Microsoft Copilot (Microsoft 365): Copilot memory in Researcher

🚨 The Signal: Copilot's Researcher feature now retains past interaction context, personalizing outputs and reducing setup. This increases the risk of sensitive data exposure if not properly governed, as Copilot can recall and reuse information from previous sessions.

The Impact

All users are affected by increased risk of sensitive data exposure through Copilot's memory recall.

  • End users: Risk of inadvertent disclosure of sensitive information through Copilot's memory.
  • Security teams: Increased surface area for data exfiltration and compliance breaches.
  • Compliance officers: New challenges in demonstrating adherence to data privacy regulations.
  • Administrators: Need to review and potentially update data governance policies for Copilot.

The Action

  1. Review and update Microsoft 365 data loss prevention (DLP) policies to include Copilot interactions and outputs.
  2. Educate users on responsible use of Copilot, emphasizing not to input highly sensitive or classified information.
  3. Implement sensitivity labels for documents and communications to restrict Copilot's access to classified data.
  4. Monitor Copilot usage logs for unusual data access patterns or potential policy violations.
  5. Evaluate Copilot's data retention settings within the Microsoft 365 admin center to align with organizational data lifecycle policies.

Domain: Agentic-AI · Impact: high · Workload: Other