Microsoft 365 Copilot: Planner capabilities in Copilot chat
🚨 The Signal: Microsoft 365 Copilot Chat gains Planner integration, allowing users to create, view, and manage tasks via natural language. This expands Copilot's data access and action capabilities, increasing the attack surface for prompt injection and unauthorized task manipulation.
The Impact
Copilot users are affected by expanded AI capabilities, increasing the risk of prompt injection and unauthorized data modification if not properly governed.
- Copilot users: Increased risk of prompt injection leading to unauthorized task creation or modification.
- Security teams: Need to monitor Copilot interactions for anomalous Planner activity.
- Data owners: Potential for unintended data changes in Planner via AI actions.
- Compliance teams: Review existing policies for AI-driven data manipulation and access.
The Action
- Review and update internal policies for Copilot usage, specifically regarding task creation and modification.
- Educate users on secure prompting practices to mitigate prompt injection risks.
- Monitor Microsoft 365 audit logs for unusual Planner activity originating from Copilot.
- Assess existing Planner permissions to ensure least privilege is maintained for all users interacting via Copilot.
Domain: Agentic-AI · Impact: high · Workload: M365 Apps