Microsoft 365 app: Add Search results as references to your Copilot Notebooks in the M365 Copilot app

🚨 The Signal: Copilot Notebooks can now directly reference M365 Search results. This streamlines information gathering but increases the potential for sensitive data to be inadvertently included in AI-generated content, impacting data governance.

The Impact

All users are affected, increasing the risk of sensitive data exposure through Copilot Notebooks.

  • End Users: Increased risk of inadvertently including sensitive search results in shared notebooks.
  • Security Teams: New vector for data exfiltration or oversharing within the M365 ecosystem.
  • Data Governance Teams: Requires updated policies for Copilot Notebook content review and classification.

The Action

  1. Review and update existing data loss prevention (DLP) policies to include Copilot Notebooks as a sensitive information location.
  2. Communicate updated data handling guidelines to end-users regarding the inclusion of search results in Copilot Notebooks.
  3. Monitor Copilot usage reports for unusual activity related to data inclusion in notebooks.
  4. Educate users on responsible AI use and data sensitivity when leveraging Copilot Notebooks.

Domain: Agentic-AI · Impact: medium · Workload: M365 Apps