s where I came in. This session tells the story of that assignment. It’s not only about sensitivity labels, but also about DLP and retention labels. Customer information, employee files and project documentation all sat side by side in Microsoft 365, within Copilot’s reach for anyone with access. I share the approach we followed, from the first workshop to the go/no-go moment, and what we ran into along the way. Like encrypted labels that worked fine internally but broke as soon as external parties got involved. The technology was only half the work. Employees needed to know which label to pick and why, so adoption got as much attention as configuration. Managers and the security team needed to see whether labels were actually used and where the risks were, so monitoring and reporting were part of the plan from day one. In parallel we delivered a new set of retention labels, both to stay compliant and to keep Copilot away from outdated information. We also set up DLP in monitoring mode, to see which sensitive data and labels show up in Copilot interactions before blocking anything. You’ll leave with the plan, the pitfalls and an honest list of what I’d do again and what I’d never do again.
Jasper Oosterveld, a Microsoft MVP and Data Security Consultant based in the Netherlands, works at Rubicon with clients to implement Microsoft Purview and Microsoft 365. Jasper is passionate about sharing his expertise and enthusiasm for Microsoft products.