Build apps in Microsoft Copilot Studio and Copilot Cowork
🚨 The Signal: New generative AI app-building in Copilot Studio and Cowork allows users to create apps from natural language. This expands the potential for rapid application development, increasing data exposure risks if not properly governed.
The Impact
Makers and administrators are affected by new app creation capabilities, increasing the risk of ungoverned data access and shadow IT.
- Makers: Can create apps easily, risking unintended data exposure.
- Administrators: Must govern a new influx of AI-generated applications.
- Security Team: Faces increased risk of shadow IT and data exfiltration via new apps.
The Action
- Review and update existing Power Platform DLP policies to encompass Copilot Studio and Cowork generated apps.
- Establish clear organizational policies for AI-generated application development and data access.
- Monitor the Microsoft 365 admin center for newly created apps and their data connectors.
- Communicate acceptable use policies for AI-assisted app creation to all users.
- Consider disabling the experience during preview if governance policies are not yet mature: Microsoft 365 admin center > Settings > Org settings > Copilot Cowork/Copilot Studio.
Domain: Agentic-AI · Impact: high · Workload: Other · Essential Eight: Application Control, Restrict Administrative Privileges · ISM: ISM-0445, ISM-0843, ISM-1175, ISM-1380, ISM-1490, ISM-1507, ISM-1508, ISM-1509, ISM-1544, ISM-1582, ISM-1647, ISM-1648, ISM-1650, ISM-1656, ISM-1657, ISM-1658, ISM-1659, ISM-1660, ISM-1686, ISM-1688, ISM-1689, ISM-1870, ISM-1871, ISM-1883, ISM-1897, ISM-1898