Troubleshooting: Control 1.14 - Data Minimization and Agent Scope Control
Last Updated: January 2026
Common Issues
| Issue | Cause | Resolution |
|---|---|---|
| DLP policy not blocking connector | Policy not applied to environment | Verify environment scope in policy |
| Agent accessing unauthorized data | Knowledge source too broad | Narrow to specific folder |
| Scope change not alerting | Alert policy misconfigured | Verify audit log and alert settings |
| Access review incomplete | No clear ownership | Assign reviewer responsibility |
| Cannot restrict existing connector | Active flows using connector | Migrate flows before blocking |
Detailed Troubleshooting
Issue: DLP Policy Not Blocking Connector
Symptoms: User can add blocked connector despite DLP policy
Diagnostic Steps:
-
Verify policy applies to the environment:
PPAC > Policies > Data policies Check environment is in policy scope -
Check connector classification:
- Verify connector is in "Blocked" category
-
Check for policy exceptions
-
Verify policy is active (not in test mode)
Resolution:
- Add environment to policy scope
- Move connector to Blocked category
- Remove any exceptions allowing the connector
- Wait 15 minutes for policy propagation
Issue: Agent Accessing Data Outside Approved Scope
Symptoms: Agent retrieves content from unauthorized locations
Diagnostic Steps:
-
Review knowledge source configuration:
Copilot Studio > Agent > Knowledge List all configured sources -
Check SharePoint permissions:
- Agent service account may have broader access
-
Inherited permissions may grant unintended access
-
Review connector permissions (OAuth scopes)
Resolution:
- Narrow knowledge source to specific folder path
- Create dedicated SharePoint group with limited permissions
- Remove agent from groups with broader access
- Review and reduce OAuth scopes
Issue: Scope Change Alert Not Firing
Symptoms: Changes to agent data sources not generating alerts
Diagnostic Steps:
-
Verify audit logging is enabled:
Purview > Audit > Audit log search Search for recent connector changes -
Check alert policy configuration:
- Correct activities selected
- Correct users/service accounts included
-
Notification recipients configured
-
Test alert with manual trigger
Resolution:
- Enable audit logging if disabled
- Update alert policy with correct activities
- Add service accounts to alert scope
- Verify email delivery for notifications
Issue: Cannot Complete Access Review
Symptoms: Access review process stalled or incomplete
Diagnostic Steps:
- Identify review owner and deadline
- Check if inventory is current
- Verify reviewer has authority to make decisions
Resolution:
- Assign clear ownership for each agent
- Provide reviewer with current inventory
- Establish escalation for stalled reviews
- Document review decisions even if "no change"
How to Confirm Configuration is Active
DLP Policy
- Navigate to PPAC > Policies > Data policies
- Open policy and verify environment is included
- Confirm connector classifications are correct
- Test by attempting to add blocked connector
Knowledge Source Scoping
- Open Copilot Studio > Agent > Knowledge
- Verify each source shows specific path
- Test agent cannot access content outside scope
Scope Change Monitoring
- Make a test change (add connector)
- Verify audit event appears in Purview
- Confirm alert notification received
Escalation Path
If issues persist after troubleshooting:
- Power Platform Admin - DLP and connector configuration
- SharePoint Admin - Site permissions and access groups
- Purview Compliance Admin - Audit logging and alerts
- AI Governance Lead - Policy decisions and access review
Known Limitations
| Limitation | Impact | Workaround |
|---|---|---|
| DLP 15-minute propagation | Policy changes not immediate | Plan ahead for changes |
| No granular knowledge permissions | Folder-level only, not file-level | Organize content appropriately |
| Connector audit limited | Some connector activities not logged | Supplement with manual review |
| No automated access review | Manual process required | Create calendar reminders |
| OAuth scope visibility | Scopes may not be clearly displayed | Review connector documentation |
Back to Control 1.14 | Portal Walkthrough | PowerShell Setup | Verification Testing