In-app browsing in Copilot app

🚨 The Signal: Copilot app for Windows and Mac will support in-app browsing for links shared in chat. This feature, available for opt-in testing now, allows websites to open directly within the Copilot interface, potentially altering data handling and user interaction with web content.

The Impact

Admins and Security Teams are affected by new web content rendering within Copilot, increasing potential for malicious content exposure and data exfiltration.

  • Security Teams: Increased risk of malicious web content exposure via Copilot's in-app browser.
  • Admins: New configuration and policy considerations for managing web content within Copilot.
  • End Users: Potential for phishing or malware delivery through embedded browser if not properly secured.

The Action

  1. Review Microsoft documentation for managing Copilot in-app browsing settings.
  2. Implement device policies to control or disable in-app browsing for Copilot on Windows and Mac.
  3. Educate users on safe browsing practices, even within trusted applications like Copilot.
  4. Monitor network traffic and endpoint logs for suspicious activity originating from the Copilot application.

Domain: Agentic-AI · Impact: high · Workload: M365 Apps · Essential Eight: User Application Hardening · ISM: ISM-1412, ISM-1485, ISM-1486, ISM-1542, ISM-1585, ISM-1667, ISM-1668, ISM-1669, ISM-1670, ISM-1823, ISM-1824, ISM-1859, ISM-1860