Simplified access to Copilot Chat on the Microsoft 365 Copilot mobile app

🚨 The Signal: Microsoft is removing two legacy mobile controls (Intune policy and privacy setting) that previously restricted Copilot Chat access on mobile devices. This change unifies the Copilot Chat experience across all platforms, potentially expanding AI access for users previously restricted on mobile.

The Impact

Users previously restricted on mobile devices will gain Copilot Chat access, increasing the attack surface for data leakage via AI interactions.

  • Security Teams: Increased risk of sensitive data exposure through Copilot Chat on mobile.
  • Admins: Existing mobile device management policies for AI access may be bypassed.
  • End Users: Unrestricted access to Copilot Chat on mobile, potentially leading to inadvertent data sharing.

The Action

  1. Review existing Intune App Protection Policies (APP) and App Configuration Policies (ACP) for Microsoft 365 Copilot mobile app.
  2. Evaluate alternative controls within Intune or Microsoft Purview to restrict Copilot Chat access on mobile if required.
  3. Communicate updated Copilot Chat usage policies and data handling guidelines to end-users, emphasizing mobile considerations.
  4. Monitor Microsoft Purview Audit logs for Copilot Chat interactions on mobile devices to identify potential policy violations.

Domain: Intune · Impact: high · Workload: M365 Apps