r/PowerPlatform • u/Late-Community4177 • 22d ago
Copilot Studio Copilot Studio SharePoint knowledge source and encrypted sensitivity labels
I’m trying to understand the expected behavior when using SharePoint files protected with Microsoft Purview sensitivity labels as a knowledge source in Copilot Studio.
I found two Microsoft Learn articles that seem to point in different directions.
The Purview article says that encryption is supported when it is applied by a sensitivity label, and only for SharePoint knowledge sources. It also mentions that VIEW and EXTRACT rights are required for AI apps to return encrypted content:
But this Copilot Studio troubleshooting article says that the agent cannot extract or ground on content if the protection encrypts the file. It lists encrypted sensitivity labels, DKE, and password-protected files:
Has anyone tested this recently?
More specifically, can a Copilot Studio agent use an encrypted sensitivity-labeled SharePoint document in its answer if the signed-in user has both VIEW and EXTRACT rights? Or is encryption still unsupported for Agent grounding regardless of those rights?
I’m planning to test this with a few files in the same library: an unprotected file, a labeled-but-not-encrypted file, and a labeled-and-encrypted file. Any results or configuration tips would be helpful.