OneDrive: Improved capabilities for files with Copilot in OneDrive Web
🚨 The Signal: Copilot in OneDrive Web now offers enhanced capabilities to analyze files, summarize content, and generate outputs directly from chat. This streamlines content creation and collaboration, but increases the attack surface for data exfiltration and prompt injection.
The Impact
All users are affected, increasing the risk of sensitive data exposure and prompt injection attacks through Copilot's enhanced file access.
- End users: Increased risk of unintentional data sharing via Copilot outputs.
- Security Team: New vectors for prompt injection and data exfiltration require monitoring.
- Data Owners: Sensitive information in OneDrive files is now more accessible to Copilot, increasing exposure risk.
- Compliance Officers: Existing DLP policies may not adequately cover Copilot's new data interaction methods.
The Action
- Review and update Microsoft Purview Data Loss Prevention (DLP) policies to include Copilot for Microsoft 365 as a workload.
- Implement or refine Microsoft Purview Information Protection (MPIP) sensitivity labels for files stored in OneDrive.
- Educate users on responsible Copilot usage, data handling, and prompt engineering best practices to mitigate prompt injection risks.
- Monitor Microsoft 365 audit logs for Copilot activities and data sharing events related to OneDrive files.
- Evaluate and configure Copilot for Microsoft 365 access controls and data governance settings in the Microsoft 365 admin center.
Domain: Agentic-AI · Impact: high · Workload: OneDrive