Microsoft 365 Copilot: Import Executive Assistant data with People connectors
🚨 The Signal: Microsoft 365 Copilot can now ingest Executive Assistant data from HR systems via People connectors. This expands Copilot's ability to identify and connect users, increasing data exposure and potential for social engineering.
The Impact
Microsoft 365 administrators and users are affected by increased exposure of executive assistant data, raising social engineering risks.
- Administrators: Must review data ingestion policies for sensitive HR information.
- Users: Executive assistant contact details are more discoverable, increasing social engineering risk.
- Security Teams: Need to assess the expanded data surface for sensitive HR information.
- Copilot Users: Copilot can leverage this data, potentially revealing sensitive organizational structures.
The Action
- Review existing People connector configurations for Executive Assistant data ingestion: Microsoft 365 admin center > Settings > Org settings > People connectors.
- Assess the sensitivity of Executive Assistant data being ingested and its necessity for Copilot functionality.
- Implement or update data loss prevention (DLP) policies to protect sensitive HR data exposed via profile cards and Copilot.
- Educate users on the increased visibility of Executive Assistant roles and the risks of social engineering.
- Monitor Copilot usage logs for unusual queries related to Executive Assistant information.
Domain: Agentic-AI · Impact: high · Workload: Microsoft Purview