Microsoft Copilot (Microsoft M365): Delegated prompt publishing for organization prompts

🚨 The Signal: Admins can now delegate Copilot prompt publishing to users or groups, allowing them to create and manage organization-wide prompts without M365 Admin Center access. This decentralises prompt governance, increasing the attack surface for prompt injection.

The Impact

Delegated users can now manage Copilot prompts, increasing the risk of malicious or poorly formed prompts impacting all users.

  • Security Teams: Increased risk of prompt injection attacks due to broader prompt creation access.
  • Admins: New delegation model requires careful permission assignment and oversight to prevent misuse.
  • End Users: Potential exposure to misleading or harmful prompts if delegated publishers are not properly vetted.
  • Compliance Teams: New audit requirements for delegated prompt publishers to maintain regulatory adherence.

The Action

  1. Identify and document all users and groups currently assigned or intended for Copilot prompt delegation.
  2. Implement a robust approval workflow for all new or modified organization prompts, even from delegated publishers.
  3. Regularly audit delegated prompt publisher assignments and prompt content for adherence to security and policy guidelines.
  4. Educate delegated prompt publishers on secure prompt engineering principles and the risks of prompt injection.
  5. Review and update existing incident response plans to include scenarios involving malicious or compromised organization prompts.

Domain: Agentic-AI · Impact: high · Workload: Other · Essential Eight: Restrict Administrative Privileges, User Application Hardening · ISM: ISM-0445, ISM-1175, ISM-1380, ISM-1412, ISM-1485, ISM-1486, ISM-1507, ISM-1508, ISM-1509, ISM-1542, ISM-1585, ISM-1647, ISM-1648, ISM-1650, ISM-1667, ISM-1668, ISM-1669, ISM-1670, ISM-1686, ISM-1688, ISM-1689, ISM-1823, ISM-1824, ISM-1859, ISM-1860, ISM-1883, ISM-1897, ISM-1898