Microsoft Copilot is an AI-powered assistant designed to help users create content, automate routine tasks, and streamline workflows. Copilot is built into core Microsoft products, including Windows, Microsoft 365 apps, and web browsers. It cannot be totally removed from a system, but it can be turned off if users choose not to use the solution.

Users can achieve significant productivity gains by using Copilot effectively. However, the product can introduce security, privacy, and compliance concerns that must be addressed when rolling out the solution in the workplace. The deep integrations of Copilot in Microsoft 365 can exacerbate existing security gaps and put your data at risk.

We are going to look at some of the main security considerations organizations face when deploying Copilot and recommend proactive steps to remediate these potential risks.

Data Access and Excessive Permissions

Copilot inherits a signed-in user’s existing M365 permissions. The tool can access content from connected services, including OneDrive, SharePoint, Exchange, and Teams, that the user has permission to read. This data may include content that a user may never have intentionally accessed, such as shared SharePoint files, documents with overly permissive access controls, and files shared with “Everyone”.

The problem is that over time, data access in M365 environments can become overly permissive for multiple reasons, including:

  • Unnecessarily sharing SharePoint files with a department or organization;
  • Creating files and folders that allow sharing by “Anyone with the link”;
  • Not revoking stale permissions;
  • Failing to apply sensitivity labels for confidential data.

Copilot may return this content in response to prompts, providing data that users should not be able to access.

Companies can take several steps to remediate this problem and control Copilot access to data resources.

  • Teams should conduct a comprehensive review of Microsoft 365 access with a tool such as Microsoft Purview Data Security Posture Management (DSPM) to identify and remediate overshared resources.
  • Sensitivity labels should be applied to all documents that contain confidential, regulated, or restricted data.
  • Group memberships such as “All Staff” should be reviewed and tightened to reduce excessive access to SharePoint files.
  • Organizations should perform regular reviews of SharePoint site access and make the necessary adjustments to protect information assets.

Identity and Authentication

Since Copilot operates in an authenticated M365 session, a compromised identity turns the solution into a powerful tool for threat actors to exploit. Service and shared accounts with Copilot licenses are attractive targets for attackers. These issues pose some significant risks to M365 data. Copilot enables attackers to leverage a compromised account to extract and exfiltrate data much more quickly than through manual means.

Teams should take the following steps to protect their M365 data.

  • Disable Copilot licensing for shared and service accounts.
  • Enforce multi-factor authentication (MFA) for all users with Copilit licenses.
  • Implement Conditional Access policies for Copilot access that require trusted locations and compliant devices.
  • Review and remediate all accounts with legacy authentication protocols that bypass MFA.
  • Enable Microsoft Entra ID Protection to detect and respond to suspicious sign-ins using accounts with Copilot licensing.

Classify and Label Sensitive Data

Companies must use Microsoft Purview sensitivity labels to prevent unauthorized Copilot sessions from accessing restricted data. Copilot does not distinguish between sensitive and non-sensitive data unless it is labeled. Without effective labeling, Copilot can use and share sensitive data with any user.

Businesses must take several steps to protect their sensitive data from misuse by Copilot.

  • Audit all content to identify repositories of sensitive data that require labeling.
  • Implement Microsoft Purview sensitivity labeling that segregates confidential and sensitive data.
  • Enact auto-labeling policies that classify unlabeled content based on content inspection.
  • Configure access policies to restrict Copilot from interacting with confidential content.
  • Label new SharePoint and OneDrive data with default labels.

Protecting Regulated Data

Organizations that process regulated information, such as credit card or healthcare data, must comply with regulatory frameworks like PCI DSS or HIPAA. Copilot accesses data from across the environment and may introduce the following compliance risks.

  • Copilot may expand the secure cardholder data environment (CDE) by adding new paths to regulated data.
  • User interactions with regulated data via Copilot may require PCI DSS documentation.
  • Copilot audit logs must be retained to demonstrate regulatory compliance.
  • User prompts containing personal data must adhere to the principles of data minimization and limitation.

Teams should take steps before deploying Copilot in a regulated environment that include:

  • Conducting a compliance review of Copilot’s data processing activities;
  • Determining if Copilot usage must be disclosed in privacy notices;
  • Disabling specific Copilot features to achieve compliance.

Enable Copilot-Specific Security Features

Several controls provided by Microsoft can manage Copilot security and should be configured before the tool is deployed.

  • Microsoft Purview audit logging for Copilot captures Copilot interaction events, including user prompts and accessed content. Teams can configure log retention to meet compliance requirements.
  • Microsoft Purview Communication Compliance policies can be configured to monitor prompts and responses for policy violations. Teams can define alerts for prompts containing sensitive keywords or regulated data.
  • Companies can restrict SharePont search to prevent Copilot from including sensitive information in its responses.
  • Microsoft Purview DLP policies can be extended to Copilot interactions to restrict the tool from responding to user prompts with sensitive information.

VAST’s M365 Experience Helps You Use Copilot Securely

VAST has extensive experience with M365 and other Microsoft products. Our Microsoft experts can help your business ensure you use Copilot securely and avoid putting sensitive data at risk. The following examples demonstrate how we can enhance M365 security to help you use Copilot more effectively.

  • Our team can review your existing M365 environment and help identify vulnerabilities to address before introducing the Copilot tool.
  • We assist in implementing M365 Conditional Access policies to minimize the chances of data breaches and protect your valuable information.
  • VAST has partnered with Semperis to offer advanced protection for your Microsoft AD and Entra ID environment. This solution offers threat detection and fast and effective recovery in the event of an AD attack.

Talk to our team today and learn more about how we can help secure your environment while you use Copilot to enhance user productivity.