Microsoft Edge: Upgraded Copilot new tab page
🚨 The Signal: Microsoft Edge's Copilot new tab page now integrates M365 Copilot chat, web search, and work content. This centralises access to sensitive organisational data and AI interactions, increasing the attack surface for data exfiltration and prompt injection.
The Impact
Users with Copilot licenses are affected, increasing the risk of sensitive data exposure and AI misuse through a consolidated interface.
- Copilot users: Increased risk of accidental data exposure via unified search.
- Copilot users: New avenues for prompt injection attacks through integrated AI chat.
- Security teams: Requires updated monitoring for data exfiltration and AI abuse.
- Admins: Need to review and enforce data loss prevention policies for Edge and Copilot.
The Action
- Review and update Microsoft Purview DLP policies to cover Microsoft Edge and Microsoft 365 Copilot interactions.
- Educate users on secure prompting practices and the risks of sharing sensitive information with AI.
- Monitor Microsoft 365 audit logs for unusual Copilot activity or data access patterns.
- Consider implementing Microsoft Defender for Cloud Apps policies to detect and prevent data exfiltration via Copilot.
- Evaluate the necessity of the Copilot new tab page for all users and disable for those without a clear business need.
Domain: Agentic-AI · Impact: high · Workload: M365 Apps