Microsoft Copilot (Microsoft 365): Review PDFs using the Copilot context menu on OneDrive iOS

🚨 The Signal: Copilot on OneDrive iOS now allows in-context PDF analysis, including summarization and custom questions. This expands AI-driven content interaction to mobile, increasing potential for data exposure and prompt injection risks on portable devices.

The Impact

All users interacting with PDFs on OneDrive iOS are affected, increasing the risk of sensitive data exposure and prompt injection.

  • End users: Increased risk of inadvertently exposing sensitive data via Copilot prompts.
  • Security teams: New mobile vector for prompt injection attacks and data exfiltration.
  • Admins: Need to review and update mobile data governance and Copilot usage policies.
  • Organisations: Potential for non-compliance with data handling regulations due to mobile AI access.

The Action

  1. Review and update Microsoft Purview Data Loss Prevention (DLP) policies to specifically address Copilot interactions with sensitive data on mobile devices.
  2. Implement or refine Microsoft Intune App Protection Policies (APP) for OneDrive iOS to restrict data transfer from Copilot-enabled PDFs.
  3. Educate end-users on secure prompting practices and the risks of sharing sensitive information with Copilot on mobile, emphasizing data classification.
  4. Monitor Microsoft 365 audit logs for unusual Copilot activity related to PDF interactions on iOS devices.
  5. Assess existing Conditional Access policies to ensure appropriate controls are in place for mobile access to Copilot and OneDrive.

Domain: Agentic-AI · Impact: high · Workload: OneDrive