An illustration shows secure document sharing across devices, with a shield blocking data from reaching cloud AI and analytics services.
Microsoft has widened an existing Purview sensitivity label setting. Labeled files in Word, Excel and PowerPoint can now be kept away from every Microsoft connected experience that analyzes content, not just some of them. Roadmap item 561320 describes the change: the label setting called "Prevent some connected experiences that analyze content" now stops files in those apps from being sent to all of Microsoft's analysis experiences. The setting's old name was more accurate than Microsoft meant it to be. "Some" is now "all," at least in these three apps on supported clients.

The roadmap entry now shows the item as Launched. It lists a May 2026 preview and June 2026 general availability on Windows desktop, Mac, iOS and Android, for Current Channel and Preview release rings. It covers Worldwide (Standard Multi-Tenant), GCC, GCC High and DoD clouds. "Launched" on a roadmap does not mean every endpoint in your tenant has the feature, though. More on that below.

What actually changed​

Microsoft announced the update in Message Center post MC1297982 on May 5, 2026. Office 365 IT Pros reported that Microsoft described the change as one that "extends support of this label setting to additional platforms and extends coverage of the label setting to include all connected experiences that analyze content in Word, Excel, and PowerPoint, rather than a subset of these experiences."

The control has been around for a while. Office 365 IT Pros notes that the BlockContentAnalysisServices setting first appeared in mid-2024 as a solution to mark individual documents that Microsoft 365 Copilot should not process. It started as a niche privacy control for compliance specialists. Copilot made it a mainstream governance tool.

The point admins most need to know: you don't have to do anything for existing labels to get the broader behavior. According to the Message Center text reproduced by M365 Admin, this change applies automatically to existing labels configured with this setting. There is no change to label configuration, and the behavior is enforced by default once the feature rolls out. If you set this up in 2024 to keep Copilot out of a few sensitive document classes, those documents will now also be blocked from other analysis features that used to work. That's good for privacy. Your helpdesk may get some confused calls.

Summary: the same switch now blocks more features. Existing labels with the setting get the wider scope automatically on supported clients.

Which features does "content analysis" include?​

Microsoft's connected-experiences documentation defines this category as experiences that use your Office content to offer design recommendations, editing suggestions, data insights and similar features. Examples it lists include:

  • PowerPoint Designer, Translator and automatic alt text
  • Analyze Data, PivotTable recommendations, Data types and Python in Excel
  • Dictation, Editor, Read Aloud, Text predictions and Transcribe
  • Similarity checker, Smart Lookup and Speaker Coach
  • Automatic or recommended sensitivity labeling, and Purview DLP policy tips
  • Publish to Power BI, Insert data from picture, and Print from the Office mobile apps

Some features still work in a basic local form when content analysis is off. Microsoft's documentation says basic Editor functionality stays available and sends no Editor content to Microsoft. Read Aloud falls back to the device's own text-to-speech when there's no internet connection.

What this setting does not do: it doesn't cut Office off from the network. Microsoft lists separate categories for experiences that download online content (templates, online pictures, cloud fonts, PowerPoint QuickStarter) and other connected experiences (co-authoring, online file storage, Safe Links, version history). This setting is about analysis of labeled content. It is not a general offline mode.

How to configure it in PowerShell​

You won't find this option in the Purview portal. Microsoft's documentation says this configuration isn't available in the Microsoft Purview portal. You must use the PowerShell advanced setting BlockContentAnalysisServices with the Set-Label or New-Label cmdlet after you've connected to Security & Compliance PowerShell. Office 365 IT Pros also criticized the Message Center wording for not telling admins how to find or manage the setting.

Steps:

  1. Connect to Security & Compliance PowerShell with an account that can manage sensitivity labels.
  2. Find the label's GUID. Every label has one, and that is the value you pass to -Identity.
  3. Turn on the advanced setting. This is Microsoft's own example (the GUID belongs to its sample "Confidential\Project Onyx" label, so use your own):

Set-Label -Identity "8faca7b8-8d20-48a3-8ea2-0f96310a848e" -AdvancedSettings @{BlockContentAnalysisServices="True"}

  1. To undo it, Microsoft says to remove the setting or set the value to False, which restores the default where labeled content can be sent for analysis.
  2. Update your end-user documentation. Microsoft recommends this whenever label settings change, and here users will see features greyed out or failing.

You can also apply the setting when creating a new label with New-Label. An earlier Message Center summary carried by M365 Admin notes that the setting requires the built-in labeling client for Microsoft Purview in Office apps; the label setting is not compatible with the legacy Azure Information Protection Add-in. That add-in is retired anyway. Microsoft's labeling documentation says the Office policy "Use the Azure Information Protection add-in for sensitivity labeling" must be Not configured or Disabled, or built-in labeling won't work.

Summary: this is PowerShell only. Use your own label GUID, and roll back by removing the setting or setting it to False.

Version check: "all" depends on the client​

The full behavior depends on which Office build each device runs. Microsoft's documentation says newer Windows clients and all supported Mac and mobile versions apply the setting to every content-analysis experience in Word, Excel and PowerPoint. Its capability table lists "Prevent all connected experiences that analyze content" as rolling out to:

Platform / channelMinimum version (rolling out)
Current Channel (Windows)2606 or later
Monthly Enterprise Channel (Windows)2606 or later
Mac16.110 or later
iOS2.111 or later
Android16.0.20026 or later

"Rolling out" means these are minimum versions, not a promise that every install at that build already has the feature.

Older Windows builds still use the original, narrower behavior. "Prevent some connected experiences that analyze content" applies from version 2406 in Current Channel and Monthly Enterprise Channel, and 2402 in Semi-Annual Enterprise Channel. On those builds the block covers only a subset: automatic alt text, automatic or recommended labeling, Microsoft 365 Copilot, Purview DLP policy tips in Outlook, PowerPoint Designer, Word's Similarity Checker and Translator.

Semi-Annual Enterprise Channel is missing from the "all" row. If your organization runs SAEC on Windows, you should assume those desktops still have the subset behavior. The same label can therefore act differently on a SAEC desktop than on an iPad or a Mac. Check what's actually deployed with your Intune or Configuration Manager inventory before you tell legal and compliance teams that labeled content is fully blocked.

One more detail: Microsoft's labeling documentation says the setting covers Word, Excel, PowerPoint and Outlook for the "all" capability. The roadmap item names only Word, Excel and PowerPoint. Treat Outlook behavior as a separate thing to verify. Don't read this roadmap update as proof that Outlook gets the expanded block.

The Copilot catch​

This setting gets talked about as a Copilot blocker, so the limits matter. Microsoft states that although content with the configured sensitivity label will be excluded from Microsoft 365 Copilot in the named Office apps, the content remains available to Microsoft 365 Copilot for other scenarios. For example, in Teams, and in Microsoft 365 Copilot Chat.

Turning this on keeps Copilot from working on a labeled document while it's open in Word, Excel or PowerPoint. It does not remove that content from Copilot everywhere. Organizations that need a stronger boundary should look at other Purview tools, such as DLP for Microsoft 365 Copilot and encryption-based label rights. That recommendation is based on general industry practice. This roadmap item doesn't establish it.

The setting also turns off things you may want. Microsoft warns that once it's set, some services won't work as designed, such as data loss prevention policy tips for Outlook, automatic and recommended labeling, and Microsoft 365 Copilot. So a label meant to protect your most sensitive files can also switch off the automatic labeling that helps users classify files in the first place. You'll need to plan around that.

Organizations using Double Key Encryption get a similar effect without the setting. M365 Admin notes that files and emails protected with DKE will automatically prevent content in use from being sent to analysis services.

Who should care, and what to do now​

Regulated industries, legal teams, M&A project rooms and anyone with "please don't let the AI read this" folders will welcome the change. One label now covers features like Python in Excel, Analyze Data and Dictation that the old subset never touched. The downside is that users working with heavily labeled files will lose more features than before, and the setting's name still says "some."

A short plan:

  • Audit: use Get-Label in Security & Compliance PowerShell to find every label that has BlockContentAnalysisServices set to True. Those labels now block more features on updated clients.
  • Check versions: compare your Office channels and builds with the table above, paying particular attention to Semi-Annual Enterprise Channel devices.
  • Test workflows: try Copilot, Designer, Analyze Data, dictation and automatic labeling on a labeled test file across Windows, Mac and mobile.
  • Brief the helpdesk: greyed-out buttons on labeled files are now expected, not a bug.
  • Describe it accurately: this is a per-label control on content analysis in specific Office apps. It doesn't block Copilot tenant-wide and it doesn't take Office offline.

Microsoft has made this label setting much broader without changing its name or adding it to the portal. If your users suddenly can't use PowerPoint Designer on a "Highly Confidential" deck, this setting is the likely cause.

 

References

  1. Microsoft Purview: Use sensitivity labels to block all connected experiences that analyze content in Word, Excel, and PowerPoint Microsoft 365 Roadmap 2026-10-06T22:56:31.053213Z
  2. Manage Sensitivity Labels in Office Apps | Microsoft Learn learn.microsoft.com
  3. RM561320 - Microsoft Purview: Use sensitivity labels to block all connected experiences that analyze content in Word, Excel, and PowerPoint | Microsoft 365 Message Center Archive mc.merill.net