{"id":259,"date":"2026-08-18T20:48:53","date_gmt":"2026-08-19T03:48:53","guid":{"rendered":"https:\/\/gozera.ai\/blog\/?p=259"},"modified":"2026-08-18T20:48:53","modified_gmt":"2026-08-19T03:48:53","slug":"copilot-for-knowledge-exclusions","status":"publish","type":"post","link":"https:\/\/gozera.ai\/blog\/copilot-for-knowledge-exclusions\/","title":{"rendered":"Copilot for Knowledge Exclusions: An Admin&#8217;s Control Guide"},"content":{"rendered":"<\/p>\n<p>To exclude or block a knowledge source in Microsoft 365 Copilot, use <strong>Copilot Studio data policies<\/strong> and <strong>Power Platform admin center<\/strong> controls at the tenant or environment level. For code repositories, use <strong>GitHub Copilot<\/strong> content-exclusion rules, configured either through repository settings or the content exclusion REST API.<\/p>\n<p>Four moves get you there. First, identify the connector or source: SharePoint, Teams, OneDrive, an external web source, or a Git repository. Second, apply a Copilot Studio data policy (for Microsoft 365 sources) or a repository-level content-exclusion rule (for GitHub). Third, test enforcement directly in the client, Copilot Chat for Microsoft 365, or the code editor for GitHub. Fourth, write the policy into your governance playbook so the next admin doesn\u2019t have to reverse-engineer it.<\/p>\n<ul>\n<li>Identify the source and its connector type<\/li>\n<li>Apply the matching data policy or exclusion rule<\/li>\n<li>Test in the actual client, not just the admin console<\/li>\n<li>Document the change and its owner<\/li>\n<\/ul>\n<p><strong>Pro Tip:<\/strong> <em>Don\u2019t treat a data policy as \u201cset and forget.\u201d Connector sync delays mean a policy can look active in the admin center for an hour before it actually blocks retrieval in Copilot Chat.<\/em><\/p>\n<h2 id=\"key-takeaways\">Key Takeaways<\/h2>\n<p>Copilot for knowledge exclusions works reliably only when tenant-level data policies, agent-level knowledge settings, and underlying source permissions are configured together and tested in the actual client.<\/p>\n<table>\n<thead>\n<tr>\n<th>Point<\/th>\n<th>Details<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Layer your controls<\/td>\n<td>Combine Copilot Studio data policies with SharePoint permissions and sensitivity labels rather than relying on one mechanism.<\/td>\n<\/tr>\n<tr>\n<td>Test in the client, not the console<\/td>\n<td>Confirm enforcement with a real prompt in Copilot Chat or the code editor, since admin screens can lag actual behavior.<\/td>\n<\/tr>\n<tr>\n<td>Watch for propagation delays<\/td>\n<td>Allow minutes to hours for policy changes to sync, and retest across desktop, web, and mobile clients.<\/td>\n<\/tr>\n<tr>\n<td>Cover symlinks and remote paths<\/td>\n<td>Content exclusion rules don\u2019t reach symbolic links or remote filesystems, so include them explicitly in test plans.<\/td>\n<\/tr>\n<tr>\n<td>Bring in Gozera for a governance sprint<\/td>\n<td>Gozera runs scoped engagements that pair exclusion policy design with telemetry and license ROI measurement for mid-market firms.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2 id=\"table-of-contents\">Table of Contents<\/h2>\n<ul>\n<li><a href=\"#what-knowledge-sources-can-you-actually-exclude\">What Knowledge Sources Can You Actually Exclude?<\/a><\/li>\n<li><a href=\"#how-do-you-block-a-knowledge-source-with-a-data-policy\">How Do You Block a Knowledge Source With a Data Policy?<\/a><\/li>\n<li><a href=\"#do-connector-permissions-matter-more-than-copilot-policies\">Do Connector Permissions Matter More Than Copilot Policies?<\/a><\/li>\n<li><a href=\"#what-happens-to-citations-and-grounded-answers-after-you-block-a-source\">What Happens to Citations and Grounded Answers After You Block a Source?<\/a><\/li>\n<li><a href=\"#what-limitations-and-edge-cases-should-you-test-for\">What Limitations and Edge Cases Should You Test For?<\/a><\/li>\n<li><a href=\"#how-do-you-confirm-an-exclusion-is-actually-enforced\">How Do You Confirm an Exclusion Is Actually Enforced?<\/a><\/li>\n<li><a href=\"#what-should-a-rollout-checklist-and-sample-policy-look-like\">What Should a Rollout Checklist and Sample Policy Look Like?<\/a><\/li>\n<li><a href=\"#how-do-exclusions-fit-into-broader-copilot-governance\">How Do Exclusions Fit Into Broader Copilot Governance?<\/a><\/li>\n<li><a href=\"#common-deployment-mistakes-weve-seen-and-fast-corrections\">Common Deployment Mistakes We\u2019ve Seen and Fast Corrections<\/a><\/li>\n<li><a href=\"#how-gozera-turns-governance-into-recovered-license-value\">How Gozera Turns Governance Into Recovered License Value<\/a><\/li>\n<li><a href=\"#frequently-asked-questions\">Frequently Asked Questions<\/a><\/li>\n<li><a href=\"#sources\">Sources<\/a><\/li>\n<\/ul>\n<h2 id=\"what-knowledge-sources-can-you-actually-exclude\">What Knowledge Sources Can You Actually Exclude?<\/h2>\n<p>Copilot pulls from a fixed set of connector types, and your exclusion options depend entirely on which one you\u2019re dealing with. Microsoft 365 Copilot draws on <a href=\"https:\/\/learn.microsoft.com\/en-us\/microsoft-copilot-studio\/knowledge-copilot-studio\" rel=\"nofollow noopener noreferrer\" target=\"_blank\">SharePoint, Teams, OneDrive, and other connected sources<\/a> that Copilot Studio classifies into supported knowledge source types for agents. GitHub Copilot works differently: it governs access at the file and path level inside a repository, not through a shared admin surface.<\/p>\n<p>Some surfaces are further along than others. GitHub\u2019s content exclusion feature is generally available on Copilot Business and Copilot Enterprise plans, but <a href=\"https:\/\/docs.github.com\/en\/copilot\/concepts\/context\/content-exclusion\" rel=\"nofollow noopener noreferrer\" target=\"_blank\">certain website and mobile features remain in public preview<\/a>, and some IDE Edit and Agent modes don\u2019t honor exclusion rules yet. If your developers work in one of those modes, assume the exclusion isn\u2019t enforced until you\u2019ve verified it.<\/p>\n<table>\n<thead>\n<tr>\n<th>Source type<\/th>\n<th>Where you configure exclusions<\/th>\n<th>Permission that matters most<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>SharePoint sites\/libraries<\/td>\n<td>Copilot Studio data policy or site permissions<\/td>\n<td>Site-level access, sensitivity label<\/td>\n<\/tr>\n<tr>\n<td>Teams files<\/td>\n<td>Copilot Studio data policy<\/td>\n<td>Team membership, file sharing scope<\/td>\n<\/tr>\n<tr>\n<td>OneDrive<\/td>\n<td>Copilot Studio data policy<\/td>\n<td>File\/folder sharing settings<\/td>\n<\/tr>\n<tr>\n<td>External web sources<\/td>\n<td>Agent knowledge source settings<\/td>\n<td>Connector credential\/API key<\/td>\n<\/tr>\n<tr>\n<td>Connected databases (Copilot Studio connectors)<\/td>\n<td>Environment-level data policy<\/td>\n<td>Connector service account scope<\/td>\n<\/tr>\n<tr>\n<td>Git repositories<\/td>\n<td>Repository settings or REST API<\/td>\n<td>Repo owner or org owner role<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>A quick gut-check before you build anything: if the source isn\u2019t in this table, Copilot Studio probably doesn\u2019t have a native exclusion path for it yet, and you\u2019ll need to control access upstream instead.<\/p>\n<h2 id=\"how-do-you-block-a-knowledge-source-with-a-data-policy\">How Do You Block a Knowledge Source With a Data Policy?<\/h2>\n<p>This is the core mechanic behind copilot for knowledge exclusions at the Microsoft 365 layer, and it runs through two admin surfaces working together: Copilot Studio and the Power Platform admin center.<\/p>\n<p><strong>Prerequisites.<\/strong> You need one of the following roles depending on scope: Power Platform admin (tenant-wide policies), Copilot Studio environment admin (environment-scoped policies), or, for GitHub repos, organization owner or repository admin. Confirm your role before you start; a mid-permission account will let you open the policy screen and then silently fail to save changes.<\/p>\n<p>Here\u2019s the sequence for Microsoft 365 sources:<\/p>\n<ol>\n<li>Open the <strong>Power Platform admin center<\/strong> and navigate to <strong>Policies<\/strong> &gt; <strong>Data policies<\/strong>.<\/li>\n<li>Create a new policy or select an existing one scoped to the environment running your Copilot agents.<\/li>\n<li>Under connector classification, move the target connector, SharePoint, a custom connector, or a specific data group, into the \u201cBlocked\u201d or \u201cBusiness data group\u201d bucket depending on your isolation model.<\/li>\n<li>Switch to <strong>Copilot Studio<\/strong>, open the affected agent, and confirm the connector no longer appears as an available knowledge source under the agent\u2019s knowledge management settings.<\/li>\n<li>If you\u2019re blocking a specific SharePoint site rather than the whole connector, remove or restrict the site ID directly in the agent\u2019s knowledge source list instead of the tenant-wide policy.<\/li>\n<li>Save, then wait for propagation before testing.<\/li>\n<\/ol>\n<p>For GitHub repositories, the pattern is different: exclusion rules live at the repository or organization level, referencing file paths (for example <code>secrets\/**<\/code> or <code>internal-docs\/*.md<\/code>) rather than connectors. Organization owners can manage these manually in repository settings or programmatically through the content exclusion REST API, which supports GET and PUT operations for bulk rule management.<\/p>\n<p>Change control matters here more than most admins expect. Route every data policy change through the same approval chain you use for conditional access policies, and require a named owner who can roll it back. Rollback is simple: remove the connector from the blocked group and re-save. What\u2019s not simple is knowing how long the old, insecure state was live if nobody logged the original change.<\/p>\n<p><strong>Timeline callout:<\/strong> expect a propagation delay of several minutes to a few hours depending on client cache refresh and connector sync cycles. Copilot Chat sessions already open when you push the policy may not reflect it until the user starts a new session.<\/p>\n<p><strong>Pro Tip:<\/strong> <em>Keep a plain-text change log outside the admin center. Policy screens don\u2019t retain history well, and if a client\u2019s connector sync stalls, you\u2019ll want a timestamp to compare against telemetry.<\/em><\/p>\n<p><img decoding=\"async\" src=\"https:\/\/gozera.ai\/blog\/wp-content\/uploads\/2026\/08\/1786984584806_Hand-logging-changes-on-digital-tablet.jpeg\" alt=\"Hand logging changes on digital tablet\"><\/p>\n<h2 id=\"do-connector-permissions-matter-more-than-copilot-policies\">Do Connector Permissions Matter More Than Copilot Policies?<\/h2>\n<p>Often, yes. A Copilot Studio data policy blocks a connector from being <em>offered<\/em> as a knowledge source. It does nothing to change what that connector\u2019s underlying credential is authorized to read. If the service account behind a SharePoint connector has read access to a confidential legal matter site, Copilot Studio policies won\u2019t retroactively fix that exposure; they just stop that particular agent from surfacing it.<\/p>\n<p>That\u2019s why permission hygiene has to come first, not second:<\/p>\n<ul>\n<li>Audit connector service accounts and strip access down to only the sites or libraries the connector actually needs.<\/li>\n<li>Treat sensitivity labels as your primary access filter, not an afterthought layered on top of Copilot settings.<\/li>\n<li>Set explicit SharePoint site permissions before you rely on any Copilot-side blocking mechanism.<\/li>\n<\/ul>\n<p>Firms that skip this step end up in a loop: Copilot Studio blocks a connector, someone builds a workaround agent using a different connector with the same overprivileged credential, and the \u201cblocked\u201d data resurfaces within weeks.<\/p>\n<p><strong>Pro Tip:<\/strong> <em>Fix source permissions and sensitivity labels first. Use Copilot Studio data policies as a second layer of enforcement, not the only layer. If the permission layer is solid, a misconfigured policy is a minor annoyance instead of a data exposure.<\/em><\/p>\n<h2 id=\"what-happens-to-citations-and-grounded-answers-after-you-block-a-source\">What Happens to Citations and Grounded Answers After You Block a Source?<\/h2>\n<p>Once a source is excluded, it should disappear entirely from the model\u2019s context, not just from the visible citation list. <a href=\"https:\/\/github.com\/github\/docs\/blob\/main\/content\/copilot\/concepts\/context\/content-exclusion.md\" rel=\"nofollow noopener noreferrer\" target=\"_blank\">GitHub\u2019s own documentation<\/a> states that excluded content will not inform inline suggestions, Copilot Chat responses, code review, or suggestions generated while working in other files.<\/p>\n<p>Microsoft 365 Copilot behaves similarly for grounding: <a href=\"https:\/\/support.microsoft.com\/en-us\/microsoft-365-copilot\/write-a-great-prompt-in-microsoft-365-copilot\" rel=\"nofollow noopener noreferrer\" target=\"_blank\">referencing specific files in a prompt<\/a> improves how tightly a response is grounded to that content, and Copilot can draw on up to 20 referenced items in Word when they\u2019re explicitly included. Exclude one of those files, and it simply won\u2019t be pulled into that reference set.<\/p>\n<p>Here\u2019s the practical difference: ask a question about an excluded document, and instead of a partial or vague answer, you should get a response that shows no awareness the document exists at all, or an explicit note that no matching source was found.<\/p>\n<blockquote>\n<p>Excluded content isn\u2019t just hidden from the citation list, it\u2019s removed from the model\u2019s working context entirely. If a document still shows up as a reference after you\u2019ve blocked it, your policy hasn\u2019t propagated yet.<\/p>\n<\/blockquote>\n<p>Moderation filters operate independently of data policies. Blocking a source changes what Copilot <em>can see<\/em>; it doesn\u2019t change how Copilot moderates whatever content it\u2019s still allowed to process.<\/p>\n<h2 id=\"what-limitations-and-edge-cases-should-you-test-for\">What Limitations and Edge Cases Should You Test For?<\/h2>\n<p>Exclusion rules have real gaps, and most of them surface during an audit, not during setup.<\/p>\n<p>Symbolic links and remote filesystems are the biggest blind spot. Content exclusions currently do not apply to symlinks or files on remote filesystems, so a symlinked path pointing at excluded content can still be readable. If your firm uses network-mounted drives or symlinked repo structures, this is not a theoretical risk.<\/p>\n<p>A few more gotchas worth building into your test plan:<\/p>\n<ul>\n<li>Some IDE Edit and Agent modes don\u2019t support content exclusion rules yet, meaning a developer switching modes can bypass a rule that works fine elsewhere.<\/li>\n<li>Mobile and web Copilot surfaces are still in public preview for some features, so behavior can differ from the desktop client.<\/li>\n<li>Indirect semantic data, type definitions, hover information, build properties, can leak context even when the source file itself is excluded, because the IDE exposes that metadata separately from the file content.<\/li>\n<li>If you manage rules via the REST API, know that it doesn\u2019t support duplicate keys and will silently drop comments on update, which erases any inline documentation your team relied on.<\/li>\n<\/ul>\n<blockquote>\n<p>Treat exclusions as one control in a layered model, never as the whole model. Symlinks, remote mounts, and IDE metadata all sit outside what a content-exclusion rule actually reaches.<\/p>\n<\/blockquote>\n<h2 id=\"how-do-you-confirm-an-exclusion-is-actually-enforced\">How Do You Confirm an Exclusion Is Actually Enforced?<\/h2>\n<p>Don\u2019t trust the admin console\u2019s green checkmark. Verify it in the client.<\/p>\n<ol>\n<li>Open the excluded file or source with only that item attached to the prompt or context window.<\/li>\n<li>Run a repeatable test prompt, something like \u201csummarize this file\u201d or \u201cwhat does this document say about X.\u201d<\/li>\n<li>Confirm the source doesn\u2019t appear as a reference or citation, and confirm the response itself reflects no awareness of the content.<\/li>\n<li>Repeat the same test from a different client (desktop app, web, mobile) since propagation can lag by surface.<\/li>\n<\/ol>\n<p>For ongoing confidence, watch these signals rather than checking manually every time:<\/p>\n<ul>\n<li>Copilot Studio policy audit logs for confirmation that a policy change was applied and when.<\/li>\n<li>Power Platform policy event logs for propagation timestamps across environments.<\/li>\n<li>GitHub API responses when pulling current exclusion rules, to catch drift between what you think is configured and what\u2019s live.<\/li>\n<li>Client-side sync timestamps, particularly for connectors known to lag.<\/li>\n<\/ul>\n<p>If a test fails and the source is still visible after a reasonable propagation window, don\u2019t keep re-testing blindly. Escalate through your normal Microsoft or GitHub support channel with the exact prompt used, timestamps, the client and version, and screenshots of both the policy configuration and the unexpected response. Vague \u201cit\u2019s not working\u201d tickets take far longer to resolve than ones with a clean repro.<\/p>\n<h2 id=\"what-should-a-rollout-checklist-and-sample-policy-look-like\">What Should a Rollout Checklist and Sample Policy Look Like?<\/h2>\n<p>A rollout that skips documentation is the single most common reason exclusions get reversed by accident six months later, usually by an admin who didn\u2019t know why a connector was blocked in the first place.<\/p>\n<p>Run through this sequence for every new exclusion:<\/p>\n<ol>\n<li>Identify the source and its owner (site owner, repo admin, connector maintainer).<\/li>\n<li>Map who currently depends on that source through Copilot.<\/li>\n<li>Draft a test plan covering normal use, symlink\/remote-path cases, and cross-client checks.<\/li>\n<li>Create the data policy or content-exclusion rule.<\/li>\n<li>Test enforcement using the checklist above.<\/li>\n<li>Document the policy, its owner, and the business reason in your governance playbook.<\/li>\n<li>Notify affected users and monitor telemetry for two to four weeks.<\/li>\n<\/ol>\n<p>A sample policy configuration pattern, using representative field names rather than an exact export, looks like this:<\/p>\n<pre><code>policy_name: block-legal-sharepoint-external\nscope: environment (Production)\nconnector: SharePoint\ndata_group: Blocked\nsite_id: {litigation-site-guid}\napplies_to_agents: all\napproved_by: {governance_owner}\neffective_date: {date}\n<\/code><\/pre>\n<p>Send a short note to affected teams before you flip the switch: name the source being blocked, the reason (client confidentiality, licensing restriction, data residency), and who to contact if it breaks a workflow they rely on.<\/p>\n<p><strong>Pro Tip:<\/strong> <em>File the sample policy pattern and communication template in your governance repository once, then reuse them for every new exclusion. Rebuilding the wheel each time is how documentation quietly stops happening.<\/em><\/p>\n<h2 id=\"how-do-exclusions-fit-into-broader-copilot-governance\">How Do Exclusions Fit Into Broader Copilot Governance?<\/h2>\n<p>Exclusions work best when they\u2019re one piece of a governance program, not a standalone fire drill every time legal flags a concern.<\/p>\n<p>Start by tying exclusion policies directly to your existing SharePoint permission structure and sensitivity label taxonomy. If a site is already labeled \u201cHighly Confidential\u201d and permissioned to a five-person partner group, a Copilot Studio exclusion is redundant, not a first line of defense. Save exclusions for cases where the connector-level access genuinely can\u2019t be scoped tightly enough through permissions alone.<\/p>\n<p>Measurement is where most mid-market firms fall short. Three metrics matter here: Copilot license utilization (are the seats you\u2019re paying for actually being used), blocked-attempt telemetry (how often users hit an excluded source, which tells you whether the exclusion is disrupting real workflows), and task completion rates before and after a governance change. A firm that blocks a source without checking whether it broke a daily workflow for twenty associates will hear about it fast, and usually not in a good way.<\/p>\n<p>Practical operational steps:<\/p>\n<ol>\n<li>Run a dedicated governance sprint rather than handling exclusions ad hoc as complaints arrive.<\/li>\n<li>Assign a named owner for data policies, separate from whoever owns license provisioning.<\/li>\n<li>Build a lightweight exceptions workflow so a user who legitimately needs access to a blocked source has a documented path to request it.<\/li>\n<li>Schedule a quarterly audit of every active exclusion to confirm it\u2019s still justified and still enforced.<\/li>\n<\/ol>\n<p>A short governance sprint from a consulting partner can compress this timeline considerably. Firms sitting on dormant Copilot licenses often discover, once someone actually reviews the <a href=\"https:\/\/gozera.ai\/blog\/microsoft-copilot-telemetry-it-managers-2026-guide\" target=\"_blank\" rel=\"noopener\">telemetry<\/a>, that the low adoption isn\u2019t a training problem. It\u2019s an access and trust problem: users stopped relying on Copilot because it kept surfacing outdated or restricted content, and nobody fixed the underlying permission structure.<\/p>\n<h2 id=\"common-deployment-mistakes-weve-seen-and-fast-corrections\">Common Deployment Mistakes We\u2019ve Seen and Fast Corrections<\/h2>\n<p>The most frequent failure pattern is straightforward: a firm builds a Copilot Studio data policy, confirms it looks right in the admin center, and calls it done. Weeks later, someone discovers the same content still surfacing through a symlinked network path or a connector nobody remembered was still active. The policy wasn\u2019t wrong. It just wasn\u2019t the only door into that data.<\/p>\n<p>The second recurring mistake is skipping documentation on rollback. When a policy causes an unexpected workflow break and gets reverted in a hurry, nobody records why it existed in the first place, so it either gets recreated incorrectly or never gets recreated at all.<\/p>\n<p>Three corrections fix most of this before it becomes a fire drill:<\/p>\n<ul>\n<li>Validate every new connector or exclusion rule in a staging tenant before touching production.<\/li>\n<li>Keep plain-language policy comments in your own change log, since API-based rule updates can silently strip comments from the source system itself.<\/li>\n<li>Run a scheduled audit after every policy change, not just at rollout, since connector syncs and client caches can quietly diverge from what the policy screen shows.<\/li>\n<\/ul>\n<h2 id=\"how-gozera-turns-governance-into-recovered-license-value\">How Gozera Turns Governance Into Recovered License Value<\/h2>\n<p>There\u2019s a version of this work you can do entirely in house: an IT admin builds the data policies, tests enforcement, writes the documentation, and hopes nothing was missed. It works, but it\u2019s slow, and the firms that go this route often discover a symlink gap or an orphaned connector months after go-live, usually because nobody had bandwidth to run the layered testing this guide describes.<\/p>\n<p>Gozera runs this as a scoped, fixed-price engagement instead of an open-ended internal project. A governance sprint covers policy design across Copilot Studio and the Power Platform admin center, enforcement testing against the edge cases most teams miss (symlinks, remote paths, connector credentials), telemetry setup so you can see blocked-attempt patterns instead of guessing, and a plan that ties the whole exercise back to license ROI.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/gozera.ai\/blog\/wp-content\/uploads\/2026\/07\/1783398003486_gozera.jpg\" alt=\"Gozera\"><\/p>\n<p>For a mid-market law, accounting, or consulting firm sitting on Copilot licenses that are only half-adopted, the exclusion work and the adoption work are usually the same root problem. If you want a scoped audit of where your knowledge exclusions and license utilization actually stand, start with a Copilot ROI consultation and get a concrete plan instead of another internal task-list item.<\/p>\n<h2 id=\"frequently-asked-questions\">Frequently Asked Questions<\/h2>\n<p><strong>Can I exclude a single SharePoint folder without blocking the entire site?<\/strong><br \/>\nYes. Scope the exclusion at the agent level in Copilot Studio\u2019s knowledge management settings rather than through a tenant-wide connector policy, and reference the specific library or folder path.<\/p>\n<p><strong>Does GitHub Copilot content exclusion work the same way as Copilot Studio data policies?<\/strong><br \/>\nNo. GitHub content exclusion operates at the file-path level within a repository, using repository settings or the content exclusion REST API, while Copilot Studio data policies block entire connectors or data groups at the environment level.<\/p>\n<p><strong>Will an excluded source still show up in Copilot\u2019s citations?<\/strong><br \/>\nIt shouldn\u2019t. Properly enforced exclusions remove the source from Copilot\u2019s working context entirely, not just from the visible citation list. If a citation still appears, the policy likely hasn\u2019t propagated yet.<\/p>\n<p><strong>Is content exclusion available on every GitHub Copilot plan?<\/strong><br \/>\nIt\u2019s available on Copilot Business and Copilot Enterprise plans, with some features still in public preview for certain website and mobile surfaces.<\/p>\n<p><strong>What\u2019s the biggest mistake firms make when rolling out knowledge exclusions?<\/strong><br \/>\nTreating a Copilot Studio policy as sufficient on its own, without first tightening the underlying SharePoint permissions and sensitivity labels that actually control who and what can read the data.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/gozera.ai\/blog\/wp-content\/uploads\/2026\/08\/1786984703711_Frequently-Asked-Questions-overview-diagram.jpeg\" alt=\"Frequently Asked Questions \u2014 overview diagram\"><\/p>\n<h2 id=\"sources\">Sources<\/h2>\n<p>Tenant-wide data policies set the outer boundary. Agent-level knowledge source settings inside Copilot Studio set the inner one, and for most mid-market firms, the inner boundary is where the real precision lives.<\/p>\n<p>Every agent built in Copilot Studio has a <strong>Knowledge<\/strong> tab where you add, remove, or filter sources independently of what the tenant policy allows. This is where classic orchestration and generative orchestration diverge in practice: classic-mode agents typically reference a fixed, manually curated list of sources, while generative-orchestration agents can dynamically pull from a broader pool unless you explicitly narrow it.<\/p>\n<p>Inside that tab, you\u2019ll see two distinct actions that get confused constantly:<\/p>\n<ul>\n<li><a href=\"https:\/\/github.com\/github\/docs\/blob\/main\/content\/copilot\/concepts\/context\/content-exclusion.md\" rel=\"nofollow noopener noreferrer\" target=\"_blank\">Content exclusion for GitHub Copilot (GitHub docs repo)<\/a><\/li>\n<li><a href=\"https:\/\/docs.github.com\/en\/copilot\/concepts\/context\/content-exclusion\" rel=\"nofollow noopener noreferrer\" target=\"_blank\">Docs<\/a><\/li>\n<li><a href=\"https:\/\/learn.microsoft.com\/en-us\/microsoft-copilot-studio\/knowledge-copilot-studio\" rel=\"nofollow noopener noreferrer\" target=\"_blank\">Knowledge sources summary &#8211; Microsoft Copilot Studio<\/a><\/li>\n<\/ul>\n<p>An environment-level data policy always wins in a conflict. If the tenant policy blocks a connector, the agent-level setting simply won\u2019t show it as available, regardless of what the agent builder tries to configure.<\/p>\n<p>So when do you reach for agent-level controls instead of a tenant policy? Use agent-level scoping when the restriction is specific to one workflow, say, an HR onboarding agent that should never touch the firm\u2019s litigation SharePoint site, even though litigation staff use the same tenant. Use tenant-wide data policies when the restriction applies to everyone, regardless of which agent they\u2019re using, like blocking an entire external web connector firm-wide.<\/p>\n<h2 id=\"recommended\">Recommended<\/h2>\n<ul>\n<li><a href=\"https:\/\/gozera.ai\/blog\/copilot-adoption-services\" target=\"_blank\" rel=\"noopener\">Copilot Adoption Services: Your 2026 Practical Guide<\/a><\/li>\n<li><a href=\"https:\/\/gozera.ai\/blog\" target=\"_blank\" rel=\"noopener\">Zera Consulting \u2013 Microsoft 365 Copilot ROI and adoption insights for mid-market professional services<\/a><\/li>\n<li><a href=\"https:\/\/gozera.ai\/blog\/co-pilot-coaching-microsoft-365\" target=\"_blank\" rel=\"noopener\">Co Pilot Coaching for Microsoft 365: 2026 Guide \u2013 Zera Consulting<\/a><\/li>\n<li><a href=\"https:\/\/gozera.ai\/blog\/microsoft-365-copilot-implementation-guide\" target=\"_blank\" rel=\"noopener\">Microsoft 365 Copilot Implementation Guide for IT Leaders<\/a><\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Master Copilot for knowledge exclusions in Microsoft 365 with our guide. Learn to control access and protect your data seamlessly.<\/p>\n","protected":false},"author":1,"featured_media":260,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-259","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Copilot for Knowledge Exclusions: An Admin&#039;s Control Guide<\/title>\n<meta name=\"description\" content=\"Master Copilot for knowledge exclusions in Microsoft 365 with our guide. Learn to control access and protect your data seamlessly.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/gozera.ai\/blog\/copilot-for-knowledge-exclusions\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Copilot for Knowledge Exclusions: An Admin&#039;s Control Guide\" \/>\n<meta property=\"og:description\" content=\"Master Copilot for knowledge exclusions in Microsoft 365 with our guide. Learn to control access and protect your data seamlessly.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/gozera.ai\/blog\/copilot-for-knowledge-exclusions\/\" \/>\n<meta property=\"og:site_name\" content=\"Zera Consulting\" \/>\n<meta property=\"article:published_time\" content=\"2026-08-19T03:48:53+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/gozera.ai\/blog\/wp-content\/uploads\/2026\/08\/1786984579213_Hands-controlling-admin-device-at-desk.jpeg\" \/>\n\t<meta property=\"og:image:width\" content=\"1080\" \/>\n\t<meta property=\"og:image:height\" content=\"720\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"zeraconsulting\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"zeraconsulting\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"16 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/gozera.ai\\\/blog\\\/copilot-for-knowledge-exclusions\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/gozera.ai\\\/blog\\\/copilot-for-knowledge-exclusions\\\/\"},\"author\":{\"name\":\"zeraconsulting\",\"@id\":\"https:\\\/\\\/gozera.ai\\\/blog\\\/#\\\/schema\\\/person\\\/7777d5b5b3475c673677bf0a07ecb4b0\"},\"headline\":\"Copilot for Knowledge Exclusions: An Admin&#8217;s Control Guide\",\"datePublished\":\"2026-08-19T03:48:53+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/gozera.ai\\\/blog\\\/copilot-for-knowledge-exclusions\\\/\"},\"wordCount\":3411,\"image\":{\"@id\":\"https:\\\/\\\/gozera.ai\\\/blog\\\/copilot-for-knowledge-exclusions\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/gozera.ai\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/1786984579213_Hands-controlling-admin-device-at-desk.jpeg\",\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/gozera.ai\\\/blog\\\/copilot-for-knowledge-exclusions\\\/\",\"url\":\"https:\\\/\\\/gozera.ai\\\/blog\\\/copilot-for-knowledge-exclusions\\\/\",\"name\":\"Copilot for Knowledge Exclusions: An Admin's Control Guide\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/gozera.ai\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/gozera.ai\\\/blog\\\/copilot-for-knowledge-exclusions\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/gozera.ai\\\/blog\\\/copilot-for-knowledge-exclusions\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/gozera.ai\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/1786984579213_Hands-controlling-admin-device-at-desk.jpeg\",\"datePublished\":\"2026-08-19T03:48:53+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/gozera.ai\\\/blog\\\/#\\\/schema\\\/person\\\/7777d5b5b3475c673677bf0a07ecb4b0\"},\"description\":\"Master Copilot for knowledge exclusions in Microsoft 365 with our guide. Learn to control access and protect your data seamlessly.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/gozera.ai\\\/blog\\\/copilot-for-knowledge-exclusions\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/gozera.ai\\\/blog\\\/copilot-for-knowledge-exclusions\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/gozera.ai\\\/blog\\\/copilot-for-knowledge-exclusions\\\/#primaryimage\",\"url\":\"https:\\\/\\\/gozera.ai\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/1786984579213_Hands-controlling-admin-device-at-desk.jpeg\",\"contentUrl\":\"https:\\\/\\\/gozera.ai\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/1786984579213_Hands-controlling-admin-device-at-desk.jpeg\",\"width\":1080,\"height\":720,\"caption\":\"Hands controlling admin device at desk\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/gozera.ai\\\/blog\\\/copilot-for-knowledge-exclusions\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/gozera.ai\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Copilot for Knowledge Exclusions: An Admin&#8217;s Control Guide\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/gozera.ai\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/gozera.ai\\\/blog\\\/\",\"name\":\"Zera Consulting\",\"description\":\"Microsoft 365 Copilot ROI and adoption insights for mid-market professional services\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/gozera.ai\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/gozera.ai\\\/blog\\\/#\\\/schema\\\/person\\\/7777d5b5b3475c673677bf0a07ecb4b0\",\"name\":\"zeraconsulting\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/4ba8b1ba6b449ed5c82c9b2b89716ea683b319e8ca3e9f626179384748b7b775?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/4ba8b1ba6b449ed5c82c9b2b89716ea683b319e8ca3e9f626179384748b7b775?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/4ba8b1ba6b449ed5c82c9b2b89716ea683b319e8ca3e9f626179384748b7b775?s=96&d=mm&r=g\",\"caption\":\"zeraconsulting\"},\"sameAs\":[\"https:\\\/\\\/gozera.ai\\\/blog\"],\"url\":\"https:\\\/\\\/gozera.ai\\\/blog\\\/author\\\/zeraconsulting\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Copilot for Knowledge Exclusions: An Admin's Control Guide","description":"Master Copilot for knowledge exclusions in Microsoft 365 with our guide. Learn to control access and protect your data seamlessly.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/gozera.ai\/blog\/copilot-for-knowledge-exclusions\/","og_locale":"en_US","og_type":"article","og_title":"Copilot for Knowledge Exclusions: An Admin's Control Guide","og_description":"Master Copilot for knowledge exclusions in Microsoft 365 with our guide. Learn to control access and protect your data seamlessly.","og_url":"https:\/\/gozera.ai\/blog\/copilot-for-knowledge-exclusions\/","og_site_name":"Zera Consulting","article_published_time":"2026-08-19T03:48:53+00:00","og_image":[{"width":1080,"height":720,"url":"https:\/\/gozera.ai\/blog\/wp-content\/uploads\/2026\/08\/1786984579213_Hands-controlling-admin-device-at-desk.jpeg","type":"image\/jpeg"}],"author":"zeraconsulting","twitter_card":"summary_large_image","twitter_misc":{"Written by":"zeraconsulting","Est. reading time":"16 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/gozera.ai\/blog\/copilot-for-knowledge-exclusions\/#article","isPartOf":{"@id":"https:\/\/gozera.ai\/blog\/copilot-for-knowledge-exclusions\/"},"author":{"name":"zeraconsulting","@id":"https:\/\/gozera.ai\/blog\/#\/schema\/person\/7777d5b5b3475c673677bf0a07ecb4b0"},"headline":"Copilot for Knowledge Exclusions: An Admin&#8217;s Control Guide","datePublished":"2026-08-19T03:48:53+00:00","mainEntityOfPage":{"@id":"https:\/\/gozera.ai\/blog\/copilot-for-knowledge-exclusions\/"},"wordCount":3411,"image":{"@id":"https:\/\/gozera.ai\/blog\/copilot-for-knowledge-exclusions\/#primaryimage"},"thumbnailUrl":"https:\/\/gozera.ai\/blog\/wp-content\/uploads\/2026\/08\/1786984579213_Hands-controlling-admin-device-at-desk.jpeg","inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/gozera.ai\/blog\/copilot-for-knowledge-exclusions\/","url":"https:\/\/gozera.ai\/blog\/copilot-for-knowledge-exclusions\/","name":"Copilot for Knowledge Exclusions: An Admin's Control Guide","isPartOf":{"@id":"https:\/\/gozera.ai\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/gozera.ai\/blog\/copilot-for-knowledge-exclusions\/#primaryimage"},"image":{"@id":"https:\/\/gozera.ai\/blog\/copilot-for-knowledge-exclusions\/#primaryimage"},"thumbnailUrl":"https:\/\/gozera.ai\/blog\/wp-content\/uploads\/2026\/08\/1786984579213_Hands-controlling-admin-device-at-desk.jpeg","datePublished":"2026-08-19T03:48:53+00:00","author":{"@id":"https:\/\/gozera.ai\/blog\/#\/schema\/person\/7777d5b5b3475c673677bf0a07ecb4b0"},"description":"Master Copilot for knowledge exclusions in Microsoft 365 with our guide. Learn to control access and protect your data seamlessly.","breadcrumb":{"@id":"https:\/\/gozera.ai\/blog\/copilot-for-knowledge-exclusions\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/gozera.ai\/blog\/copilot-for-knowledge-exclusions\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/gozera.ai\/blog\/copilot-for-knowledge-exclusions\/#primaryimage","url":"https:\/\/gozera.ai\/blog\/wp-content\/uploads\/2026\/08\/1786984579213_Hands-controlling-admin-device-at-desk.jpeg","contentUrl":"https:\/\/gozera.ai\/blog\/wp-content\/uploads\/2026\/08\/1786984579213_Hands-controlling-admin-device-at-desk.jpeg","width":1080,"height":720,"caption":"Hands controlling admin device at desk"},{"@type":"BreadcrumbList","@id":"https:\/\/gozera.ai\/blog\/copilot-for-knowledge-exclusions\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/gozera.ai\/blog\/"},{"@type":"ListItem","position":2,"name":"Copilot for Knowledge Exclusions: An Admin&#8217;s Control Guide"}]},{"@type":"WebSite","@id":"https:\/\/gozera.ai\/blog\/#website","url":"https:\/\/gozera.ai\/blog\/","name":"Zera Consulting","description":"Microsoft 365 Copilot ROI and adoption insights for mid-market professional services","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/gozera.ai\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/gozera.ai\/blog\/#\/schema\/person\/7777d5b5b3475c673677bf0a07ecb4b0","name":"zeraconsulting","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/4ba8b1ba6b449ed5c82c9b2b89716ea683b319e8ca3e9f626179384748b7b775?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/4ba8b1ba6b449ed5c82c9b2b89716ea683b319e8ca3e9f626179384748b7b775?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/4ba8b1ba6b449ed5c82c9b2b89716ea683b319e8ca3e9f626179384748b7b775?s=96&d=mm&r=g","caption":"zeraconsulting"},"sameAs":["https:\/\/gozera.ai\/blog"],"url":"https:\/\/gozera.ai\/blog\/author\/zeraconsulting\/"}]}},"_links":{"self":[{"href":"https:\/\/gozera.ai\/blog\/wp-json\/wp\/v2\/posts\/259","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/gozera.ai\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/gozera.ai\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/gozera.ai\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/gozera.ai\/blog\/wp-json\/wp\/v2\/comments?post=259"}],"version-history":[{"count":1,"href":"https:\/\/gozera.ai\/blog\/wp-json\/wp\/v2\/posts\/259\/revisions"}],"predecessor-version":[{"id":263,"href":"https:\/\/gozera.ai\/blog\/wp-json\/wp\/v2\/posts\/259\/revisions\/263"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/gozera.ai\/blog\/wp-json\/wp\/v2\/media\/260"}],"wp:attachment":[{"href":"https:\/\/gozera.ai\/blog\/wp-json\/wp\/v2\/media?parent=259"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/gozera.ai\/blog\/wp-json\/wp\/v2\/categories?post=259"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/gozera.ai\/blog\/wp-json\/wp\/v2\/tags?post=259"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}